Implementing Regulation of the Personal Data Protection Law

Article 1: Definitions

  • The terms and phrases used in this Regulation shall have the meanings assigned to them in Article (1) of the Personal Data Protection Law issued by Royal Decree No. (M/19) dated 9/2/1443H and amended by Royal Decree No. (M/148) dated 5/9/1444 AH.

  • The following terms and phrases - wherever used in this Regulation - shall have the meanings assigned to them, unless the context requires otherwise:

    • 1. Regulation: The Implementing Regulation of the Law.

    • 2. Direct Marketing: Communicate with the Data Subject by any direct physical or electronic means with the aim of directing marketing material, this includes but is not limited to advertisements or promotions.

    • 3. Personal Data Breach: Any incident that leads to the Disclosure, Destruction, or unauthorized access to Personal Data, whether intentional or accidental, and by any means, whether automated or manual.

    • 4. Vital Interest: Any interest necessary to preserve the life of a Data Subject.

    • 5. Actual Interest: refers to any moral or material interest of the Data Subject that is directly linked to the purpose of Processing Personal Data, and the Processing is necessary to achieve that interest.

    • 6. Legitimate Interest: refers to any necessary interest of the Controller that requires the Processing of Personal Data for a specific purpose, provided it does not adversely affect the rights and interests of the data subject.

    • 7. Pseudonymisation: Conversion of the main identifiers that indicate the identity of the Data Subject into codes that make it difficult to directly identify them without using additional data or information. Such additional data or information should be kept separately, and appropriate technical and administrative controls should be implemented to ensure that they are not specifically linked to data subject's identity.

    • 8. Anonymization: Removal of direct and indirect identifiers that indicate the identity of the Data Subject in a way that permanently makes it impossible to identify the Data Subject.

    • 9. Explicit Consent: Direct and explicit consent given by the Data Subject in any form that clearly indicates the Data Subject's acceptance of the Processing of their Personal Data in a manner that cannot be interpreted otherwise, and whose obtention can be proven.

Article 2: Personal or family use

  • 1- The provisions of the Law and its Regulations shall not apply to an individual Processing Personal Data for purposes not exceeding personal or family use.

  • 2- Personal or family use, as referred to in Article 2 of the Law, means that an individual Processing Personal Data within their family or limited social circle as part of any social or family activity.

  • 3- The following shall not be considered personal or family use:

    • a) An individual publishing Personal Data to the public or disclosing it to any person outside the scope specified in paragraph (2) of this article.

    • b) Using Personal Data for professional, commercial, or non-profit purposes.

Article 3: General provisions for Data Subject Rights

  • 1- The Controller shall, upon receiving a request from the Data Subject regarding their rights as stipulated in the Law, do the following:

    • a) Act on the request of the Data Subject for exercising their rights under the Law within a period not exceeding (30) days and without delay. This period may be extended in case the implementation requires disproportionate effort, or if the Controller receives multiple requests from the data subject, provided that the extension period does not exceed an additional (30) days and the Data Subject is notified in advance of the extension with the reasons for the delay.

    • b) Take the necessary technical, administrative, and organizational measures to ensure a prompt response to requests related to exercising rights.

    • c) Take appropriate measures to verify the identity of the requester before executing the request in accordance with relevant legal requirements.

    • d) Take the necessary measures to document and keep record of all received requests including oral requests.

    • 2- The Controller may refuse to act on request when it is repetitive, manifestly unfounded, or requires disproportionate efforts, in which the Data Subject shall be notified of such reason.

  • 3- In cases where the Data Subject fully or partially lacks legal capacity, their legal guardian shall exercise their rights on their behalf.

Article 4: Right to be informed

  • 1- If the Personal Data is collected directly from the Data Subject, the Controller shall, before or when collecting the Data, take the necessary measures to inform the Data Subject of the following:

    • a) Controller’s identity, its contact details, and any other details related to the channels established by the Controller for the purpose of communicating in relation with Personal Data protection.

    • b) Contact details of the data protection officer appointed by the Controller, where applicable.

    • c) The legal basis and a specific, clear, and explicit purpose for collecting and Processing Personal Data.

    • d) The period for which the Personal Data will be stored, or if that is not possible, the criteria used to determine that period.

    • e) Explanation about Data Subject’s rights, as stipulated in Article (4) of the Law and the mechanisms for exercising those rights.

    • f) Explanation on how to withdraw consent given to process of any Personal Data.

    • g) Explaining whether collecting or Processing Personal Data is mandatory or optional.

  • 2- Paragraph (1) of this article shall not apply if the information specified in subparagraphs (a) to (g) is already available to the Data Subject, or if providing such information conflicts with any of the existing laws in the Kingdom.

  • 3- If Personal Data is collected from a party other than the Data Subject, the Controller shall, without undue delay and within a period not exceeding (30) days, take necessary steps to provide to the Data Subject information specified in paragraph (1) of this article, in addition to the categories of Personal Data being processed and the source from which the Controller obtained it.

  • 4- Paragraph (3) of this article shall not apply in any of the following conditions if:

    • a) The information is already available to the Data Subject.

    • b) the provision of such information proves impossible or would involve a disproportionate effort.

    • c) The Controller collects data to fulfil a legal requirement.

