Skip to main content

Compliance with the Updated Personal Data Protection Law and its Implementing Regulations

No: 45015218 Date(g): 18/9/2023 | Date(h): 4/3/1445 Status: In-Force

Translated Document

Further to the instructions of SAMA communicated through Circular No. (43045328) dated 19/05/1443 H regarding Adherence to the Personal Data Protection Law and Data Governance Policies, Regulations and Rules , and in reference to the Royal Decree No. (M/148) dated 05/09/1444 H which includes the approval of amendments to the Personal Data Protection Law issued by Royal Decree No. (M/19) dated 09/02/1443 H, and to its implementing regulations issued by the competent authority.

Based on the aforementioned circumstances and given that the provisions of the aforementioned law and its implementing regulations have come into force on 29/02/1445 H corresponding to 14/09/2023 G, SAMA emphasizes that financial institutions must adhere to the following:

First:  Implement the updated Personal Data Protection Law in accordance with Royal Decree No. (M/148) dated 05/09/1444 H, and its implementing regulations issued by the relevant authority. Review related internal policies and procedures to ensure they are amended to comply with the law and its implementing regulations within a period of one year from the effective date mentioned above.

Second:  Provide SAMA with a compliance status using the evaluation form that will be shared via email before the date 28/09/2023 G, and submitted semi-annually in mid-January and mid-July of each year, starting from 2024 G, via the following email

Third: SAMA will serve as the communication channel for financial institutions regarding the implementation of the aforementioned law and its implementing regulations, using the email mentioned above. 

For your information and to act accordingly from this date. Please note that SAMA, as part of its supervisory and regulatory role, will conduct inspection visits to financial institutions to ensure the implementation of the aforementioned law and its implementing regulations.