Alqanoni

PersonalDataDestructionAnonymizationAndEncryptionGuideline

Art. 25
Status unknownSaudi ArabiaRegulation

Issued by Saudi Data & AI Authority / NDMO

C) Implement appropriate organizational, administrative, and technical measures to mitigate risks, ensuring that these measures are up-to-date and aligned with technological advancements and evolving anonymization techniques. D) Evaluate the effectiveness of implemented anonymization techniques and implement requisite adjustments to ensure the sustained irreversibility of the anonymization process. Third: Pseudonymisation Pseudonymisation is defined as the process of transforming primary identifiers that reveal the identity of the data subject into codes that render the direct identification of the data subject infeasible without the use of additional data or information. Such additional data or information shall be maintained separately and subjected to adequate technical and administrative controls to ensure that it cannot be definitively linked to the data subject. Pseudonymised data is considered personal data because it may be used, in one way or another, to identify a specific individual. “Pseudonymisation” serves as a protective measure for personal data and is deemed an appropriate technical safeguard against the risks associated with personal data processing. However, Public Classification: Document its effectiveness in safeguarding personal data is not equivalent to that of “anonymization”. One example of Pseudonymisation is substituting one or more of the data subject's PII elements. For instance, the name is substituted with a symbol (such as a reference number). Pseudonymisation shall be applied whenever personal data, including personal data linked to an individual other than the data subject, is disclosed. In such instances, the personal data of the individual shall be Pseudonymised to ensure their privacy. Pseudonymisation shall also be applied when personal data is collected or processed for scientific, research, or statistical purposes without the data subject's consent, provided that such Pseudonymisation does not compromise the purpose for which the data is being processed. Examples of Anonymization and Pseudonymisation Techniques: Technical measures employed to anonymize and Pseudonyms personal data vary depending on the specific data being processed and the Controller's regulations. These measures must be regularly reviewed and updated to ensure that the data cannot be linked to a specific data subject. Examples of Commonly Used Techniques: A) Data Generalization: The substitution of specific attributes with more generalized values. For instance, aggregating ages into age bands (20-30, 30-40) rather than using precise age values. B) Data Aggregation: The consolidation of individual data points into a range, group, or category, for instance, recording only the birth year instead of the full birthdate. It should ensured that the aggregated data cannot be used to infer information about specific individuals. Public Classification: Document C) Data Encryption: The process of transforming personal data into a secure code using robust cryptographic algorithms. Cryptographic keys must be stored securely and separately from the encrypted data. D) Data Masking: The application of data masking techniques to conceal or obscure specific data elements. Fourth: General Guidelines 1- All activities involving data anonymization, destruction, and Pseudonymisation shall be conducted in compliance with the Personal Data Protection Law, its Implementing Regulations, and any applicable regulatory requirements issued by relevant competent authorities. 2- All employees involved in data security shall be adequately trained on the importance of secure data Pseudonymisation and anonymization. 3- The Controller shall ensure that no personal data is lost, misplaced, or disclosed to any unauthorized third party during the destruction, anonymization, or Pseudonymisation process. 4- All printed documents shall be disposed of in a manner that renders the personal data irretrievable (e.g., shredding using secure shredding machines and disposing of the waste securely) in accordance with the regulatory requirements issued by relevant competent authorities. 5- Detailed records shall be maintained of all data anonymization and destruction activities, including the techniques used, the justification for their selection, and ensuring that such records are available upon request from the competent authority. 6- The Controller shall regularly review and update its data anonymization, destruction, and Pseudonymisation techniques to address emerging risks and technological advancements. Public Classification: Document

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Related articles

No related articles found.

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.