Personal Data Protection Law and its Executive Regulations

Preamble

Previous Amendments
  • Royal Decree No. (M/19) dated 09/02/1443 AH

  • By the grace of Allah

  • We, Salman bin Abdulaziz Al Saud

  • King of the Kingdom of Saudi Arabia

  • Pursuant to Article (Seventy) of the Basic Law of Governance, issued by Royal Order No. (A/90) dated 27/8/1412 AH.

  • Pursuant to Article (Twenty) of the Law of the Council of Ministers, issued by Royal Order No. (A/13) dated 3/3/1414 AH.

  • Pursuant to Article (Eighteen) of the Law of the Shura Council, issued by Royal Order No. (A/91) dated 27/8/1412 AH.

  • Having reviewed Shura Council Decisions No. (19/96) dated 3/7/1442 AH and No. (40/213) dated 3/12/1442 AH.

  • Having reviewed Council of Ministers Decision No. (98) dated 7/2/1443 AH.

  • We decree as follows:

  • First: Approval of the Personal Data Protection Law, in the form attached hereto.

    • Second: Repealed.
    • Third: The Controllers—referred to in Paragraph (18) of Article (One) of the Personal Data Protection Law—shall rectify their status in accordance with the provisions of the Law within a period not exceeding one year commencing from the date of its entry into force. The Competent Authority may, for reasons it deems appropriate, grant additional periods to certain entities to rectify their status.
    • Fourth: The application of the provisions of the Personal Data Protection Law and its Implementing Regulations shall not prejudice the powers and duties of the National Cybersecurity Authority in its capacity as the competent security authority for cybersecurity and the national reference authority for cybersecurity affairs in the Kingdom, in accordance with its Statute issued by Royal Order No. (6801) dated 11/2/1439 AH.
    • Fifth: The Deputy Prime Minister, Ministers, and Heads of the concerned independent bodies—each within their respective jurisdiction—shall implement this Decree.
  • Salman bin Abdulaziz Al Saud

  • Decision No. (98) dated 07/02/1443 AH

  • The Council of Ministers,

  • Having reviewed the correspondence received from the Royal Court under No. 70420 dated 4/12/1442 AH, including the Ministry of Interior’s telegram No. 41168 dated 22/4/1436 AH concerning the draft Personal Data Protection Law.

  • Having reviewed Supreme Orders No. (5727/M B) dated 23/8/1432 AH and No. (29549) dated 17/6/1433 AH.

  • Having reviewed the Statute of the National Cybersecurity Authority, issued by Royal Order No. (6801) dated 11/2/1439 AH.

  • Having reviewed the Law of the Saudi Central Bank, issued by Royal Decree No. (M/36) dated 11/4/1442 AH.

  • Having reviewed the Statute of the Communications and Information Technology Commission, issued by Council of Ministers Decision No. (74) dated 5/3/1422 AH, as amended.

  • Having reviewed the Organizational Arrangements of the Saudi Data and Artificial Intelligence Authority, issued by Council of Ministers Decision No. (292) dated 27/4/1441 AH.

  • Having reviewed Minutes No. (201) dated 1/3/1438 AH, No. (1135) dated 20/8/1439 AH, No. (1263) dated 12/7/1440 AH, and No. (215) dated 10/4/1442 AH, and Memoranda No. (420) dated 25/5/1441 AH, No. (961) dated 13/6/1442 AH, No. (1359) dated 15/8/1442 AH, No. (1783) dated 15/10/1442 AH, No. (2334) dated 29/12/1442 AH, and No. (73) dated 10/1/1443 AH, prepared by the Bureau of Experts at the Council of Ministers.

  • Having reviewed the Minutes of the Council of Political and Security Affairs No. 10664 dated 29/5/1442 AH.

  • Having reviewed the recommendation prepared by the Council of Economic and Development Affairs No. (1-43/4/D) dated 18/1/1443 AH.

  • Having considered Shura Council Decisions No. (19/96) dated 3/7/1442 AH and No. (40/213) dated 3/12/1442 AH.

  • Having reviewed the recommendation of the General Committee of the Council of Ministers No. (926) dated 30/1/1443 AH.

  • Hereby decides as follows:

    • First: Approval of the Personal Data Protection Law, in the form attached hereto.
    • Second: The Competent Authority shall be the Saudi Data and Artificial Intelligence Authority for a period of two years, during which consideration shall be given—in light of the results of applying the provisions of the Personal Data Protection Law and its Implementing Regulations, and in light of the level of maturity in the data sector—to transferring the power to supervise the application of the provisions of the Law and its Implementing Regulations to the National Data Management Office.
    • Third: Repealed.
    • Fourth: The Controllers—referred to in Paragraph (18) of Article (One) of the Personal Data Protection Law—shall rectify their status in accordance with the provisions of the Law within a period not exceeding (one year) commencing from the date of its entry into force. The Competent Authority may, for reasons it deems appropriate, grant additional periods to certain entities to rectify their status.
    • Fifth: The application of the provisions of the Personal Data Protection Law and its Implementing Regulations shall not prejudice the powers and duties of the National Cybersecurity Authority in its capacity as the competent security authority for cybersecurity and the national reference authority for cybersecurity affairs in the Kingdom, in accordance with its Statute issued by Royal Order No. (6801) dated 11/2/1439 AH.
    • A draft Royal Decree has been prepared concerning the matters set out in Items (First), (Third), (Fourth), and (Fifth) of this Decision, the form of which is attached hereto.
    • Sixth: The Competent Authority and the Saudi Central Bank shall coordinate to prepare a memorandum of understanding regulating certain aspects related to the application of the provisions of the Personal Data Protection Law and its Implementing Regulations to entities subject, from a regulatory perspective, to the supervision of the Saudi Central Bank, and defining the role of each of them in this regard, in order to prevent any overlap in their respective jurisdictions concerning the application of the provisions of the Law and its Implementing Regulations to entities subject, from a regulatory perspective, to the supervision of the Saudi Central Bank, prevent any effect on the independence of the Saudi Central Bank, account for the special nature of financial and banking transactions, and promote the stability and growth of the sectors supervised by the Saudi Central Bank, provided that the memorandum is completed and signed concurrently with the entry into force of the Law.
    • Seventh: The Competent Authority and the Communications and Information Technology Commission shall coordinate to prepare a memorandum of understanding regulating certain aspects related to the application of the provisions of the Personal Data Protection Law and its Implementing Regulations to entities subject to the regulation of the Communications and Information Technology Commission, and to prevent any effect on the Communications and Information Technology Commission in its capacity as an independent regulatory authority supervising sensitive sectors associated with individuals’ personal transactions, and to promote the stability and growth of the sectors it supervises, provided that the memorandum is completed and signed concurrently with the entry into force of the Law.
    • Eighth: The Competent Authority shall, in coordination with such entities as it deems appropriate, conduct an ongoing awareness campaign for Personal Data Subjects, as well as for the employees of Controllers—referred to in Paragraph (18) of Article (One) of the Personal Data Protection Law—or their personnel, to explain the rights and obligations set out in the Law after its entry into force.
    • Ninth: The Controller—referred to in Paragraph (18) of Article (One) of the Personal Data Protection Law—shall take the necessary measures to hold work sessions and the like for its employees or personnel, to familiarize them with the terms and principles set out in the Law after its entry into force. Such entities may coordinate with the Competent Authority whenever necessary for the purpose of providing advice and support.
    • Tenth: The Competent Authority shall, in coordination with such relevant entities as it deems appropriate, evaluate the results of applying the Personal Data Protection Law and express views concerning it, including proposing any amendments that may be necessary thereto, within (five) years from the date of its entry into force, and submit whatever is necessary to complete the required procedures.
    • Eleventh: Within a period not exceeding (one year) from the date of entry into force of the Personal Data Protection Law, the Competent Authority shall, in coordination with such relevant entities as it deems appropriate, review the provisions of the relevant laws, decisions, and regulations that address provisions relating to the protection of individuals’ Personal Data, propose amendments thereto in a manner consistent with the provisions of the Law, and submit whatever requires the completion of statutory procedures in this regard.
    • Twelfth: In preparing the Implementing Regulations of the Personal Data Protection Law, the Competent Authority shall take into account the establishment of provisions and regulations concerning the organizational, administrative, and technical procedures and means related to the storage of Personal Data by Controllers—referred to in Paragraph (18) of Article (One) of the Law—in a manner that ensures the preservation of Personal Data according to its nature and degree of sensitivity, based on the provisions of Article (Nineteen) of the Law.
  • The Prime Minister

Related files
Hide
Related file link

Article 1

Previous Amendments
  • In this Law, the following words and phrases shall have the meanings assigned thereto, unless the context requires otherwise:

    • 1. Law: Personal Data Protection Law.

    • 2. Regulations: The Implementing Regulations of this Law.

    • 3. Competent Authority: The authority to be determined pursuant to a resolution by the Council of Ministers.

    • 4. Personal Data: All data, regardless of its source or form, that would identify an individual or make it possible to identify him directly or indirectly, including his name, personal identification number, address, contact numbers, license numbers, records, and personal property, bank accounts, and credit card numbers, still or moving images, and any other data of a personal nature.

    • 5. Processing: Any operation performed on personal data by manual or automated means, such as the collection, recording, preservation, indexing, organization, alignment, storage, modification, update, combination, retrieval, use, disclosure, transfer, publication, sharing or interconnection, blockage, erasure, or destruction of personal data.

    • 6. Collection: Obtaining personal data by the controller in accordance with this Law, whether directly from its owner, or from the owner’s representative or legal guardian, or another party.

    • 7. Destruction: Any procedure performed on personal data that renders such data inaccessible or irretrievable, or makes it impossible to identify the data subject.

    • 8. Disclosure:Enabling any person, other than the controller or the processor, as the case may be, to obtain, use, or access personal data by any means and for any purpose.

    • 9. Transfer: Transferring personal data from one place to another for processing.

    • 10. Publication: Transmitting or making available any personal data through any written, audio, or visual medium.

    • 11. Sensitive Data: Any personal data that is related to a person's racial or ethnic origin; religious, intellectual, or political beliefs; security and criminal data; identifying biometric data; genetic data; health data; and data that indicate that one, or both, of an individual’s parents are unknown.

    • 12. Genetic Data: Any personal data relating to the inherited or acquired genetic characteristics of a natural person which uniquely determine his physiology or health, and which are obtained from an analysis of a biological specimen from such person, such as deoxyribonucleic acid analysis (DNA), or from an analysis of another specimen which results in obtaining genetic data.

    • 13. Health Data: Any personal data relating to the physical or mental health of an individual or to the health services provided thereto.

    • 14. Health Services: Services relating to the health of an individual including preventive, curative, and rehabilitative services as well as hospitalization and the provision of medicines.

    • 15. Credit Data: Any personal data relating to an individual’s application for financing or receipt thereof from a funding entity for personal or family purposes, including any data relating to his creditworthiness or credit history.

    • 16. Data Subject: An individual to whom personal data relate.

    • 17. Public Entity: Any ministry; public department, institution, or authority; or any independent public agency in the Kingdom, or any affiliate thereof.

    • 18. Controller: Any public entity or any private natural or legal person that determines the purpose and manner of personal data processing, whether it conducts such processing on its own orthrough a processor.

    • 19. Processor: Any public entity or any private natural or legal person that processes personal data for the benefit or on behalf of the controller.

Regulations
Show all
Regulation name

Regulation title

Regulation content

Article 2

  • 1. This Law shall apply to any form of processing of personal data relating to individuals that is carried out in the Kingdom as well as any form of processing of personal data relating to individuals residing in the Kingdom that is carried out by an entity outside the Kingdom. This shall include the data of any deceased person if such data would identify such person or a member of his family.

  • 2. This Law shall not apply to the processing of personal data by an individual for personal or family use, provided he does not publish or disclose such data to a third party. The Regulations shall specify the meaning of personal and family use set forth in this paragraph.

Regulations
Show all
Regulation name

Regulation title

Regulation content

Article 3

  • The provisions and procedures stipulated in this Law shall not prejudice any provision stipulated in another law or international agreement to which the Kingdom is a party which grants a right to a data subject or provides for better protection of such data.

Article 4

Previous Amendments
  • The data subject shall, pursuant to this Law and the Regulations, have the following rights:

    • 1. Right to be informed: It includes informing the data subject of the legal justification and purpose of collecting his personal data.

    • 2. Right of access: The right of the data subject to access his personal data that are held by the controller, pursuant to the controls and procedures determined by the Regulations and without prejudice to Article 9 of this Law.

    • 3. Right to request personal data: The right of the data subject to request a clear and legible copy of his personal data that are maintained by the controller pursuant to the controls and procedures determined by the Regulations.

    • 4. Right to rectification: The right of the data subject to request rectification, completion, or update of his personal data that are held by the controller.

    • 5. Right to erasure: The right of the data subject to request the erasure of his personal data that are held by the controller in cases where they are no longer necessary, without prejudice to the provisions of Article 18 of this Law.

Related files
Hide
Related file link
Regulations
Show all
Regulation name

Regulation title

Regulation content

Article 5

Previous Amendments
  • 1. Except for the cases provided for in this Law, personal data may not be processed or processed for a purpose other than that for which such data are obtained without the consent of the data subject. The Regulations shall specify the conditions for consent, the cases where the consent must be expressly made, and the terms and conditions for obtaining consent from the legal guardian if the data subject is partially or fully incompetent.

  • 2. In all cases, a data subject may, at any time, withdraw the consent referred to in paragraph (1) of this Article. The Regulations shall specify the necessary controls.

Regulations
Show all
Regulation name

Regulation title

Regulation content

Article 6

Previous Amendments
  • The processing of personal data shall not require the consent referred to in Article 5(1) of this Law in the following cases:

    • 1. If processing entails a real benefit for the data subject, and contacting the data subject is difficult or impossible.

    • 2. If processing is conducted pursuant to another law or to a prior agreement to which the data subject is a party.

    • 3. If the controller is a public entity and the processing is required for security purposes or to satisfy judicial requirements.

    • 4. If the processing is required to achieve a legitimate interest for the controller, provided that such processing does not violate the data subject’s rights or conflict with his interests, and that the data are not sensitive. The Regulations shall determine the necessary controls and procedures.

Regulations
Show all
Regulation name

Regulation title

Regulation content

Article 7

  • The consent referred to in Article 5(1) of this Law shall not be a condition for providing a service or a benefit, unless such service or benefit is related to the personal data processing for which the consent was made.

Article 8

Previous Amendments
  • Subject to the provisions relating to the disclosure of personal data provided for in this Law and the Regulations, the controller shall select a processor that provides the necessary guarantees for implementing the provisions of this Law and the Regulations, and shall verify the processor’s compliance with the provisions of this Law and the Regulations. This shall not prejudice the controller’s responsibilities towards the data subject or the Competent Authority, as the case may be. The Regulations shall specify the necessary provisions therefor, provided that they include the provisions relating to any subsequent contracts concluded by the processor.

Regulations
Show all
Regulation name

Regulation title

Regulation content

Article 9

Previous Amendments
  • 1. The controller may specify the periods for exercising the right of access stipulated in Article 4(2) of this Law, in accordance with the Regulations. The controller may limit such right in the following cases:

    • a) If such limitation is necessary to protect the data subject or others from any harm, subject to the Regulations.

    • b) If the controller is a public entity and such limitation is required for security purposes, to enforce another law, or to satisfy judicial requirements.

  • 2. The controller shall not allow the data subject to access his data in any of the cases stipulated in Article 16(1,2,3,4,5, and 6) of this Law.

Regulations
Show all
Regulation name

Regulation title

Regulation content

Next section title

Next section content