This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Personal Data Protection Law (Saudi Arabia) | |
|---|---|
| Name | Personal Data Protection Law (Saudi Arabia) |
| Enacted | 2021 |
| Jurisdiction | Saudi Arabia |
| Enacted by | Council of Ministers |
| Date assented | 2021 |
| Status | in force |
Personal Data Protection Law (Saudi Arabia)
The Personal Data Protection Law enacted in the Kingdom of Saudi Arabia establishes a statutory framework governing the processing of personal data within the Kingdom of Saudi Arabia, aligning national practice with international norms such as those reflected in the General Data Protection Regulation and regional instruments like the Abu Dhabi Global Market Data Protection Regulations. The statute creates rights for individuals and duties for entities while empowering the Saudi Data and Artificial Intelligence Authority to supervise implementation and enforcement across sectors including finance, health, and telecommunications linked to institutions such as the Saudi Arabian Monetary Authority and the Ministry of Health (Saudi Arabia). The law forms part of the broader Vision 2030 (Saudi Arabia) reform agenda and interacts with other statutes like the Anti-Cybercrime law (Saudi Arabia) and rules issued by the Communications and Information Technology Commission (Saudi Arabia).
The law’s genesis involved consultations among bodies including the Saudi Data and Artificial Intelligence Authority, the Ministry of Interior (Saudi Arabia), the Ministry of Commerce (Saudi Arabia), and advisory input from international actors such as the European Commission and the Organisation for Economic Co-operation and Development. Drafting followed precedents set by the General Data Protection Regulation, the Personal Information Protection and Electronic Documents Act, and the Data Protection Act 2018 with legislative endorsement by the Shura Council (Saudi Arabia) and promulgation under royal decree alongside policy initiatives like National Transformation Program 2020. Implementation milestones referenced standards from entities like the International Organization for Standardization and involved stakeholder engagement with firms including Saudi Telecom Company, Al Rajhi Bank, and international consultancies such as Deloitte and PwC.
The law defines core terms referencing data subjects, data controllers, and data processors, situating definitions within the legal regimes of countries such as United Kingdom, France, and Germany for comparative interpretation. It applies to processing of personal data by natural persons and legal entities operating in the Kingdom of Saudi Arabia and to certain cross-border processing involving jurisdictions like the United States, the United Arab Emirates, and Bahrain when operations link to Saudi residents. Definitions cover categories including special personal data akin to concepts in the GDPR, and exceptions intersect with national security provisions administered by the Ministry of Interior (Saudi Arabia), the General Directorate of Public Security (Saudi Arabia), and intelligence-related mandates from bodies like the Presidency of State Security (Saudi Arabia).
The statute codifies principles such as lawfulness, purpose limitation, data minimization, accuracy, storage limitation, and confidentiality, echoing jurisprudence from the European Court of Justice, doctrinal frameworks from the Council of Europe, and standards promoted by the International Association of Privacy Professionals. Data subject rights include access, rectification, erasure, objection, and portability, resonating with rights in the GDPR and legislative models from the California Consumer Privacy Act and the Brazilian General Data Protection Law. The law also addresses automated decision-making and profiling in contexts similar to regulatory guidance issued by the UK Information Commissioner's Office and the French Commission Nationale de l'Informatique et des Libertés.
Obligations require controllers and processors to implement organizational and technical safeguards, maintain records of processing, conduct impact assessments, and appoint representatives where applicable, reflecting practices enforced by agencies such as the European Data Protection Board and supervisory models in the Netherlands and Sweden. Entities in sectors like banking, healthcare, and telecommunications—examples include National Commercial Bank (Saudi Arabia), Ministry of Health (Saudi Arabia), and Mobily—must ensure contractual stipulations with processors, breach notification to authorities, and data protection by design similar to mandates from the Monetary Authority of Singapore and the Hong Kong Privacy Commissioner for Personal Data.
The Saudi Data and Artificial Intelligence Authority serves as the primary regulator, empowered to issue regulations, guidance, and enforcement actions, in a manner comparable to the European Data Protection Supervisor and national authorities such as the Data Protection Commission (Ireland). The authority coordinates with ministries including the Ministry of Commerce (Saudi Arabia), the Ministry of Interior (Saudi Arabia), and international partners like the European Commission and the United Nations Educational, Scientific and Cultural Organization on capacity building and cross-border cooperation.
The law prescribes administrative fines, corrective orders, and remedial measures for non-compliance, with thresholds and sanctioning powers reflecting comparable regimes such as the GDPR and the Brazilian General Data Protection Law. Penalties can affect corporations like Saudi Aramco or financial institutions and may involve requirements for audits, suspension of processing, or data deletion, enforced through administrative procedures similar to those used by the UK Information Commissioner's Office and judicial review in courts such as the Board of Grievances (Saudi Arabia).
Cross-border data transfers are regulated through mechanisms including adequacy determinations, contractual clauses, and safeguards inspired by instruments like the EU–US Data Privacy Framework proposals and standard contractual clauses from the European Commission. Transfers involving jurisdictions such as the United States, United Kingdom, United Arab Emirates, and Bahrain require compliance measures to ensure equivalent protection, with multinational enterprises such as Google, Microsoft, and Amazon expected to adapt data flows according to determinations by the Saudi Data and Artificial Intelligence Authority and related international agreements.
Category:Law of Saudi Arabia