Skip to main content

Article 37

No: 000044093096 Date(g): 13/6/2023 | Date(h): 24/11/1444 Status: In-Force
 (1)A Licensee must comply with the applicable laws in relation to data protection in the Kingdom, as well as with any other regulations, resolutions, instructions and circulars issued by SAMA.
 
 (2)A Licensee must protect Client Data and maintain their confidentiality, including when it is held by a third party or an Agent of the Licensee. The personal information of Clients may be accessed and used by personnel authorized by the Licensee only to comply with regulatory requirement applicable in the Kingdom, including in relation to suspicion of money laundering reporting, fraud and financial crime reporting.
 
 (3)

Subject to applicable laws, a Licensee must not disclose Client Data except where the following:
 

(a)In compliance with SAMA requirements or under the request of other competent authorities from SAMA inside and outside the Kingdom.
 
(b)The disclosure is made with the prior specified written consent of the Client.
 
 (4)A Licensee must put in place and maintain adequate policies, procedures and controls, as well as employee awareness training, to protect Client data from any information security risks.
 
 (5)A Licensee must put in place data protection controls in accordance with what is issued by SAMA and other competent authorities in the Kingdom in this regard.