{
  "meta": {
    "source": "https://www.wadiraksa.com",
    "license": "CC BY 4.0 — attribute Wadira (https://www.wadiraksa.com)",
    "generated_at": "2026-08-19T19:39:47.538Z",
    "data_updated_at": "2026-08-13",
    "counts": {
      "frameworks": 8,
      "authorities": 6,
      "instruments": 85,
      "provisions": 98
    }
  },
  "tiers": [
    {
      "tier": 0,
      "label": "Foundational: Sharia & Basic Law",
      "label_ar": "تأسيسي: الشريعة والنظام الأساسي للحكم"
    },
    {
      "tier": 1,
      "label": "Primary law: niẓām (Royal Decree M/…)",
      "label_ar": "التشريع الأساسي: نظام (مرسوم ملكي م/…)"
    },
    {
      "tier": 2,
      "label": "Cabinet instruments: CoM Resolution",
      "label_ar": "أدوات مجلس الوزراء: قرار مجلس الوزراء"
    },
    {
      "tier": 3,
      "label": "Implementing & executive regulation",
      "label_ar": "اللائحة التنفيذية واللوائح التنظيمية"
    },
    {
      "tier": 4,
      "label": "Rules, controls & standards",
      "label_ar": "القواعد والضوابط والمعايير"
    },
    {
      "tier": 5,
      "label": "Guidelines & circulars",
      "label_ar": "الإرشادات والتعاميم"
    }
  ],
  "frameworks": [
    {
      "slug": "constitutional",
      "name": "Constitutional foundation",
      "name_ar": "الأساس الدستوري",
      "description": "The Basic Law of Governance and the foundational instruments the regime rests on.",
      "description_ar": "النظام الأساسي للحكم والأدوات التأسيسية التي يقوم عليها المنظومة."
    },
    {
      "slug": "pdpl",
      "name": "Personal Data Protection (PDPL)",
      "name_ar": "حماية البيانات الشخصية (PDPL)",
      "description": "Saudi Arabia's data-protection regime: the PDPL, its Implementing Regulation, and the rules and guidelines beneath them.",
      "description_ar": "منظومة حماية البيانات في المملكة العربية السعودية: نظام حماية البيانات الشخصية (PDPL) ولائحته التنفيذية والقواعد والإرشادات المنبثقة عنها."
    },
    {
      "slug": "data-management-and-governance",
      "name": "Data Management & Governance",
      "name_ar": "إدارة البيانات وحوكمتها",
      "description": "Saudi Arabia's national data-management and governance regime: the NDMO data-management standards and domains, the national data policies on classification, sharing, open data, freedom of information and monetisation, and the National Data Index.",
      "description_ar": "منظومة إدارة البيانات وحوكمتها الوطنية في المملكة العربية السعودية: معايير ومجالات إدارة البيانات الصادرة عن المكتب الوطني لإدارة البيانات (NDMO)، والسياسات الوطنية للبيانات المتعلقة بالتصنيف والمشاركة والبيانات المفتوحة وحرية المعلومات وتوليد الإيرادات، والمؤشر الوطني للبيانات."
    },
    {
      "slug": "cyber",
      "name": "Cybersecurity",
      "name_ar": "الأمن السيبراني",
      "description": "The Anti-Cyber Crime Law and the National Cybersecurity Authority's controls and frameworks (ECC, CCC and more).",
      "description_ar": "نظام مكافحة الجرائم المعلوماتية وضوابط الهيئة الوطنية للأمن السيبراني وأطرها (الضوابط الأساسية للأمن السيبراني ECC وضوابط الأمن السيبراني للحوسبة السحابية CCC وغيرها)."
    },
    {
      "slug": "financial",
      "name": "Financial services",
      "name_ar": "الخدمات المالية",
      "description": "SAMA and CMA laws, frameworks and rules governing banks and capital-market institutions.",
      "description_ar": "أنظمة البنك المركزي السعودي (SAMA) وهيئة السوق المالية (CMA) وأطرهما وقواعدهما التي تحكم البنوك ومؤسسات السوق المالية."
    },
    {
      "slug": "ai",
      "name": "Artificial Intelligence",
      "name_ar": "الذكاء الاصطناعي",
      "description": "SDAIA's AI laws, frameworks and guidelines, including generative-AI and deepfakes guidance.",
      "description_ar": "أنظمة الذكاء الاصطناعي وأطره وإرشاداته الصادرة عن الهيئة السعودية للبيانات والذكاء الاصطناعي (SDAIA)، بما في ذلك إرشادات الذكاء الاصطناعي التوليدي والتزييف العميق."
    },
    {
      "slug": "telecom",
      "name": "Telecommunications & Cloud",
      "name_ar": "الاتصالات والحوسبة السحابية",
      "description": "CST's cloud-computing and telecom regulatory framework and licensing.",
      "description_ar": "الإطار التنظيمي للحوسبة السحابية والاتصالات والترخيص الصادر عن هيئة الاتصالات والفضاء والتقنية (CST)."
    },
    {
      "slug": "health",
      "name": "Health data",
      "name_ar": "البيانات الصحية",
      "description": "Health-sector data-protection rules and standards.",
      "description_ar": "قواعد ومعايير حماية البيانات في القطاع الصحي."
    }
  ],
  "authorities": [
    {
      "slug": "sdaia",
      "acronym": "SDAIA / NDMO",
      "name": "Saudi Data & AI Authority / National Data Management Office",
      "name_ar": "الهيئة السعودية للبيانات والذكاء الاصطناعي / مكتب إدارة البيانات الوطنية",
      "short_desc": "National authority for data & AI; the PDPL regulator and, via the NDMO, government data governance.",
      "short_desc_ar": "الجهة الوطنية للبيانات والذكاء الاصطناعي؛ الجهة المنظِّمة لنظام حماية البيانات الشخصية (PDPL)، ومن خلال مكتب إدارة البيانات الوطنية (NDMO)، حوكمة البيانات الحكومية."
    },
    {
      "slug": "nca",
      "acronym": "NCA",
      "name": "National Cybersecurity Authority",
      "name_ar": "الهيئة الوطنية للأمن السيبراني",
      "short_desc": "National cybersecurity regulator; ECC/CCC and related controls across government, CNI and cloud.",
      "short_desc_ar": "الجهة الوطنية المنظِّمة للأمن السيبراني؛ الضوابط الأساسية للأمن السيبراني (ECC) وضوابط الأمن السيبراني للحوسبة السحابية (CCC) وما يتصل بها من ضوابط تشمل الجهات الحكومية والبنى التحتية الوطنية الحساسة والحوسبة السحابية."
    },
    {
      "slug": "sama",
      "acronym": "SAMA",
      "name": "Saudi Central Bank",
      "name_ar": "البنك المركزي السعودي",
      "short_desc": "Central bank; its Cyber Security Framework is mandatory for licensed financial institutions.",
      "short_desc_ar": "البنك المركزي؛ إطار الأمن السيبراني الصادر عنه إلزامي للمؤسسات المالية المرخّصة."
    },
    {
      "slug": "cst",
      "acronym": "CST",
      "name": "Communications, Space & Technology Commission",
      "name_ar": "هيئة الاتصالات والفضاء والتقنية",
      "short_desc": "Telecom/ICT, cloud and space regulator; CSP tiers and government data localisation.",
      "short_desc_ar": "الجهة المنظِّمة لقطاعات الاتصالات وتقنية المعلومات والحوسبة السحابية والفضاء؛ تصنيف مزوّدي الخدمات السحابية وتوطين البيانات الحكومية."
    },
    {
      "slug": "cma",
      "acronym": "CMA",
      "name": "Capital Market Authority",
      "name_ar": "هيئة السوق المالية",
      "short_desc": "Capital market regulator; cybersecurity guidelines for Capital Market Institutions (~188), not issuers.",
      "short_desc_ar": "الجهة المنظِّمة للسوق المالية؛ إرشادات الأمن السيبراني لمؤسسات السوق المالية (نحو 188 مؤسسة)، وليس الجهات المُصدِرة."
    },
    {
      "slug": "moh",
      "acronym": "MOH",
      "name": "Ministry of Health",
      "name_ar": "وزارة الصحة",
      "short_desc": "Health regulator; health data is PDPL-sensitive, with HIE policies and health data rules.",
      "short_desc_ar": "الجهة المنظِّمة لقطاع الصحة؛ البيانات الصحية بيانات حساسة بموجب نظام حماية البيانات الشخصية (PDPL)، مع سياسات تبادل المعلومات الصحية وقواعد البيانات الصحية."
