ImplementingRegulationPersonalDataProtectionLaw
Art. 9Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
1- When a Controller anonymizes the Personal Data of a Data Subject, it shall comply
with the following:
a) Ensure that re-identification of the Data Subject is impossible after Anonymisation.
b) Evaluate the impact, including the possibility of re-identifying the Data Subject, in
the circumstances specified in Paragraph (1) of Article 25 of this Regulation.
c) Take the necessary organizational, administrative, and technical measures to avoid
risks, taking
into
account technological
developments
and
methods of
Anonymisation, and update those methods considering such developments.
d) Evaluate the effectiveness of the applied techniques for Personal Data
Anonymization and make necessary adjustments to ensure that re-identification of
Data Subject is impossible.
2- Anonymized data shall no longer be considered as Personal Data.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded