Alqanoni

ImplementingRegulationPersonalDataProtectionLaw

Art. 25
Status unknownSaudi ArabiaRegulation

Issued by Saudi Data & AI Authority / NDMO

1- The Controller shall prepare a written and documented assessment of the potential impacts and risks that may affect the Data Subject as a result of Personal Data Processing. Impact assessment shall be conducted in the following cases: a) Processing of Sensitive Data. b) Collecting, comparing, or linking two or more datasets of Personal Data obtained from different sources. Public c) The activity of the Controller includes - large scale and repetitive - Processing of Personal Data of those who lack full or partial legal capacity, or processing operations that by their nature require constant monitoring of Data Subjects, or Processing Personal Data based on newly adopted technologies, or making decisions based on automated Personal Data Processing. d) Providing a product or service that involves Processing Personal Data that is likely to cause serious harm to Data Subjects privacy. 2- The impact assessment shall include at least the following elements: a) Purpose of the Processing and its legal basis. b) Description of the nature of the Processing to be conducted, the types and sources of Personal Data to be processed, and any entities to whom the Personal Data is to be Disclosed. c) Description of the scope of the Processing, which identifies the type of Personal Data and the geographical scope of the Processing. d) Description of the Processing context, which identifies the relationship between the Data Subjects, the Controller, and the Processors, as well as any other relevant circumstances. e) Necessity and proportionality of the measures to be taken to enable the Controller and Processors to process the minimum Personal Data necessary to achieve the purposes of the Processing. f) Impact of the Processing, based on the severity of its impact, materially and morally, and the likelihood of any negative impact on Data Subjects, including any psychological, social, physical, or financial impact, and the likelihood of their occurrence. g) Measures that to be taken to prevent or mitigate risks. h) The suitability of planned measures to prevent identified risks. 3- The Controller shall provide a copy of the impact assessment to any Processor acting on its behalf in relation to the relevant Processing. 4- If the impact assessment mentioned in this article indicates that a Processing operation it to harm Data Subjects privacy, the Controller shall address the causes of such harm and re-conduct an impact assessment. Public

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.