PersonalDataProtectionLaw
Art. 33Status unknownSaudi ArabiaRegulation
Issued by Ministry of Investment (misa.gov.sa)
1-The Competent Authority shall set the requirements for practicing commercial,
professional or non-profit activities related to Personal Data protection in the Kingdom, in
coordination with the competent authorities, and without prejudice to the other
requirements set by those authorities in their domain of competence.
2-The Competent Authority may grant licenses to entities that issue accreditation
certificates to Controllers and Processors. The Competent Authority shall set the rules to
regulate the issuance of such certificates.
3-The Competent Authority may grant licenses to entities that conduct audits or checks of
Personal Data Processing activities related to the Controller’s activity, in accordance with
the provisions stipulated in the Regulations. The Competent Authority shall set the
conditions and criteria to grant such licenses, and the rules regulating them.
4-The Competent Authority shall specify the appropriate tools and mechanisms to monitor
compliance of Controllers and Processors outside the Kingdom in regard with their
obligations as stated in the Law and the Regulations when Processing personal data
related to individuals residing in the Kingdom by any means, and shall define procedures to
enforce the provisions of the Law and the Regulations outside the Kingdom.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded