Royal Decree No. (M/106) dated 1443/11/2 AH
By the grace of God Almighty
We, Salman bin Abdulaziz Al Saud
King of the Kingdom of Saudi Arabia
Based onArticle (Seventy) of the Basic Law of Governanceissued by Royal Order No. (A/90) dated 27/8/1412 AH.
And based onArticle (Twenty) of the Council of Ministers Lawissued by Royal Order No. (A/13) dated 3/3/1414 AH.
And based onArticle (Eighteen) of the Shura Council Lawissued by Royal Order No. (A/91) dated 27/8/1412 AH.
After reviewing Shura Council Decision No. (16/85) dated 16/5/1443 AH.
After reviewing Council of Ministers Decision No. (592) dated 1/11/1443 AH.
We decree the following:
First:Approval of the Communications and Information Technology Law, in the attached form.
Second:The provisions of the law - referred to in item (First) of this decree - shall not affect the validity of licenses issued before its implementation, and anyone providing communications or information technology services at the time of the law’s implementation must regularize their status in accordance with its provisions within twelve (12) months from the date of its implementation.
Third:The application of the law - referred to in item (First) of this decree - and its executive regulations shall not prejudice the powers and tasks of the National Cybersecurity Authority.
Fourth:The Communications and Information Technology Commission shall monitor the service provider’s commitment to exercising due diligence to ensure the protection of cybersecurity and critical infrastructure, in accordance with what is issued by the National Cybersecurity Authority, and it shall have the following powers in this regard:
A- Obliging service providers to conclude agreements among themselves to achieve this in accordance with what is issued by the National Cybersecurity Authority. B- Monitoring the cybersecurity level of the service provider to verify its adequacy, in accordance with what is issued by the National Cybersecurity Authority. C- Charging the service provider the cost of this monitoring in case of proven negligence. D- Imposing the penalties stipulated in Article (Twenty-Seven) of the law - referred to in item (First) of this decree - on the service provider violating the provisions of this item.
The Board of Directors of the National Cybersecurity Authority shall have the authority to decide to terminate the application of this item after coordination with the Communications and Information Technology Commission.
Fifth:His Highness the Deputy Prime Minister, the Ministers, and the heads of the concerned independent bodies - each within their jurisdiction - shall implement this decree.
Salman bin Abdulaziz Al Saud
In the name of God, the Most Gracious, the Most Merciful
Council of Ministers Decision No. (592) dated 1443/11/1 AH
The Council of Ministers
After reviewingthe correspondence received from the Royal Court No. 32021 dated 22/5/1443 AH, including the telegram of His Excellency the Minister of Communications and Information Technology No. 01/40/5118 dated 18/9/1440 AH, regarding the draft Communications and Information Technology Law.
After reviewingthe aforementioned draft law.
After reviewingtheCommunications Lawissued by Royal Decree No. (M/12) dated 12/3/1422 AH.
After reviewingmemorandums No. (1157) dated 11/7/1442 AH, No. (1955) dated 11/11/1442 AH, No. (2273) dated 18/12/1442 AH, No. (359) dated 12/2/1443 AH, and No. (2192) dated 24/9/1443 AH, prepared by the Bureau of Experts at the Council of Ministers.
After reviewingthe recommendation prepared by the Council of Economic and Development Affairs No. (12 - 46/43/D) dated 11/10/1443 AH.
After consideringShura Council Decision No. (85/16) dated 16/5/1443 AH.
After reviewingthe recommendation of the General Committee of the Council of Ministers No. (9465) dated 29/10/1443 AH.
It is decided as follows:
First:Approval of the Communications and Information Technology Law, in the attached form.
Second:The provisions of the law - referred to in item (First) of this decision - shall not affect the validity of licenses issued before its implementation, and anyone providing communications or information technology services at the time of the law’s implementation must regularize their status in accordance with its provisions within twelve (12) months from the date of its implementation.
Third:The application of the law - referred to in item (First) of this decision - and its executive regulations shall not prejudice the powers and tasks of the National Cybersecurity Authority.
Fourth:The Communications and Information Technology Commission shall monitor the service provider’s commitment to exercising due diligence to ensure the protection of cybersecurity and critical infrastructure, in accordance with what is issued by the National Cybersecurity Authority, and it shall have the following powers in this regard:
A- Obliging service providers to conclude agreements among themselves to achieve this in accordance with what is issued by the National Cybersecurity Authority. B- Monitoring the cybersecurity level of the service provider to verify its adequacy, in accordance with what is issued by the National Cybersecurity Authority. C- Charging the service provider the cost of this monitoring in case of proven negligence. D- Imposing the penalties stipulated in Article (Twenty-Seven) of the law - referred to in item (First) of this decision - on the service provider violating the provisions of this item.
The Board of Directors of the National Cybersecurity Authority shall have the authority to decide to terminate the application of this item after coordination with the Communications and Information Technology Commission.
A draft Royal Decree has been prepared accordingly, its text attached hereto.
Fifth:The financial fees referred to in Article (Four) and Article (Thirty-Nine) of the law - referred to in item (First) of this decision - shall be determined in agreement with the Ministry of Finance and the Non-Oil Revenues Development Center, until the issuance and implementation of the (Regulation on the Practice of Public Authorities and Institutions and Equivalent Entities Imposing Financial Fees for Services and Works They Provide).
Sixth:The amount deducted from the financial fee stipulated in paragraph (2) of Article (Four) of the law - referred to in item (First) of this decision - shall be deposited in the current account of the Ministry of Finance at the Saudi Central Bank for the benefit of the Ministry of Communications and Information Technology.
Seventh:The amount deducted for the Ministry of Communications and Information Technology from the financial fee - as stipulated in paragraph (2) of Article (Four) of the law referred to in item (First) of this decision - shall be included within its appropriations in its budget.
Eighth:The Ministry of Communications and Information Technology shall disburse from the account referred to in item (Sixth) of this decision or from other bank accounts established for this purpose.
Ninth:The Ministry of Communications and Information Technology and the Ministry of Finance shall establish a mechanism to govern the disbursement of the deducted amount as referred to in paragraph (2) of Article (Four) of the law referred to in item (First) of this decision.
Prime Minister
