Implementing Regulation of the Electronic Transactions Law

Chapter 1: General Provisions

Article 1: Definitions

  • 1/1 The terms and phrases defined in Article One of the Electronic Transactions Law shall have the same meanings assigned to them in the law when used in this Regulation.

  • 1/2 The following terms and phrases - wherever they appear in this Regulation - shall have the meanings specified next to each, unless the context requires otherwise:

    • 1- Law: Electronic Transactions Law.

    • 2- Center: National Information Center.

    • 3- Digital Certificate Policy: A document issued by the Center or the Certificate Service Provider containing the terms and guidelines that inform the certificate user about the suitability of the digital certificate for their needs, the reliability associated with it, as well as specifying the legitimate and illegitimate uses of the certificate, and the role of Registration Centers.

    • 4- Registration Center: The entity responsible for the registration process and verifying the identity of applicants using the mechanism approved by the issuing authority to obtain digital certificates.

    • 5- Digital Certification Procedures: A document issued by the Center or the Certificate Service Provider containing the technical and procedural methods followed to issue a digital certificate by the Certificate Service Provider.

    • 6- Electronic Seal: Electronic data included in an electronic transaction or added to it or logically associated with it, used to prove the validity of the seal's association with the identity of the person to whom it is attributed and their certification of the electronic transaction, and to detect any modifications that occur to this transaction after it has been sealed.

    • 7- Timestamp: Electronic data recorded in an electronic log or added to it or logically associated with it, for the purpose of determining the date and time of the action taken on this log, and to detect any modifications that occur to it.

    • 8- Beneficiary: The holder of the certificate, which is the person in whose name the digital certificate is registered.

    • 9- Party relying on the certificate: The person who relies on the digital certificate in their electronic transactions and depends on its validity.

Chapter 2: Preservation of Records and Electronic Data

Article 2: Controls for the Preservation of Electronic Records and Data

  • 2 /1 Records and data related to electronic transactions must be preserved in accordance with the requirements of any laws, regulations, or procedures related to the preservation of traditional records and data, without prejudice to Article 6 of the Law.

  • 2/2 Records that are inherently issued must be preserved with all their original data, and they may be stored (archived) in any form of electronic data that does not compromise the content and quality of the record.

  • 2 /3 Subject to the provisions of the previous paragraph (2 /1) of this article, the electronic record must include data that identifies the record, its connection to the electronic transaction, and other electronic records. This data must include the following elements as a minimum:

    • A- Information about the creator of the electronic record.

    • B- Information about the sender of the electronic record, if different from the creator.

    • C- Information about the recipient of the electronic record.

    • D- The transaction number included in the electronic record and its nature.

    • E- The date and time of the creation of the electronic record.

    • F- The date and time of the sending of the electronic record.

    • G- The date and time of the receipt of the electronic record.

    • H- Information about retransmission, modification, or cancellation, as well as acknowledgment of receipt messages if required by the sender.

Article 3: The party obligated to maintain electronic records

  • A- To determine the person obligated to maintain an electronic record, the relevant regulations, rules, and decisions regarding the preservation of documents related to the transaction subject to the electronic record shall apply.

  • B- The person obligated to maintain the electronic record may seek the services of another party to fulfill the preservation requirements, without affecting their responsibility as stipulated in this article.

  • C- The parties involved in the electronic transaction are obligated to adhere to the bilateral agreements concluded between them regarding the preservation of electronic data, provided that it does not conflict with the relevant regulations.

Article 4: Duration of Retention of Electronic Records

  • A- Records and data related to any electronic transaction must be preserved in accordance with the requirements of any regulations or procedures related to determining the time periods during which records and data must be retained.

  • B- Subject to the provisions of the previous paragraph (4/1) of this article, records and data related to any electronic transaction must be preserved in accordance with the agreements concluded between the parties to the electronic transaction.

Article 5: Conditions for the Preservation of Electronic Records

  • 5 /1 When storing electronic records and data, the following conditions must be met:

    • 1- Adhering to clear and documented rules and procedures for storing electronic records, in accordance with the relevant laws and regulations.

    • 2- Storing electronic records and data in any format that is consistent with the system in place by the entity performing the storage.

    • 3- If any provision in this regulation requires the specification of date and time or their preservation or display, the following must be adhered to as a minimum:

      • A- The date must be specified according to the Gregorian calendar at a minimum, with the addition of the Hijri calendar if required by any legal text, and the time must be specified to the hour, minute, and second as a minimum.

      • B- The date and time must align with the official time adopted in the Kingdom of Saudi Arabia, unless the parties agree otherwise.

    • 4- In the event that the electronic record requires proof of the time, the record must contain a timestamp issued by the center or by the certification service provider, in accordance with what is issued by the authority.

    • 5- Using appropriate technologies to ensure that the electronic record is preserved in the same form in which it was created, sent, or received, or to ensure that its content matches the content with which it was created, sent, or received.

  • 5 /2 The party obligated to store electronic records must conduct archiving and backup operations periodically, ensuring the rights of those who rely on these records, and in accordance with the requirements of the relevant laws and regulations.

Chapter 3: Presentation of the Electronic Record

Article 6: Conditions for Presenting and Accessing Electronic Records and Data

  • 6 /1 It is required for the presentation of electronic records and data that the information related to electronic transactions is available in a standard electronic format that is readable, understandable, and complete.

  • 6 /2 Entities that maintain electronic records and data are obligated to define the access and handling permissions for their employees based on work needs, and in a manner that does not conflict with relevant laws and regulations.

  • 6 /3 Entities that maintain electronic records are required to implement appropriate technical solutions to log all instances where those electronic records are accessed, retrieved, modified, or altered.

  • 6 /4 Either party in the electronic transaction or any legally authorized entity has the right to obtain information from the electronic transaction records held by the maintaining entities; otherwise, the entity that maintains the electronic records is not permitted to provide them to any third party without prior agreement between the parties involved in the transaction.

Chapter 4: Issuance and Receipt of the Electronic Register

Next section title

Next section content