CertificatesControllersProcessorsAuditingInspectionPersonalDataProcessingActivities
Art. 1Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
The Terms and Phrases set forth in these Rules shall bear the meanings assigned to them in Article (1) of
the Personal Data Protection Law (The Law) issued by Royal Decree No. (M/19), dated 9/2/1443 AH, and its
amendments, as well as Article (1) of the Implementing Regulation of the Personal Data Protection Law
and Article (1) of the Regulation on Personal Data Transfer Outside the Kingdom (The Regulations). Unless
the context requires otherwise, the following terms and expressions, wherever mentioned in these Rules,
shall have the meanings expressed herein.
1. Rules: The rules governing the licensing of activities for issuing accreditation certificates for
Controllers and Processors and for auditing and inspection activities related to the processing of
personal data.
2. License: A document issued by the Competent Authority granting an Applicant the power to conduct
the activities stipulated in Paragraphs (4) and (5) of this Article.
3. Applicant: The entity that submits a license application to the Competent Authority to conduct audits
or inspections of personal data processing activities or issue accreditation certificates to Controllers
and Processors.
4. License for Issuing Accreditation Certificates: A document issued by the Competent Authority to a
legal person with special capacity authorizing engagement in the activity of issuing accreditation
certificates for Controllers and Processors.
5. License for Auditing and Inspection Activities: A document issued by the Competent Authority to a
legal person with special capacity authorizing engagement in auditing and inspection activities
related to personal data processing at Controllers and Processors.
6. Licensee: The entity authorized by the Competent Authority to issue accreditation certificates or
conduct audits or inspections, pursuant to the Competent Authority's decision on the submitted
license applications and in accordance with the requirements specified in these Rules.
7. Accreditation Certificate: A certificate issued by the Licensee to Controllers or Processors,
confirming that the practices and procedures followed by the Controllers and Processors in processing
personal data comply with the provisions of the Law, the Regulations, and the requirements
stipulated in the Rules Governing the Issuance of Accreditation Certificates for Controllers and
Processors.
8. Audits or Inspections: An activity carried out by the Licensee to verify the comprehensiveness of
personal data processing activities at the entity by conducting audits and inspections, and to
determine the effectiveness of the controls and measures taken to protect personal data.
9. Audit or Inspection Report: A report prepared by a Licensee to conduct audits or inspections,
outlining the findings of the audit or inspection of the personal data processing activities subject to
the audit or inspection pursuant to the provisions of the Law and the Regulations.
عام
Document Classification: Public
10. Certification Issuance Assessment Report: A report prepared by the Licensee that includes the
results of the evaluation of the practices and procedures in processing personal data pursuant to the
provisions of the Law and the Regulations, in accordance with the mechanism and standards set by
the Competent Authority.
11. Competent Authority Platform: An online platform operated by the Competent Authority to support
the implementation and enforcement of the provisions of the Law and the Regulations.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded