General Rules for the Protection of Personal Data Privacy

1- Introduction

In accordance with the regulations of the Communications and Information Technology Commission issued by the Council of Ministers Decision No. (74) dated 5/3/1422 H, and amended by the Council of Ministers Decision No. (133) dated 21/5/1424 H, which stipulates that the Commission shall undertake the tasks of information technology, and in reference to the Telecommunications Law issued by the Council of Ministers Decision No. (74) dated 5/3/1422 H, its amendments, and its executive regulations, and to the Council of Ministers Decision No. (403) dated 12/7/1440 H, which assigned the regulatory and supervisory tasks over the postal sector to the Communications and Information Technology Commission, and based on the Commission's role in protecting the personal data of users in the telecommunications, information technology, and postal sectors, the Commission has prepared the document titled "General Rules for Maintaining the Privacy of Users' Personal Data" in the telecommunications and information technology and postal sectors.

The document of the general rules for maintaining the privacy of users' personal data in both the telecommunications and information technology sector and the postal sector aims to achieve the following objectives:

  • - To maintain the privacy of users' personal data and protect their rights in accordance with the best global practices.

  • - To enhance the level of trust in telecommunications, information technology, and postal services that rely on the processing of users' personal data.

  • - To establish the principles and regulatory foundations that enable service providers to invest and innovate in services and applications that provide added value to users by utilizing personal data.

2- Definitions

The following words and terms shall have the meanings indicated for each, unless the context requires otherwise:

The Authority: Communications and Information Technology Commission.

Service Provider: Provider of telecommunications, information technology, or postal services in accordance with the Authority's regulations.

User: Natural Personality who uses any of the telecommunications, information technology, or postal services from the Service Provider.

Personal Data: Any information -regardless of its source or form- that can lead to the identification of the User specifically, or makes them identifiable directly or indirectly, including but not limited to names, personal identification numbers, addresses, contact numbers, license and registration numbers, personal property numbers, bank account numbers and credit card numbers, still or moving images of the User, and other data of a personal nature.

Processing of Personal Data: All operations performed on personal data by any means, whether manual or automated, including these operations -for example and not limited to- data collection, transmission, storage, sharing, destruction, analysis, pattern extraction, inference, and linking with other data.

Data Breach: The declaration, disclosure, publication, acquisition, or enabling access to personal data without a legal basis, whether intentionally or unintentionally.

3- General Provisions

1-3 These rules apply to all service providers, and the service provider must comply with the rules set forth in this document, and provide evidence of compliance through the mechanisms established by the Authority.

2-3 The service provider must periodically verify the compliance of all parties contracted to process users' personal data for purposes defined by the service provider, with the rules set forth in this document and provide evidence of that compliance through the mechanisms established by the Authority.

3-3 The service provider is prohibited from any practices that violate these rules, and in the event of a violation, the violations will be addressed in accordance with the Authority's regulations, and the service provider shall not be exempt from liability in the event of contracting with other parties.

4-3 These rules do not affect any regulatory document issued by the Authority or other relevant entities that provides a higher level of protection for the privacy of users' personal data.

4- Fundamental Principles for Protecting Users' Personal Data Privacy

The following fundamental principles must be observed when processing users' personal data:

1-4 Users' personal data must be processed in a lawful and transparent manner, and the results of processing users' personal data must be fair, ensuring that there is no unjustified negative impact on the users' interests.

2-4 Users' personal data must be processed for specific and clear purposes for the user.

3-4 Only the minimum amount of users' personal data necessary to achieve the purposes of data processing should be collected.

4-4 Users' personal data must not be retained in a form that allows identification of the data subjects for longer than is necessary to achieve the purposes of data processing.

5-4 Users' personal data must be protected in a manner that ensures its privacy and prevents unauthorized access, leakage, tampering, or misuse.

5- Obligations of Service Providers

1-5 The service provider is obligated to develop and implement a program to maintain the privacy of users' personal data, which includes the development, documentation, and implementation of policies and procedures related to the maintenance of users' personal data privacy and monitoring compliance with them. The program must be approved by the primary responsible person at the service provider or by an authorized delegate. The service provider is also obligated to submit the program plan to the authority for approval and to periodically report to the authority on the program's activities after its approval. The authority has the right to request any modifications it deems appropriate.

2-5 The service provider is obligated to assign the tasks and responsibilities of personal data privacy for users to an independent unit established for this purpose, providing it with the appropriate support to enable it to carry out its work while ensuring that there is no conflict of interest.

3-5 The service provider is obligated to develop, approve, and publish a policy for personal data privacy, which must include the types of users' personal data that will be processed, the purpose of such processing, whether it will be shared with other parties inside or outside the Kingdom, the retention period, protection measures, users' rights regarding their personal data, and how to exercise these rights.

4-5 The service provider is obligated to process users' personal data within the Kingdom, and it is not permitted to process it outside the Kingdom without obtaining written approval from the authority.

5-5 The service provider is obligated to retain users' personal data for specified purposes and durations, in accordance with the instructions issued by the authority.

6-5 The service provider is obligated to notify the authority immediately upon the occurrence of any personal data breach involving users, through the mechanisms and procedures established by the authority.

6- Users' Rights Regarding the Privacy of Their Personal Data

1-6 The processing of users' personal data shall not be permitted without their explicit consent, and users may withdraw their consent at any time, except as required by applicable laws, regulations, and related instructions.

2-6 Users must be enabled to review the personal data privacy policy before their personal data is processed.

3-6 Users must be enabled to access their personal data processed by the service provider at any time and to correct it in case of any incorrect or inaccurate data.

4-6 Users must be enabled to obtain a copy of their personal data in electronic format, in accordance with what is stipulated by the authority.