Privacy Risk Assessment Guide for Telecommunications, Information Technology, and Postal Service Providers

Introduction

According to the regulations of the Communications and Information Technology Commission, and to the Communications and Information Technology System issued by the Council of Ministers Decision No. (592) dated 1/11/1443 AH and its executive regulations, and based on the Commission's Decision No. (416) dated 12/9/1441 AH, which approved the procedures for launching services or products based on users' personal data or sharing personal data, the Commission has prepared the document "Guide for Privacy Risk Assessment for Providers of Communications and Information Technology Services."

This document aims to provide guidelines on the process of privacy risk assessment in services and products for providers of communications and information technology services, in order to clarify the privacy risk assessment process and what it fundamentally entails for service providers to meet the approved privacy requirements.

The privacy risk assessment process is the essential requirement expected from service providers when launching services or products based on users' personal data or sharing personal data, according to the document "Procedures for Launching Services or Products Based on Users' Personal Data or Sharing Personal Data." This guidance serves as a non-comprehensive reference, outlining the appropriate minimum to meet the requirements of relevant regulations concerning the implementation of the privacy risk assessment process.

The terms contained in this document are subject to the definitions provided in "Procedures for Launching Services or Products Based on Users' Personal Data or Sharing Personal Data."

Privacy Risk Assessment Process

The process of assessing privacy risks revolves around identifying potential risks when conducting operations involving the processing of personal data and preparing a mechanism to address and mitigate these risks. The process includes several aspects that are taken into consideration, including the risks of non-compliance with regulations or legislation related to privacy, the rights of personal data owners, and the potential negative impact on individuals or society in general.

  • It is worth noting that the process of assessing privacy risks is an ongoing process, where the assessment is continuously reviewed to ensure its relevance and comprehensiveness, taking into account all developments at every step, and reflecting them on the results of the assessment and the appropriateness of the decisions made regarding it. This includes ensuring the following:

    • 1. The relevance of information regarding the nature of the processing, its scope, purpose, and justifications, as well as the necessity and appropriateness of the processing.

    • 2. Coverage of all risks related to the processing mechanism associated with personal data.

    • 3. Compliance with the regulations and legislation issued by the authority or other entities related to privacy.

1.2. Determining the Need for Conducting a Privacy Risk Assessment

There is no need to conduct a complete privacy risk assessment according to the cases mentioned in the document "Criteria for Determining the Necessity of Conducting a Privacy Risk Assessment." 

In the absence of necessity, it is sufficient to specify the basic information such as the purpose, justification, and assessment of the necessity and proportionality concerning the scope and nature of the processing, and to mention the similar service, as outlined in the notice template provided in Annex (2) to be submitted to the authority.

Detailed Steps for Conducting a Privacy Risk Assessment

1.3. Purpose of Processing

  • The purpose of processing personal data is determined, which includes clarifying the interest achieved from executing processing operations and the expected benefit for data subjects and society as a whole. The responsible entity for determining the purpose varies as follows:

    •  The purpose is determined by the service provider in the following cases:

      • - Launching services or products based on personal data

      • - Sharing personal data with an entity that processes it on behalf of the service provider for its purposes.

  • While the purpose is determined by the entity requesting the data in the case of sharing personal data with an entity for purposes defined by that entity.

  • The entity that determines the purpose is the one that has an interest in processing the data, and it is primarily responsible for assessing privacy risks and meeting privacy requirements.

 

3.2. Legal Bases

The legal justification for processing the data is clarified, either by obtaining the consent of the data subject for the specified purpose, or by the existence of other legal bases exempted from consent.

3.3 Scope of Processing

  • The scope of the personal data to be processed, the scope of processing, and the assessment of the necessity for it, or its exclusion if it becomes clear that it is not needed, shall be determined; and among this, the following shall be specified: 

    • - The nature of the data subjects: for example: (age range, presence of sensitive categories such as persons with disabilities, or vulnerable individuals, or children)

    • - The systems related to the personal data and relied upon, whether those systems are (programs, networks, individuals, or others).

    • - The general nature of the personal data, for example: (digital, paper, aggregated, distributed).

    • - The volume of personal data: for example: (number of individuals, number of records, geographical scope). 

    • - The expected duration for processing the personal data.

    • - The pace and depth of the personal data processing operations.

4.3. Balancing the Necessity of Treatment and Its Proportionality to the Expected Benefit (Necessity and Proportionality)

The necessity of processing is evaluated to achieve the purpose and its relation to it, as well as its suitability with the anticipated benefit from the processing operations, taking into account its scope and nature, and studying other possible alternative methods to achieve the purpose without resorting to the processing of personal data.

Next section title

Next section content