Play video
Good day, I'm James Watson, I'm the line of business owner for our privacy solutions here at EPI-USE Labs. Throughout the world, we're now seeing a large uptake in new privacy laws. Obviously GDPR is the most commonly understood regulation out there. There are currently, as we stand in 2023, an additional seven US states that have issued their own privacy laws. We have the PDPA over in Asia covering Singapore and Thailand. There is also New Zealand Australia is moving forward, and it does look like there will be a federal law within the United States at some point this year or next. So the privacy problem for clients is becoming quite a large issue, and we've spent years on the assumption that more data is more value. And being able to capture all of the information about your consumers within your industry allows you to better market, allows you to better cycle through, and sell and ultimately improve your business. Unfortunately, now the new privacy laws mean that that data that's been captured is our liability. And it requires a direct approach to be able to manage retention periods, the actual removal of data, potentially archiving. There is a number of different items that you may need to address. At EPI-USE Labs, we've got professional services consultants that are experienced in delivering this project. We have unique technology, which is based on an engine that's existed for more than twenty years dealing with SAP Data Management. And now we can bring that to bear within our privacy solutions where we have Data Disclose, Data Redact, Data Retain, dealing with the production data, and also Data Secure that allows you to consistently anonymize your non production system. So between our professional services and IP team, we can provide you a with full solution for your privacy needs under these regulations, whether that is the US, GDPR or PDPA. They all have the same base understandings of a legal retention period for the data that you hold in your systems.
이 비디오에는 한국어 자막이 있습니다
icons__Data_disclose_icons 657
GDPR과 같은 글로벌 개인정보 보호 법규 준수
icons__Data_disclose_icons 653
SAP 비운영(non-production) 환경에서 민감한 데이터를 스크램블
icons__Data_disclose_icons 654
SAP 환경 전반에서 특정 주체의 데이터 흔적을 즉시 검색하여, 해당 데이터를 신속하게 식별·조회·제공
icons__Data_disclose_icons 655
참조 무결성에 영향을 주지 않고 필드 데이터를 신속하고 원활하게 삭제(redact)
icons__Data_disclose_icons 656
유연한 규칙을 기반으로 삭제 대상 데이터 주체를 사전에 탐지

글로벌 프라이버시 환경은 현대 사회에서 데이터 사용과 공유 방식에 따라 빠르게 변화하고 있습니다. 최신(및 향후) 개인정보 보호 법안/규정 전반에는 다음과 같은 공통된 규칙이 포함됩니다:

  • 보유 중인 정보에 대한 데이터 주체의 열람권
  • 보유 데이터의 삭제 및/또는 정정을 요청할 권리
  • 개인식별정보(PII)의 사전적·적극적 관리 필요성
  • 데이터 활용 방식에 대한 데이터 주체의 명시적·사전 동의

이러한 변화는 SAP와 같은 대규모 ERP 플랫폼을 사용하는 모든 기업에게 복잡할 수밖에 없습니다. 이는 ERP 솔루션이 통합된 데이터 모델을 기반으로 설계되어 있기 때문입니다. SAP 데이터 모델 전문가로서, 당사는 데이터 프라이버시 준수에 필요한 핵심적 문제를 해결하는 맞춤형 솔루션을 제공합니다.

global_privacy_laws_map_animation_KOREAN_website_loop_15_12_25_001_iteration_2

 

2025년 12월 기준

Play video
The first challenge that most businesses face from a privacy point of view is actually understanding how much of the risk they're holding within their data. Most industries have spent, fifteen, twenty years customizing an SAP environment, making it correct for their business process, with no consideration as to how much data they're then proliferating into additional tables. So actually then understanding and mapping that data is quite a large challenge especially because the people that built them have likely retired, moved on, and gone through natural attrition. So it does create quite a large business challenge, and to be able to build your business case for an investment in a privacy solution you first need to know how much risk you are mitigating to be able to follow it through. So to help with that, EPI-USE Labs have utilized our data model mapping that we've been using for the last twenty years to manage SAP data to build a discovery program. Now unlike some of the other competitors on the market, EPI-USE Labs are utilizing SAP domain knowledge that we've built to understand the data dictionary within your system, and we're able to complete a key search of the data elements within that environment based on the list of PII data items that we've already identified. The output list is then validated against whether the data is actually populated because, of course, just because it's in the system doesn't mean you've actually populated it. And we'll then go through a workshop and detailed analysis process with one of our professional services consultants where we will analyze and understand how we can integrate that data back to a data subject for a customer, a vendor or an employee, but also understand what values are maintained and map out that PII challenge for your SAP system. We collect all that information into a single document that has both the business functional requirements from the workshop, as to what retention periods you would like and how data should be affected based on those retention periods - so whether it should be cleared or transformed to a new value, and the same for non-production, for a system copy that you're going to use for testing, you need to have the real data from Production to improve your DevOps process. But you can't have the real data because that is a PII risk, and you would have to have informed and explicit consent from every data subject in your environment to use that data as testing, and no company has entered those clauses into a contract so far to be able to say they're ready. So with that documentation, you have the business requirements of how data should be transformed and then also the technical specification of exactly which tables and fields grouped according to data type to be able to understand where the names, where the telephone numbers, where the bank details exist within the environment. Additionally we now have an enhanced discovery working with one of our strategic partners Soterion. They offer GRC solutions as an alternative to SAP GRC. They have pre-delivered rule sets that are able to analyse your segregation of duties risk. They also have specific rule-sets to review your access to privacy data, to be able to understand who can actually see sensitive data within your SAP system. We also have queries to be able to understand where there's cross legal jurisdictional access. So where somebody from the US is able to access European employee data or vice-versa. Through that analysis, we're able to provide a clear risk assessment of both the access to sensitive data, and where that data is within your environment. Both of these options come as a license free, there is no license cost upfront, there is some professional services cost for around about one and a half to two weeks elapsed time, so in a very short turnaround period we're able to provide you this documentation, which we've seen from some of our clients is being used as audit evidence and passed through to their auditors to be able to help them understand your data model and how you're compliant to the laws. So the data discovery and enhanced data discovery are available from your Account Executives, and we would be happy to discuss them with you. As well as the output of the document, we will also then give you a fixed price, fixed scope implementation cost if you were to choose EPI-USE Labs as your privacy partner to be able to manage that data moving forward.
이 비디오에는 한국어 자막이 있습니다

민감한 SAP 데이터를 탐지·매핑하고 액세스 리스크 벤치마킹

EPI-USE Labs의 SAP 데이터 프라이버시 진단보고서 서비스를 통해 귀사의 개인식별정보(PII)를 이해·식별·매핑하십시오.

SAP 솔루션용 Data Privacy Suite

SAP 솔루션용 Data Privacy Suite는 업계 선도 제품인 Data Sync Manager™ Suite를 기반으로 하며, SAP 환경에 대한 의미 기반 이해와 데이터 서브세팅 및 보안 규칙 기반 마스킹 기능을 제공합니다.
Data Secure, Data Disclose, Data Redact, Data Retain은 기존 기술과 지적 자산을 기반으로 구축되어 PIPA, GDPR, CCPA, POPIA 등 글로벌 개인정보 보호 법규 준수를 지원합니다.

Play video
Data_Secure_KR_V2
Data_Disclose_KR_V2
Data_Redact_KR_V2
Data_Retain_KR_V2

SAP에서 개인정보 보호 법규를 준수하는 방법

SAP는 세계에서 가장 견고한 시스템 중 하나이지만 동시에 가장 복잡한 시스템 중 하나입니다. 수십 년 동안 SAP는 다양한 구성 요소와 솔루션을 인수·통합해 왔으며, 이러한 구조는 데이터 프라이버시 컴플라이언스를 매우 까다롭게 만듭니다. 여러 SAP 객체 및 시스템 간의 교차 기능적 통합을 이해하고 매핑하려면 상세한 도메인 지식이 필요합니다.

EPI-USE Labs는 30년 이상 SAP 파트너로 활동하며 SAP 데이터 구조에 대한 깊은 이해를 보유하고 있습니다. SAP의 다양한 버전 및 특성, 활용 방식에 대한 지식을 축적했으며, 필드 단위부터 시스템 간까지 정교한 무결성 매핑을 구축했습니다. 2000년 이후 우리는 고객의 비운영 데이터 스크램블링을 통해 개인정보 보호 법규 준수를 지원해 왔으며, 운영(Production) 환경의 데이터 비식별화 역시 Data Redact 기술로 지원합니다.

SAP 솔루션용 Data Privacy Suite는 업계 선도 기술인 Data Sync Manager™ Suite 기반이며, ‘Integration with RISE with SAP S/4HANA Cloud’ SAP 인증을 받았습니다. Global Professional Services 팀은 CISSP, CIPPT, CIPPM 자격을 보유하고 있으며, 전 세계 다양한 국가와 산업의 프로젝트 경험을 바탕으로 귀사의 데이터 프라이버시 과제 해결을 위한 전문적인 인사이트를 제공합니다.

지금, 귀사의 데이터 현황을 진단해 보세요.

SAP_Certi_Integration_RISE_w_SAP_S4HANACloud_R

고객 성공 사례 확인

데이터 개인정보 보호 법규를 준수할 수 있는 방법 알아보기

DSM-assessment
SAP 데이터 프라이버시 진단 서비스 예약

SAP 데이터 프라이버시 진단 서비스를 통해 민감한 데이터 노출 위험을 최소화하고, 데이터 보안을 관리하며, 글로벌 개인정보 보호 법규를 준수하세요.

DSM-assessment
데이터 보안 블로그 글

전 세계 최대 규모의 기업, 대학 및 컨설팅 회사와 수십 년간 함께 일해 온 데이터 보안 전문가들의 인사이트를 제공하며, SAP 솔루션에 특히 중점을 둡니다.

DSM-FAQ
질문 답변 살펴보기

DSM과 그 활용 방법에 대해 궁금한 점이 있으신가요? 다른 고객들이 자주 묻는 질문에 대한 답변을 살펴보세요.

문의하기

개인정보 보호 법규 준수: SAP 솔루션을 위한 Data Privacy Suite