FreedomOfInformationPolicy
Para. 4.4Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
Obligations of Public Entities
1. A public entity shall be responsible for preparing and implementing policies
and procedures related to exercising the right to access or obtain public
information, and the head of the entity shall be responsible for adopting and
approving these policies and procedures.
2. A public entity shall establish an administrative unit linked to the data
management offices at government entities established pursuant to the Royal
Order no. 59766, dated 20/11/1439H. This unit shall be assigned the
responsibility to develop, document and monitor the implementation of
policies and procedures approved by the entity’s senior management and
related to the right to access public information. The functions and
responsibilities of that unit shall include development of appropriate
standards to determine the data classification levels in case of their absence
– according to the Data Classification Policy – and to use these standards as
a main reference upon addressing the requests for access to or obtainment
of public information.
3. A public entity shall determine and provide possible means (forms for
public information requests) – whether in paper or electronic form – through
which an applicant can request access to or obtainment of public information.
4. A public entity shall verify the identity of individuals before granting them
the right to access or obtain public information in accordance with the
controls approved by the National Cyber Security Authority and the relevant
entities.
5. A public entity shall set the necessary standards for determining the fees
for processing requests to access or obtain public information based on the
Public
nature and size of the data, the effort spent, and the time taken, as per the
Data Monetization Framework Policy1.
6. A public entity shall document all records of requests to access or obtain
public information and the decisions made with regard thereto, provided that
these records are revised to address cases of misuse or non-response.
7. A public entity shall prepare and document policies and procedures for
proper record keeping and for disposal thereof, in accordance with the laws
and regulations related to entity functions and activities.
8. A public entity shall prepare and document the necessary procedures to
manage, process, and document the requests for extension and denied
requests. It shall also define the roles and responsibilities of the concerned
staff and shall decide on the cases to be notified to the Regulatory Authority
and NDMO as per the administrative hierarchy and in accordance with the
time period specified for processing requests.
9. A public entity shall notify an applicant – in an appropriate manner – in the
event that his request is rejected in whole or in part, explaining the reasons
for denial and highlighting the right to appeal and how to exercise this right
within a period not exceeding 15 days from the date on which the decision
was made.
10. A public entity shall launch awareness-raising programs to promote a
culture of transparency and raise awareness pursuant to the Freedom of
Information Policies and Procedures approved by the senior management of
the entity.
11. A public entity shall be responsible for monitoring compliance with the
Freedom of Information Policies and Procedures on a periodical basis and for
!!!"#$%#&#'()*#+,$(-$.$/.,.$0(+#,12.,1(+$34.*#5(46$7('189$1:$+(5$1+$)4(;4#::<!
Public
presenting the results to the head of the entity (or his designee). It shall also
determine and document the corrective measures to be taken in case of non-
compliance and shall notify the Regulatory Authority and NDMO as per the
administrative hierarchy.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded