个人资料保护法_第1页
个人资料保护法_第2页
个人资料保护法_第3页
个人资料保护法_第4页
个人资料保护法_第5页
已阅读5页,还剩11页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

PersonalDataProtectionLaw

Article1

ForthepurposeofimplementingthisLaw,thefollowingtermsshallhavethemeaningsassignedthereto,unlessthecontextrequiresotherwise:

Law:ThePersonalDataProtectionLaw.

Regulations:TheImplementingRegulationsoftheLaw.

CompetentAuthority:TheauthoritytobedeterminedbyaresolutionoftheCouncilofMinisters.

PersonalData:Anydata,regardlessofitssourceorform,thatmayleadtoidentifyinganindividualspecifically,orthatmaydirectlyorindirectlymakeitpossibletoidentifyanindividual,includingname,personalidentificationnumber,addresses,contactnumbers,licensenumbers,records,personalassets,bankandcreditcardnumbers,photosandvideosofanindividual,andanyotherdataofpersonalnature.

Processing:AnyoperationcarriedoutonPersonalDatabyanymeans,whethermanualorautomated,includingcollecting,recording,saving,indexing,organizing,formatting,storing,modifying,updating,consolidating,retrieving,using,disclosing,transmitting,publishing,sharing,linking,blocking,erasinganddestroyingdata.

Collection:ThecollectionofPersonalDatabyControllerinaccordancewiththeprovisionsofthisLaw,eitherfromtheDataSubjectdirectly,arepresentativeoftheDataSubject,anylegalguardianovertheDataSubjectoranyotherparty.

Destruction:AnyactiontakenonPersonalDatathatmakesitunreadableandirretrievable,orimpossibletoidentifytherelatedDataSubject.

Disclosure:Enablinganyperson-otherthantheControllerortheProcessor,asthecasemaybe-toaccess,collectorusepersonaldatabyanymeansandforanypurpose.

Transfer:ThetransferofPersonalDatafromoneplacetoanotherforProcessing.

Publishing:TransmittingormakingavailableanyPersonalDatausinganywritten,audioorvisualmeans.

SensitiveData:PersonalDatarevealingracialorethnicorigin,orreligious,intellectualorpoliticalbelief,datarelatingtosecuritycriminalconvictionsandoffenses,biometricorGeneticDataforthepurposeofidentifyingtheperson,HealthData,anddatathatindicatesthatoneorbothoftheindividual’sparentsareunknown.

GeneticData:AnyPersonalDatarelatedtothehereditaryoracquiredcharacteristicsofanaturalpersonthatuniquelyidentifiesthephysiologicalorhealthcharacteristicsofthat

person,andderivedfrombiologicalsampleanalysisofthatperson,suchasDNAoranyothertestingthatleadstogeneratingGeneticData.

HealthData:AnyPersonalDatarelatedtoanindividual'shealthcondition,whethertheirphysical,mentalorpsychologicalconditions,orrelatedtoHealthServicesreceivedbythatindividual.

HealthServices:Servicesrelatedtothehealthofanindividual,includingpreventive,curative,rehabilitativeandhospitalizingservices,aswellastheprovisionofmedications.

CreditData:AnyPersonalDatarelatedtoanindividual'srequestfor,orobtainingof,financingfromafinancingentity,whetherforapersonalorfamilypurpose,includinganydatarelatingtothatindividual’sabilitytoobtainandrepaydebts,andthecredithistoryofthatperson.

DataSubject:TheindividualtowhomthePersonalDatarelate.

PublicEntity:Anyministry,department,publicinstitutionorpublicauthority,anyindependentpublicentityintheKingdom,oranyaffiliatedentitytherewith.

Controller:AnyPublicEntity,naturalpersonorprivatelegalpersonthatspecifiesthepurposeandmannerofProcessingPersonalData,whetherthedataisprocessedbythatControllerorbytheProcessor.

Processor:AnyPublicEntity,naturalpersonorprivatelegalpersonthatprocessesPersonalDataforthebenefitandonbehalfoftheController.

Article2

TheLawappliestoanyProcessingofPersonalDatarelatedtoindividualsthattakesplaceintheKingdombyanymeans,includingtheProcessingofPersonalDatarelatedtoindividualsresidingintheKingdombyanymeansfromanypartyoutsidetheKingdom.Thisincludesthedataofthedeceasedifitwouldleadtothemoramemberoftheirfamilybeingidentifiedspecifically.

ThescopeofapplyingtheLawexcludestheindividual'sPersonalDataProcessingforpurposesthatdonotgobeyondpersonalorfamilyuse,aslongastheDataSubjectdidnotpublishordiscloseittoothers.TheRegulationsshalldefinepersonalandfamilyuseprovidedinthisParagraph.

Article3

TheprovisionsandproceduresstatedinthisLawshallnotprejudiceanyprovisionthatgrantsarighttotheDataSubjectorconfersbetterprotectiontoPersonalDatapursuanttoanyotherlaworaninternationalagreementtowhichtheKingdomisaparty.

Article4

DataSubjectshallhavethefollowingrightspursuanttothisLawandassetoutintheRegulations:

TherighttobeinformedaboutthelegalbasisandthepurposeoftheCollectionoftheirPersonalData.

TherighttoaccesstheirPersonalDataheldbytheController,inaccordancewiththerulesandproceduressetoutintheRegulations,andwithoutprejudicetotheprovisionsofArticle(9)ofthisLaw.

TherighttorequestobtainingtheirPersonalDataheldbytheControllerinareadableandclearformat,inaccordancewiththecontrolsandproceduresspecifiedbytheRegulations.4-Therighttorequestcorrecting,completing,orupdatingtheirPersonalDataheldbytheController.

5-TherighttorequestaDestructionoftheirPersonalDataheldbytheControllerwhensuchPersonalDataisnolongerneededbyDataSubject,withoutprejudicetotheprovisionsofArticle(18)ofthisLaw.

Article5

ExceptforthecasesstatedinthisLaw,neitherPersonalDatamaybeprocessednorthepurposeofPersonalDataProcessingmaybechangedwithouttheconsentoftheDataSubject.TheRegulationsShallsetouttheconditionsoftheconsent,thecasesinwhichtheconsentmustbeexplicit,andthetermsandconditionsrelatedtoobtainingtheconsentofthelegalguardianiftheDataSubjectfullyorpartiallylackslegalcapacity.

Inallcases,DataSubjectmaywithdrawtheconsentmentionedinParagraph(1)ofthisArticleatanytime;theRegulationsdeterminesthenecessarycontrolsforsuchcase.

Article6

Inthefollowingcases,ProcessingofPersonalDatashallnotbesubjecttotheconsentreferredtoinParagraph(1)ofArticle(5)herein:

IftheProcessingservesactualinterestsoftheDataSubject,butcommunicatingwiththeDataSubjectisimpossibleordifficult.

IftheProcessingispursuanttoanotherlaworinimplementationofapreviousagreementtowhichtheDataSubjectisaparty.

IftheControllerisaPublicEntityandtheProcessingisrequiredforsecuritypurposesortosatisfyjudicialrequirements.

IftheProcessingisnecessaryforthepurposeoflegitimateinterestoftheController,withoutprejudicetotherightsandinterestsoftheDataSubject,andprovidedthatnoSensitiveDataistobeprocessed.RelatedprovisionsandcontrolsaresetoutintheRegulations.

Article7

Theconsentreferredtoinparagraph(1)ofArticle(5)ofthisLawmaynotformaconditionofprovidingaserviceorabenefit,unlesssuchserviceorbenefitisdirectlyrelatedtotheProcessingofPersonalDataforwhichtheconsentisgiven.

Article8

SubjecttotheprovisionsofthisLawandtheRegulationsregardingtheDisclosureofPersonalData,theControllershallonlyselectProcessorsprovidingthenecessaryguaranteestoimplementtheprovisionsofthisLawandtheRegulations.TheControllershallalsomonitorthecomplianceofsaidProcessorswiththeprovisionsofthisLawandtheRegulations.ThisshallnotprejudicetheController’sresponsibilitiestowardstheDataSubjectortheCompetentAuthorityasthecasemaybe.TheRegulationsshallsetouttheprovisionsnecessaryinthisregard,includingprovisionsrelatedtoanysubsequentcontractsconductedbytheProcessor.

Article9

TheControllermaysettimeframesforexercisingtherighttoaccessPersonalDatastatedinParagraph(2)ofArticle(4)hereinasstipulatedintheRegulations.TheControllermaylimittheexerciseofthisrightinthefollowingcases:

IfthisisnecessarytoprotecttheDataSubjectorotherpartiesfromanyharm,accordingtotheprovisionssetforththeRegulations.

IftheControllerisaPublicEntityandtherestrictionisrequiredforsecuritypurposes,requiredbyanotherlaw,orrequiredtofulfilljudicialrequirements.

TheControllershallpreventtheDataSubjectfromaccessingPersonalDatainanyofthesituationsstatedinParagraphs(1,2,3,4,5)and(6)ofArticle(16)herein.

Article10

TheControllermayonlycollectPersonalDatadirectlyfromtheDataSubjectandmayonlyprocessPersonalDataforthepurposesforwhichtheyhavebeencollected.However,theControllermaycollectPersonalDatafromasourceotherthattheDataSubjectandmayprocessPersonalDataforpurposesotherthantheonesforwhichtheyhavebeencollectedinthefollowingsituations:

TheDataSubjectgivestheirconsentinaccordancewiththeprovisionsofthisLaw.

PersonalDataispubliclyavailableorwascollectedfromapubliclyavailablesource.

TheControllerisaPublicEntity,andtheCollectionorProcessingofthePersonalDataisrequiredforpublicinterestorsecuritypurposes,ortoimplementanotherlaw,ortofulfilljudicialrequirements.

ComplyingwiththismayharmtheDataSubjectoraffecttheirvitalinterests

PersonalDataCollectionorProcessingisnecessarytoprotectpublichealth,publicsafety,ortoprotectthelifeorhealthofspecificindividuals.

PersonalDataisnottoberecordedorstoredinaformthatmakesitpossibletodirectlyorindirectlyidentifytheDataSubject.

PersonalDataCollectionisnecessarytoachievelegitimateinterestsoftheController,withoutprejudicetotherightsandinterestsoftheDataSubject,andprovidedthatnoSensitiveDataistobeprocessed.

TheRegulationsshallsetouttheprovisions,controlsandproceduresrelatedtowhatisstatedinparagraphs(2)to(7)ofthisArticle.

Article11

ThepurposeforwhichPersonalDataiscollectedshallbedirectlyrelatedtotheController’spurposes,andshallnotcontraveneanylegalprovisions.

ThemethodsandmeansofPersonalDataCollectionshallnotconflictwithanylegalprovisions,shallbeappropriateforthecircumstancesoftheDataSubject,shallbedirect,clearandsecure,andshallnotinvolveanydeception,misleadingorextortion.

ThecontentofthePersonalDatashallbeappropriateandlimitedtotheminimumamountnecessarytoachievethepurposeoftheCollection.ContentthatmayleadtospecificallyidentifyingDataSubjectoncethepurposeofCollectionisachievedshallbeavoided.TheRegulationsshallsetoutthenecessarycontrolsinthisregard.

IfthePersonalDatacollectedisnolongernecessaryforthepurposeforwhichithasbeencollected,theControllershall,withoutunduedelay,ceasetheirCollectionanddestroypreviouslycollectedPersonalData.

Article12

TheControllershalluseaprivacypolicyandmakeitavailabletoDataSubjectsfortheirinformationpriortocollectingtheirPersonalData.ThepolicyshallspecifythepurposeofCollection,PersonalDatatobecollected,themeansusedforCollection,Processing,storageandDestruction,andinformationabouttheDataSubjectrightsandhowtoexercisesuchrights.

