SAUDI ARABIA
Since 2016
Pillar Content access |
Indicator Licensing schemes for digital services and applications
Executive Regulation for Electronic Publishing
Online publishers (including publishers of blogs, forums and short messaging) cannot operate without explicit approval from the highest levels of government. The Executive Regulation for Electronic Publishing Activity stipulates licensing by the Media Ministry as a requirement for those seeking to publish online (Article 7). The regulation requires applicants to be Saudi nationals, at least 25 years old, a university graduate, of “good conduct,” and not be employed by the government. Article 15 of the Law prohibits publishing anything that contravenes Islamic law, violates public order, or serves “foreign interests,” as well as material inciting a “spirit of discord” within society.
Coverage Online publishers, including publishers of blogs, forums and short messaging
SAUDI ARABIA
Since October 2023
Pillar Content access |
Indicator Licensing schemes for digital services and applications
Cloud Computing Services Provisioning Regulations
The communications regulator in the Kingdom of Saudi Arabia, the Communications, Space and Technology Commission, has issued updated Cloud Computing Services Provisioning Regulations, which replace version 3 of the Cloud Computing Regulatory Framework (CCRF v3). Under the cloud regulatory framework, any cloud computing service provider that exercises direct or effective control over a data centre or other critical cloud infrastructure hosted and used in Saudi Arabia for the provision of cloud computing services must be registered with CST. In addition, such providers are required to use telecommunications infrastructure (including international connectivity) only through operators licensed by CST.
Coverage Cloud computing
SAUDI ARABIA
N/A
Pillar Cross-border data policies |
Indicator Participation in trade agreements committing to open cross-border data flows
Lack of participation in agreements with binding commitments on data flows
Saudi Arabia has not joined any agreement with binding commitments to open transfers of data across borders.
Coverage Horizontal
SAUDI ARABIA
Since September 2021, entry into force in September 2023
Pillar Domestic data policies |
Indicator Framework for data protection
Personal Data Protection Law, implemented by Royal Decree M/19
(مرسوم ملكي رقم (م/19) وتاريخ 1443/2/9هـ نظام حماية البيانات الشخصية)
(مرسوم ملكي رقم (م/19) وتاريخ 1443/2/9هـ نظام حماية البيانات الشخصية)
The Personal Data Protection Law (PDPL) establishes a comprehensive data protection regime in Saudi Arabia. The PDPL applies to any processing of personal data carried out in Saudi Arabia by companies or public entities by any means, including the processing of personal data of Saudi residents by entities located outside the Kingdom. Furthermore, the second clause of the law establishes the Saudi Data & Artificial Intelligence Authority (SDAIA) as the competent authority to supervise the implementation of the provisions of the system and its regulations. However, a transfer of supervision to the National Data Management Office (NDMO) will be considered in the future.
Coverage Horizontal
SAUDI ARABIA
Since September 2019 until 2024
Pillar Domestic data policies |
Indicator Minimum period for data retention
Internet of Things (IoT) Regulatory Framework
الإطار التنظيمي لإنترنت الأشياء
الإطار التنظيمي لإنترنت الأشياء
Art. 7 of the Internet of Things (IoT) Regulatory Framework requires that IoT service providers must provide the technical capabilities in the IoT devices and machines to save and maintain the data to make it possible to be reviewed for a duration not less than 12 months or any other duration specified by the Communications, Space & Technology Commission (CST). This requirement is not included in the in force IoT Regulatory Framework of 2024.
Coverage IoT Services
Sources
SAUDI ARABIA
Since September 2021, entry into force in September 2023
Since September 2023
Since September 2023
Pillar Domestic data policies |
Indicator Minimum period for data retention
Personal Data Protection Law, implemented by Royal Decree M/19
مرسوم ملكي رقم (م/19) وتاريخ 1443/2/9هـ نظام حماية البيانات الشخصية
Implementing Regulation of the Personal Data Protection Law
مرسوم ملكي رقم (م/19) وتاريخ 1443/2/9هـ نظام حماية البيانات الشخصية
Implementing Regulation of the Personal Data Protection Law
Pursuant to Art. 31 of the Personal Data Protection Law, the Controller must maintain records of personal data processing activities, in a manner appropriate to the nature of its operations, and make such records available to the competent authority upon request. Art. 33 of the Implementing Regulation further specifies this obligation, requiring the Controller to retain these records for the entire duration of the processing and for an additional five years following the end of any personal data processing activity.
