Procedures for Launching Services or Products Based on Personal Data

1- Introduction

According to the regulations of the Communications and Information Technology Commission issued by the Council of Ministers Decision No. (74) dated 5/3/1422 H, and amended by the Council of Ministers Decision No. (133) dated 21/5/1424 H, which stipulates that the Commission shall undertake the tasks of information technology. And to the Telecommunications System issued by the Council of Ministers Decision No. (74) dated 5/3/1422 H, its amendments, and its executive regulations and amendments, and to the Council of Ministers Decision No. (403) dated 12/7/1440 H, which assigned the regulatory and supervisory tasks over the postal sector to the Communications and Information Technology Commission, and based on the Commission's role in protecting the personal data of users in the telecommunications, information technology, and postal sectors, and based on the Commission's Decision No. (415) dated 23/8/1441 H, approving the "Document of General Principles for Maintaining the Privacy of Personal Data," the Commission has prepared a document titled "Procedures for Launching Services or Products Based on Users' Personal Data or Sharing Personal Data in the Telecommunications and Information Technology and Postal Sectors."

The purpose of this document is to organize and govern the development and launch of services or products based on users' personal data by telecommunications and information technology and postal service providers, and the sharing of personal data between service providers and external parties, thereby enhancing the level of trust in telecommunications, information technology, and postal services that rely on the processing of users' personal data.

2- Definitions

The following words and terms shall have the meanings specified for each, unless the context requires otherwise:

The Authority: Communications and Information Technology Commission.

Service Provider: Provider of telecommunications, information technology, or postal services in accordance with the Authority's regulations.

User: The natural personality who uses any of the telecommunications, information technology, or postal services from the service provider.

Personal Data: Any information - regardless of its source or form - that can lead to the identification of the user specifically, or makes them identifiable directly or indirectly, including but not limited to names, personal identification numbers, addresses and contact numbers, license and registration numbers, personal property numbers, bank account and credit card numbers, still or moving images of the user, and other personal data.

Processing of Personal Data: All operations performed on personal data by any means, whether manual or automated, including but not limited to the collection, transmission, storage, sharing, destruction, analysis, extraction of patterns, inference, and linking with other data.

Sharing of Personal Data: The declaration of personal data of users by the service provider to another entity.

Privacy Impact Assessment: A study conducted by the service provider prior to launching a service or product that relies on personal data or data sharing, aimed at assessing the impact of this service or product on the privacy of personal data of new or existing users, including but not limited to specifying the required data, describing the purpose of its processing, the scope and nature of the processing, and identifying and assessing privacy risks and methods of addressing them.

3- General Provisions

  • 1-3 Taking into account the regulations and decisions of the relevant authority, this document applies to the service provider in all of the following cases:

    • 1-1-3 Launching a new service or product, or making a change to an existing service or product, relying on personal data, except for the processing of the user's personal data that occurs within the service provider's systems for the purpose of providing services to them.

    • 2-1-3 Sharing personal data.

  • 2-3 The authority has the right to amend the periods or procedures stipulated in this document, at its sole discretion.

  • 3-3 The service provider is prohibited from any practices that violate these procedures, and in the event of a violation, the violations will be dealt with in accordance with the authority's regulations.

4- Procedures for Launching Services or Products Based on Users' Personal Data or Sharing Personal Data