DataClassificationPolicy
Para. 1.4Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
Data Classification Controls
Based on the data classification levels, entities shall identify and
implement appropriate data protection controls to ensure secure handling,
processing, sharing and disposal of data. If data is not classified at the time
of creation or receipt as per the classification criteria, it shall be treated as
“Restricted” until correctly classified.
The data that was not classified at the time of issuing these Policies
shall be classified within a specific period of time according to an action plan
to be prepared by the entity and approved by its head. Below are some
Public
examples of the controls that can be used when classifying data (refer to the
data protection controls and guidelines published by the National
Cybersecurity Authority).
Data Classification controls include but are not limited to the following:
Protective Marking
!! Protective marking shall be applied to paper and electronic documents
(including emails) as per each classification level.
Access
!! Access to data – logical and physical – shall be granted based on the
principles of “Least Privilege” and “Need to Know.”
!! Access shall be denied immediately upon the expiration or termination
of the professional service of entity employees.
Usage
!! Classified data shall be used as per the requirements of the
classification levels. For example, “Top Secret” data shall only be used
within specified locations whether physical (e.g. offices) or virtual (e.g.
using cryptography or special applications).
Storage
!! Data classified as “Top Secret,” “Secret” and “Restricted,” as well as
mobile devices that process or store such data, shall not be left
unattended.
!! Unattended “Top Secret,” “Secret” and “Restricted” data shall be
protected while being physically or electronically stored, using any of
Public
the encryption mechanisms approved by the National Cybersecurity
Authority.
Data Sharing
!! Entities shall decide on the appropriate physical and digital means of
secure data sharing that ensure minimization of potential risks and
compliance with data sharing regulations.
!! Entities shall agree on the data sharing mechanism, whether they will
utilize existing sharing mediums, e.g. Government Service Bus, National
Information Center Network, or Secured Government Network, or will
set up a new direct connection, removable storage media, Wi-Fi,
remote access, VPN, etc.
Data Retention
!! A schedule defining the retention period of all data shall be prepared.
!! The retention period shall be defined based on the applicable business,
contractual, regulatory and legal requirements.
!! The retention schedule shall be reviewed periodically/annually or when
there are changes in the relevant requirements.
Disposal of Data
!! All data shall be securely disposed of according to the data retention
schedule upon the approval of the relevant Business Data Executive.
!! Data which is classified as “Top Secret” or “Secret” and which is
electronically controlled shall be disposed of by using the latest
electronic media disposal methods.
!! All paper-based data shall be disposed of using a cross-cut shredder.
!! A detailed log of all disposed of data shall be maintained.
Public
Archiving
!! Data shall be archived in secure storage locations, as recommended by
the relevant Business Data Executive.
!! Archived data shall be backed up.
!! Archived data classified as “Top Secret” and “Secret” shall be
protected using any of the encryption mechanisms approved by the
National Cybersecurity Authority.
!! A detailed list of users authorized to access archived data shall be
prepared and documented.
Declassification
!! Data shall be declassified or downgraded upon the expiration of the
classification period, or when protection is no longer required at the
original classification level.
!! In case data has been wrongly classified, a data user shall notify the
Business Data Executive to determine the extent to which it is required
to re-classify such data appropriately.
!! Data declassification triggers shall be set when the initial classification
levels are first applied and shall be captured in the data register. These
triggers may include:
o A specified period after data creation or receipt (e.g. two years after
creation);
o A specified period after taking the last action on data (e.g. six months
from the date of the last use);
o After the lapse of a specific date (e.g. to be reviewed on 1 January
Public
o After particular circumstances or events that have a direct impact on
the data (e.g. a change of strategic priorities or a change of the
employees of government entities).
!! Declassification or downgrading of data, beyond the clear
declassification triggers, shall require a sound understanding of both
the sensitive data content and its context.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded