16/04/2025
🇸🇦 Since September… have you progressed under Saudi Arabia’s PDPL?
Back in September 2024, we published the article below after SDAIA issued the Rules Governing the National Register of Controllers.
It is now April 2025 and if your organisation is based in Saudi Arabia or outside in Saudi Arabia, but processes personal data of individuals in Saudi Arabia, this is a crucial time to assess your internal practices.
Here are some key areas to revisit:
🔹 Registration: Have you registered as a Controller through the National Data Governance Platform?
🔹 DPO Assessment: Do you meet the criteria that require the appointment of a Data Protection Officer ?
🔹 Third-Party Relationships: Have you properly structured your data processing roles (controller, processor, joint controller)? Are vendor assessments, data processing agreements, and other contractual safeguards in place?
🔹 Internal Policies: Are the required privacy policies and procedures documented, in place, and followed?
🔹Privacy Notice: Does your privacy notice comply with the PDPL requirements and does it accurately and transparently reflect your personal data handling practices?
🔹 International Data Transfers: Have you reviewed whether your cross-border data transfers comply with PDPL requirements, and whether appropriate safeguards are applied?
🔹 Gap Analysis: Have you undertaken a structured assessment to identify your compliance status areas for improvement?
🔹 Multi-Jurisdictional Alignment: Are your practices compatible with other applicable data protection laws, such as the GDPR and UAE PDPL?
🔍 How we can assist
At Privacy Minders, we have been advising on data protection matters since 2018. Our work spans multiple jurisdictions and sectors, and we are backed by Raphael Legal the law firm of our group, combining legal expertise with regulatory insight.
Our services include:
✅ Conducting PDPL gap assessments
✅ Evaluating the requirement for DPO appointment
✅ Acting as your outsourced DPO, where needed
✅ Drafting and reviewing your privacy notice, mandatory policies and internal procedures
✅ Supporting contractual arrangements with third parties
✅ Advising on international data transfers
✅ Managing the overlap of data protection obligations across jurisdictions, making sure that compliance with the KSA PDPL does not jeopardize your compliance with other data protection laws, should your organization fall within their scope.
📩 Contact us at [email protected]
or via our contact form: https://lnkd.in/drhjWW5a
Saudi Arabia Data Protection Compliance: National Register for Controllers and Data Protection Officer Requirements