1-5 Unless otherwise specified in the future in any of the Authority's regulations or related laws: The licensee providing digital certification services must comply with the document titled "Regulations for Providing Digital Certification Services" (this document), the Electronic Transactions Law and its executive regulations, and the decisions and guidelines issued by the Authority.
2-5 The obligations of the licensee in providing services to users (beneficiaries) and the public are subject to the provisions contained in the Authority's regulations, the provisions of this document, the Electronic Transactions Law and its executive regulations, and any decisions, guidelines, and regulations issued by the Authority and other applicable laws in the Kingdom.
3-5 The relationship between the licensee and the users is subject to the Authority's regulations and the provisions of the Electronic Transactions Law and its executive regulations, the terms and conditions of the license, in addition to the texts of the announcements issued by the licensee that do not conflict with or are consistent with the Authority's regulations.
4-5 The licensee is obligated to submit periodic reports to the Authority and provide any other information requested by the Authority, which will specify the types of those reports, the nature of the required information, and the time for submission.
5-5 The licensee must adhere to high-quality performance levels that comply with recognized international standards, along with complying with what the Authority stipulates in this regard in the future.
6-5 Implement all obligations stipulated by the Authority's regulations and the provisions of the Electronic Transactions Law and its executive regulations, including the continuous provision of services and working on their development and improvement in line with the objectives of the law.
7-5 Implement all decisions, controls, and instructions issued by the Authority and other official entities regarding the provision of digital certification services, and comply with them.
8-5 Inform beneficiaries (users) of the digital certification services covered by the provisions of Article Twenty-Two of the Electronic Transactions Law regarding the responsibilities of the certificate holder.
9-5 The digital certification policy issued by the National Center for Digital Certification.
10-5 The privacy policy issued by the National Center for Digital Certification, which can be viewed on the Center's website (www.ncdc.gov.sa), and the protection of the privacy of subscribers and their accounts.
11-5 Compliance with any amendments or additional requirements for the services provided as determined by the Authority or the Center, as necessitated by regulatory rules and in a manner that serves the interests of the beneficiaries (users).
12-5 Provide the service to beneficiaries without discrimination.
13-5 Provide digital certification services according to the service deployment plan.
14-5 Ensure the accuracy of the certified information contained in the certificate at the time of delivery, and the accuracy of the relationship between the certificate holder and its electronic data, and the certificate holder shall be liable for any harm caused to any person who relied - in good faith - on the accuracy of that information.
15-5 Appoint a sufficient number of employees in the registration centers who possess expertise in information technology and its security, provide services to beneficiaries, and establish a call center that operates around the clock to handle emergencies and certificate cancellations. The employees responsible for registering certificates and verifying the identity and data of subscribers must be citizens.
16-5 All devices, software, and servers used in digital certification procedures must be located within the Kingdom.
17-5 Provide the Authority and the Center with all required information.
18-5 Provide the necessary facilities for the Center or its delegate to conduct audits according to the auditing procedures approved by the Center.
19-5 Submit periodic reports every six (6) months or as requested by the Center regarding the services provided, including the number of registered beneficiaries.
20-5 Notify the Center immediately of any emergency issue, such as a breach of the service provider's system or other problems that may affect the services of the users.
22-5 Issue the digital certificate to the subscriber within a maximum of five (5) working days from the date of the subscriber's application.
23-5 Cancel the digital certificate upon receiving a cancellation request from the subscriber according to the procedures specified by the Center in coordination with the Authority.
24-5 User data (such as contact numbers or email addresses, or numbers generated by them) may not be shared with any third party or used for any commercial purposes such as sending advertisements.
25-5 The service provider shall retain user data for no less than 12 calendar months.
26-5 The Center provides its services to licensed entities free of charge during the initial service authorization period (the first five years), and fees may be added to cover the Center's costs after the initial service authorization period ends.
27-5 All claims related to confidentiality and the processing of all confidential information are subject to the regulatory rules of the Authority and the provisions of the Electronic Transactions Law and its executive regulations.
28-5 The service provider must act with integrity and in good faith, without discrimination between users, while ensuring the preservation of their privacy.
29-5 The service provider must clearly state - in advance - the financial compensation and characteristics of the services it offers to those wishing to obtain them before they use them.
30-5 The service provider must comply with copyright and other rights according to the relevant regulatory rules when providing any programs to users, ensuring that the service provider obtains the Authority's approval and the approval of the relevant entities before providing the service.
31-5 The service provider must provide the necessary equipment to deliver the service according to the technical standards approved by the Authority and the Center, and the use of that equipment is limited to providing the services covered by this license.
32-5 The service provider may not use the contact numbers or email addresses of users that they provided or disclosed to him for any purpose, such as using them in advertising campaigns or selling databases available to the licensee that contain these numbers and addresses to another party without prior consent from the owner.
33-5 The service provider provides the technical capabilities in the devices and materials of its network used to connect its devices and equipment, and the special requirements form for operating and using the network must be filled out and signed.
34-5 The service provider must provide the technical capabilities in the devices and materials of its network that can be used to identify user data for reference when needed for no less than twelve (12) calendar months or as determined by the Authority.