    }
  ],
  "instruments": [
    {
      "slug": "basic-law-governance",
      "name": "Basic Law of Governance (Arts 37 & 40)",
      "name_ar": "النظام الأساسي للحكم (المادتان 37 و40)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Basic Law of Governance: Articles 37 (sanctity of the home) and 40 (privacy of communications) anchor the privacy framework.",
      "summary_ar": "النظام الأساسي للحكم: تُرسي المادتان 37 (حرمة المساكن) و40 (سرّية المراسلات) ركيزة إطار الخصوصية.",
      "type": "Law",
      "tier": 0,
      "legal_status": "Foundational",
      "framework": "constitutional",
      "authority": null,
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/basic-law-governance",
      "date_note": "Royal Order A/90, 1992",
      "date_note_ar": "الأمر الملكي أ/90، 1992",
      "provisions": []
    },
    {
      "slug": "sharia",
      "name": "Sharia (Qur'an & Sunnah)",
      "name_ar": "الشريعة الإسلامية (القرآن والسنة)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Sharia principles, including tajassus (prohibition on spying), satr (concealment), amanah (trust) and the sanctity of the home, form the backdrop to privacy norms.",
      "summary_ar": "مبادئ الشريعة الإسلامية، ومنها التجسّس (النهي عن التجسّس) والستر والأمانة وحرمة المسكن، تشكّل الخلفية التي تستند إليها معايير الخصوصية.",
      "type": "Framework",
      "tier": 0,
      "legal_status": "Foundational",
      "framework": "constitutional",
      "authority": null,
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/sharia",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "anti-cyber-crime-law",
      "name": "Anti-Cyber Crime Law",
      "name_ar": "نظام مكافحة الجرائم المعلوماتية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Anti-Cyber Crime Law (M/17, 2007): Articles 3 & 6 are central to interception/surveillance offences. Applies to all.",
      "summary_ar": "نظام مكافحة الجرائم المعلوماتية (M/17، 2007): تُعدّ المادتان 3 و6 محوريتين في جرائم الاعتراض/المراقبة. وينطبق على الجميع.",
      "type": "Law",
      "tier": 1,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/anti-cyber-crime-law",
      "date_note": "Royal Decree M/17, 2007",
      "date_note_ar": "مرسوم ملكي م/17، 2007",
      "provisions": []
    },
    {
      "slug": "global-ai-hub-law",
      "name": "Global AI Hub Law",
      "name_ar": "نظام المركز العالمي للذكاء الاصطناعي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "A draft law to position Saudi Arabia as a global AI hub, issued by the Communications, Space & Technology Commission (CST) for public consultation on 14 April 2025. It remains a draft as of mid-2026; the competent authority is to be designated by the Council of Ministers.",
      "summary_ar": "مشروع نظام يهدف إلى ترسيخ مكانة المملكة العربية السعودية بوصفها مركزًا عالميًا للذكاء الاصطناعي، طرحته هيئة الاتصالات والفضاء والتقنية (CST) للاستطلاع العام في 14 أبريل 2025. ولا يزال مشروعًا حتى منتصف عام 2026، على أن يُحدِّد مجلس الوزراء الجهة المختصة.",
      "type": "Law",
      "tier": 1,
      "legal_status": "Draft",
      "framework": "ai",
      "authority": "CST",
      "parent": null,
      "in_library": false,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/global-ai-hub-law",
      "date_note": "Public consultation closed 14 May 2025. Not enacted; no public text available.",
      "date_note_ar": "أُغلقت المشاورة العامة في 14 مايو 2025 ولم يُسَنّ بعد؛ لا يتوفر نص علني.",
      "provisions": []
    },
    {
      "slug": "the-capital-market-law",
      "name": "The Capital Market Law",
      "name_ar": "نظام السوق المالية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **Capital Market Law** is the founding statute of Saudi Arabia's securities regime, issued by Royal Decree M/30 (2/6/1424H, 16 June 2003) and since amended. Its ten chapters and 67 articles establish the **Capital Market Authority (CMA)** as the sector regulator and create the market's core institutions (the Exchange (Tadawul), the Securities Depository Center and the Clearing Center), together with the Committee for the Resolution of Securities Disputes.\n\nThe Law regulates brokers and Exchange members, investment funds and collective investment schemes, issuer **disclosure**, and proxy solicitations; it prohibits market manipulation and insider trading, and closes with sanctions and penalties. The CMA issues the Implementing Regulations that give the Law operational effect, under which its rules for capital-market institutions (including technology and cyber-security requirements) are made.\n\nAlongside the Saudi Central Bank Law, it is one of the Kingdom's two tier-1 financial statutes: it defines who regulates capital-market data, disclosure and record-keeping. The hosted English text is an unofficial translation; the Arabic original prevails.",
      "summary_ar": "**نظام السوق المالية** هو النظام المؤسِّس لمنظومة الأوراق المالية في المملكة العربية السعودية، الصادر بالمرسوم الملكي رقم (م/30) وتاريخ 2/6/1424هـ (16 يونيو 2003) وما لحقه من تعديلات. وتُنشئ فصوله العشرة ومواده السبع والستون **هيئة السوق المالية** بوصفها الجهة التنظيمية للقطاع، كما تُنشئ المؤسسات الأساسية للسوق (السوق المالية (تداول)، ومركز إيداع الأوراق المالية، ومركز المقاصة) إضافة إلى لجنة الفصل في منازعات الأوراق المالية ولجنة الاستئناف.\n\nوينظّم النظام أعمال الوسطاء وأعضاء السوق، وصناديق الاستثمار وأنظمة الاستثمار الجماعي، و**الإفصاح** المستمر من جانب المُصدرين، وطلبات التوكيل وعمليات الشراء المقيدة؛ ويحظر التلاعب بالسوق والتداول بناءً على معلومات داخلية، ويُختتم بفصل عن العقوبات والجزاءات. وتملك الهيئة صلاحية إصدار اللوائح التنفيذية، أي القواعد والتعليمات والإجراءات التي تُفعِّل النظام، والتي تصدر بموجبها قواعدها لمؤسسات السوق المالية، بما في ذلك المتطلبات التقنية ومتطلبات الأمن السيبراني.\n\nوبالنسبة لأطلس وديرة، يُعد هذا النظام أحد النظامين الماليين من المستوى الأول في المملكة إلى جانب نظام البنك المركزي السعودي: فهو يحدد الجهة التي تنظّم بيانات السوق المالية والإفصاح وحفظ السجلات. والنص الإنجليزي المستضاف هنا ترجمة غير رسمية، والعبرة بالنص العربي الأصلي.",
      "type": "Law",
      "tier": 1,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "CMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/the-capital-market-law",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "pdpl-law",
      "name": "Personal Data Protection Law (PDPL)",
      "name_ar": "نظام حماية البيانات الشخصية (PDPL)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Personal Data Protection Law (PDPL) is Saudi Arabia's first comprehensive data-protection statute, issued by Royal Decree M/19 (9/2/1443H, 16 September 2021), published in the Umm al-Qura Official Gazette on 24 September 2021, amended by Royal Decree M/148 (27 March 2023), and in force since 14 September 2023, with SDAIA's compliance grace period ending 14 September 2024. The Saudi Data & Artificial Intelligence Authority (SDAIA) supervises implementation as the competent authority (Art. 30).\n\n**Who it applies to.** The Law covers any processing of personal data in the Kingdom and, notably, processing of Saudi residents' data by parties outside the Kingdom (Art. 2). It extends to data of the deceased where it could identify them or a family member; purely personal or family use is excluded.\n\n**How it regulates.** Processing rests on consent by default (Art. 5), with exceptions including the data subject's actual interest, another law or prior agreement, public-entity security or judicial requirements, and the controller's legitimate interest for non-sensitive data (Arts. 6, 10, 15). Data subjects can be informed, access, obtain a copy, correct and destroy their data (Art. 4). Controllers must publish a privacy policy (Art. 12), verify accuracy (Art. 14), secure data (Art. 19), notify breaches (Art. 20: 72 hours to SDAIA under the Implementing Regulation), conduct impact assessments (Art. 22) and keep records of processing (Art. 31). Cross-border transfers are permitted for defined purposes subject to safeguards (Art. 29, detailed in the Transfer Regulation).\n\n**Penalties.** Disclosing sensitive data with intent to harm or for personal gain is a criminal offence: up to two years' imprisonment and/or a SAR 3,000,000 fine, prosecuted by the Public Prosecution (Art. 35). Any other violation draws a warning or a fine up to SAR 5,000,000, doubled for repeat violations, imposed by SDAIA violation committees with appeal to the competent court (Art. 36). Courts may order confiscation and publication of judgments (Art. 38), and injured individuals may claim compensation (Art. 40).\n\n## Frequently asked questions\n\n**Does the Saudi PDPL apply to companies outside Saudi Arabia?**\n\nYes. Article 2 extends the Law to any processing of the personal data of individuals residing in the Kingdom by parties outside it, and Article 33 directs the competent authority to set mechanisms for monitoring and enforcing compliance by controllers and processors abroad.\n\n**Is consent always required to process personal data?**\n\nNo. Consent is the default legal basis (Art. 5), but Articles 6, 10 and 15 permit processing without it, including for the data subject's actual interest where contact is impossible or difficult, under another law or a prior agreement with the data subject, for public-entity security or judicial purposes, and for the controller's legitimate interest provided no sensitive data is processed.\n\n**What are the penalties for violating the PDPL?**\n\nUnlawful disclosure of sensitive data with intent to harm or for personal benefit carries up to two years' imprisonment and/or SAR 3 million (Art. 35). Other violations carry a warning or a fine up to SAR 5 million, doubled for repeat violations (Art. 36), plus possible confiscation and publication of the judgment (Art. 38) and civil compensation (Art. 40).\n\n**When did the PDPL come into force?**\n\nThe Law took effect on 14 September 2023, 720 days after Official Gazette publication (Art. 43), and SDAIA's transition period for full compliance ended on 14 September 2024. The Implementing Regulation accompanied it, and the Transfer Regulation was reissued as version 2.0 in September 2024.",