Coverage Horizontal
Sources
- https://web.archive.org/web/20230628152743/https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf
- https://web.archive.org/web/20240217053800/https://sdaia.gov.sa/en/SDAIA/about/Documents/ImplementingRegulation.pdf
- https://web.archive.org/web/20250424162418/https://sdaia.gov.sa/Documents/PersonalDataProcessingActivitiesRecordsGuideline.pdf
- https://digitalpolicyalert.org/event/14282-published-implementing-regulation-of-the-personal-data-protection-law
- Show more...
SAUDI ARABIA
Since April 2020
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
General Principles for Personal Data Protection in the Telecommunication, IT, and Postal Services
( القواعد العامة للمحافظة على خصوصية البيانات الشخصية للمستخدمين في قطاع الاتصالات وتقنية المعلومات)
( القواعد العامة للمحافظة على خصوصية البيانات الشخصية للمستخدمين في قطاع الاتصالات وتقنية المعلومات)
According to Art. 5.2 of the General Principles for Personal Data Protection in the Telecommunication, IT, and Postal Services, service providers in certain sectors, including telecom and IT, are mandated to assign the role and responsibilities of customers’ personal data protection to an independent function, which can be intended as a data protection officer.
Coverage Telecommunications and IT sectors
Sources
SAUDI ARABIA
Since September 2021, entry into force in September 2023
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Personal Data Protection Law, implemented by Royal Decree M/19
(مرسوم ملكي رقم (م/19) وتاريخ 1443/2/9هـ نظام حماية البيانات الشخصية)
(مرسوم ملكي رقم (م/19) وتاريخ 1443/2/9هـ نظام حماية البيانات الشخصية)
The Personal Data Protection Law mandates data privacy impact assessments whereby controllers must conduct an evaluation of the effects of processing associated with any product or service provided to the public.
Coverage Horizontal
SAUDI ARABIA
Since September 2021, entry into force in September 2023
Since September 2023
Since September 2023
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Personal Data Protection Law, implemented by Royal Decree M/19
(مرسوم ملكي رقم (م/19) وتاريخ 1443/2/9هـ نظام حماية البيانات الشخصية)
Implementing Regulation of the Personal Data Protection Law
(مرسوم ملكي رقم (م/19) وتاريخ 1443/2/9هـ نظام حماية البيانات الشخصية)
Implementing Regulation of the Personal Data Protection Law
Arts. 6, 10, and 15 of the Personal Data Protection Law delineate the circumstances under which a public entity may request access to data: namely, for purposes of public interest, security, implementing another law, or fulfilling judicial requirements. Notably, there is no stipulation requiring the presence of a court order or warrant. However, Art. 21 of the Implementing Regulations imposes additional obligations on public entities that process personal data obtained indirectly from data subjects for public interest purposes. These obligations include ensuring that the processing is necessary to achieve a clearly defined public interest, that such interest is related to a mandate specified by law, and that appropriate measures are taken to mitigate any potential harm resulting from the processing.
Coverage Horizontal
Sources
- https://web.archive.org/web/20240811/https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf
- https://web.archive.org/web/20240217053800/https://sdaia.gov.sa/en/SDAIA/about/Documents/ImplementingRegulation.pdf
- https://web.archive.org/web/20210511080612/https://www.dataguidance.com/notes/saudi-arabia-third-country-assessment
- Show more...
SAUDI ARABIA
Since February 2024
Pillar Domestic data policies |
Indicator Requirement to allow the government to access personal data collected
Regulations for the Classification of Licenses for Telecommunications Services
تنظيمات تصنيف تراخيص خدمات الاتصالات
تنظيمات تصنيف تراخيص خدمات الاتصالات
Art. 9.3 of the "Regulations for the Classification of Licences for Telecommunications Services" stipulates that telecom service providers must furnish the Communications, Space and Technology Commission (CST) with any data it requests within the prescribed timeframe. In addition, providers are required to update the CST promptly in the event of any change to their submitted information. However, the provision does not clarify whether the disclosure of such data must be supported by a judicial warrant or court order.
Coverage Telecommunications sector
SAUDI ARABIA
Since July 2019, entry into force in October 2019
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for copyright infringement
E-Commerce Law
نظام التجارة الإلكترونية
نظام التجارة الإلكترونية
The E-commerce Law establishes a safe harbour regime for intermediaries for copyright infringements. Art. 12 of the law provides a safe harbour for intermediary liabilities by excluding them from penalties if the intermediary platforms delete any content that violates the provisions of the laws and regulations within one day from the date of notification by the government.
Coverage Intermediaries
Sources
- https://web.archive.org/web/20220927072244/https://mc.gov.sa/en/regulations/pages/details.aspx?lawid=aaa4d4cf-ca57-41ff-a3f9-aa8500a3512c
- https://web.archive.org/web/20221006164636/https://openknowledge.worldbank.org/bitstream/handle/10986/33521/Digital-Trade-in-MENA-Regulatory-Readiness-Assessment.pdf
SAUDI ARABIA
Since July 2019, entry into force in October 2019
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for any activity other than copyright infringement
E-Commerce Law
نظام التجارة الإلكترونية
نظام التجارة الإلكترونية
The E-commerce Law establishes a safe harbour regime for intermediaries beyond copyright infringement. Art. 12 of the law provides a safe harbour for intermediary liabilities by excluding them from penalties if the intermediary platforms delete any content that violates the provisions of the laws and regulations within one day from the date of notification by the government.
Coverage Intermediaries
Sources
- https://web.archive.org/web/20220927072244/https://mc.gov.sa/en/regulations/pages/details.aspx?lawid=aaa4d4cf-ca57-41ff-a3f9-aa8500a3512c
- https://web.archive.org/web/20221006164636/https://openknowledge.worldbank.org/bitstream/handle/10986/33521/Digital-Trade-in-MENA-Regulatory-Readiness-Assessment.pdf
SAUDI ARABIA
Since September 2019 until 2024
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Internet of Things (IoT) Regulatory Framework
الإطار التنظيمي لإنترنت الأشياء
الإطار التنظيمي لإنترنت الأشياء
Art. 7 of the Internet of Things (IoT) Regulatory Framework requires all servers, devices, and network components providing an IoT service and all data relating to the service must be located within Saudi Arabia. This requirement is not included in the 2024 amendment of the framework.
Coverage IoT services
Sources
- https://web.archive.org/web/20230418073635/https://www.cst.gov.sa/en/RulesandSystems/RegulatoryDocuments/Documents/IoT_REGULATORY_FRAMEWORK.pdf
- https://web.archive.org/web/20231113183333/https://cms.law/en/int/expert-guides/cms-expert-guide-to-data-protection-and-cyber-security-laws/saudi-arabia
- https://cyrilla.org/api/files/1732736943174dktu12le27e.pdf
- Show more...
SAUDI ARABIA
Since August 2008
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Insurance Market Code of Conduct Regulation
اللائحة التنظيمية لسلوكيات سوق التأمين
اللائحة التنظيمية لسلوكيات سوق التأمين
Art. 17 of the Insurance Market Code of Conduct Regulation stipulates that insurance companies are required, at all times, to ensure the protection of customers’ personal data. This obligation entails, inter alia, that such data must be retained within the Kingdom and must not be disclosed to any third party without the prior authorisation of the Saudi Arabian Monetary Agency (SAMA), except in the case of the companies’ auditors, actuaries, reinsurers, and co-insurers.
Coverage Insurance companies
SAUDI ARABIA
Since January 2021
Pillar Cross-border data policies |
Indicator Local storage requirement
Implementing Regulations of the Income Tax Law
اللائحة التنفيذية لنظام ضريبة الدخل الصادرة بالقرار الوزاري رقم (1535) وتاريخ 1425/6/11هـ و
اللائحة التنفيذية لنظام ضريبة الدخل الصادرة بالقرار الوزاري رقم (1535) وتاريخ 1425/6/11هـ و
Art. 56 of the Implementing Regulations of the Income Tax Law requires that a taxpayer's books be kept in Saudi Arabia.
Coverage Horizontal
Sources
- https://web.archive.org/web/20240610065833/https://zatca.gov.sa/en/RulesRegulations/Taxes/Documents/Regulations_of_Income_Tax.pdf
- https://web.archive.org/web/20250522232934/https://digitalpolicyalert.org/event/14647-adopted-implementing-regulations-of-the-income-tax-law-including-localisation-requirement