Article13

WhencollectingPersonalDatadirectlyfromtheDataSubject,theControllershalltakeappropriatemeasurestoinformtheDataSubjectofthefollowinguponCollection:

ThelegalbasisforcollectingtheirPersonalData.

ThepurposeoftheCollection,andshallspecifythePersonalDatawhoseCollectionismandatoryandthePersonalDatawhoseCollectionisoptional.TheDataSubjectshallbeinformedthatthePersonalDatawillnotbesubsequentlyprocessedinamannerinconsistentwiththeCollectionpurposeorincasesotherthanthosestatedinArticle(10)ofthisLaw.

UnlesstheCollectionisforsecuritypurposes,theidentityofthepersoncollectingthePersonalDataandtheaddressofitsrepresentative,ifnecessary.

TheentitiestowhichthePersonalDatawillbedisclosed,thecapacityofsuchentities,andwhetherthePersonalDatawillbetransferred,disclosedorprocessedoutsidetheKingdom.

ThepotentialconsequencesandrisksthatmayresultfromnotcollectingthePersonalData.

TherightsoftheDataSubjectpursuanttoArticle(4)herein.

SuchotherelementsassetoutintheRegulationsbasedonthenatureoftheactivitydonebytheController.

Article14

TheControllermaynotprocessPersonalDatawithouttakingsufficientstepstoverifythePersonalDataaccuracy,completeness,timelinessandrelevancetothepurposeforwhichitiscollectedinaccordancewiththeprovisionsoftheLaw.

Article15

TheControllermaynotDisclosePersonalDataexceptinthefollowingsituations:

DataSubjectconsentstotheDisclosureinaccordancewiththeprovisionsoftheLaw.

PersonalDatahasbeencollectedfromapubliclyavailablesource.

TheentityrequestingDisclosureisaPublicEntity,andtheCollectionorProcessingofthePersonalDataisrequiredforpublicinterestorsecuritypurposes,ortoimplementanotherlaw,tofulfilljudicialrequirements.

TheDisclosureisnecessarytoprotectpublichealth,publicsafety,ortoprotectthelivesorhealthofspecificindividuals.

TheDisclosurewillonlyinvolvesubsequentProcessinginaformthatmakesitimpossibletodirectlyorindirectlyidentifytheDataSubject.

TheDisclosureisnecessarytoachievelegitimateinterestsoftheController,withoutprejudicetotherightsandinterestsoftheDataSubject,andprovidedthatnoSensitiveDataistobeprocessed.

TheRegulationsshallsetouttheprovisions,controlsandproceduresrelatedtowhatisstatedinparagraphs(2)to(6)ofthisArticle.

Article16

TheControllershallnotdisclosePersonalDatainthesituationsstatedinParagraphs(1,2,5)and(6)ofArticle(15)iftheDisclosure:

Representsathreattosecurity,harmsthereputationoftheKingdom,orconflictswiththeinterestsoftheKingdom.

AffectstheKingdom’srelationswithanyotherstate.

Preventsthedetectionofacrime,affectstherightsofanaccusedtoafairtrial,oraffectstheintegrityofexistingcriminalprocedures.

Compromisesthesafetyofanindividual.

ResultsinviolatingtheprivacyofanindividualotherthantheDataSubject,assetoutintheRegulations.

Conflictswiththeinterestsofapersonthatfullyorpartiallylackslegalcapacity.

Violateslegallyestablishedprofessionalobligations.

Involvesaviolationofanobligation,procedure,orjudicialdecision.

Exposestheidentityofaconfidentialsourceofinformationinamannerdetrimentaltothepublicinterest.

Article17

IfPersonalDataiscorrected,completedorupdated,theControllershallnotifysuchamendmenttoalltheotherentitiestowhichsuchPersonalDatahasbeentransferredandmaketheamendmentavailabletosuchentities.

TheRegulationsshallsetoutthetimeframesforcorrectionandupdatingofPersonalData,typesofcorrection,andtheproceduresrequiredtoavoidtheconsequencesofProcessingincorrect,inaccurateoroutdatedPersonalData.

Article18

TheControllershall,withoutunduedelay,DestroythePersonalDatawhennolongernecessaryforthepurposeforwhichtheywerecollected.However,theControllermayretaindataafterthepurposeoftheCollectionceasestoexist;providedthatitdoesnotcontainanythingthatmayleadtospecificallyidentifyingDataSubjectpursuanttothecontrolsstipulatedintheRegulations.

Inthefollowingcases,theControllershallretainthePersonalDataafterthepurposeoftheCollectionceasestoexist:

IfthereisalegalbasisforretainingthePersonalDataforaspecificperiod,inwhichcasethePersonalDatashallbedestroyeduponthelapseofthatperiodorwhenthepurposeoftheCollectionissatisfied,whicheverlonger.

IfthePersonalDataiscloselyrelatedtoacaseunderconsiderationbeforeajudicialauthorityandtheretentionofthePersonalDataisrequiredforthatpurpose,inwhichcasethePersonalDatashallbedestroyedoncethejudicialproceduresareconcluded.

Article19

TheControllershallimplementallthenecessaryorganizational,administrativeandtechnicalmeasurestoprotectPersonalData,includingduringtheTransferofPersonalData,inaccordancewiththeprovisionsandcontrolssetoutintheRegulations.

Article20

TheControllershallnotifytheCompetentAuthorityuponknowingofanybreach,damage,orillegalaccesstopersonaldata,inaccordancewiththeRegulations.

TheControllershallnotifytheDataSubjectofanybreach,damageorillegalaccesstotheirPersonalDatathatwouldcausedamagetotheirdataorcauseprejudicetotheirrightsandinterests,inaccordancewiththeRegulations.

Article21

TheControllershallrespondtotherequestsoftheDataSubjectpertainingtotheirrightsunderthisLawwithinsuchperiodandinsuchmethodassetoutintheRegulations.

Article22

TheControllershallconductanimpactassessmentofPersonalDataProcessinginrelationtoanyproductorservice,basedonthenatureoftheactivitycarriedoutbytheController,inaccordancewiththerelevantprovisionsoftheRegulations.

Article23

WithoutprejudicetothisLaw,theRegulationsshallsetoutadditionalcontrolsandproceduresfortheProcessingofHealthDatainamannerthatensurestheprivacyoftheDataSubjectandprotectstheirrightsunderthisLaw.Suchadditionalcontrolsandproceduresshallincludethefollowing:

RestrictingtherighttoaccessHealthData,includingmedicalfiles,totheminimumnumberofemployeesorworkersandonlytotheextentnecessarytoprovidetherequiredHealthServices.

RestrictingHealthDataProcessingproceduresandoperationstotheminimumextentpossibleofemployeesandworkersasnecessarytoprovideHealthServicesorofferhealthinsuranceprograms.

Article24

WithoutprejudicetothisLaw,theRegulationsshallsetoutadditionalcontrolsandproceduresfortheProcessingofCreditDatainamannerthatensurestheprivacyoftheDataSubjectandprotectstheirrightsunderthisLawandtheCreditInformationLaw.Suchcontrolsandproceduresshallincludethefollowing:

ImplementingappropriatemeasurestoverifythattheDataSubjecthasgiventheirexplicitconsenttotheCollectionofthePersonalData,changingthepurposeoftheCollection,orDisclosureorPublishingofthePersonalDatainaccordancewiththeprovisionsofthisLawandtheCreditInformationLaw.

RequiringthattheDataSubjectbenotifiedwhenarequestforDisclosureoftheirCreditDataisreceivedfromanyentity.

Article25

Withtheexceptionoftheawareness-raisingmaterialssentbyPublicEntities,Controllermaynotusepersonalmeansofcommunication,includingthepostandemail,oftheDataSubjecttosendadvertisingorawareness-raisingmaterials,unless:

Obtainingthepriorconsentofthetargetedrecipientforsuchmaterials.

Thesenderofthematerialshallprovideaclearmechanism,assetoutintheRegulations,thatenablesthetargetedrecipienttorequeststoppingreceivingsuchmaterialsiftheydesireso.

TheRegulationsshallsetouttheprovisionsconcerningtheaforementionedadvertisingandawareness-raisingmaterials,aswellastheconditionsandsituationsconcerningtheconsentoftherecipienttoreceiveaforementionedmaterials.

Article26

WiththeexceptionofSensitiveData,PersonalDatamaybeprocessedformarketingpurposes,ifitiscollecteddirectlyfromtheDataSubjectandtheirconsentisgiveninaccordancewiththeprovisionsofLaw;theRegulationsshallsetoutthecontrolsinsuchregard.

Article27

Personaldatamaybecollectedorprocessedforscientific,research,orstatisticalpurposeswithouttheconsentoftheDataSubjectinthefollowingsituations:

IfitdoesnotspecificallyidentifytheDataSubject.

IfevidenceoftheDataSubject’sidentitywillbedestroyedduringtheProcessingandpriortoDisclosureofsuchdatatoanyotherentity,ifitisnotSensitiveData.

IfpersonaldataiscollectedorprocessedforthesepurposesisrequiredbyanotherlaworinimplementationofapreviousagreementtowhichtheDataSubjectisaparty.

TheRegulationsshallsetoutthecontrolsrequiredbytheprovisionsofthisArticle.

Article28

ItisnotpermissibletocopyofficialdocumentswhereDataSubjectsareidentifiable,exceptwhereitisrequiredbylaw,orwhenacompetentpublicauthorityrequestscopyingsuchdocumentspursuanttotheRegulations.

Article29

SubjecttotheprovisionsofParagraph(2)ofthisArticle,aControllermayTransferPersonalDataoutsidetheKingdomordiscloseittoapartyoutsidetheKingdom,inordertoachieveanyofthefollowingpurposes:

Ifthisisrelatingtoperforminganobligationunderanagreement,towhichtheKingdomisaparty.

IfitistoservetheinterestsoftheKingdom.

IfthisistotheperformanceofanobligationtowhichtheDataSubjectisaparty

IfthisistofulfillotherpurposesassetoutintheRegulations.

TheconditionsthatmustbemetwhenthereisaTransferorDisclosureofPersonalData,accordingtowhatisstatedinParagraph(1)ofthisArticle,areasfollows:

TheTransferorDisclosureshallnotcauseanyprejudicetonationalsecurityorthevitalinterestsoftheKingdom.

ThereisanadequatelevelofprotectionforPersonalDataoutsidetheKingdom.SuchlevelofprotectionshallbeatleastequivalenttothelevelofprotectionguaranteedbytheLawandRegulations,accordingtotheresultsofanassessmentconductedbytheCompetentAuthorityincoordinationwithwhomeveritdeemsappropriatefromtheotherrelevantauthorities.

TheTransferorDisclosureshallbelimitedtotheminimumamountofPersonalDataneeded.

Paragraph(2)ofthisArticleshallnotapplytocasesofextremenecessitytopreservethelifeorvitalinterestsoftheDataSubjectortoprevent,examineortreatdisease.

TheRegulationsshallsetouttheprovisions,criteriaandproceduresrelatedtotheimplementingthisArticle,includingapplicableexceptionsforControllersregardingconditionsreferredtoinSubparagraphs(b)and(c)ofParagraph(2)ofthisArticle,aswellascontrolsandproceduresforsuchexemptions.

Article30

WithoutprejudicetotheprovisionsofthisLawandthepowersoftheSaudiCentralBankpursuanttoapplicablelegalprovisions,theCompetentAuthorityshallbetheentityinchargeofoverseeingtheimplementationofthisLawandtheRegulations.

TheRegulationsshallidentifythesituationswheretheControllershallappointoneormorepersonsaspersonaldataprotectionofficer(s).andshallsettheresponsibilitiesofanysuchpersoninaccordancewiththeprovisionsofthisLaw.

TheControllershallcooperatewiththeCompetentAuthorityinperformingitsdutiestosupervisetheimplementationoftheprovisionsofthisLawandtheRegulations,andshalltakesuchstepsasnecessaryinconnectionwiththerelatedmattersreferredtotheControllerbytheCompetentAuthority.

TheCompetentAuthority,inordertocarryoutitsdutiesrelatedtosupervisingtheimplementationoftheprovisionsoftheLawandRegulations,may:

RequestthenecessarydocumentsorinformationfromtheControllertoensureitscompliancewiththeprovisionsoftheLawandRegulations.

RequestthecooperationofanyotherpartyforthepurposesofsupportinaccomplishingsupervisorydutiesandenforcementoftheprovisionsoftheLawandRegulations.

SpecifytheappropriatetoolsandmechanismsformonitoringControllers’compliancewiththeprovisionsoftheLawandtheRegulations,includingmaintaininganationalregisterofControllersforthispurpose.

ProvideservicesrelatedtoPersonalDataprotectionthroughthenationalregisterreferredtoinSubparagraph(c)ofthisParagraphorthroughanyothermeansdeemedappropriate.TheCompetentAuthoritymaycollectafeeforthePersonalDataprotectionservicesitmayprovide.

TheCompetentAuthoritymay,atitsdiscretion,delegatetootherauthoritiestheaccomplishmentofsomeofitsdutiesthatarerelatedtosupervisionorenforcementoftheprovisionsoftheLawandRegulations.

Article31

WithoutprejudicetoArticle(18)herein,theControllershallmaintainrecords,forsuchaperiodasrequiredundertheRegulations,ofthePersonalDataProcessingactivities,basedonthenatureoftheactivitycarriedoutbytheController.SuchrecordsaretobeavailablewheneverrequestedbytheCompetentAuthority.Therecordsshallcontainthefollowinginformationataminimum:

ContactdetailsoftheController.

ThepurposeofthePersonalDataProcessing.

DescriptionofthecategoriesofPersonalDataSubjects.

AnyotherentitytowhichPersonalDatahasbeen,orwillbe,disclosed.

WhetherthePersonalDatahasbeenorwillbetransferredoutsidetheKingdomordisclosedtoanentityoutsidetheKingdom.

TheexpectedperiodforwhichPersonalDatashallberetained.

Article32

Repealed.

Article33

TheCompetentAuthorityshallsettherequirementsforpracticingcommercial,professionalornon-profitactivitiesrelatedtoPersonalDataprotectionintheKingdom,incoordinationwiththecompetentauthorities,andwithoutprejudicetotheotherrequirementssetbythoseauthoritiesintheirdomainofcompetence.

TheCompetentAuthoritymaygrantlicensestoentitiesthatissueaccreditationcertificatestoControllersandProcessors.TheCompetentAuthorityshallsettherulestoregulatetheissuanceofsuchcertificates.

TheCompetentAuthoritymaygrantlicensestoentitiesthatconductauditsorchecksofPersonalDataProcessingactivitiesrelatedtotheController’sactivity,inaccordancewiththeprovisionsstipulatedintheRegulations.TheCompetentAuthorityshallsettheconditionsandcriteriatograntsuchlicenses,andtherulesregulatingthem.

TheCompetentAuthorityshallspecifytheappropriatetoolsandmechanismstomonitorcomplianceofControllersandProcessorsoutsidetheKingdominregardwiththeirobligationsasstatedintheLawandtheRegulationswhenProcessingpersonaldatarelatedtoindividualsresidingintheKingdombyanymeans,andshalldefineprocedurestoenforcetheprovisionsoftheLawandtheRegulationsoutsidetheKingdom.

Article34

ADataSubjectmaysubmittotheCompetentAuthorityanycomplaintthatmayariseoutoftheimplementationofthisLawandthe

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论