DORA · Banks and insurers
Since January 2025, DORA's rules on ICT risk expect EU financial entities to keep only anonymised, pseudonymised or randomised production data in non-production environments. Real production data needs approval, a time limit and reporting. Synthesized masks SAP data before it reaches test, so that exception stays rare.
Not legal advice: check the requirement with your compliance team. Auf Deutsch lesen

On SAP, we measure results on your own data in a 10-day validation.
What it says
Non-production environments hold only anonymised, pseudonymised or randomised production data.
Production data is allowed only for specific testing occasions.
The integrity and confidentiality of data in non-production environments are protected.
Paraphrased from the regulation. Read the text for your own obligations.
Read the source: Commission Delegated Regulation (EU) 2024/1774 on EUR-Lex
In an SAP landscape
03Platform
A scan flags personal data in SAP tables and the systems around them, then masking replaces it with realistic values, the same way everywhere.

Choose company codes, date ranges or business objects, and the subset keeps every related record so tests still run end to end.

Generate customers, orders and edge cases for scenarios production doesn't contain yet, configured as code or in the UI.

How Synthesized helps
| What the rule expects | How Synthesized supports it |
|---|---|
| Only anonymised, pseudonymised or randomised data in non-production | SAP data is masked, or replaced with generated values, before it's written to the test system |
| Exceptions approved, time-limited and reported | Fewer exceptions to manage, because masked refreshes become the default |
| Integrity and confidentiality in non-production | The same replacement values across SAP and connected systems, so integration tests still pass |
| Showing what was done | A record of every refresh: scope, rules applied, time and who ran it |
Who it applies to
DORA covers banks, investment firms, insurers and reinsurers, payment and e-money institutions and other financial entities. If your finance, HR or customer processes run on SAP, the SAP test systems count.
We've got you covered

Under the RTS on ICT risk management, non-production environments should hold only anonymised, pseudonymised or randomised production data. Real production data is the exception: for specific testing occasions, time-limited, approved and reported to the ICT risk management function.

No. DORA's digital operational resilience testing, including threat-led penetration testing (TLPT), checks how your ICT systems hold up against incidents and attacks. This page is about the data inside non-production environments, which the RTS on ICT risk management covers.

The rule allows anonymised, pseudonymised or randomised data. Under GDPR, pseudonymised data is still personal data, so GDPR duties still apply to it.

The requirement covers your non-production environments wherever they run. See SuccessFactors anonymization.

We provide the refresh records and masking rules. Your compliance team decides what evidence the supervisor needs.
Next step
A scan of one SAP test system shows where production data sits today, in standard and custom tables.
SAP, S/4HANA, SAP HANA, SuccessFactors, Ariba, Concur and other SAP products and services mentioned herein, as well as their respective logos, are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. All other product and service names mentioned are the trademarks of their respective companies.