• Sectors we work in banner(2)

    Quick Reads

Safeguarding Data Privacy: Saudi Arabia's New Rules for Personal Data Protection Officers

Following the implementation of the Kingdom of Saudi Arabia’s (KSA) new Personal Data Protection Law (PDPL), the Saudi Data & AI Authority (SDAIA) has issued new rules for appointing Personal Data Protection Officers (DPOs). This represents a significant step in reinforcing data protection and privacy in Saudi Arabia. These rules are designed to align with international best practices and to ensure that entities processing personal data are doing so in a manner that respects individual rights and complies with the PDPL.

The requirement for certain data controllers to appoint a DPO is in line with similar requirements in other jurisdictions, such as the European Union's General Data Protection Regulation (GDPR). The criteria set forth for determining what constitutes large-scale processing and regular and systematic monitoring are crucial for controllers to understand whether they fall under the obligation to appoint a DPO.

DPO Requirements

The emphasis on the qualifications of the DPO, including academic background, experience, and knowledge of data protection and risk management, underscores the importance of the role. The DPO is not just a nominal position but is expected to have a substantive impact on the controller's data protection practices.

The flexibility in allowing the DPO to be either an employee or an external contractor provides controllers with the ability to choose the best arrangement for their operations. However, regardless of the employment status, the DPO's contact details must be made available to both the SDAIA and data subjects, a measure intended to enhance transparency and accountability.

The detailed roles and tasks of the DPO, including policy advising, contributing to data breach response plans, and monitoring regulatory updates, show that the DPO is expected to be actively involved in all aspects of data protection within their organisations.

The requirement for controllers to support the DPO with necessary resources and ensure their independence is also critical. It is envisaged that this will assist with preventing conflicts of interest and will also ensure that the DPO can perform their duties without undue influence from the controller.

Looking Ahead

The encouragement of training and professional development for DPOs is a forward-thinking approach that recognises the evolving nature of data protection laws and practices in the Kingdom. These new rules represent a comprehensive approach to data protection governance, ensuring that entities in KSA are held to a high standard when it comes to handling personal data.

Organisations should consider undertaking a review of their data policies and procedures to ensure that they are in compliance with KSA legislation.

Our thinking

  • IBA Annual Conference 2025

    Simon Ridpath

    Events

  • Dalal Alhouti and Robin Hayden write for The Oath on enhancing arbitration with AI

    Dalal Alhouti

    In the Press

  • Triple Play "Bid Fever": UK Tech's ability to scale and go global

    Mark Howard

    Quick Reads

  • The Future of AI and Copyright Regulation in the UK: The Data (Use and Access) Bill finally gets Lords approval in the UK

    Rebecca Steer

    Quick Reads

  • Navigating International M&A Disputes: Insights and Strategies for 2025

    Stephen Burns

    Quick Reads

  • Ahmad Anani, Jihane Rizk and Sevcan Aydemir write for Wealth Briefing on the rise of private equity in Middle East family businesses

    Ahmad Anani

    In the Press

  • London International Disputes Week: Navigating International M&A Disputes: Insights and Strategies for 2025

    Stephen Burns

    Events

  • Representative actions: lessons learnt from two recent cases

    Simon Heatley

    Insights

  • Please, sir, I want some more… consideration for your MSV survey

    Samuel Lear

    Quick Reads

  • Umbrella Clauses in Investment Treaty Arbitration

    Peter Brabant

    Insights

  • Rebecca Steer writes for Drapers on how retailers can prepare for upcoming cyber legislation

    Rebecca Steer

    In the Press

  • Rebecca Steer writes for Infosecurity Magazine on the UK's new Cyber Security Bill

    Rebecca Steer

    In the Press

  • Arbitration of Trust Disputes

    Thomas R. Snider

    Insights

  • Law Middle East profiles Nicola Jackson, Corporate Restructuring and Insolvency Partner based in our Dubai office

    Nicola Jackson

    In the Press

  • Nick Hurley and Rachel Hearn write for ELA Briefing on a landmark decision in the case of Mahmood v Standard Chartered Bank

    Nick Hurley

    In the Press

  • Mahmood v Standard Chartered Bank: a landmark decision in discrimination and victimisation

    Nick Hurley

    Insights

  • Navigating Team Moves and Business Protection in the DIFC and ADGM: A Legal Perspective

    Nick Hurley

    Quick Reads

  • Detailed analysis of new Government guidance for businesses on Modern Slavery Act section 54 statements

    Kerry Stares

    Insights

  • Unlocking Opportunities: Introduction of the Re-domiciliation Regime in Hong Kong

    Shirley Fu

    Insights

  • From Tradition to Transaction - The Rise of Private Equity in Family Businesses in the Middle East

    Ahmad Anani

    Insights

Back to top