GDPR · Test and development
GDPR covers personal data in every copy of production, not only production itself. SAP's privacy tools work where data is used; test, QA and sandbox copies of S/4HANA, SuccessFactors, Ariba and Concur still hold real names, bank details and employee records. Synthesized masks them with one policy, the same way in every system.
Not legal advice: your data protection officer decides what your test data needs. Auf Deutsch: Datenmaskierung
On SAP, we measure results on your own data in a 10-day validation.
What GDPR asks
Purpose limitation, Art. 5(1)(b): data collected to serve customers isn't collected for testing.
Data minimisation, Art. 5(1)(c): only the personal data a purpose needs, and tests rarely need real people.
Data protection by design and by default, Art. 25: build privacy into how systems are set up, test systems included.
Security of processing, Art. 32: pseudonymisation is named as one of the measures.
Paraphrased. Read the regulation for your own obligations.
Read the source: Regulation (EU) 2016/679 (GDPR) on EUR-Lex
By SAP app
| SAP app | Personal data in non-production copies | The usual gap |
|---|---|---|
| S/4HANA and ECC | KNA1, LFA1, BUT000, ADRC, HR infotypes such as PA0002, and custom Z-tables | System and client copies bring every record across as it is |
| SuccessFactors | Employee Central and recruiting records | Instance Refresh anonymizes a fixed list of fields. See SuccessFactors anonymization. |
| SAP Ariba | Supplier contacts, bank details and user data | Test realms are often loaded from the same supplier master data as S/4HANA. Mask it there, with the same pseudonyms. See procure-to-pay test data. |
| SAP Concur | Travellers, expense reports and receipts | Test entities hold whatever traveller and expense data is loaded or synced into them, often from the HR system |
One policy
We've got you covered

Yes, whenever they hold personal data. A QA client copied from production holds the same customers, suppliers and employees as production, so the same rules apply to it.

Yes. Pseudonymised data can be linked back to a person with extra information, so GDPR still applies. Only data that can no longer identify anyone falls outside it.

They solve different problems. SAP ILM manages retention, blocking and deletion, and UI masking hides fields from users on screen. Neither changes the values stored in a test copy.

With the same policy as S/4HANA: scan the test copy, mask the personal fields, and give each person the same pseudonym in every system so cross-app tests still work.

Yes. California's privacy law treats deidentified data differently from personal information, and the same masking policy applies to US customer and employee data. Your privacy team decides what counts as deidentified.

Your data protection officer. We provide the masking rules and the refresh records they need to decide.
Next step
A scan of one test system shows the personal data in standard and custom tables, and in the apps around them.
SAP, S/4HANA, SAP HANA, SuccessFactors, Ariba, Concur and other SAP products and services mentioned herein, as well as their respective logos, are trademarks or registered trademarks of SAP SE (or an SAP affiliate company) in Germany and other countries. All other product and service names mentioned are the trademarks of their respective companies.