ImplementingRegulationPersonalDataProtectionLaw
Art. 27Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
Without prejudice to the provisions of the Credit Information Law, the Controller shall
take organizational, technical, and administrative measures to protect Credit Data
from any unauthorized use, misuse, access by unauthorized individuals, use for
purposes other than for which it was collected, and Disclosure. The Controller shall
adopt the following controls and procedures:
1- Adopt and implement requirements and controls issued by the Saudi Central Bank
and other relevant authorities, which define the roles and responsibilities of
employees of establishments providing credit information services and of the
parties that have contracts with such establishments to process Credit Data.
2- Controller shall obtain Data Subject consent and notify them of any request to
disclose their Credit Data in accordance with the provisions of the Credit
Information Law, while considering the provisions stated in subparagraph (d) of
paragraph (1) of Article 11 of the Regulation.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded