Meet the Authors

Key Takeaways What you need to know
  1. OneTrust has introduced purpose-built connectors for SAP HANA, SAP Sybase, and SAP Gigya, simplifying data subject request handling and consent management within SAP environments.

  2. These integrations allow SAP customers to service data subject access requests, classify personal data, and manage consent without building native logic for each SAP system.

  3. The solutions provide a consistent privacy mechanism across varying SAP data landscapes, ensuring compliance with regulations like CCPA and GDPR and supporting continuous data inventory.

OneTrust has built direct integrations across multiple layers of the SAP ecosystem, connecting products from its privacy and consent platform to SAP HANA, SAP Sybase, and SAP Gigya. The integrations, developed by OneTrust, give SAP customers a consistent way to service data subject access requests, discover and classify personal data, and manage consent signals without building that logic natively into each SAP system.

Closing the Privacy Rights Gap Across SAP HANA and SAP Sybase

SAP HANA and SAP Sybase sit at different points in a typical SAP data landscape, yet OneTrust applies the same privacy mechanism to both. OneTrust Privacy Rights Automation integrates with each database to access stored information and service data subject access requests, helping organizations comply with regulations such as CCPA and GDPR. OneTrust DataDiscovery also lets customers discover, classify, and govern data residing within either database, while OneTrust Data Mapping Automation maintains what the company describes as an evergreen inventory of that data. Both integrations were developed by OneTrust.

Many enterprises continue to run SAP Sybase, a legacy database and middleware platform, alongside newer SAP HANA deployments, resulting in a mixed data landscape across SAP systems. Locating personal data quickly across that landscape complicates data subject access requests, since a request touching customer records may require pulling information from an in-memory analytics platform and an older transactional database at the same time. GDPR and CCPA both set defined response windows for data subject access requests, so the operational burden of searching across differing SAP database technologies falls on privacy and data teams working against a fixed clock. Applying the same Privacy Rights Automation and DataDiscovery mechanism to both platforms gives those teams one integration pattern to manage across both database generations.

Explore related questions

The evergreen inventory model, maintained through Data Mapping Automation, keeps data discovery ongoing instead of treating it as a one-time exercise ahead of a regulatory deadline. The integration is built to keep the inventory current as data in SAP HANA or SAP Sybase changes. Organizations managing both platforms benefit from that continuous approach, which reduces the risk that a request arrives before the underlying data map is updated.

Extending Consent and Preference Management Into SAP Customer Experience

Where the HANA and Sybase integrations address data at rest, the OneTrust integration with SAP Gigya addresses consent at the point of customer interaction. Gigya’s customer identity and access management and consent management capabilities are now part of the SAP Customer Experience portfolio, following SAP’s acquisition of the platform. OneTrust Consent and Preference Management integrates with Gigya to capture consent and preference data and use it to drive marketing segmentation based on what a customer has actually agreed to. OneTrust developed this integration as well.

Folding CIAM and consent management into the SAP Customer Experience suite made consent handling a standard consideration for organizations implementing SAP marketing and commerce tools. Personalization and segmentation workflows built on that suite depend on knowing which consent and preference signals a customer has actually given, since segmentation built on stale or unverified consent data risks running counter to the regulations it is meant to satisfy. The OneTrust integration positions consent capture as an input to segmentation itself, connecting what a customer has agreed to with how that customer is subsequently marketed to within the SAP environment.

Taken together with the HANA and Sybase integrations, the Gigya connection extends OneTrust’s presence from the SAP data platform layer into the SAP customer experience layer. A SAP customer running HANA or Sybase for transactional data and Gigya for identity and consent now has a documented integration path for privacy rights and data governance on one side and consent activation on the other, built by the same vendor across both.

What This Means for SAPinsiders

  • Mixed SAP database estates complicate DSAR response. Teams running both SAP HANA and SAP Sybase must coordinate discovery and fulfillment across two distinct database technologies to meet regulatory deadlines. A single integration pattern across both platforms reduces the number of separate processes a privacy team must maintain.
  • Consent management is now a CX buying criterion. Organizations evaluating SAP Customer Experience or Gigya deployments need to treat consent and preference integration as a core requirement rather than a later addition. Segmentation strategies built on unverified consent signals carry compliance risk that surfaces after launch.
  • Privacy tooling must span legacy and current SAP stacks. Governance teams need integration coverage across both current platforms like SAP HANA and legacy systems like SAP Sybase, not just the newest deployment. Maintaining an evergreen data inventory across both reduces the chance a request outpaces the map.

Events

29Oct
SAPinsider Summit New Orleans 2026New Orleans, Louisiana, United States
View All