      "summary_ar": "يُعد نظام حماية البيانات الشخصية أول نظام شامل لحماية البيانات في المملكة العربية السعودية، فقد صدر بالمرسوم الملكي رقم (م/19) (9/2/1443هـ، 16 سبتمبر 2021)، ونُشر في جريدة أم القرى الرسمية في 24 سبتمبر 2021، وعُدِّل بالمرسوم الملكي رقم (م/148) بتاريخ 27 مارس 2023، وأصبح نافذًا اعتبارًا من 14 سبتمبر 2023، مع انتهاء المهلة التصحيحية للامتثال التي منحتها سدايا في 14 سبتمبر 2024. وتتولى الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا) الإشراف على تنفيذ النظام بوصفها الجهة المختصة (المادة (30)).\n\n**نطاق التطبيق.** يسري النظام على أي معالجة للبيانات الشخصية تجري داخل المملكة، كما يسري، وهو أمر جدير بالملاحظة، على معالجة البيانات الشخصية للمقيمين في المملكة من قِبل جهات خارج المملكة (المادة (2)). ويمتد النظام ليشمل بيانات المتوفين إذا كان من شأنها أن تؤدي إلى التعرف عليهم أو على أحد أفراد أسرهم؛ ويُستثنى من نطاقه الاستخدام الشخصي أو العائلي المحض.\n\n**كيفية التنظيم.** تقوم المعالجة على الموافقة بوصفها الأصل العام (المادة (5))، مع استثناءات تشمل تحقيق مصلحة فعلية لصاحب البيانات الشخصية، أو الاستناد إلى نظام آخر أو اتفاق سابق، أو المتطلبات الأمنية أو القضائية للجهات العامة، أو المصلحة المشروعة لجهة التحكم فيما لا يتصل بالبيانات الحساسة (المواد (6) و(10) و(15)). ولصاحب البيانات الشخصية الحق في العلم بمعالجة بياناته، والاطلاع عليها، والحصول على نسخة منها، وتصحيحها، وإتلافها (المادة (4)). ويجب على جهة التحكم نشر سياسة الخصوصية (المادة (12))، والتحقق من دقة البيانات (المادة (14))، وحماية البيانات (المادة (19))، والإشعار عن حوادث تسرب البيانات (المادة (20)، خلال (72) ساعة إلى سدايا بموجب اللائحة التنفيذية)، وإجراء تقييم الأثر (المادة (22))، والاحتفاظ بسجلات أنشطة المعالجة (المادة (31)). ويجوز نقل البيانات إلى خارج المملكة لأغراض محددة مع مراعاة الضمانات المقررة (المادة (29)، وتفصّلها لائحة نقل البيانات الشخصية إلى خارج المملكة).\n\n**العقوبات.** يُعد إفشاء البيانات الحساسة بقصد الإضرار بصاحبها أو بقصد تحقيق منفعة شخصية جريمة جنائية، عقوبتها السجن مدة لا تزيد على سنتين وغرامة لا تزيد على (3,000,000) ريال أو إحدى هاتين العقوبتين، وتتولى النيابة العامة الادعاء في شأنها (المادة (35)). وتستوجب أي مخالفة أخرى الإنذار أو غرامة لا تزيد على (5,000,000) ريال، تُضاعف في حال تكرار المخالفة، وتوقعها لجان النظر في المخالفات لدى سدايا مع جواز التظلم أمام المحكمة المختصة (المادة (36)). ويجوز للمحكمة الحكم بالمصادرة ونشر الأحكام (المادة (38))، ولمن لحقه ضرر المطالبة بالتعويض (المادة (40)).\n\n## الأسئلة الشائعة\n\n**هل يسري نظام حماية البيانات الشخصية السعودي على الشركات خارج المملكة العربية السعودية؟**\n\nنعم. تمد المادة (2) نطاق سريان النظام ليشمل أي معالجة للبيانات الشخصية الخاصة بالأفراد المقيمين في المملكة من قِبل جهات خارجها، وتقضي المادة (33) بأن تضع الجهة المختصة آليات لمراقبة امتثال جهات التحكم وجهات المعالجة خارج المملكة وإنفاذ ذلك الامتثال.\n\n**هل تُشترط الموافقة دائمًا لمعالجة البيانات الشخصية؟**\n\nلا. الموافقة هي الأساس النظامي الأصل للمعالجة (المادة (5))، غير أن المواد (6) و(10) و(15) تجيز المعالجة من دونها، بما في ذلك تحقيق مصلحة فعلية لصاحب البيانات الشخصية متى كان الاتصال به مستحيلًا أو صعبًا، أو الاستناد إلى نظام آخر أو اتفاق سابق مع صاحب البيانات الشخصية، أو الأغراض الأمنية أو القضائية للجهات العامة، أو تحقيق المصلحة المشروعة لجهة التحكم شريطة عدم معالجة أي بيانات حساسة.\n\n**ما العقوبات المترتبة على مخالفة نظام حماية البيانات الشخصية؟**\n\nيعاقَب على الإفشاء غير المشروع للبيانات الحساسة بقصد الإضرار أو تحقيق منفعة شخصية بالسجن مدة لا تزيد على سنتين وغرامة لا تزيد على (3,000,000) ريال أو بإحدى هاتين العقوبتين (المادة (35)). وتستوجب المخالفات الأخرى الإنذار أو غرامة لا تزيد على (5,000,000) ريال تُضاعف في حال تكرار المخالفة (المادة (36))، إضافة إلى إمكانية الحكم بالمصادرة ونشر الحكم (المادة (38)) والتعويض المدني (المادة (40)).\n\n**متى دخل نظام حماية البيانات الشخصية حيز النفاذ؟**\n\nدخل النظام حيز النفاذ في 14 سبتمبر 2023، أي بعد (720) يومًا من نشره في الجريدة الرسمية (المادة (43))، وانتهت الفترة الانتقالية التي حددتها سدايا للامتثال الكامل في 14 سبتمبر 2024. وقد صاحبت النظامَ اللائحةُ التنفيذية، وأُعيد إصدار لائحة نقل البيانات الشخصية إلى خارج المملكة بالإصدار 2.0 في سبتمبر 2024.",
      "type": "Law",
      "tier": 1,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/PersonalDataProtectionLaw.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/pdpl-law",
      "date_note": "M/19 (2021), amended M/148 (2023); in force 14 Sep 2023",
      "date_note_ar": "م/19 (2021)، المعدّل م/148 (2023)؛ ساري المفعول في 14 سبتمبر 2023",
      "provisions": [
        {
          "kind": "article",
          "code": "Art. 1",
          "label": "Definitions",
          "label_ar": "التعريفات",
          "summary": "Definitional article setting out nineteen terms used throughout the Law, including Personal Data, Processing, Collection, Disclosure, Transfer, Sensitive Data, Genetic Data, Health Data, Credit Data, Data Subject, Public Entity, Controller, Processor and the Competent Authority, whose meanings apply unless the context requires otherwise.",
          "summary_ar": "مادة تعريفية تحدد تسعة عشر مصطلحًا مستخدمًا في النظام، منها البيانات الشخصية والمعالجة والجمع والإفصاح والنقل والبيانات الحساسة والبيانات الوراثية والبيانات الصحية والبيانات الائتمانية وصاحب البيانات الشخصية والجهة العامة وجهة التحكم وجهة المعالجة والجهة المختصة، وتسري هذه المعاني ما لم يقتضِ السياق خلاف ذلك.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:30.579605+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 2",
          "label": "Scope of Application",
          "label_ar": "نطاق سريان النظام",
          "summary": "Defines the Law's scope: it applies to any Processing of Personal Data in the Kingdom, including Processing of residents' data by parties outside the Kingdom, and to deceased persons' data if it would identify them or a family member. Purely personal or family use is excluded unless published or disclosed; the Regulations define such use.",
          "summary_ar": "تحدد نطاق سريان النظام؛ إذ يسري على أي معالجة للبيانات الشخصية تتم في المملكة بأي وسيلة، بما في ذلك معالجة بيانات المقيمين فيها من أي جهة خارج المملكة، ويشمل بيانات المتوفين إذا كانت تؤدي إلى تحديد هويتهم أو هوية أحد أفراد أسرهم تحديدًا. ويُستثنى الاستخدام الشخصي أو العائلي ما لم تُنشر البيانات أو يُفصح عنها للغير، وتحدد اللوائح هذا الاستخدام.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:30.618378+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 3",
          "label": "Relationship With Other Laws",
          "label_ar": "العلاقة بالأنظمة الأخرى",
          "summary": "States that the Law's provisions and procedures do not prejudice any provision that grants a right to the Data Subject or confers better protection of Personal Data under any other law or an international agreement to which the Kingdom is a party.",
          "summary_ar": "تنص على أن ما تضمنه النظام من أحكام وإجراءات لا يخل بأي حكم يمنح صاحب البيانات الشخصية حقًا أو يقرر حماية أفضل للبيانات الشخصية بموجب أي نظام آخر أو اتفاقية دولية تكون المملكة طرفًا فيها.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:30.78637+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 5",
          "label": "Consent and Withdrawal",
          "label_ar": "الموافقة وسحبها",
          "summary": "Prohibits Processing Personal Data or changing the Processing purpose without the Data Subject's consent, except in cases stated in the Law. The Regulations set consent conditions, cases requiring explicit consent, and legal-guardian consent where capacity is lacking. Consent may be withdrawn at any time, subject to controls in the Regulations.",
          "summary_ar": "تحظر معالجة البيانات الشخصية أو تغيير الغرض من معالجتها دون موافقة صاحبها إلا في الحالات التي نص عليها النظام. وتحدد اللوائح شروط الموافقة والحالات التي يجب أن تكون فيها صريحة والأحكام المتعلقة بموافقة الولي إذا كان صاحب البيانات فاقد الأهلية أو ناقصها. ولصاحب البيانات سحب موافقته في أي وقت وفق الضوابط التي تحددها اللوائح.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:30.824257+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 6",
          "label": "Exceptions to Consent Requirement",
          "label_ar": "حالات الاستثناء من الموافقة",
          "summary": "Lists four cases where Processing does not require consent: it serves the Data Subject's actual interests and contacting them is impossible or difficult; it is pursuant to another law or a prior agreement with the Data Subject; a Public Entity requires it for security or judicial purposes; or the Controller's legitimate interest, excluding Sensitive Data.",
          "summary_ar": "تعدد أربع حالات لا تخضع فيها المعالجة للموافقة: إذا حققت مصلحة فعلية لصاحب البيانات وتعذر الاتصال به أو صعب؛ أو كانت بموجب نظام آخر أو تنفيذًا لاتفاق سابق يكون طرفًا فيه؛ أو كانت جهة التحكم جهة عامة وتطلبتها أغراض أمنية أو متطلبات قضائية؛ أو كانت لازمة لمصلحة مشروعة لجهة التحكم دون معالجة بيانات حساسة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:30.860117+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 4",
          "label": "Data Subject Rights",
          "label_ar": "حقوق صاحب البيانات",
          "summary": "The data subject's rights: to be informed, to access their data, to obtain a copy in a readable format, to request correction/completion/update, and to request destruction.",
          "summary_ar": "حقوق صاحب البيانات: الحق في العلم، والوصول إلى بياناته، والحصول على نسخة بصيغة مقروءة، وطلب تصحيحها أو إكمالها أو تحديثها، وطلب إتلافها.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-06-23T23:51:17.066942+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 7",
          "label": "Consent Not a Service Condition",
          "label_ar": "عدم اشتراط الموافقة لتقديم الخدمة",
          "summary": "Provides that consent to Processing may not be made a condition for providing a service or benefit, unless the service or benefit is directly related to the Personal Data Processing for which the consent is given.",
          "summary_ar": "تقضي بأنه لا يجوز أن تكون الموافقة على المعالجة شرطًا لتقديم خدمة أو الحصول على مزية، ما لم تكن الخدمة أو المزية مرتبطة ارتباطًا مباشرًا بمعالجة البيانات الشخصية التي تُمنح الموافقة من أجلها.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:30.897521+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 20",
          "label": "Breach Notification (duty)",
          "label_ar": "الإبلاغ عن الانتهاك (الالتزام)",
          "summary": "Imposes the duty to notify the Competent Authority and affected data subjects of a personal-data breach. The Law sets no fixed deadline, and the 72-hour timeline is set by IR Art. 24.",
          "summary_ar": "يفرض واجب إشعار الجهة المختصة وأصحاب البيانات المتأثرين بانتهاك البيانات الشخصية. ولا يحدد النظام مهلة؛ ومهلة الـ72 ساعة مقررة في المادة 24 من اللائحة التنفيذية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-08-12T09:46:21.657801+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 8",
          "label": "Processor Selection and Oversight",
          "label_ar": "اختيار جهة المعالجة والرقابة عليها",
          "summary": "Requires the Controller to select only Processors that provide sufficient guarantees to implement the Law and Regulations, and to monitor their compliance. The Controller remains responsible towards the Data Subject and the Competent Authority. The Regulations govern related matters, including subsequent contracts concluded by the Processor.",
          "summary_ar": "توجب على جهة التحكم ألا تختار إلا جهات معالجة تقدم الضمانات اللازمة لتطبيق أحكام النظام واللوائح، وأن تراقب التزامها بها. وتظل جهة التحكم مسؤولة تجاه صاحب البيانات الشخصية والجهة المختصة. وتحدد اللوائح الأحكام اللازمة في هذا الشأن، بما فيها الأحكام المتعلقة بالعقود اللاحقة التي تبرمها جهة المعالجة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:30.932164+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 22",
          "label": "Impact Assessment",
          "label_ar": "تقييم الأثر",
          "summary": "The Controller shall conduct an impact assessment for any product or service involving personal-data processing, in accordance with the Regulations (detailed in IR Art. 25).",
          "summary_ar": "تُجري جهة التحكم تقييماً للأثر لأي منتج أو خدمة تتضمن معالجة بيانات شخصية، وفقاً للائحة (مفصَّلة في المادة 25 من اللائحة التنفيذية).",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-06-23T23:51:17.066942+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 9",
          "label": "Restrictions on Access Right",
          "label_ar": "قيود حق الاطلاع",
          "summary": "Permits the Controller to set time frames for exercising the right of access and to limit that right where necessary to protect the Data Subject or others from harm, or where a Public Entity requires it for security, legal or judicial reasons. Access must be prevented in the situations listed in Article 16.",
          "summary_ar": "تجيز لجهة التحكم وضع أطر زمنية لممارسة حق الاطلاع على البيانات الشخصية وتقييد هذا الحق إذا كان ذلك لازمًا لحماية صاحب البيانات أو غيره من أي ضرر، أو إذا كانت جهة التحكم جهة عامة واقتضت ذلك أغراض أمنية أو نظام آخر أو متطلبات قضائية. ويجب منع الاطلاع في الحالات الواردة في المادة السادسة عشرة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:30.964076+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 10",
          "label": "Collection Sources and Purpose Limits",
          "label_ar": "مصادر الجمع وحدود الغرض",
          "summary": "Requires collecting Personal Data directly from the Data Subject and Processing it only for the Collection purpose, subject to seven exceptions: consent; publicly available data; Public Entity requirements; avoiding harm to the Data Subject or their vital interests; protecting public health, safety or lives; non-identifying storage; and the Controller's legitimate interests excluding Sensitive Data.",
          "summary_ar": "توجب جمع البيانات الشخصية من صاحبها مباشرة وقصر معالجتها على الغرض الذي جُمعت من أجله، مع سبع حالات استثنائية: الموافقة؛ والبيانات المتاحة للعموم؛ ومتطلبات الجهات العامة؛ وتفادي الإضرار بصاحب البيانات أو المساس بمصالحه الحيوية؛ وحماية الصحة العامة أو السلامة العامة أو حياة الأفراد؛ والحفظ بصورة لا تحدد الهوية؛ والمصلحة المشروعة لجهة التحكم دون معالجة بيانات حساسة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:30.997975+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 31",
          "label": "Records of Processing (Law)",
          "label_ar": "سجلات المعالجة (النظام)",
          "summary": "Lists the information that a controller's records of processing activities must contain (elaborated by IR Art. 33).",
          "summary_ar": "يحدد المعلومات التي يجب أن يتضمنها سجل أنشطة المعالجة لدى جهة التحكم (تفصّلها المادة 33 من اللائحة التنفيذية).",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-06-23T23:51:17.066942+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 11",
          "label": "Lawful Collection and Data Minimization",
          "label_ar": "ضوابط جمع البيانات",
          "summary": "Sets Collection standards: the purpose must relate directly to the Controller's purposes and comply with law; methods must be lawful, appropriate, direct, clear, secure and free of deception, misleading or extortion; content must be limited to the minimum necessary; and Collection must cease and collected data be destroyed when no longer needed.",
          "summary_ar": "تضع معايير للجمع: أن يكون الغرض مرتبطًا ارتباطًا مباشرًا بأغراض جهة التحكم وغير مخالف لأي نص نظامي؛ وأن تكون أساليب الجمع ووسائله نظامية ومناسبة ومباشرة وواضحة وآمنة وخالية من الخداع أو التضليل أو الابتزاز؛ وأن يقتصر المحتوى على الحد الأدنى اللازم لتحقيق الغرض؛ مع إيقاف الجمع وإتلاف ما سبق جمعه متى انتفت الحاجة إليه.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.033522+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 12",
          "label": "Privacy Policy",
          "label_ar": "سياسة الخصوصية",
          "summary": "Requires the Controller to adopt a privacy policy and make it available to Data Subjects before collecting their Personal Data. The policy must state the purpose of Collection, the data collected, the means of Collection, Processing, storage and Destruction, and the Data Subject's rights and how to exercise them.",
          "summary_ar": "توجب على جهة التحكم اعتماد سياسة خصوصية وإتاحتها لأصحاب البيانات الشخصية قبل جمع بياناتهم. ويجب أن تبين السياسة الغرض من الجمع، والبيانات الشخصية المراد جمعها، ووسيلة جمعها ومعالجتها وحفظها وإتلافها، ومعلومات عن حقوق صاحب البيانات وكيفية ممارستها.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.069815+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 13",
          "label": "Notice Upon Direct Collection",
          "label_ar": "الإحاطة عند الجمع المباشر",
          "summary": "Obliges the Controller, when collecting Personal Data directly, to inform the Data Subject of the legal basis, the purpose, which data is mandatory or optional, the collector's identity, recipient entities, any Transfer or Processing outside the Kingdom, consequences of not collecting, the Data Subject's rights, and other elements the Regulations specify.",
          "summary_ar": "تلزم جهة التحكم عند جمع البيانات الشخصية من صاحبها مباشرة بإحاطته بالسند النظامي للجمع، والغرض منه، وما هو إلزامي وما هو اختياري من البيانات، وهوية جهة الجمع، والجهات التي سيُفصح لها عنها، وما إذا كانت ستُنقل أو تُعالج خارج المملكة، والآثار المحتملة لعدم الجمع، وحقوقه بموجب النظام، وما تحدده اللوائح من عناصر أخرى.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.108753+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 14",
          "label": "Accuracy of Personal Data",
          "label_ar": "دقة البيانات الشخصية",
          "summary": "Prohibits the Controller from Processing Personal Data without first taking sufficient steps to verify the data's accuracy, completeness, timeliness and relevance to the purpose for which it was collected, in accordance with the provisions of the Law.",
          "summary_ar": "تحظر على جهة التحكم معالجة البيانات الشخصية دون اتخاذ خطوات كافية للتحقق من دقتها واكتمالها وحداثتها وملاءمتها للغرض الذي جُمعت من أجله، وذلك وفقًا لأحكام النظام.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.141779+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 15",
          "label": "Permitted Disclosure Cases",
          "label_ar": "حالات جواز الإفصاح",
          "summary": "Restricts Disclosure of Personal Data to six situations: the Data Subject's consent; data from a publicly available source; a Public Entity's request for public interest, security, legal or judicial purposes; protection of public health, safety or specific lives; non-identifying subsequent Processing; or the Controller's legitimate interests excluding Sensitive Data.",
          "summary_ar": "تقصر الإفصاح عن البيانات الشخصية على ست حالات: موافقة صاحب البيانات؛ أو جمعها من مصدر متاح للعموم؛ أو طلب جهة عامة لأغراض المصلحة العامة أو لأغراض أمنية أو لتنفيذ نظام آخر أو متطلبات قضائية؛ أو حماية الصحة العامة أو السلامة العامة أو حياة أفراد بعينهم؛ أو معالجة لاحقة بصورة لا تحدد الهوية؛ أو مصلحة مشروعة لجهة التحكم دون بيانات حساسة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.308296+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 16",
          "label": "Prohibited Disclosures",
          "label_ar": "حالات حظر الإفصاح",
          "summary": "Prohibits Disclosure under several of Article 15's grounds where it would threaten security, harm the Kingdom's reputation, interests or foreign relations, impede crime detection or fair trial, compromise an individual's safety, violate another person's privacy, harm persons lacking legal capacity, breach professional obligations or judicial decisions, or expose confidential sources against the public interest.",
          "summary_ar": "تحظر الإفصاح في عدد من حالات المادة الخامسة عشرة إذا كان يمثل تهديدًا للأمن، أو يضر بسمعة المملكة أو مصالحها أو علاقاتها مع الدول الأخرى، أو يحول دون اكتشاف جريمة أو يمس حق متهم في محاكمة عادلة، أو يعرض سلامة فرد للخطر، أو ينتهك خصوصية شخص آخر، أو يتعارض مع مصلحة ناقص الأهلية أو فاقدها، أو يخل بالتزامات مهنية أو بقرار قضائي، أو يكشف مصدرًا سريًا للمعلومات بما يضر بالمصلحة العامة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.340477+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 17",
          "label": "Notification of Data Corrections",
          "label_ar": "الإشعار بتصحيح البيانات",
          "summary": "Procedural article: when Personal Data is corrected, completed or updated, the Controller must notify all entities to which the data was transferred and make the amendment available to them. The Regulations set time frames, types of correction, and procedures to avoid Processing incorrect, inaccurate or outdated data.",
          "summary_ar": "مادة إجرائية: عند تصحيح البيانات الشخصية أو إكمالها أو تحديثها، يجب على جهة التحكم إشعار جميع الجهات التي نُقلت إليها البيانات بالتعديل وإتاحته لها. وتحدد اللوائح المدد الزمنية للتصحيح والتحديث وأنواع التصحيح والإجراءات اللازمة لتفادي آثار معالجة بيانات غير صحيحة أو غير دقيقة أو غير محدثة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.373415+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 18",
          "label": "Data Destruction and Retention",
          "label_ar": "إتلاف البيانات والاحتفاظ بها",
          "summary": "Requires the Controller to Destroy Personal Data without undue delay once no longer necessary, while permitting retention in a form that cannot identify the Data Subject. Retention is mandatory where a legal basis prescribes a specific period or the data relates to a case before a judicial authority, with Destruction afterwards.",
          "summary_ar": "توجب على جهة التحكم إتلاف البيانات الشخصية دون تأخير متى انتفت الحاجة إليها، مع جواز الاحتفاظ بها بصورة لا تؤدي إلى تحديد هوية صاحبها وفق ضوابط اللوائح. ويجب الاحتفاظ بها بعد انتهاء الغرض إذا وُجد سند نظامي يقضي بذلك لمدة محددة أو كانت متصلة بقضية منظورة أمام جهة قضائية، على أن تُتلف بعد ذلك.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.409802+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 19",
          "label": "Data Security Measures",
          "label_ar": "التدابير الأمنية لحماية البيانات",
          "summary": "Requires the Controller to implement all necessary organizational, administrative and technical measures to protect Personal Data, including during its Transfer, in accordance with the provisions and controls set out in the Regulations.",
          "summary_ar": "توجب على جهة التحكم اتخاذ جميع التدابير التنظيمية والإدارية والتقنية اللازمة لحماية البيانات الشخصية، بما في ذلك عند نقلها، وفقًا للأحكام والضوابط التي تحددها اللوائح.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.44167+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 21",
          "label": "Responding to Data Subject Requests",
          "label_ar": "الاستجابة لطلبات أصحاب البيانات",
          "summary": "Procedural provision requiring the Controller to respond to Data Subjects' requests concerning their rights under the Law within the period and in the manner set out in the Regulations.",
          "summary_ar": "حكم إجرائي يلزم جهة التحكم بالاستجابة لطلبات صاحب البيانات الشخصية المتعلقة بحقوقه بموجب النظام خلال المدة وبالطريقة اللتين تحددهما اللوائح.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.477515+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 23",
          "label": "Health Data Processing Controls",
          "label_ar": "ضوابط معالجة البيانات الصحية",
          "summary": "Mandates additional controls in the Regulations for Processing Health Data, protecting Data Subjects' privacy and rights. These include restricting access to Health Data, including medical files, to the minimum number of employees necessary to provide Health Services, and limiting Processing operations to what health services or insurance programs require.",
          "summary_ar": "تقضي بأن تتضمن اللوائح ضوابط وإجراءات إضافية لمعالجة البيانات الصحية بما يضمن خصوصية أصحابها ويحمي حقوقهم، ومنها قصر الاطلاع على البيانات الصحية، بما فيها الملفات الطبية، على أقل عدد ممكن من الموظفين والعاملين وبالقدر اللازم لتقديم الخدمات الصحية، وقصر عمليات المعالجة على القدر اللازم لتقديم الخدمات الصحية أو برامج التأمين الصحي.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.512865+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 24",
          "label": "Credit Data Processing Controls",
          "label_ar": "ضوابط معالجة البيانات الائتمانية",
          "summary": "Requires the Regulations to set additional controls for Processing Credit Data consistent with this Law and the Credit Information Law, including verifying the Data Subject's explicit consent to Collection, purpose changes, Disclosure or Publishing, and notifying the Data Subject whenever a request to disclose their Credit Data is received.",
          "summary_ar": "توجب أن تتضمن اللوائح ضوابط وإجراءات إضافية لمعالجة البيانات الائتمانية بما يتفق مع هذا النظام ونظام المعلومات الائتمانية، ومنها التحقق من موافقة صاحب البيانات الصريحة على جمعها أو تغيير الغرض من جمعها أو الإفصاح عنها أو نشرها، وإشعاره عند ورود طلب من أي جهة للإفصاح عن بياناته الائتمانية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.546612+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 25",
          "label": "Advertising and Awareness Communications",
          "label_ar": "المواد الدعائية والتوعوية",
          "summary": "Prohibits using a Data Subject's personal means of communication, including post and email, to send advertising or awareness-raising materials, except Public Entities' awareness materials, unless the recipient gave prior consent and the sender provides a clear mechanism to stop receiving them; the Regulations govern such materials and recipient consent.",
          "summary_ar": "تحظر استخدام وسائل الاتصال الشخصية لصاحب البيانات، بما فيها البريد العادي والإلكتروني، لإرسال مواد دعائية أو توعوية، باستثناء المواد التوعوية التي ترسلها الجهات العامة، ما لم تتوافر موافقة مسبقة من المستهدف ويوفر المرسل آلية واضحة تمكنه من طلب إيقاف إرسالها. وتحدد اللوائح الأحكام المتعلقة بهذه المواد وبموافقة المستقبِل.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.578852+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 26",
          "label": "Processing for Marketing Purposes",
          "label_ar": "المعالجة للأغراض التسويقية",
          "summary": "Permits Processing Personal Data, other than Sensitive Data, for marketing purposes only where the data was collected directly from the Data Subject and their consent was given in accordance with the Law. The Regulations set out the applicable controls.",
          "summary_ar": "تجيز معالجة البيانات الشخصية، عدا البيانات الحساسة، للأغراض التسويقية بشرط أن تكون قد جُمعت من صاحبها مباشرة وأن يكون قد وافق على ذلك وفقًا لأحكام النظام، وتحدد اللوائح الضوابط اللازمة في هذا الشأن.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.617208+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 27",
          "label": "Scientific, Research and Statistical Purposes",
          "label_ar": "الأغراض العلمية والبحثية والإحصائية",
          "summary": "Allows Collection or Processing of Personal Data without consent for scientific, research or statistical purposes where the data does not specifically identify the Data Subject, identity evidence is destroyed before Disclosure and the data is not Sensitive, or another law or a prior agreement so requires. The Regulations set the required controls.",
          "summary_ar": "تجيز جمع البيانات الشخصية أو معالجتها دون موافقة صاحبها للأغراض العلمية أو البحثية أو الإحصائية إذا كانت لا تدل على هويته تحديدًا، أو أُتلف ما يدل على هويته أثناء المعالجة وقبل الإفصاح عنها ولم تكن بيانات حساسة، أو كان ذلك مقتضى نظام آخر أو تنفيذًا لاتفاق سابق يكون طرفًا فيه. وتحدد اللوائح الضوابط اللازمة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.652951+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 28",
          "label": "Copying Official Documents",
          "label_ar": "نسخ الوثائق الرسمية",
          "summary": "Prohibits copying official documents that identify Data Subjects, except where copying is required by law or a competent public authority requests such copies in accordance with the Regulations.",
          "summary_ar": "تحظر نسخ الوثائق الرسمية التي تدل على هوية أصحاب البيانات الشخصية، إلا إذا كان النسخ مطلوبًا بموجب نص نظامي أو بطلب من جهة عامة مختصة وفقًا لما تحدده اللوائح.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.832693+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 29",
          "label": "Cross-Border Data Transfers",
          "label_ar": "نقل البيانات خارج المملكة",
          "summary": "Permits Transfer or Disclosure of Personal Data outside the Kingdom for agreements the Kingdom is party to, the Kingdom's interests, obligations the Data Subject is party to, or other purposes per the Regulations, subject to national security, an adequate protection level assessed by the Competent Authority, and data minimization, waived in extreme necessity involving life or health.",
          "summary_ar": "تجيز نقل البيانات الشخصية إلى خارج المملكة أو الإفصاح عنها لجهة خارجها تنفيذًا لاتفاقية تكون المملكة طرفًا فيها، أو خدمةً لمصالحها، أو تنفيذًا لالتزام يكون صاحب البيانات طرفًا فيه، أو لأغراض أخرى تحددها اللوائح؛ وذلك بشروط تتعلق بعدم المساس بالأمن الوطني، ووجود مستوى حماية مناسب تُقيّمه الجهة المختصة، والاقتصار على الحد الأدنى من البيانات، وتُستثنى من الشروط حالات الضرورة القصوى المتعلقة بالحياة أو الصحة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.871265+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 30",
          "label": "Supervisory Role of Competent Authority",
          "label_ar": "إشراف الجهة المختصة",
          "summary": "Designates the Competent Authority, without prejudice to the Saudi Central Bank's powers, as overseer of the Law's implementation. The Regulations identify when Controllers must appoint personal data protection officers. Controllers must cooperate with the Authority, which may request documents, seek other parties' assistance, maintain a national register of Controllers, charge service fees, and delegate supervisory duties.",
          "summary_ar": "تُسند إلى الجهة المختصة، دون إخلال بصلاحيات البنك المركزي السعودي، مهمة الإشراف على تنفيذ النظام واللوائح. وتحدد اللوائح الحالات التي يجب فيها على جهة التحكم تعيين مسؤول (أو أكثر) لحماية البيانات الشخصية. وتلتزم جهة التحكم بالتعاون مع الجهة المختصة، التي لها طلب الوثائق والمعلومات، والاستعانة بالغير، وإنشاء سجل وطني لجهات التحكم، وتحصيل مقابل مالي عن خدماتها، وتفويض بعض مهماتها إلى جهات أخرى.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.902432+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 32",
          "label": "Repealed Provision",
          "label_ar": "مادة ملغاة",
          "summary": "The text of this article states only that it has been repealed. It contains no operative provisions in the amended version of the Law, reflecting the removal of its former content while the article numbering of the Law is preserved.",
          "summary_ar": "يقتصر نص هذه المادة على بيان أنها مُلغاة، فلا تتضمن أي أحكام نافذة في النسخة المعدلة من النظام، بما يعكس إلغاء محتواها السابق مع المحافظة على تسلسل ترقيم مواد النظام.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.936844+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 33",
          "label": "Licensing, Accreditation and Audits",
          "label_ar": "التراخيص والاعتماد والتدقيق",
          "summary": "Empowers the Competent Authority to set requirements for commercial, professional or non-profit personal data protection activities, license entities issuing accreditation certificates to Controllers and Processors, license entities auditing Processing activities, and establish tools and procedures for monitoring and enforcing compliance of Controllers and Processors outside the Kingdom processing residents' data.",
          "summary_ar": "تخوّل الجهة المختصة وضع متطلبات مزاولة الأنشطة التجارية أو المهنية أو غير الربحية المتعلقة بحماية البيانات الشخصية، ومنح تراخيص للجهات التي تصدر شهادات اعتماد لجهات التحكم وجهات المعالجة، ومنح تراخيص لجهات التدقيق والفحص على أنشطة معالجة البيانات، وتحديد الأدوات والآليات والإجراءات اللازمة لمراقبة التزام جهات التحكم والمعالجة خارج المملكة التي تعالج بيانات المقيمين فيها وإنفاذ أحكام النظام خارجها.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:31.970849+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 34",
          "label": "Complaints to Competent Authority",
          "label_ar": "الشكاوى لدى الجهة المختصة",
          "summary": "Procedural article entitling Data Subjects to submit to the Competent Authority any complaint arising from the implementation of the Law and the Regulations, and directing the Regulations to set out the rules for processing such complaints.",
          "summary_ar": "مادة إجرائية تخوّل صاحب البيانات الشخصية التقدم إلى الجهة المختصة بأي شكوى تنشأ عن تطبيق النظام واللوائح، وتقضي بأن تحدد اللوائح قواعد معالجة تلك الشكاوى.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.008201+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 35",
          "label": "Criminal Penalties for Sensitive Data",
          "label_ar": "عقوبة الإفصاح عن البيانات الحساسة",
          "summary": "Penal provision: disclosing or publishing Sensitive Data in violation of the Law, with intent to harm the Data Subject or gain personal benefit, is punishable by imprisonment up to two years and/or a fine up to three million riyals. The Public Prosecution prosecutes; the competent court adjudicates and may double fines for recidivism.",
          "summary_ar": "حكم جزائي: يعاقب من يفصح عن بيانات حساسة أو ينشرها بالمخالفة لأحكام النظام بقصد الإضرار بصاحب البيانات أو تحقيق منفعة شخصية بالسجن مدة لا تزيد على سنتين أو بغرامة لا تزيد على ثلاثة ملايين ريال أو بهما معًا. وتتولى النيابة العامة التحقيق والادعاء، وتختص المحكمة المختصة بالفصل ولها مضاعفة الغرامة في حال العود.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.045273+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 36",
          "label": "Administrative Penalties",
          "label_ar": "العقوبات الإدارية",
          "summary": "For violations not covered by Article 35, provides a warning or fine up to five million riyals, doublable for repeat violations. A committee of at least three members formed by the Competent Authority's president examines violations and imposes penalties, subject to the president's approval; decisions are appealable before the competent court.",
          "summary_ar": "تقرر في غير الحالات المشمولة بالمادة الخامسة والثلاثين عقوبة الإنذار أو غرامة لا تزيد على خمسة ملايين ريال، مع جواز مضاعفتها عند تكرار المخالفة. وتتولى لجنة (أو أكثر) لا يقل أعضاؤها عن ثلاثة، تُشكل بقرار من رئيس الجهة المختصة، النظر في المخالفات وإيقاع العقوبات بعد اعتماد قراراتها من الرئيس، ويجوز الاعتراض عليها أمام المحكمة المختصة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.080978+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 37",
          "label": "Inspection and Seizure Powers",
          "label_ar": "صلاحيات الضبط والتفتيش",
          "summary": "Grants employees appointed by the Competent Authority's president powers to control and inspect violations of the Law and Regulations, under rules the president issues. Such employees may seek assistance from criminal investigation and other competent authorities, and the Competent Authority may seize the means or tools used in committing a violation.",
          "summary_ar": "تمنح الموظفين والعاملين المعينين بقرار من رئيس الجهة المختصة صلاحيات ضبط مخالفات أحكام النظام واللوائح والتفتيش عليها وفق القواعد التي يصدرها الرئيس، ولهم الاستعانة بجهات التحري الجنائي وغيرها من الجهات المختصة لأداء مهماتهم، وللجهة المختصة حجز الوسائل أو الأدوات المستخدمة في ارتكاب المخالفة حتى يُبت فيها.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.114629+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 38",
          "label": "Confiscation and Judgment Publication",
          "label_ar": "المصادرة ونشر الأحكام",
          "summary": "Empowers the competent court to order confiscation of funds obtained from violations, without prejudice to bona fide third parties. The court or the violations committee may also order publication of a summary of the penalty decision at the violator's expense once final, according to the violation's type, seriousness and impact.",
          "summary_ar": "تجيز للمحكمة المختصة، دون إخلال بحقوق الغير حسن النية، الحكم بمصادرة الأموال المتحصلة من ارتكاب المخالفات المنصوص عليها في النظام. كما يجوز للمحكمة أو للجنة النظر في المخالفات تضمين الحكم أو القرار النص على نشر ملخصه على نفقة المخالف بعد صيرورته نهائيًا، بحسب نوع المخالفة وجسامتها وأثرها.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.147349+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 39",
          "label": "Disciplining Public Entity Employees",
          "label_ar": "تأديب موظفي الجهات العامة",
          "summary": "Requires Public Entities, without prejudice to the penalties in Article 35 and Paragraph 1 of Article 36, to discipline any of their employees who violate the Law or the Regulations, in accordance with the disciplinary provisions and procedures prescribed by law.",
          "summary_ar": "توجب على الجهة العامة، دون إخلال بما ورد في المادة الخامسة والثلاثين والفقرة الأولى من المادة السادسة والثلاثين، تأديب أي من موظفيها يخالف أيًا من أحكام النظام واللوائح، وفقًا لأحكام وإجراءات التأديب المقررة نظامًا.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.181521+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 40",
          "label": "Compensation for Damage",
          "label_ar": "التعويض عن الضرر",
          "summary": "Entitles any individual who suffers damage as a result of a violation of the Law or the Regulations to apply to the competent court for compensation proportionate to the material or moral damage sustained, without prejudice to the penalties prescribed by the Law.",
          "summary_ar": "تخوّل كل من لحقه ضرر ناتج عن مخالفة أي من الأحكام الواردة في النظام أو اللوائح اللجوء إلى المحكمة المختصة للمطالبة بتعويض يتناسب مع الضرر المادي أو المعنوي الذي أصابه، دون إخلال بالعقوبات المقررة في النظام.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.356234+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 41",
          "label": "Ongoing Confidentiality Obligation",
          "label_ar": "الالتزام المستمر بالسرية",
          "summary": "Imposes a duty of confidentiality on any person who engages in the Processing of Personal Data, requiring them to protect the confidentiality of that data even after the end of their occupational or contractual relationship.",
          "summary_ar": "تفرض على كل من يشارك في معالجة البيانات الشخصية التزامًا بالمحافظة على سريتها، ويستمر هذا الالتزام حتى بعد انتهاء علاقته الوظيفية أو التعاقدية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.388295+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 42",
          "label": "Issuance of Implementing Regulations",
          "label_ar": "إصدار اللوائح التنفيذية",
          "summary": "Directs the president of the Competent Authority to issue the Regulations within seven hundred twenty days of the Law's publication, after coordination with seven named bodies, including the communications and foreign affairs ministries, the cybersecurity and digital government authorities, the Saudi Health Council and the Saudi Central Bank, each within its jurisdiction.",
          "summary_ar": "توجب على رئيس الجهة المختصة إصدار اللوائح خلال مدة لا تتجاوز سبعمائة وعشرين يومًا من تاريخ نشر النظام، بعد التنسيق مع سبع جهات محددة، منها وزارة الاتصالات وتقنية المعلومات ووزارة الخارجية والهيئة الوطنية للأمن السيبراني وهيئة الحكومة الرقمية والمجلس الصحي السعودي والبنك المركزي السعودي، كل فيما يخصه.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.420606+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 43",
          "label": "Entry Into Force",
          "label_ar": "بدء العمل بالنظام",
          "summary": "Final provision stating that the Law shall come into force after seven hundred and twenty days commencing on the date of its publication in the Official Gazette.",
          "summary_ar": "حكم ختامي ينص على أن يُعمل بالنظام بعد مضي سبعمائة وعشرين يومًا من تاريخ نشره في الجريدة الرسمية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.453977+00:00"
        }
      ]
    },
    {
      "slug": "saudi-central-bank-law",
      "name": "Saudi Central Bank Law",
      "name_ar": "نظام البنك المركزي السعودي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **Saudi Central Bank Law** is the constitutive statute of the Saudi Central Bank (SAMA), issued by Royal Decree M/36 (11/4/1442H, 26 November 2020), superseding the Saudi Arabian Monetary Authority Law of 1377H. The Bank is a financially and administratively independent legal person reporting to the King, with three statutory objectives: maintaining monetary stability, supporting the stability of, and trust in, the financial sector, and supporting economic growth (Art. 3).\n\nArticle 4 grants the Bank its toolkit: issuing and regulating currency, supervising financial institutions and issuing regulations and directives to them, conducting monetary policy and managing foreign reserves, operating national payment, settlement and clearing infrastructure, licensing and supervising financial-technology platforms, and issuing consumer-protection directives. \"Financial institution\" is defined broadly as any person subject to the Bank's supervision.\n\nSix chapters and 27 articles long, the Law is the foundation on which SAMA's supervisory rulebook rests, including its Cyber Security Framework, the Cyber Resilience Fundamental Requirements and the Payment Services Provider Regulations.",
      "summary_ar": "**نظام البنك المركزي السعودي** هو النظام التأسيسي للبنك المركزي السعودي (ساما)، الصادر بالمرسوم الملكي رقم (م/36) وتاريخ 11/4/1442هـ (26 نوفمبر 2020)، ليحل محل نظام مؤسسة النقد العربي السعودي الصادر عام 1377هـ. والبنك شخصية اعتبارية مستقلة مالياً وإدارياً ترتبط بالملك، وله ثلاثة أهداف نظامية: المحافظة على الاستقرار النقدي، ودعم استقرار القطاع المالي وتعزيز الثقة فيه، ودعم النمو الاقتصادي (المادة 3).\n\nوتمنح المادة (4) البنك كامل صلاحياته: إصدار النقد وتنظيمه، والإشراف والرقابة على المؤسسات المالية، وإصدار اللوائح والتعليمات المتعلقة بها، ورسم السياسة النقدية وإدارتها، وإدارة الاحتياطيات الأجنبية، وإنشاء وتشغيل البنى التحتية الوطنية لأنظمة المدفوعات والتسوية والمقاصة، وترخيص منصات التقنية المالية والإشراف عليها، وإصدار التعليمات لحماية عملاء المؤسسات المالية. ويُعرَّف مصطلح «المؤسسة المالية» تعريفاً واسعاً يشمل كل شخص يخضع لإشراف البنك ورقابته.\n\nويتكون النظام من ستة فصول و27 مادة، وهو الأساس النظامي الذي تستند إليه منظومة ساما الرقابية بأكملها، بما فيها إطار الأمن السيبراني، والمتطلبات الأساسية للمرونة السيبرانية، وقواعد مقدمي خدمات المدفوعات.",
      "type": "Law",
      "tier": 1,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/saudi-central-bank-law",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "sdaia-organizational-arrangements",
      "name": "SDAIA Organizational Arrangements",
      "name_ar": "الترتيبات التنظيمية للهيئة السعودية للبيانات والذكاء الاصطناعي",
      "subtitle": "الترتيبات التنظيمية للهيئة السعودية للبيانات والذكاء الاصطناعي",
      "subtitle_ar": "الترتيبات التنظيمية للهيئة السعودية للبيانات والذكاء الاصطناعي",
      "summary": "SDAIA's constitutive charter: the **Organizational Arrangements** of the Saudi Data & AI Authority.\n\nIssued by **Council of Ministers Resolution No. 292** (27/4/1441 AH) and amended by **Resolution No. 195** (15/3/1444 AH), under **Royal Order A/471** (29/12/1440 AH), the order that established SDAIA and created the NDMO and NCAI.\n\nIt constitutes the Authority and defines its powers, as distinct from the substantive laws SDAIA administers (e.g. the PDPL). In Saudi terms this is a Cabinet-level organizational instrument (tartībāt tanẓīmiyya), **not** a niẓām (Law) or an implementing regulation.\n\n_English text is an unofficial translation; the Arabic text governs._",
      "summary_ar": "الوثيقة التأسيسية لـSDAIA: **الترتيبات التنظيمية** للهيئة السعودية للبيانات والذكاء الاصطناعي.\n\nصدرت بموجب **قرار مجلس الوزراء رقم 292** (27/4/1441هـ) وعُدّلت بموجب **القرار رقم 195** (15/3/1444هـ)، استنادًا إلى **الأمر الملكي رقم أ/471** (29/12/1440هـ)، وهو الأمر الذي أنشأ SDAIA واستحدث مكتب إدارة البيانات الوطني NDMO والمركز الوطني للذكاء الاصطناعي NCAI.\n\nوتؤسس هذه الوثيقة الهيئة وتحدد صلاحياتها، بوصفها متمايزة عن الأنظمة الموضوعية التي تتولى الهيئة إدارتها (مثل نظام حماية البيانات الشخصية). وهي بالمصطلح السعودي أداة تنظيمية على مستوى مجلس الوزراء (ترتيبات تنظيمية)، وليست نظامًا (قانونًا) ولا لائحة تنفيذية.\n\n_النص الإنجليزي ترجمة غير رسمية؛ والنص العربي هو المعتمَد._",
      "type": "Council of Ministers Resolution",
      "tier": 2,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/sdaia-organizational-arrangements",
      "date_note": "CoM Resolution No. 292 (27/4/1441 AH), amended by No. 195 (15/3/1444 AH); under Royal Order A/471 (29/12/1440 AH)",
      "date_note_ar": "قرار مجلس الوزراء رقم 292 (27/4/1441هـ)، المعدّل بالقرار رقم 195 (15/3/1444هـ)؛ بموجب الأمر الملكي أ/471 (29/12/1440هـ)",
      "provisions": []
    },
    {
      "slug": "payment-services-provider-regulations",
      "name": "PAYMENT SERVICES PROVIDER REGULATIONS",
      "name_ar": "لائحة مقدمي خدمات المدفوعات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **Payment Services Provider Regulations** (updated August 2020) are the Saudi Central Bank's licensing and supervisory regime for non-bank payment service providers in the Kingdom. SAMA issued them under its powers in the Banking Control Law, the SAMA Charter and the Anti-Money Laundering Law, pursuant to Council of Ministers Resolution No. 226 (2/5/1440H); the subsequent Law of Payments and Payment Services (Royal Decree M/26, 22/3/1443H) has since placed the payments sector on its own statutory footing.\n\nThe Regulations define which payment services are in and out of scope, and establish **four licence categories**, Micro and Major Payment Institutions (PIs) and Micro and Major Electronic Money Institutions (EMIs), with common requirements for all applicants plus category-specific capital and governance thresholds.\n\nBeyond licensing, the Regulations impose ongoing obligations on governance, safeguarding of funds, record-keeping, outsourcing and reporting to SAMA. For the atlas, they anchor the payments limb of SAMA's rulebook, alongside the January 2020 Regulatory Guidelines that preceded them.",
      "summary_ar": "**قواعد مقدمي خدمات المدفوعات** (بصيغتها المحدَّثة في أغسطس 2020) هي منظومة الترخيص والإشراف التي يفرضها البنك المركزي السعودي على مقدمي خدمات المدفوعات من غير البنوك في المملكة. أصدرتها ساما استناداً إلى صلاحياتها بموجب نظام مراقبة البنوك ونظام مؤسسة النقد ونظام مكافحة غسل الأموال، وبموجب قرار مجلس الوزراء رقم (226) وتاريخ 2/5/1440هـ؛ ثم جاء نظام المدفوعات وخدماتها (المرسوم الملكي م/26 وتاريخ 22/3/1443هـ) ليمنح قطاع المدفوعات لاحقاً أساسه النظامي المستقل.\n\nوتحدد القواعد خدمات المدفوعات الداخلة في النطاق والخارجة عنه، وتُنشئ **أربع فئات ترخيص**: مؤسسات المدفوعات الصغرى والكبرى، ومؤسسات النقود الإلكترونية الصغرى والكبرى، مع متطلبات مشتركة لجميع المتقدمين إضافةً إلى حدود لرأس المال والحوكمة خاصة بكل فئة.\n\nوإلى جانب الترخيص، تفرض القواعد التزامات مستمرة تتعلق بالحوكمة وحماية الأموال وحفظ السجلات والإسناد إلى الغير ورفع التقارير إلى ساما. وبالنسبة للأطلس، تشكّل هذه القواعد ركيزة شق المدفوعات في منظومة ساما التنظيمية، إلى جانب الأدلة الإرشادية التنظيمية الصادرة في يناير 2020 التي سبقتها.",
      "type": "Regulation",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/payment-services-provider-regulations",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cloud-regs",
      "name": "Cloud Computing Regulatory Framework",
      "name_ar": "الإطار التنظيمي للحوسبة السحابية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "CST framework for cloud computing; CSP Class A/B/C tiers.",
      "summary_ar": "إطار هيئة الاتصالات والفضاء والتقنية (CST) للحوسبة السحابية؛ تصنيف مزوّدي الخدمات السحابية إلى الفئات CSP من النوع A/B/C.",
      "type": "Regulation",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "telecom",
      "authority": "CST",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cloud-regs",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ndmo-standards",
      "name": "NDMO Data Management & Personal Data Protection Standards",
      "name_ar": "معايير إدارة البيانات وحماية البيانات الشخصية الصادرة عن NDMO",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "77 controls / 191 specifications; mandatory for government entities.",
      "summary_ar": "77 ضابطًا / 191 مواصفة؛ إلزامية للجهات الحكومية.",
      "type": "Standard",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/DataManagementPersonalDataProtectionStandards.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/ndmo-standards",
      "date_note": null,
      "date_note_ar": null,
      "provisions": [
        {
          "kind": "control",
          "code": "PDP.1",
          "label": "Plan",
          "label_ar": "الخطة",
          "summary": "Personal Data Protection domain, control PDP.1, and the PDP plan. NDMO DM & PDP Standards: 15 domains → 77 controls → 191 specifications; codes are PDP.x (control) / PDP.x.x (specification), e.g. PDP.1.1. (No 'CS'/'MQ' infix exists.)",
          "summary_ar": "نطاق حماية البيانات الشخصية، الضابط PDP.1، خطة حماية البيانات. معايير NDMO: 15 مجالاً ← 77 ضابطاً ← 191 مواصفة؛ والرموز بصيغة PDP.x للضابط وPDP.x.x للمواصفة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-08-12T09:46:21.827302+00:00"
        },
        {
          "kind": "control",
          "code": "PDP.2",
          "label": "Training and Awareness",
          "label_ar": "التدريب والتوعية",
          "summary": "Personal Data Protection domain, control PDP.2, training and awareness.",
          "summary_ar": "نطاق حماية البيانات الشخصية، الضابط PDP.2، التدريب والتوعية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-08-12T09:46:21.883168+00:00"
        },
        {
          "kind": "control",
          "code": "PDP.3",
          "label": "Data Breach",
          "label_ar": "انتهاك البيانات",
          "summary": "Personal Data Protection domain, control PDP.3, data-breach detection, logging and notification to the regulator.",
