Database

Browse Database

SAUDI ARABIA

Since December 2020

Pillar Content access  |  Sub-pillar Licensing schemes for digital services and applications
Cloud Computing Regulatory Framework
The telecommunications regulator in the Kingdom of Saudi Arabia (The Communication and Information Technology Commission (CITC), issued a revised version 3 of its Cloud Computing Regulatory Framework (CCRF v3), which came into effect on 18/04/1442 H (corresponding to 3 December 2020). The CCRF v3 replaces version 2 of the Cloud Computing Regulatory Framework (CCRF v2). According to Art. 3.2.1 of the CCRF v3, no service provider has the right to exercise direct or effective control over the data center or the critical infrastructure of a cloud computing system hosted and used in Saudi Arabia for the purpose of providing cloud computing services unless it is validly registered with the CITC. Whilst this registration obligation is not new, the CCRF v3 imposes a new obligation on a CSP that exercises control of such data centers to use telecommunications infrastructure (including international infrastructure) through operators licensed by the CITC.
Coverage Cloud computing

SAUDI ARABIA

Since 2016

Pillar Content access  |  Sub-pillar Licensing schemes for digital services and applications
Executive Regulation for Electronic Publishing
Online publishers (including publishers of blogs, forums and short messaging) cannot operate without explicit approval from the highest levels of government. The Executive Regulation for Electronic Publishing Activity stipulates licensing by the Media Ministry as a requirement for those seeking to publish online (Article 7). The regulation requires applicants to be Saudi nationals, be at least 25 years old, be a university graduate, be of “good conduct,” and not be employed by the government. Article 15 of the Law prohibits publishing anything that contravenes Islamic law, violates public order, or serves “foreign interests,” as well as material inciting a “spirit of discord” within society.
Coverage Online publishers, including publishers of blogs, forums and short messaging

SAUDI ARABIA

Reported in 2016, 2020, 2021

Pillar Content access  |  Sub-pillar Blocking or filtering of commercial web content
Blocking of commercial web content
It is reported that over 500,000 websites were blocked in the Saudi Arabia between 2007 and 2020. The websites of the London-based Al-Araby al-Jadeed and its English-language New Arab were blocked in January 2016 and remain blocked as of June 2021.
It is also reported that Saudi authorities frequently block news and other websites due to geopolitical considerations. Some Qatari, Iranian, and Turkish news sites were blocked in 2017, 2018, and 2020 respectively, amid continued political tensions between those countries and Saudi Arabia. News sites with opposing views to the Saudi government are also blocked, including the website of Beirut-based broadcaster al-Manar.
Coverage Online news, websites

SAUDI ARABIA

Reported in 2022

Pillar Content access  |  Sub-pillar Presence of Internet shutdowns
Presence of Internet shutdowns
The indicator "6.2.4 - Government Internet shut down in practice" of the V-Dem Dataset, which measures whether the government has the technical capacity to actively make internet service cease, thus interrupting domestic access to the internet or whether the government has decided to do so, has a score of 2 in Saudi Arabia. This corresponds to "The government shut down domestic access to the Internet several times this year."
Coverage Internet access

SAUDI ARABIA

Reported in 2016, 2021

Pillar Intermediary liability  |  Sub-pillar User identity requirement
User Identity Requirement
Individuals must use their legal names when signing mobile-service contracts and must provide a national identification card or residence permit. This information is then shared with a database maintained by the Interior Ministry.
Coverage Mobile services

SAUDI ARABIA

Reported in 2016, 2021

Pillar Intermediary liability  |  Sub-pillar User identity requirement
User Identity Requirement
It is reported that since 2016, the Communications and Information Technology Commission (CITC) has required mobile service providers to register the fingerprints of new SIM card subscribers.
Coverage Horizontal

SAUDI ARABIA

Since July 2019

Pillar Intermediary liability  |  Sub-pillar Safe harbour for intermediaries for copyright infringement
Royal Decree No. M/126 of 07/11/1440H on E-commerce Law
The E-commerce Law establishes a safe harbour regime for intermediaries for copyright infringements. Art. 12 of the law provides a safe harbor for intermediary liabilities by excluding them from penalties if the intermediary platforms delete any content that violates the provisions of the laws and regulations within one day from the date of notification by the government.
Coverage Intermediaries

SAUDI ARABIA

Since July 2019

Pillar Intermediary liability  |  Sub-pillar Safe harbour for intermediaries for any activity other than copyright infringement
Royal Decree No. M/126 of 07/11/1440H on E-commerce Law
The E-commerce Law establishes a safe harbour regime for intermediaries beyond copyright infringement. Art. 12 of the law provides a safe harbor for intermediary liabilities by excluding them from penalties if the intermediary platforms delete any content that violates the provisions of the laws and regulations within one day from the date of notification by the government.
Coverage Intermediaries

SAUDI ARABIA

Since 2021, entry into force in March 2022

Pillar Domestic data policies  |  Sub-pillar Requirement to allow the government to access personal data collected
Royal Decree M/19 of 9/2/1443H on Personal Data Protection Law
The Personal Data Protection Law states that a data owner’s prior consent is required to process their personal data unless the data controller is a government entity and the processing is required for security purposes or to satisfy judicial requirements. It is not clear whether the government can access personal data without a court order for security purposes.
Coverage Horizontal

SAUDI ARABIA

Since April 2020

Pillar Domestic data policies  |  Sub-pillar Requirement to perform an impact assessment (DPIA) or have a data protection officer (DPO)
General Principles for Personal Data Protection in the Telecommunication, IT, and Postal Services
According to Art. 5.2 of the General Principles for Personal Data Protection in the Telecommunication, IT, and Postal Services, service providers are mandated to assign the role and responsibilities of customers’ personal data protection to an independent function.
Coverage Telecommunication, IT, and Postal Services

SAUDI ARABIA

Since 2021, entry into force in March 2022

Pillar Domestic data policies  |  Sub-pillar Requirement to perform an impact assessment (DPIA) or have a data protection officer (DPO)
Royal Decree M/19 of 9/2/1443H on Personal Data Protection Law
The Personal Data Protection Law mandates data privacy impact assessments whereby controllers must conduct an evaluation of the effects of processing associated with any product or service provided to the public.
Coverage Horizontal

SAUDI ARABIA

Since September 2021, entry into force in March 2022

Pillar Domestic data policies  |  Sub-pillar Framework for data protection
Royal Decree M/19 of 9/2/1443H on Personal Data Protection Law
The Personal Data Protection Law (PDPL) establishes a comprehensive data protection regime in Saudi Arabia. The PDPL applies to any processing of personal data carried out in Saudi Arabia by companies or public entities by any means, including the processing of personal data of Saudi residents by entities located outside the Kingdom. Furthermore, the second clause of the law establishes the Saudi Data & Artificial Intelligence Authority (SDAIA) as the competent authority to supervise the implementation of the provisions of the system and its regulations, however, a transfer of supervision to the National Data Management Office (NDMO) will be considered in the future.
Coverage Horizontal

SAUDI ARABIA

Since September 2019

Pillar Domestic data policies  |  Sub-pillar Minimum period for data retention
Internet of Things (IoT) Regulatory Framework
Art. 7 of the Internet of Things (IoT) Regulatory Framework requires that IoT service providers must provide the technical capabilities in the IoT devices and machines to save and maintain the data to make it possible to be reviewed for a duration not less than 12 months or any other duration specified by the Communication and Information Technology Commission (CITC).
Coverage IoT Services

SAUDI ARABIA

N/A

Pillar Cross-border data policies  |  Sub-pillar Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
Saudi Arabia has not joined any agreement with binding commitments to open transfers of data across borders.
Coverage Horizontal

SAUDI ARABIA

Since 2021, entry into force in March 2022

Pillar Cross-border data policies  |  Sub-pillar Conditional flow regime
Royal Decree M/19 of 9/2/1443H on Personal Data Protection Law
Art. 29 of the Personal Data Protection Law generally prohibits data controllers from transferring personal data outside of Saudi Arabia or disclosing personal data to an entity outside of Saudi Arabia, except where:
- the transfer or disclosure will not adversely affect the national security or the vital interests of the Kingdom;
- sufficient guarantees are provided to safeguard the data transferred or disclosed and to protect the confidentiality of the same and that they meet the minimum criteria stipulated in the Regulation;
- the Personal Data is exported is limited to the minimum amount necessary;
- consent of the Data Authority has been obtained in respect of the transfer or disclosure concerned.
Coverage Horizontal

Report issue     Report new measure