The words and phrases contained in this Regulation shall have the meanings specified next to each of them in Article (1) of the Personal Data Protection System, issued by Royal Decree No. (M/19) dated 9/2/1443 AH, and amended by Royal Decree No. (M/148) dated 5/9/1444 AH and its executive regulation. The following terms and phrases - wherever they appear in this Regulation - shall have the meanings specified next to each of them, unless the context requires otherwise:
1. Regulation: Regulation for the Transfer of Personal Data Outside the Kingdom.
2. Transfer of Personal Data: The transfer of personal data outside the Kingdom for the purpose of processing it.
3. Regulations: The executive regulations of the Personal Data Protection System.
1. Subject to the provisions of the Law and its regulations, the data controller may transfer personal data or declare it to an entity outside the Kingdom, unless such transfer or declaration affects national security or the vital interests of the Kingdom, or if the transfer or declaration is in violation of another law in the Kingdom.
2. The data controller shall limit the transfer of personal data outside the Kingdom or declare it to an entity outside the Kingdom to the minimum necessary to achieve the purpose of the transfer or declaration, which shall be determined by using any appropriate means, including data schemes that demonstrate the need to transfer each piece of data or declare it and link that to each processing objective outside the Kingdom.
3. When transferring personal data or declaring it to an entity outside the Kingdom, the data controller must ensure that this will not affect the privacy of the personal data owners or the level of protection guaranteed for personal data under the Law and its regulations, by ensuring that the transfer or declaration process does not infringe - at a minimum - on any of the following:
A- The ability of the personal data owner to exercise their rights guaranteed under the Law.
B- The ability of the personal data owner to depart from their consent to the processing operation.
C- The ability of the data controller to comply with the notification requirements regarding personal data breach incidents.
D- The ability of the data controller to comply with the provisions, controls, and procedures for declaring personal data.
E- The ability of the data controller to comply with the provisions and controls for the destruction of personal data.
F- The ability of the data controller to take the necessary organizational, administrative, and technical measures to ensure the security of personal data.
4. The data controller may transfer personal data outside the Kingdom or declare it to an entity outside the Kingdom in accordance with the purposes stipulated in paragraph (1) of Article (Twenty-Nine) of the Law, in addition to the following purposes:
A- Conducting operational processing activities to enable the data controller to carry out its activities, including central management operations.
B- Providing a service or benefit to the personal data owner.
C- Conducting research and scientific studies.
1. The competent authority and the relevant entities coordinating with it - each according to its jurisdiction - shall assess the level of protection of personal data outside the Kingdom, in accordance with the following criteria:
A- The existence of systems that ensure the protection of personal data and the preservation of the rights of its owners, at a level of protection that is no less than that guaranteed by the Law and its regulations.
B- The supremacy of the systems, and the guarantee of the rights of personal data owners and the preservation of their privacy.
C- The effectiveness of the application of personal data protection systems.
D- The ability of personal data owners to exercise their rights, and the availability of necessary means for them to file complaints or claims related to the processing of personal data.
E- The existence of a supervisory body responsible for monitoring the compliance of controllers with the requirements for personal data protection.
F- The readiness of the supervisory body to cooperate with the competent authority in the Kingdom on matters related to personal data protection.
G- The clarity and appropriateness of the regulatory requirements related to the declaration of personal data to government and regulatory entities.
2. The assessment of the level of protection of personal data referred to in this article may be conducted for countries, specific sectors within them, or for international organizations.
1. The competent authority shall submit the results of the assessment of the level of personal data protection outside the Kingdom to the Prime Minister, detailing all related information, including the opinions of the participating entities in the assessment and the recommendations of the competent authority.
2. The recommendations of the competent authority referred to in paragraph (1) of this article shall be as follows:
A- To recommend issuing a decision of approval based on the results of the assessment of the level of personal data protection, whether all or some of the criteria stipulated in paragraph (1) of Article (3) of this regulation have been met.
B- To recommend entering into an international agreement - in accordance with the applicable legal procedures - as appropriate.
C- To recommend not issuing a decision of approval or entering into an international agreement, with a statement of the justifications for that.
3. The competent authority shall review the assessment of the level of personal data protection in countries, sectors, or international organizations that have been granted approval decisions or have signed an international agreement with them every four years or as necessary, taking into account all relevant developments in those countries, sectors, or international organizations in accordance with the criteria set forth in paragraph (1) of Article (3) of this regulation.
4. The competent authority shall submit to the Prime Minister a proposal to revoke, amend, or suspend any of the decisions made regarding the level of personal data protection outside the Kingdom, if it becomes evident through the review of the level of personal data protection that the country, sector, or international organization no longer guarantees an adequate level of protection for personal data.
1. In the event that there is no appropriate level of protection for personal data outside the Kingdom, the data controller may transfer personal data or declare it outside the Kingdom, provided that the regulatory requirements of the country or the international organization do not negatively affect the privacy of personal data owners or the ability of the data controller to comply with the application of appropriate safeguards. The appropriate safeguards are represented in any of the following:
A- Binding common rules, which apply to each concerned party in the group of entities engaged in a shared economic activity, including their employees, and whose provisions and terms are approved by the competent authority upon requests submitted to it in each individual case.
B- Standard contractual clauses that ensure an adequate level of protection for personal data when transferred outside the Kingdom, according to a standard model issued by the competent authority.
C- Certificates of compliance with the law and regulation in the Kingdom, issued by an entity licensed by the competent authority, with the data controller or processor outside the Kingdom committing to apply the appropriate safeguards.
D- Binding codes of conduct, which are approved by the competent authority upon requests submitted to it in each individual case, with the data controller or processor outside the Kingdom committing to apply the appropriate safeguards.
2. The binding common rules referred to in subparagraph (A) of paragraph (1) of this article include at least the following matters:
A- Commercial registry data and contact information details of the group of entities engaged in a shared economic activity.
B- Description of personal data transfer operations or a set of transfer operations, including the type of personal data, the type of processing, its purposes, and identifying the country or countries to which the data will be transferred.
C- The obligation of all parties in the rules to apply what is stated therein.
D- Provisions for the protection of personal data that must be applied, including specifying the purpose of processing, collecting the minimum data, retention periods, legal justifications for processing, controls for processing personal data, and requirements related to subsequent transfers to entities not bound by the rules.
E- The rights of the personal data owner regarding processing and the means to exercise those rights, including the right to file a complaint with the competent authority.
F- Provisions of the data controller's liability for any violations of the rules by its parties.
G- How to provide information related to the rules to data owners in addition to other information that will be provided in accordance with the law and its regulations.
H- The tasks of the personal data protection officer - if any - or any person or entity responsible for monitoring compliance with the rules within the entities engaged in a shared economic activity.
I- Mechanism for handling complaints and dealing with personal data breach incidents.
J- Mechanisms to ensure and monitor compliance within the group of entities engaged in a shared economic activity to ensure continuous and effective verification of compliance with the rules, provided that these mechanisms include audits for the protection of personal data and methods for implementing corrective actions, in addition to the obligation to make the results of this audit available to the competent authority upon request.
K- Mechanism for requesting approval from the competent authority for any amendments to the rules.
L- Mechanism for cooperation and communication with the competent authority to ensure compliance by each party in the group of entities engaged in the shared economic activity.
M- Clarification of any regulatory requirements for the declaration of personal data that the group of entities engaged in the shared economic activity in another country is subject to, which may negatively impact the provisions stipulated in the rules, and the mechanism for dealing with situations where regulatory requirements outside the Kingdom conflict with the provisions of the law and its regulations.
N- Mechanism for training and qualifying employees who have permanent or regular access to personal data and sensitive data.
3. The application of what is stated in this article does not affect the responsibilities of the data controller stipulated in the law and its regulations.
1- The data controller, in the event of transferring personal data or declaring it to an entity outside the Kingdom in accordance with Article (5) or (6) of this regulation, must cease the transfer of personal data or declare it to an entity outside the Kingdom in any of the following cases:
A- If it is determined that the transfer or declaration process affects national security or the vital interests of the Kingdom.
B- If the results of the risk assessment of transferring personal data outside the Kingdom or declaring it to an entity outside the Kingdom indicate that the transfer or declaration will result in high risks to the privacy of personal data owners.
C- The cessation of the applicability of the appropriate safeguards implemented by the data controller.
D- The inability of the data controller to comply with the appropriate safeguards implemented by it.
2- In the event that any of the conditions stipulated in paragraph (1) of this article apply, the data controller must do the following:
A- Cease -without unjustified delay- the transfer of personal data outside the Kingdom or declaring it to an entity outside the Kingdom.
B- Re-conduct a risk assessment of transferring personal data outside the Kingdom or declaring it to an entity outside the Kingdom.
3- The competent authority shall continuously evaluate and review the conditions and procedures for departing from the exemption.