ImplementingRegulationPersonalDataProtectionLaw
Art. 36Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
1- The purpose of auditing and controlling is to ensure that the entity is properly
protecting Personal Data through audits and checks of Personal Data processing
activities, and related controls and procedures, and identification of compliance gaps
with the Law and its Regulations.
2- When carrying out audits or controls of Personal Data Processing activities, the
following shall be respected:
a) Providing services with independence according to applicable professional
standards.
b) Developing the necessary administrative and organizational procedures and
controls to ensure the accuracy and integrity issued output.
3- The Competent Authority shall issue the rules for licensing entities that undertake
auditing or checking of Personal Data Processing activities in accordance with
paragraph (3) of Article 33 of the Law. The Competent Authority shall also coordinate
with the Digital Government Authority regarding licensing for entities providing
services on behalf of government entities.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded