logo

Are you need IT Support Engineer? Free Consultant

GDPR-Compliant Business Partner Replication – Phase 1: Introducing Data Controller

  • By Sanjay
  • 03/08/2026
  • 23 Views



GDPR Meets Business Partner Replication 

GDPR requires that personal data is only processed by entities — and systems — that have a legal basis to do so. In SAP terms, a Business Partner's data should only be replicated to systems that are authorized to receive it. A connected system run by a different legal entity may have no right to receive a business partner’s name, address, or contact details. 

In an  landscape, Business Partner master data flows between systems via SOAP services. After the introduction of GDPR, Business Partner handles the requirements of GDPR via Data Controller and Purpose (DCP) framework, rolled out across three phases. This blog is the story of Phase 1. The blog is co-written by @Karunaharan.

The blog focuses only on GDPR-compliant data replication. For information about how to be compliant in the Business Partner apps, see  Data Controller and Purpose.

 

What Is a Data Controller? 

In GDPR terms, a Data Controller is the legal entity responsible for deciding why and how personal data must be processed. In SAP S/4HANA Cloud Public Edition, a Data Controller maps to the organizational unit responsible for doing business with a given Business Partner. For example, a company code. 

The DCP framework lets you declare: “This Business Partner is assigned with Data Controller X. Only systems authorized for Data Controller X may receive this business partner’s data.” 

Phase 1 introduced exactly this: the ability to assign a Data Controller to a Business Partner and use that assignment to govern SOAP-based replication. 

 

What Phase 1 Delivers 

1. Data Controller Assignment for Business Partners 

A Business Partner can be assigned with one or more Data Controllers. This assignment is the foundation of all DCP-based access control. 

  • For business partner of category person: required — personal data must always be protected under a responsible controller. 
  • For business partner of category organizations: optional — companies can opt out via the DataControllerIsNotRequiredIndicator field in the SOAP service if the organization is not a natural person and therefore there is no need to protect by default.

2. Outbound Filtering via DRF 

The Data Replication Framework (DRF) enforces Data Controller compliance during outbound replication. A new DRF Object Filter checks each Business Partner before it is sent: 

  • If the Business Partner has a Data Controller assignment, it is only replicated to target systems whose Communication Arrangement (SAP_COM_0008) is configured with a matching Data Controller. 
  • Business Partners with no Data Controller assignment (unprotected records) continue to replicate freely — backward compatibility is preserved. 

The filter also produces application log entries when Business Partners are withheld, so administrators can see exactly which records were filtered and why. 

3. Inbound Processing with Data Controller Preservation 

On the receiving side, inbound SOAP messages carry Data Controller information. The inbound processing: 

  • Maps Data Controller fields from the incoming SOAP message to the Business Partner. 
  • Validates that the incoming Data Controller is recognized in the target system. 
  • Preserves any existing Data Controller assignments already stored in the target that were not included in the incoming payload — preventing accidental data loss. 

4. Communication Arrangement SAP_COM_0008 — New “Data Controller” Property 

Each connected system is represented by a Communication Arrangement using the communication scenario SAP_COM_0008. Phase 1 extends this with a new field relevant for data controller in the Additional Property. 

When a Communication Arrangement is saved, the DRF configuration is updated automatically, so that DRF knows which Data Controllers are valid for each target system. 

 

How to Configure Phase 1 

Step 1: Activate the DCP Configuration 

Look out for the configuration activity “Manage Data Controller and Purpose Settings for Business Partner” (104809) and activate the configuration ID BP_DC_CTRLR. 

Step 2: Maintain Data Controllers 

Look out for the configuration activity “Maintain Data Controllers”. Each organization entity that acts as a legal Data Controller should be registered here. For example, company code or purchasing organization. 

Step 3: Configure Communication Arrangement 

For each connected system, open the Communication Arrangement created with the communication scenario SAP_COM_0008 and assign the relevant Data Controllers under the Additional Properties section. This tells DRF which Data Controllers the target system is authorized to receive. 

Navigate to the following path: 
Additional Property-> Data Controller and Purpose-> New Instance-> Data Controller Name.

Assign the relevant data controllers.

 

Step 4: Assign Data Controllers to Business Partners 

Assign the same Data Controllers to Business Partners via the Business Partner apps or via inbound SOAP replication from a source system that already carries the assignments. 

 

Backward Compatibility 

 Phase 1 is designed to be non-breaking for existing landscapes: 

  • Business Partners without any Data Controller assignment are treated as unprotected and replicate freely — no change from pre-DCP behavior. 
  • Target systems without a Data Controller configured in their Communication Arrangement will not receive DCP-protected Business Partners but will continue to receive unprotected ones. 
  • The DataControllerIsNotRequiredIndicator flag allows organizations to be explicitly excluded from DCP protection. 

 

How Replication Filtering Works 

Dcp Flow.png

 

 

Summary 

Phase 1 of the DCP framework brings GDPR-aware replication to Business Partner in SAP S/4HANA Cloud Public Edition. By introducing Data Controller assignments at the Business Partner level and enforcing them in both the DRF outbound filter and inbound processing, you ensure that personal data only reaches systems with the legal authority to process it. 

This is a foundational capability — and Phase 2 takes it further by introducing Purpose-based replication, enabling even finer-grained control over which data flows where, and why.





Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Chat with us on WhatsApp!