PersonalDataDestructionAnonymizationAndEncryptionGuideline
Art. 25Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
C) Implement appropriate organizational, administrative, and technical
measures to mitigate risks, ensuring that these measures are up-to-date
and aligned with technological advancements and evolving anonymization
techniques.
D) Evaluate the effectiveness of implemented anonymization techniques and
implement requisite adjustments to ensure the sustained irreversibility of the
anonymization process.
Third: Pseudonymisation
Pseudonymisation is defined as the process of transforming primary identifiers
that reveal the identity of the data subject into codes that render the direct
identification of the data subject infeasible without the use of additional data or
information. Such additional data or information shall be maintained separately
and subjected to adequate technical and administrative controls to ensure that it
cannot be definitively linked to the data subject.
Pseudonymised data is considered personal data because it may be used, in one
way or another, to identify a specific individual. “Pseudonymisation” serves as a
protective measure for personal data and is deemed an appropriate technical
safeguard against the risks associated with personal data processing. However,
Public
Classification:
Document
its effectiveness in safeguarding personal data is not equivalent to that of
“anonymization”. One example of Pseudonymisation is substituting one or more
of the data subject's PII elements. For instance, the name is substituted with a
symbol (such as a reference number).
Pseudonymisation shall be applied whenever personal data, including personal
data linked to an individual other than the data subject, is disclosed. In such
instances, the personal data of the individual shall be Pseudonymised to ensure
their privacy. Pseudonymisation shall also be applied when personal data is
collected or processed for scientific, research, or statistical purposes without the
data subject's consent, provided that such Pseudonymisation does not
compromise the purpose for which the data is being processed.
Examples of Anonymization and Pseudonymisation Techniques:
Technical measures employed to anonymize and Pseudonyms personal data vary
depending on the specific data being processed and the Controller's regulations.
These measures must be regularly reviewed and updated to ensure that the data
cannot be linked to a specific data subject.
Examples of Commonly Used Techniques:
A) Data Generalization: The substitution of specific attributes with more
generalized values. For instance, aggregating ages into age bands (20-30,
30-40) rather than using precise age values.
B) Data Aggregation: The consolidation of individual data points into a range,
group, or category, for instance, recording only the birth year instead of the
full birthdate. It should ensured that the aggregated data cannot be used to
infer information about specific individuals.
Public
Classification:
Document
C) Data Encryption: The process of transforming personal data into a secure
code using robust cryptographic algorithms. Cryptographic keys must be
stored securely and separately from the encrypted data.
D) Data Masking: The application of data masking techniques to conceal or
obscure specific data elements.
Fourth: General Guidelines
1- All
activities
involving
data
anonymization,
destruction,
and
Pseudonymisation shall be conducted in compliance with the Personal Data
Protection Law, its Implementing Regulations, and any applicable
regulatory requirements issued by relevant competent authorities.
2- All employees involved in data security shall be adequately trained on the
importance of secure data Pseudonymisation and anonymization.
3- The Controller shall ensure that no personal data is lost, misplaced, or
disclosed to any unauthorized third party during the destruction,
anonymization, or Pseudonymisation process.
4- All printed documents shall be disposed of in a manner that renders the
personal data irretrievable (e.g., shredding using secure shredding
machines and disposing of the waste securely) in accordance with the
regulatory requirements issued by relevant competent authorities.
5- Detailed records shall be maintained of all data anonymization and
destruction activities, including the techniques used, the justification for
their selection, and ensuring that such records are available upon request
from the competent authority.
6- The Controller shall regularly review and update its data anonymization,
destruction, and Pseudonymisation techniques to address emerging risks
and technological advancements.
Public
Classification:
Document
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded