The true colours of GDPR: How can we help?

07-12-2017 | 3 min read | Data Privacy, GDPR Compliance, SAP Data Management

GDPR is not just a regulation; it’s a business imperative. In an era where data drives every decision, customers and regulators expect businesses to handle personal information with responsibility, transparency, and care. For organisations running SAP systems, compliance can become complex at times. The vast amounts of data stored in the system make it difficult to keep track of what’s necessary, what’s outdated, and what could be putting your business at risk. In this blog, let’s understand how TJC Group can help organisations take control of their SAP data, reduce compliance risks and turn GDPR compliance into a strategic opportunity.

The General Data Protection Regulation (GDPR) is built around a simple yet powerful principle: Individuals should control their personal data. However, meeting compliance goes far beyond ticking checkboxes.

Fines for non-compliance can reach up to €20 million or 4% of your annual global turnover. However, remember that the real price is reputational. In a highly digitalised world, customer trust is fragile. A single breach or compliance failure can do lasting damage to your brand.

Beyond penalties, complying with GDPR signals to your customers, partners, and regulators that your organisation operates with transparency and accountability.

SAP systems are designed to handle complex business processes, but they are not necessarily equipped to manage data compliance with GDPR requirements. Consequently, they do not automatically:

  • Identify personal data across different modules
  • Track retention timelines by regulation
  • Provide ready-to-use audit trails for GDPR reviews

This is exactly where many businesses fall short, not because of negligence, but due to a lack of tools and transparency.

We address the two parts of SAP GDPR compliance: extracting information from the SAP system about a citizen in an acceptable format, and removing information from SAP systems.

For the second part, as archiving and ILM specialists, we support SAP’s vision of the deletion process. We believe some solutions currently on the market do not guarantee database integrity and put the SAP maintenance contract at risk. We believe that companies claiming they know the SAP process better than SAP seem like an overstatement beyond any reasonable doubt.

As data archiving specialists with a focus on ensuring audit-ready data, our position also raises a crucial question: How do you balance not over-deleting data while still meeting GDPR compliance?

Click on the banner below to learn everything about data archiving:

SAP Data Archiving: Everything you need to know

Our challenge will be to position ourselves on SAP only when the subject is largely involving personal information obtained via websites, for example. Here is an introductory video from SAP that discusses their recommended integration solution, which includes data archiving and deletion.

However, clients are seeking partners who can ensure full compliance with the General Data Protection Regulation. We would not want to implement a complete GDPR solution due to our commitment to audit-ready data and our simultaneous respect for GDPR. This is currently a very delicate and complex subject due to the different types of data and local retention policies.

What we can do now is to offer expertise (an assessment and evaluation) that can guarantee the success within the unique areas of archive and deletion in your SAP system for GDPR.

We believe that GDPR compliance, tax, and audit constraints must be taken into account together. We believe a reasonable vision of the GDPR requirements will emerge, and this approach will eventually align with the interests of European citizens and the feasibility of corporate and IT systems.

Needless to say, TJC Group is here with you now! Contact us!