Alqanoni

ImplementingRegulationPersonalDataProtectionLaw

Art. 9
Status unknownSaudi ArabiaRegulation

Issued by Saudi Data & AI Authority / NDMO

1- When a Controller anonymizes the Personal Data of a Data Subject, it shall comply with the following: a) Ensure that re-identification of the Data Subject is impossible after Anonymisation. b) Evaluate the impact, including the possibility of re-identifying the Data Subject, in the circumstances specified in Paragraph (1) of Article 25 of this Regulation. c) Take the necessary organizational, administrative, and technical measures to avoid risks, taking into account technological developments and methods of Anonymisation, and update those methods considering such developments. d) Evaluate the effectiveness of the applied techniques for Personal Data Anonymization and make necessary adjustments to ensure that re-identification of Data Subject is impossible. 2- Anonymized data shall no longer be considered as Personal Data.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.