ImplementingRegulationPersonalDataProtectionLaw
Art. 23Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
The Controller shall take the necessary organizational, administrative, and technical
measures to ensure Personal Data security and Data Subjects privacy, and shall comply
with the following:
a) Implement necessary security and technical measures to limit security risks related
to Personal Data breach.
b) Adopt all relevant controls, standards, and rules issued by the National
Cybersecurity Authority, or adopt recognized best practices and cybersecurity
standards If the Controller is not obligated to follow the controls, standards, and
rules issued by the National Cybersecurity Authority.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded