Alqanoni

ImplementingRegulationPersonalDataProtectionLaw

Art. 17
Status unknownSaudi ArabiaRegulation

Issued by Saudi Data & AI Authority / NDMO

1- The Controller shall ensure that any Processor selected provides sufficient guarantees to protect Personal Data, and that the agreement with the Processor includes the following: a) Purpose of the Processing. b) Categories of Personal Data being processed. c) Duration of the Processing. d) Processor's commitment to notify, without undue delay, the Controller in case of a Personal Data Breach occurs, in accordance with the provisions of the Lawthis Regulation. e) Clarification of whether the Processor is subject to Regulations in other countries and the impact on their compliance with the Law and its Regulations. f) Not requiring the Data Subject's prior consent for mandatory Disclosure of Personal Data under the applicable laws in the Kingdom, provided that the Processor notifies the Controller of such Disclosure. g) Identifying any subcontractors contracted by the Processor, or any other party to whom Personal Data will be disclosed. 2- The Controller shall issue clear instructions to the Processor, and in case of any violation of the Controller’s instructions or any applicable laws in the Kingdom, the Processor shall notify the Controller in writing without undue delay. 3- The Controller is responsible to periodically assess Processor's compliance with the Law and its Regulations, and ensuring that all regulatory requirements are met, whether the Processing is achieved by the Processor or third parties acting under their behalf. The Controller may appoint an independent third party to assess and monitor Processor’s compliance on its behalf. 4- If Processor violates the instructions issued by the Controller or the agreement regarding the Processing of Personal Data, the Processor shall be considered as a Controller and held directly accountable for any violation of any provisions of the Law. 5- Before entering any subsequent contracts with sub-Processors, the Processor shall abide by the following: a) Take sufficient guarantees to ensure that such contracts would not impact the level of protection provided to the Personal Data being processed. Public b) Choose only sub-Processors that provide the sufficient guarantees to comply with the Law and its Regulations. c) Obtain prior acceptance from Controller, with the Controller being notified before entering into such contracts and enabling the Controller to object to them within a timeframe agreed upon between the Controller and the Processor.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.