RulesGoverningIssuanceAccreditationCertificatesControllersProcessers
Art. 4Status unknownSaudi ArabiaRegulation
Issued by Saudi Data & AI Authority / NDMO
Requirements for Obtaining Accreditation Certificates
An Applicant shall have the following in place:
1. The tools, means, and procedures for verifying the implementation of personal data processing
activities in accordance with the provisions of the Law and the Regulations.
2. Documented and approved procedures to identify and implement appropriate organizational,
administrative, and technical measures to protect personal data, as well as procedures for
periodically monitoring the effectiveness of such measures.
3. Documented and approved procedures for handling personal data breach incidents, and for
periodically reviewing such procedures.
4. Qualified legal and technical personnel with experience in the regulatory and technical aspects
of personal data protection practices and procedures, with no less than three (3) years of relevant
experience, in addition to a designated Personal Data Protection Officer.
5. Annual plans that include training, awareness programs, and workshops in the field of personal
data protection, directed at employees across different roles and responsibilities.
6. Any additional requirements prescribed by the Licensee, provided they align with the provisions
of the Law and the Regulations and comply with instructions issued by the Competent Authority
regarding their implementation.
Chapter Three: Application Procedures for Accreditation
Certificates
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded