PersonalDataProtectionLaw
Art. 29Status unknownSaudi ArabiaRegulation
Issued by Ministry of Investment (misa.gov.sa)
1-Subject to the provisions of Paragraph (2) of this Article, a Controller may Transfer
Personal Data outside the Kingdom or disclose it to a party outside the Kingdom, in
order to achieve any of the following purposes:
A.! If this is relating to performing an obligation under an agreement, to which the
Kingdom is a party.
B.! If it is to serve the interests of the Kingdom.
C.! If this is to the performance of an obligation to which the Data Subject is a party
D.! If this is to fulfill other purposes as set out in the Regulations.
2-The conditions that must be met when there is a Transfer or Disclosure of
Personal Data, according to what is stated in Paragraph (1) of this Article, are as
follows:
A.! The Transfer or Disclosure shall not cause any prejudice to national security or
the vital interests of the Kingdom.
B.! There is an adequate level of protection for Personal Data outside the Kingdom.
Such level of protection shall be at least equivalent to the level of protection
guaranteed by the Law and Regulations, according to the results of an
assessment conducted by the Competent Authority in coordination with
whomever it deems appropriate from the other relevant authorities.
C.! The Transfer or Disclosure shall be limited to the minimum amount of Personal
Data needed.
3-Paragraph (2) of this Article shall not apply to cases of extreme necessity to preserve
the life or vital interests of the Data Subject or to prevent, examine or treat disease.
4-The Regulations shall set out the provisions, criteria and procedures related to the
implementing this Article, including applicable exceptions for Controllers regarding
conditions referred to in Subparagraphs (b) and (c) of Paragraph (2) of this Article, as
well as controls and procedures for such exemptions.
Public
1-! Without prejudice to the provisions of this Law and the powers of the Saudi Central
Bank pursuant to applicable legal provisions, the Competent Authority shall be the
entity in charge of overseeing the implementation of this Law and the Regulations.
2-! The Regulations shall identify the situations where the Controller shall appoint one or
more persons as personal data protection officer(s). and shall set the responsibilities
of any such person in accordance with the provisions of this Law.
3-! The Controller shall cooperate with the Competent Authority in performing its duties
to supervise the implementation of the provisions of this Law and the Regulations,
and shall take such steps as necessary in connection with the related matters
referred to the Controller by the Competent Authority.
4-! The Competent Authority, in order to carry out its duties related to supervising the
implementation of the provisions of the Law and Regulations, may:
A.! Request the necessary documents or information from the Controller to ensure
its compliance with the provisions of the Law and Regulations.
B.! Request the cooperation of any other party for the purposes of support in
accomplishing supervisory duties and enforcement of the provisions of the Law
and Regulations.
C.! Specify the appropriate tools and mechanisms for monitoring Controllers’
compliance with the provisions of the Law and the Regulations, including
maintaining a national register of Controllers for this purpose.
D.! Provide services related to Personal Data protection through the national register
referred to in Subparagraph (c) of this Paragraph or through any other means
deemed appropriate. The Competent Authority may collect a fee for the Personal
Data protection services it may provide.
5-! The Competent Authority may, at its discretion, delegate to other authorities the
accomplishment of some of its duties that are related to supervision or enforcement
of the provisions of the Law and Regulations.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded