Preamble
Royal Decree No. (M/19) dated 09/02/1443 AH
By the grace of Allah
We, Salman bin Abdulaziz Al Saud
King of the Kingdom of Saudi Arabia
Pursuant to Article (Seventy) of the Basic Law of Governance, issued by Royal Order No. (A/90) dated 27/8/1412 AH.
Pursuant to Article (Twenty) of the Law of the Council of Ministers, issued by Royal Order No. (A/13) dated 3/3/1414 AH.
Pursuant to Article (Eighteen) of the Law of the Shura Council, issued by Royal Order No. (A/91) dated 27/8/1412 AH.
Having reviewed Shura Council Decisions No. (19/96) dated 3/7/1442 AH and No. (40/213) dated 3/12/1442 AH.
Having reviewed Council of Ministers Decision No. (98) dated 7/2/1443 AH.
We decree as follows:
First: Approval of the Personal Data Protection Law, in the form attached hereto.
- Second: Repealed.
- Third: The Controllers—referred to in Paragraph (18) of Article (One) of the Personal Data Protection Law—shall rectify their status in accordance with the provisions of the Law within a period not exceeding one year commencing from the date of its entry into force. The Competent Authority may, for reasons it deems appropriate, grant additional periods to certain entities to rectify their status.
- Fourth: The application of the provisions of the Personal Data Protection Law and its Implementing Regulations shall not prejudice the powers and duties of the National Cybersecurity Authority in its capacity as the competent security authority for cybersecurity and the national reference authority for cybersecurity affairs in the Kingdom, in accordance with its Statute issued by Royal Order No. (6801) dated 11/2/1439 AH.
- Fifth: The Deputy Prime Minister, Ministers, and Heads of the concerned independent bodies—each within their respective jurisdiction—shall implement this Decree.
Salman bin Abdulaziz Al Saud
Decision No. (98) dated 07/02/1443 AH
The Council of Ministers,
Having reviewed the correspondence received from the Royal Court under No. 70420 dated 4/12/1442 AH, including the Ministry of Interior’s telegram No. 41168 dated 22/4/1436 AH concerning the draft Personal Data Protection Law.
Having reviewed Supreme Orders No. (5727/M B) dated 23/8/1432 AH and No. (29549) dated 17/6/1433 AH.
Having reviewed the Statute of the National Cybersecurity Authority, issued by Royal Order No. (6801) dated 11/2/1439 AH.
Having reviewed the Law of the Saudi Central Bank, issued by Royal Decree No. (M/36) dated 11/4/1442 AH.
Having reviewed the Statute of the Communications and Information Technology Commission, issued by Council of Ministers Decision No. (74) dated 5/3/1422 AH, as amended.
Having reviewed the Organizational Arrangements of the Saudi Data and Artificial Intelligence Authority, issued by Council of Ministers Decision No. (292) dated 27/4/1441 AH.
Having reviewed Minutes No. (201) dated 1/3/1438 AH, No. (1135) dated 20/8/1439 AH, No. (1263) dated 12/7/1440 AH, and No. (215) dated 10/4/1442 AH, and Memoranda No. (420) dated 25/5/1441 AH, No. (961) dated 13/6/1442 AH, No. (1359) dated 15/8/1442 AH, No. (1783) dated 15/10/1442 AH, No. (2334) dated 29/12/1442 AH, and No. (73) dated 10/1/1443 AH, prepared by the Bureau of Experts at the Council of Ministers.
Having reviewed the Minutes of the Council of Political and Security Affairs No. 10664 dated 29/5/1442 AH.
Having reviewed the recommendation prepared by the Council of Economic and Development Affairs No. (1-43/4/D) dated 18/1/1443 AH.
Having considered Shura Council Decisions No. (19/96) dated 3/7/1442 AH and No. (40/213) dated 3/12/1442 AH.
Having reviewed the recommendation of the General Committee of the Council of Ministers No. (926) dated 30/1/1443 AH.
Hereby decides as follows:
- First: Approval of the Personal Data Protection Law, in the form attached hereto.
