ImplementingRegulationPersonalDataProtectionLaw
Art. 25Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
1- The Controller shall prepare a written and documented assessment of the potential
impacts and risks that may affect the Data Subject as a result of Personal Data
Processing. Impact assessment shall be conducted in the following cases:
a) Processing of Sensitive Data.
b) Collecting, comparing, or linking two or more datasets of Personal Data obtained
from different sources.
Public
c) The activity of the Controller includes - large scale and repetitive - Processing of
Personal Data of those who lack full or partial legal capacity, or processing
operations that by their nature require constant monitoring of Data Subjects, or
Processing Personal Data based on newly adopted technologies, or making
decisions based on automated Personal Data Processing.
d) Providing a product or service that involves Processing Personal Data that is likely
to cause serious harm to Data Subjects privacy.
2- The impact assessment shall include at least the following elements:
a) Purpose of the Processing and its legal basis.
b) Description of the nature of the Processing to be conducted, the types and sources
of Personal Data to be processed, and any entities to whom the Personal Data is
to be Disclosed.
c) Description of the scope of the Processing, which identifies the type of Personal
Data and the geographical scope of the Processing.
d) Description of the Processing context, which identifies the relationship between the
Data Subjects, the Controller, and the Processors, as well as any other relevant
circumstances.
e) Necessity and proportionality of the measures to be taken to enable the Controller
and Processors to process the minimum Personal Data necessary to achieve the
purposes of the Processing.
f) Impact of the Processing, based on the severity of its impact, materially and
morally, and the likelihood of any negative impact on Data Subjects, including any
psychological, social, physical, or financial impact, and the likelihood of their
occurrence.
g) Measures that to be taken to prevent or mitigate risks.
h) The suitability of planned measures to prevent identified risks.
3- The Controller shall provide a copy of the impact assessment to any Processor acting
on its behalf in relation to the relevant Processing.
4- If the impact assessment mentioned in this article indicates that a Processing
operation it to harm Data Subjects privacy, the Controller shall address the causes of
such harm and re-conduct an impact assessment.
Public
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded