ImplementingRegulationPersonalDataProtectionLaw
Art. 33Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
1- The Controller shall keep a record of Personal Data Processing activities during all
the period Personal Data is being processed, and till to five years after the date of
end of any Personal Data Processing activity.
2- Records of Personal Data Processing activities shall be written.
3- Controller shall ensure that the records of Personal Data Processing activities are
accurate and up to date.
4- Controller shall provide access to the records of Personal Data Processing activities
to the Competent Authority upon request.
5- The record of Personal Data Processing activities shall include, at a minimum, the
following:
a) Controller’s name and relevant contact details.
b) Information about the Data Protection Officer, where required in accordance with
Article (32) of this Regulation.
c) Purposes of the Personal Data processing.
d) Description of Personal Data categories being processed and Data Subjects
categories.
e) Retention periods for each Personal Data category, where possible.
f) Categories of recipients to whom the Personal Data is disclosed.
g) Description of operations of Personal Data Transfer outside the Kingdom,
including the legal basis for the Transfer and recipient parties.
h) Description of the procedures and organizational, administrative, and technical
measures in place that ensure the security of Personal Data, where possible.
6- Competent Authority shall provide templates of records of Personal Data
Processing activities.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded