saudi-pdpl.com

Table of Contents

Article 1

Article 2

Article 3

Article 4

Article 5

Article 6

Article 7

Article 8

Article 9

Article 10

Article 11

Article 12

Article 13

Article 14

Article 15

Article 16

Article 17

Article 18

Article 19

Article 20

Article 21

Article 22

Article 23

Article 24

Article 25

Article 26

Article 27

Article 28

Article 29

Article 30

Article 31

Article 32

Article 33

Article 34

Article 35

Article 36

Article 37

Article 38

Article 39

Article 40

Article 41

Article 42

Article 43

Article 13

When collecting Personal Data directly from the Data Subject, the Controller shall take appropriate measures to inform the Data Subject of the following upon Collection:

  1. The legal basis for collecting their Personal Data.
  2. The purpose of the Collection, and shall specify the Personal Data whose Collection is mandatory and the Personal Data whose Collection is optional. The Data Subject shall be informed that the Personal Data will not be subsequently processed in a manner inconsistent with the Collection purpose or in cases other than those stated in Article (10) of this Law.
  3. Unless the Collection is for security purposes, the identity of the person collecting the Personal Data and the address of its representative, if necessary.
  4. The entities to which the Personal Data will be disclosed, the capacity of such entities, and whether the Personal Data will be transferred, disclosed or processed outside the Kingdom.
  5. The potential consequences and risks that may result from not collecting the Personal Data.
  6. The rights of the Data Subject pursuant to Article (4) herein.
  7. Such other elements as set out in the Regulations based on the nature of the activity done by the Controller.

FAQs

When an organization (Controller) collects your personal data directly from you, it must provide key information to ensure transparency. This is often done through a privacy notice and includes: 

  • Legal Basis and Purpose: The specific legal justification for collecting your data and a clear explanation of what it will be used for. The Controller must also state that your data will not be used for any other purpose unless permitted by law. 
  • Collector’s Identity: The identity of the person or entity collecting the data and the contact address of their representative, unless the collection is for security purposes. 
  • Data Recipients: The entities or categories of entities your personal data will be disclosed to. 

Yes, the Controller must inform you about these details at the time of collection. This is part of ensuring fair and transparent processing. You must be informed of: 

  • Your Rights: A summary of your rights as a Data Subject under the law, such as the rights to access, correct, and request the destruction of your data. 
  • International Transfers: Whether your data will be transferred, disclosed, or processed outside the Kingdom. This aligns with global data protection standards that require informing individuals about cross-border data flows.

You are not necessarily required to provide all the data an organization asks for. The Controller must clarify this for you by: 

  • Distinguishing Data Types: Specifying which pieces of personal data are mandatory to provide and which are optional. For example, an online store might mark required fields like a shipping address with a star (*), making it clear that other fields are optional. 
  • Explaining Consequences: Informing you of the potential consequences and risks if you choose not to provide the requested data. For example, failure to provide a required piece of information might prevent you from accessing a service or completing a transaction.
Scroll to Top