Skip to main content

Adherence to the Personal Data Protection Law and Data Governance Policies, Regulations and Rules

No: 43045328 Date(g): 23/12/2021 | Date(h): 19/5/1443 Status: In-Force

Translated Document

Referring to the Personal Data Protection Law, issued by Royal Decree No. (M/19) dated 09/02/1443H*, and to the policies, controls and rules issued by the Saudi Data and Artificial Intelligence Authority and the National Data Management Office regarding data governance, based on the powers vested to the same under Cabinet Resolution No. (292) dated 27/04/1441H. Given that the Law, policies, controls and rules referred to above contribute to protecting and building confidence in the data sector in KSA, and that some of the above shall be implemented by the financial institutions supervised by SAMA, SAMA would like to emphasize the following:

First:  Review the approved internal policies and procedures and ensure their compatibility and/or amendment in accordance with the following:

Second:  Evaluate the organizational gaps (Gap Analysis) with the Law, policies, controls and rules referred to above and develop a time plan to correct and present them to the Board of Directors for approval.

Pursuant to Circular No. (44043873) dated 24/05/1444H; based on the powers vested to SAMA under the relevant laws and regulations; and given what has been observed that there are some practices that require individual customers to disclose some of their personal data before providing the service or product without it being necessary, whether directly or through a third party, SAMA affirms that all financial institutions shall fully adhere to the protection of customers’ personal data in accordance with the regulations and instructions referred to above and SAMA’s instructions in this regard; review the procedures related to the practices of disclosing customers’ personal data and take the necessary measures to preserve them; develop the necessary procedures and controls to ensure its security, integrity, and use for the purposes for which it was collected; and provide SAMA with a report explaining the measures taken in this regard

Communication in this regard with SAMA shall be via the following e-mail: (CRC.Compliance@SAMA.GOV.SA).


*This Law has been amended by Royal Decree No. M/148 dated 05/09/1444H.