    • d) The Controller is a Public Entity and the Collection of Personal Data is for security purposes, or to fulfil judicial requirements, or to achieve a Public Interest.

    • e) The Personal Data is subject to an obligation to a professional secrecy regulated by a law.

  • 5- A Controller whose activities require continuous or large scale Processing of Personal Data on individuals lacking full or partial legal capacity or whose parents are unknown, continuous monitoring of Data Subjects, adoption of new technologies, or making automated decisions based on Personal Data, shall take the necessary measures to inform the Data Subject of what is stipulated in paragraph (1) of this Article, in addition to the following:

    • a) Means and methods of collecting and Processing Sensitive Data, where applicable.

    • b) Means and procedures taken to protect Personal Data.

    • c) Indicate whether decisions will be made based solely on automated Processing of Personal Data.

  • 6- When the Controller engages in an additional Processing of Personal Data for a purpose other than the one for which it was initially collected for, it shall provide the Data Subject with the necessary information in accordance with the provisions of this article, before conducting such additional Processing.

  • 7- The Controller shall provide the required information in an appropriate language as stipulated in this Article when aware that the Data Subject lacks full or partial legal capacity.

Article 5: Right of access to Personal Data

  • 1- Without prejudice to the provisions of Articles (9) and (16) of the Law, the Data Subject shall have the right to access their Personal Data at the disposal of the Controller, subject to the following:

    • a) Exercising the right to access Personal Data shall not adversely affect the rights of others, such as intellectual property rights or trade secrets.

    • b) Accessing to Personal Data at a request from the Data Subject, or via a channel provided by the Controller to the Data Subject allowing direct access to their Personal Data without the need to make a request.

  • 2- When granting the Data Subject access their Personal Data, the Controller shall ensure that no Personal Data identifying another individual is not disclosed.

Article 6: Right to Request Access to Personal Data

  • Subject to the provisions of Article (4) of the Law, the Data Subject shall have the right to request a copy of their Personal Data in a readable and clear format, subject to the following:

    • 1- Exercising the right to access Personal Data shall not adversely affect the rights of others, such as intellectual property rights or trade secrets.

    • 2- Personal Data shall be provided to the Data Subject in a commonly used electronic format and the Data Subject may request a printed hard copy if feasible.

    • 3- When granting a Data Subject access to their Personal Data, the Controller shall ensure that it does not involve disclosing Personal Data that identifies another individual.

Article 7: Right to Request Correction of Personal Data

  • 1- Data Subject shall have the right to obtain from the Controller a restriction of Processing when the accuracy of the Personal Data is contested by the Data Subject, for a period enabling the Controller to verify the accuracy of the Personal Data. The aforementioned restriction shall not apply if providing such data contravenes provisions of the Law and this Regulation.

  • 2- Controller may request needed supporting documents or evidence to verify in order to update, correct, or complete the Personal Data, provided that such documents or evidence are destroyed once the verification process is completed.

  • 3- Upon correcting Personal Data, the Controller shall notify without undue delay the parties to whom Personal Data have been previously disclosed.

Article 8: Right to Request Destruction of Personal Data

  • 1- The Controller shall destroy Personal Data in any of the following cases:

    • a) Upon Data Subject's request.

    • b) If the Personal Data are no longer necessary to achieve the purpose for which they were collected.

    • c) If the Data Subject withdraws their consent, and consent is the sole legal basis for Processing.

    • d) If the Controller becomes aware that the Personal Data have been unlawfully processed.

  • 2- When destroying Personal Data, the Controller shall take the following steps:

    • a) Take appropriate measures to notify other parties to whom the Controller has disclosed such Personal Data and request their Destruction.

    • b) Take the appropriate measures to notify the individuals to whom the Personal Data have been disclosed by any means and request their Destruction.

    • c) Destroy all copies of the Personal Data stored in the Controller's systems, including backups, in accordance with relevant regulatory requirements.

  • 3- The provisions of this article shall not prejudice the requirements specified in Article 18 of the Law and the legal requirements established by the relevant Competent Authorities.

Article 9: Anonymisation

  • 1- When a Controller anonymizes the Personal Data of a Data Subject, it shall comply with the following:

    • a) Ensure that re-identification of the Data Subject is impossible after Anonymisation.

    • b) Evaluate the impact, including the possibility of re-identifying the Data Subject, in the circumstances specified in Paragraph (1) of Article 25 of this Regulation.

    • c) Take the necessary organizational, administrative, and technical measures to avoid risks, taking into account technological developments and methods of Anonymisation, and update those methods considering such developments.

    • d) Evaluate the effectiveness of the applied techniques for Personal Data Anonymization and make necessary adjustments to ensure that re-identification of Data Subject is impossible.

  • 2- Anonymized data shall no longer be considered as Personal Data.

Article 10: Means of Communication

  • The Controller is required to provide appropriate means to process requests related to Data Subject rights as stipulated in the Law. The Data Subject shall have the choice to use one or many among the following means according to their preference considering options made available by the Controller:

    • 1- E-mail.

    • 2- Text messages.

    • 3- The national address.

    • 4- Communication via electronic applications.

    • 5- Any other lawful communication mean provided by the Controller for this purpose.

Next section title

Next section content