Skip to main content

K. Data Confidentiality and Security

No: 41027017 Date(g): 15/12/2019 | Date(h): 18/4/1441

Effective from 2019-12-15 - Dec 14 2019
To view other versions open the versions tab on the right

24.Banks should ensure that, prior to providing customer and financial data to a third-party service provider, the proposed outsourcing arrangement complies with the relevant statutory requirements related to confidentiality of its customers. In particular, with the provision of Article #19 of the Banking Control Law dated 22/2/1386 H, regulations and instructions issued by Saudi Central Bank and other relevant local laws.
 
25.Banks should establish appropriate safeguards to protect the integrity and confidentiality of customer and financial data.
 
26.Upon termination of the outsourcing arrangement and contract, banks should ensure that any sensitive/confidential data is either retrieved from the third-party service provider or destroyed in a controlled manner, with any exceptions to be reported immediately to Saudi Central Bank.