Table of Contents
Article 1
Article 2
Article 3
Article 4
Article 5
Article 6
Article 7
Article 8
Article 9
Article 10
Article 11
Article 12
Article 13
Article 14
Article 15
Article 16
Article 17
Article 18
Article 19
Article 20
Article 21
Article 22
Article 23
Article 24
Article 25
Article 26
Article 27
Article 28
Article 29
Article 30
Article 31
Article 32
Article 33
Article 34
Article 35
Article 36
Article 37
Article 38
Article 39
Article 40
Article 41
Article 42
Article 43
Article 13
When collecting Personal Data directly from the Data Subject, the Controller shall take appropriate measures to inform the Data Subject of the following upon Collection:
- The legal basis for collecting their Personal Data.
- The purpose of the Collection, and shall specify the Personal Data whose Collection is mandatory and the Personal Data whose Collection is optional. The Data Subject shall be informed that the Personal Data will not be subsequently processed in a manner inconsistent with the Collection purpose or in cases other than those stated in Article (10) of this Law.
- Unless the Collection is for security purposes, the identity of the person collecting the Personal Data and the address of its representative, if necessary.
- The entities to which the Personal Data will be disclosed, the capacity of such entities, and whether the Personal Data will be transferred, disclosed or processed outside the Kingdom.
- The potential consequences and risks that may result from not collecting the Personal Data.
- The rights of the Data Subject pursuant to Article (4) herein.
- Such other elements as set out in the Regulations based on the nature of the activity done by the Controller.
FAQs
When an organization (Controller) collects your personal data directly from you, it must provide key information to ensure transparency. This is often done through a privacy notice and includes:
- Legal Basis and Purpose: The specific legal justification for collecting your data and a clear explanation of what it will be used for. The Controller must also state that your data will not be used for any other purpose unless permitted by law.
- Collector’s Identity: The identity of the person or entity collecting the data and the contact address of their representative, unless the collection is for security purposes.
- Data Recipients: The entities or categories of entities your personal data will be disclosed to.
Yes, the Controller must inform you about these details at the time of collection. This is part of ensuring fair and transparent processing. You must be informed of:
- Your Rights: A summary of your rights as a Data Subject under the law, such as the rights to access, correct, and request the destruction of your data.
- International Transfers: Whether your data will be transferred, disclosed, or processed outside the Kingdom. This aligns with global data protection standards that require informing individuals about cross-border data flows.
You are not necessarily required to provide all the data an organization asks for. The Controller must clarify this for you by:
- Distinguishing Data Types: Specifying which pieces of personal data are mandatory to provide and which are optional. For example, an online store might mark required fields like a shipping address with a star (*), making it clear that other fields are optional.
- Explaining Consequences: Informing you of the potential consequences and risks if you choose not to provide the requested data. For example, failure to provide a required piece of information might prevent you from accessing a service or completing a transaction.