- Second: The Competent Authority shall be the Saudi Data and Artificial Intelligence Authority for a period of two years, during which consideration shall be given—in light of the results of applying the provisions of the Personal Data Protection Law and its Implementing Regulations, and in light of the level of maturity in the data sector—to transferring the power to supervise the application of the provisions of the Law and its Implementing Regulations to the National Data Management Office.
- Third: Repealed.
- Fourth: The Controllers—referred to in Paragraph (18) of Article (One) of the Personal Data Protection Law—shall rectify their status in accordance with the provisions of the Law within a period not exceeding (one year) commencing from the date of its entry into force. The Competent Authority may, for reasons it deems appropriate, grant additional periods to certain entities to rectify their status.
- Fifth: The application of the provisions of the Personal Data Protection Law and its Implementing Regulations shall not prejudice the powers and duties of the National Cybersecurity Authority in its capacity as the competent security authority for cybersecurity and the national reference authority for cybersecurity affairs in the Kingdom, in accordance with its Statute issued by Royal Order No. (6801) dated 11/2/1439 AH.
- A draft Royal Decree has been prepared concerning the matters set out in Items (First), (Third), (Fourth), and (Fifth) of this Decision, the form of which is attached hereto.
- Sixth: The Competent Authority and the Saudi Central Bank shall coordinate to prepare a memorandum of understanding regulating certain aspects related to the application of the provisions of the Personal Data Protection Law and its Implementing Regulations to entities subject, from a regulatory perspective, to the supervision of the Saudi Central Bank, and defining the role of each of them in this regard, in order to prevent any overlap in their respective jurisdictions concerning the application of the provisions of the Law and its Implementing Regulations to entities subject, from a regulatory perspective, to the supervision of the Saudi Central Bank, prevent any effect on the independence of the Saudi Central Bank, account for the special nature of financial and banking transactions, and promote the stability and growth of the sectors supervised by the Saudi Central Bank, provided that the memorandum is completed and signed concurrently with the entry into force of the Law.
- Seventh: The Competent Authority and the Communications and Information Technology Commission shall coordinate to prepare a memorandum of understanding regulating certain aspects related to the application of the provisions of the Personal Data Protection Law and its Implementing Regulations to entities subject to the regulation of the Communications and Information Technology Commission, and to prevent any effect on the Communications and Information Technology Commission in its capacity as an independent regulatory authority supervising sensitive sectors associated with individuals’ personal transactions, and to promote the stability and growth of the sectors it supervises, provided that the memorandum is completed and signed concurrently with the entry into force of the Law.
- Eighth: The Competent Authority shall, in coordination with such entities as it deems appropriate, conduct an ongoing awareness campaign for Personal Data Subjects, as well as for the employees of Controllers—referred to in Paragraph (18) of Article (One) of the Personal Data Protection Law—or their personnel, to explain the rights and obligations set out in the Law after its entry into force.
- Ninth: The Controller—referred to in Paragraph (18) of Article (One) of the Personal Data Protection Law—shall take the necessary measures to hold work sessions and the like for its employees or personnel, to familiarize them with the terms and principles set out in the Law after its entry into force. Such entities may coordinate with the Competent Authority whenever necessary for the purpose of providing advice and support.
- Tenth: The Competent Authority shall, in coordination with such relevant entities as it deems appropriate, evaluate the results of applying the Personal Data Protection Law and express views concerning it, including proposing any amendments that may be necessary thereto, within (five) years from the date of its entry into force, and submit whatever is necessary to complete the required procedures.
- Eleventh: Within a period not exceeding (one year) from the date of entry into force of the Personal Data Protection Law, the Competent Authority shall, in coordination with such relevant entities as it deems appropriate, review the provisions of the relevant laws, decisions, and regulations that address provisions relating to the protection of individuals’ Personal Data, propose amendments thereto in a manner consistent with the provisions of the Law, and submit whatever requires the completion of statutory procedures in this regard.
- Twelfth: In preparing the Implementing Regulations of the Personal Data Protection Law, the Competent Authority shall take into account the establishment of provisions and regulations concerning the organizational, administrative, and technical procedures and means related to the storage of Personal Data by Controllers—referred to in Paragraph (18) of Article (One) of the Law—in a manner that ensures the preservation of Personal Data according to its nature and degree of sensitivity, based on the provisions of Article (Nineteen) of the Law.
The Prime Minister
