ImplementingRegulationPersonalDataProtectionLaw
Art. 32Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
1- The Controller shall appoint one or more individuals to be responsible for the
protection of Personal Data in any of the following cases:
a) The Controller is a Public Entity that provides services involving Processing of
Personal Data on a large scale.
b) The controller’s primary activities are based on processing operations that, by their
nature, require regular and systematic monitoring of Data Subjects.
Public
c) Core activities of the Controller are based on processing sensitive Personal Data.
2- Subject to the requirements of paragraph (1) of this Article, the data protection
officer may be an executive, an employee or an external contractor of the
Controller.
3- The personal data protection officer is responsible for monitoring the
implementation of the provisions of the Law and its Regulations, overseeing the
procedures adopted by the Controller, and receiving requests related to Personal
Data in accordance with the provisions of the Law and its Regulations. Specifically,
their responsibilities include:
a) Acting as the direct point of contact with the Competent Authority and implementing
its decisions and instructions regarding the application of the provisions of the Law
and its Regulations.
b) Supervising impact assessment procedures, audit and control reporting related to
Personal Data protection requirements, documenting assessment results, and
issuing necessary recommendations.
c) Enabling the Data Subject to exercise their rights as stipulated in the Law.
d) Notifying the Competent Authority of Personal Data Breach incidents.
e) Responding to requests from Data Subjects and addressing complaints filed by
them in accordance with the provisions of the Law and its Regulations
f) Monitoring and updating the records of personal data processing activities of the
Controller.
g) Handling Controller’s violations related to Personal Data and taking corrective
actions accordingly.
4. The Competent Authority shall issue rules for the appointment of the data protection
officer, which shall include the circumstances under which a data protection officer shall
be appointed.
Public
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded