ImplementingRegulationPersonalDataProtectionLaw
Art. 24Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
1- The Controller shall notify the Competent Authority within a delay not exceeding (72)
hours of becoming aware of the incident, if such incident potentially causes harm to
the Personal Data, or to Data Subject or conflict with their rights or interests. the
notification shall include the following:
a) A description of the Personal Data Breach incident, including the time, date, and
circumstances of the breach and the time when the Controller became aware of it.
b) Data categories, actual or approximate numbers of impacted Data Subjects, and
the type of Personal Data.
c) Description of the risks of the Personal Data Breach, including the actual or
potential impact on Personal Data and Data Subjects, and the actions and
measures taken by the Controller to prevent or limit the impact of those risks and
mitigate them, as well as the future measures that will be taken to avoid a
recurrence of the breach.
d) A Statement if the Data Subject has been notified of the breach of their Personal
Data, as stipulated in Paragraph (5) of this Article.
e) Contact details of the Controller or its data protection officer, if any, or any other
official having information regarding the reported incident.
Public
2- If the Controller is not able to provide any of the required information within (72) hours
from the time it became aware of the Personal Data Breach in accordance with
paragraph (1) of this article, it shall provide it as soon as possible, along with
justifications for the delay.
3- The Controller shall keep a copy of the reports submitted to the Competent Authority
under paragraph (1) of this article and document the corrective measures taken in
relation with the Personal Data Breach, as well as any relevant documents or
supporting evidence.
4- The provisions of this article do not prejudice the obligations of the Controller or
Processor to submit any report or notification about Personal Data Breaches
according to what is issued by the National Cybersecurity Authority or any laws and
Regulations applicable in the Kingdom.
5- The Controller shall, without undue delay, notify the Data Subject of a Personal Data
Breach, if it may cause damage to their data or conflict with their rights or interests,
provided that the notification is in simple and clear language, and that it includes the
following:
a) Description of the Personal Data Breach.
b) Description of the potential risks arising from the Personal Data Breach, and the
measures taken to prevent or limit those risks and limit their impact.
c) Name and contact details of the Controller and its data protection officer, if any, or
any other appropriate means of communication with the Controller.
d) Any recommendations or advice that may assist the Data Subject in taking
appropriate measures to avoid the identified risks or limit their impact.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded