GDPR · Test and development

SAP GDPR compliance for test and development systems

GDPR covers personal data in every copy of production, not only production itself. SAP's privacy tools work where data is used; test, QA and sandbox copies of S/4HANA, SuccessFactors, Ariba and Concur still hold real names, bank details and employee records. Synthesized masks them with one policy, the same way in every system.

Not legal advice: your data protection officer decides what your test data needs. Auf Deutsch: Datenmaskierung

Personal data in non-production copiesExample
S/4HANA QA
Customers, vendors, employees
Masked
SuccessFactors preview
Employee and candidate records
Masked
Ariba test
Supplier contacts and bank details
Masked
Concur test
Travellers and expense receipts
In scope
One policy, and the same person gets the same pseudonym in every system.
One policy for every SAP app
Results measured in live deployments outside SAP
30%
faster testing and development cycles
Global bank · self-service test data
20bn
rows masked and subsetted in hours
Digital health platform · replaced a legacy TDM tool · Read the case study
28M
production rows protected, 100% referential integrity
Global specialty insurer · 40+ core applications · Read the case study
200×
more test data, from 100K to 20M entries
Telecom operator · masking and synthetic generation

On SAP, we measure results on your own data in a 10-day validation.

What GDPR asks

Four principles that reach your test systems

General Data Protection Regulation (EU) 2016/679

What applies to copies of production

Purpose limitation, Art. 5(1)(b): data collected to serve customers isn't collected for testing.

Data minimisation, Art. 5(1)(c): only the personal data a purpose needs, and tests rarely need real people.

Data protection by design and by default, Art. 25: build privacy into how systems are set up, test systems included.

Security of processing, Art. 32: pseudonymisation is named as one of the measures.

Paraphrased. Read the regulation for your own obligations.

Read the source: Regulation (EU) 2016/679 (GDPR) on EUR-Lex

Masked, pseudonymised or anonymous?

Anonymous data is outside GDPR
Data that can no longer identify anyone falls outside the regulation (Recital 26).
Pseudonymised data is still personal
Pseudonymised data can be linked back with extra information, so GDPR still applies (Art. 4(5)).
Your DPO decides
Which method counts as anonymous depends on the data and who can see it.

By SAP app

Where personal data sits, and what test copies miss

SAP appPersonal data in non-production copiesThe usual gap
S/4HANA and ECCKNA1, LFA1, BUT000, ADRC, HR infotypes such as PA0002, and custom Z-tablesSystem and client copies bring every record across as it is
SuccessFactorsEmployee Central and recruiting recordsInstance Refresh anonymizes a fixed list of fields. See SuccessFactors anonymization.
SAP AribaSupplier contacts, bank details and user dataTest realms are often loaded from the same supplier master data as S/4HANA. Mask it there, with the same pseudonyms. See procure-to-pay test data.
SAP ConcurTravellers, expense reports and receiptsTest entities hold whatever traveller and expense data is loaded or synced into them, often from the HR system

One policy

The same person masked the same way, in every SAP app

S/4HANA and ECCCustomers, vendors, employees
SuccessFactorsEmployee records
SAP AribaSupplier contacts, bank details
SAP ConcurTravellers, expense receipts
S/4HANA QAMasked, same pseudonyms
SuccessFactors testMasked, same pseudonyms
Ariba testMasked, same pseudonyms
Concur testMasked, same pseudonyms
SynthesizedOne masking policy for every SAP app, the same person masked the same way
Production
Test and development
One policy across SAP apps. A person masked in S/4HANA gets the same pseudonym in SuccessFactors, Ariba and Concur test systems.
DiscoveryFind itA scan flags personal data in standard tables, custom Z-tables and connected apps.
MaskingMask it onceOne set of rules for every SAP app, so a person keeps one pseudonym everywhere.
EvidenceShow itEach refresh records its scope, the rules applied and who ran it.

We've got you covered

Questions about SAP GDPR compliance in test systems

Does GDPR apply to SAP test systems?

Yes, whenever they hold personal data. A QA client copied from production holds the same customers, suppliers and employees as production, so the same rules apply to it.

Is pseudonymised SAP data still personal data?

Yes. Pseudonymised data can be linked back to a person with extra information, so GDPR still applies. Only data that can no longer identify anyone falls outside it.

Do SAP ILM or UI masking cover test copies?

They solve different problems. SAP ILM manages retention, blocking and deletion, and UI masking hides fields from users on screen. Neither changes the values stored in a test copy.

How do we handle Ariba and Concur test data?

With the same policy as S/4HANA: scan the test copy, mask the personal fields, and give each person the same pseudonym in every system so cross-app tests still work.

Does this help with CCPA and CPRA in the US?

Yes. California's privacy law treats deidentified data differently from personal information, and the same masking policy applies to US customer and employee data. Your privacy team decides what counts as deidentified.

Who signs off that our test data is compliant?

Your data protection officer. We provide the masking rules and the refresh records they need to decide.

Next step

See where personal data sits in your SAP test systems

A scan of one test system shows the personal data in standard and custom tables, and in the apps around them.

Runs in your environmentNothing installed in SAPRead-only access to SAPSecurity and deployment
Updated October 2026

SAP, S/4HANA, SAP HANA, SuccessFactors, Ariba, Concur and other SAP products and services mentioned herein, as well as their respective logos, are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. All other product and service names mentioned are the trademarks of their respective companies.