ImplementingRegulationPersonalDataProtectionLaw
Art. 17Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
1- The Controller shall ensure that any Processor selected provides sufficient guarantees
to protect Personal Data, and that the agreement with the Processor includes the
following:
a) Purpose of the Processing.
b) Categories of Personal Data being processed.
c) Duration of the Processing.
d) Processor's commitment to notify, without undue delay, the Controller in case of a
Personal Data Breach occurs, in accordance with the provisions of the Lawthis
Regulation.
e) Clarification of whether the Processor is subject to Regulations in other countries
and the impact on their compliance with the Law and its Regulations.
f) Not requiring the Data Subject's prior consent for mandatory Disclosure of
Personal Data under the applicable laws in the Kingdom, provided that the
Processor notifies the Controller of such Disclosure.
g) Identifying any subcontractors contracted by the Processor, or any other party to
whom Personal Data will be disclosed.
2- The Controller shall issue clear instructions to the Processor, and in case of any
violation of the Controller’s instructions or any applicable laws in the Kingdom, the
Processor shall notify the Controller in writing without undue delay.
3- The Controller is responsible to periodically assess Processor's compliance with the
Law and its Regulations, and ensuring that all regulatory requirements are met,
whether the Processing is achieved by the Processor or third parties acting under their
behalf. The Controller may appoint an independent third party to assess and monitor
Processor’s compliance on its behalf.
4- If Processor violates the instructions issued by the Controller or the agreement
regarding the Processing of Personal Data, the Processor shall be considered as a
Controller and held directly accountable for any violation of any provisions of the Law.
5- Before entering any subsequent contracts with sub-Processors, the Processor shall
abide by the following:
a) Take sufficient guarantees to ensure that such contracts would not impact the level
of protection provided to the Personal Data being processed.
Public
b) Choose only sub-Processors that provide the sufficient guarantees to comply with
the Law and its Regulations.
c) Obtain prior acceptance from Controller, with the Controller being notified before
entering into such contracts and enabling the Controller to object to them within a
timeframe agreed upon between the Controller and the Processor.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded