ImplementingRegulationPersonalDataProtectionLaw
Art. 8Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
1- The Controller shall destroy Personal Data in any of the following cases:
a) Upon Data Subject's request.
b) If the Personal Data are no longer necessary to achieve the purpose for which they
were collected.
c) If the Data Subject withdraws their consent, and consent is the sole legal basis for
Processing.
d) If the Controller becomes aware that the Personal Data have been unlawfully
processed.
2- When destroying Personal Data, the Controller shall take the following steps:
a) Take appropriate measures to notify other parties to whom the Controller has
disclosed such Personal Data and request their Destruction.
b) Take the appropriate measures to notify the individuals to whom the Personal Data
have been disclosed by any means and request their Destruction.
c) Destroy all copies of the Personal Data stored in the Controller's systems, including
backups, in accordance with relevant regulatory requirements.
3- The provisions of this article shall not prejudice the requirements specified in Article
18 of the Law and the legal requirements established by the relevant Competent
Authorities.
Public
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded