Skip to main content

K. Data Confidentiality and Security

No: 41027017 Date(g): 15/12/2019 | Date(h): 18/4/1441 Status: In-Force
24.Banks should ensure that, prior to providing customer and financial data to a third-party service provider, the proposed outsourcing arrangement complies with the relevant statutory requirements related to confidentiality of its customers. In particular, with the provision of Article #19 of the Banking Control Law dated 22/2/1386 H, regulations and instructions issued by SAMA and other relevant local laws.
 
25.Banks should establish appropriate safeguards to protect the integrity and confidentiality of customer and financial data.
 
26.Upon termination of the outsourcing arrangement and contract, banks should ensure that any sensitive/confidential data is either retrieved from the third-party service provider or destroyed in a controlled manner, with any exceptions to be reported immediately to SAMA.