          "summary_ar": "نطاق حماية البيانات الشخصية، الضابط PDP.3، اكتشاف انتهاكات البيانات وتسجيلها والإشعار بها للجهة المنظِّمة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-08-12T09:46:21.938064+00:00"
        },
        {
          "kind": "control",
          "code": "PDP.4",
          "label": "Data Lifecycle Management",
          "label_ar": "إدارة دورة حياة البيانات",
          "summary": "Personal Data Protection domain, control PDP.4, data lifecycle management; its specifications include risk-assessment findings (PDP.4.3) and monitoring (PDP.4.4).",
          "summary_ar": "نطاق حماية البيانات الشخصية، الضابط PDP.4، إدارة دورة حياة البيانات؛ وتشمل مواصفاته نتائج تقييم المخاطر (PDP.4.3) والمراقبة (PDP.4.4).",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-08-12T09:46:21.996937+00:00"
        },
        {
          "kind": "control",
          "code": "PDP.5",
          "label": "Artifacts",
          "label_ar": "المُخرجات",
          "summary": "Personal Data Protection domain, control PDP.5, artifacts (records and registers).",
          "summary_ar": "نطاق حماية البيانات الشخصية، الضابط PDP.5، المُخرجات (السجلات والقيود).",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-08-12T09:46:21.595259+00:00"
        }
      ]
    },
    {
      "slug": "implementing-regulation",
      "name": "Implementing (Executive) Regulation",
      "name_ar": "اللائحة التنفيذية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Implementing Regulation (September 2023) gives the PDPL its operational detail across 38 articles. **Amendments are pending**: a third public consultation closed on 27 May 2025 and had not been enacted as of August 2026; the provisions below reflect the Regulation as in force.\n\n**What it covers.** Data-subject requests must be answered within 30 days, extendable by a further 30 (Art. 3). Consent must be freely given, purpose-specific, documented and separate per purpose, and **explicit** for sensitive data, credit data and solely automated decision-making (Art. 11); withdrawal must be as easy as consenting (Art. 12). Legitimate-interest processing requires a documented prior assessment and excludes public entities and sensitive data (Art. 16). Processor relationships need contracts covering purpose, data categories, breach notification and subcontracting (Art. 17). Security follows the National Cybersecurity Authority's controls, or recognised best practice where those are not mandatory (Art. 23). Personal-data breaches must be notified to SDAIA **within 72 hours** where harm is possible, and to affected individuals without undue delay (Art. 24). Impact assessments are mandatory for sensitive data, dataset linking, constant monitoring, new technologies and automated decisions (Art. 25). Sector rules cover health data (Art. 26) and credit data (Art. 27); advertising and direct marketing are opt-in with easy, free opt-out (Arts. 28–29). Controllers must appoint a **data protection officer** in the cases of Art. 32, keep records of processing for the duration of processing plus five years (Art. 33), and register on the national register per SDAIA's rules (Art. 34). Complaints go to SDAIA within 90 days (Art. 37).\n\n## Frequently asked questions\n\n**When must a data breach be notified in Saudi Arabia?**\n\nArticle 24 requires the controller to notify SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the data subject, or conflict with their rights or interests. Affected data subjects must be notified without undue delay where the breach may cause them damage; there is no GDPR-style \"unlikely risk\" carve-out.\n\n**Who must appoint a data protection officer (DPO)?**\n\nArticle 32 requires a DPO where the controller is a public entity providing large-scale processing services, where core activities involve regular and systematic monitoring of data subjects, or where core activities consist of processing sensitive data. The DPO may be an employee or an external provider.\n\n**What triggers a data protection impact assessment?**\n\nArticle 25 lists the mandatory cases: processing sensitive data; collecting, comparing or linking two or more datasets; large-scale or repetitive processing of persons lacking capacity; operations requiring constant monitoring; newly adopted technologies; solely automated decision-making; and any product or service likely to cause serious privacy harm.\n\n**What is changing in the pending amendments?**\n\nThe May 2025 consultation proposed consolidating the DPO and controller-registration rules into the Regulation, simplifying the records-of-processing format, easing some direct-marketing provisions and removing the 90-day complaint window. None of this had been enacted as of August 2026; the September 2023 text remains in force.",
      "summary_ar": "توفر اللائحة التنفيذية (سبتمبر 2023) التفاصيل التشغيلية لنظام حماية البيانات الشخصية عبر (38) مادة. **وثمة تعديلات قيد الإقرار**: فقد أُغلقت مشاورة عامة ثالثة في 27 مايو 2025 دون أن تُقر التعديلات حتى أغسطس 2026، وتعكس الأحكام الواردة أدناه اللائحة بصيغتها النافذة.\n\n**ما تغطيه اللائحة.** يجب الاستجابة لطلبات أصحاب البيانات الشخصية خلال (30) يومًا مع إمكانية التمديد لمدة (30) يومًا إضافية (المادة (3)). ويجب أن تكون الموافقة صادرة عن إرادة حرة، ومحددة الغرض، وموثقة، ومنفصلة لكل غرض على حدة، وأن تكون **صريحة** عند معالجة البيانات الحساسة والبيانات الائتمانية واتخاذ القرارات المبنية بالكامل على المعالجة الآلية (المادة (11))؛ ويجب أن يكون الرجوع عن الموافقة بالسهولة ذاتها التي مُنحت بها (المادة (12)). وتتطلب المعالجة القائمة على المصلحة المشروعة تقييمًا مسبقًا موثقًا، وتُستبعد منها الجهات العامة والبيانات الحساسة (المادة (16)). وتستلزم العلاقة مع جهة المعالجة عقودًا تغطي الغرض وفئات البيانات والإشعار عن حوادث التسرب والتعاقد من الباطن (المادة (17)). ويخضع أمن البيانات لضوابط الهيئة الوطنية للأمن السيبراني، أو لأفضل الممارسات المعتبرة حيثما لا تكون تلك الضوابط إلزامية (المادة (23)). ويجب إشعار سدايا بحوادث تسرب البيانات الشخصية **خلال (72) ساعة** متى كان وقوع الضرر محتملًا، وإشعار الأفراد المتأثرين دون تأخير غير مبرر (المادة (24)). ويكون تقييم الأثر إلزاميًا في حالات البيانات الحساسة، وربط مجموعات البيانات، والمراقبة المستمرة، والتقنيات الحديثة، والقرارات المؤتمتة (المادة (25)). وتتناول الأحكام القطاعية البيانات الصحية (المادة (26)) والبيانات الائتمانية (المادة (27))؛ ويقوم الإعلان والتسويق المباشر على الموافقة المسبقة مع إتاحة إيقافهما بطريقة ميسّرة ودون مقابل (المادتان (28) و(29)). ويجب على جهة التحكم تعيين **مسؤول حماية البيانات** في الحالات المنصوص عليها في المادة (32)، والاحتفاظ بسجلات أنشطة المعالجة طوال مدة المعالجة مضافًا إليها خمس سنوات (المادة (33))، والتسجيل في السجل الوطني وفقًا للقواعد التي تضعها سدايا (المادة (34)). وتُقدَّم الشكاوى إلى سدايا خلال (90) يومًا (المادة (37)).\n\n## الأسئلة الشائعة\n\n**متى يجب الإشعار عن حادثة تسرب البيانات في المملكة العربية السعودية؟**\n\nتوجب المادة (24) على جهة التحكم إشعار سدايا خلال (72) ساعة من علمها بحادثة التسرب إذا كان من شأنها الإضرار بالبيانات الشخصية أو بصاحبها، أو التعارض مع حقوقه أو مصالحه. كما يجب إشعار أصحاب البيانات الشخصية المتأثرين دون تأخير غير مبرر إذا كان من شأن الحادثة إلحاق ضرر بهم، ولا يوجد استثناء من قبيل «الخطر المستبعد» على نمط اللائحة الأوروبية العامة لحماية البيانات (GDPR).\n\n**من الملزم بتعيين مسؤول حماية البيانات (DPO)؟**\n\nتوجب المادة (32) تعيين مسؤول حماية البيانات إذا كانت جهة التحكم جهة عامة تقدم خدمات تنطوي على معالجة واسعة النطاق، أو إذا كانت الأنشطة الأساسية لجهة التحكم تتضمن مراقبة منتظمة ومنهجية لأصحاب البيانات الشخصية، أو إذا كانت أنشطتها الأساسية تقوم على معالجة البيانات الحساسة. ويجوز أن يكون مسؤول حماية البيانات موظفًا لدى الجهة أو مقدم خدمة خارجيًا.\n\n**ما الحالات التي تستوجب إجراء تقييم الأثر لحماية البيانات الشخصية؟**\n\nتعدد المادة (25) الحالات الإلزامية، وهي: معالجة البيانات الحساسة؛ وجمع مجموعتين أو أكثر من مجموعات البيانات أو مقارنتها أو ربطها؛ والمعالجة الواسعة النطاق أو المتكررة لبيانات فاقدي الأهلية؛ والعمليات التي تتطلب مراقبة مستمرة؛ والتقنيات حديثة الاعتماد؛ واتخاذ القرارات المبنية بالكامل على المعالجة الآلية؛ وأي منتج أو خدمة يُرجَّح أن يُلحق ضررًا جسيمًا بالخصوصية.\n\n**ما الذي سيتغير في التعديلات قيد الإقرار؟**\n\nاقترحت مشاورة مايو 2025 دمج قواعد مسؤول حماية البيانات وقواعد تسجيل جهات التحكم في اللائحة، وتبسيط نموذج سجلات أنشطة المعالجة، وتخفيف بعض أحكام التسويق المباشر، وإلغاء مهلة تقديم الشكاوى المحددة بـ(90) يومًا. ولم يكن أي من ذلك قد أُقر حتى أغسطس 2026، ويظل نص سبتمبر 2023 هو النافذ.",
      "type": "Implementing Regulation",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "pdpl-law",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/ImplementingRegulationPersonalDataProtectionLaw.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/implementing-regulation",
      "date_note": "Amendments pending: consultation closed 27 May 2025; not enacted as of Aug 2026",
      "date_note_ar": "تعديلات قيد الإعداد: أُغلقت المشاورة في 27 مايو 2025؛ لم تُسَنّ حتى أغسطس 2026",
      "provisions": [
        {
          "kind": "article",
          "code": "Art. 4",
          "label": "Right to be informed",
          "label_ar": "الحق في العلم",
          "summary": "The data subject's right to be informed, and the transparency / privacy-notice obligation at or before collection (IR Arts. 3-8 set out the data-subject rights).",
          "summary_ar": "حق صاحب البيانات في العلم، التزام الشفافية وإشعار الخصوصية عند الجمع أو قبله (تنظّم المواد 3-8 من اللائحة حقوق صاحب البيانات).",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-08-12T09:46:21.326215+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 1",
          "label": "Definitions",
          "label_ar": "التعريفات",
          "summary": "Adopts the definitions of Article 1 of the Personal Data Protection Law and defines additional terms used in the Regulation, including Direct Marketing, Personal Data Breach, Vital Interest, Actual Interest, Legitimate Interest, Pseudonymisation, Anonymization, and Explicit Consent.",
          "summary_ar": "تعتمد التعريفات الواردة في المادة الأولى من نظام حماية البيانات الشخصية، وتحدد معاني مصطلحات إضافية مستخدمة في اللائحة، منها التسويق المباشر، وتسرب البيانات الشخصية، والمصلحة الحيوية، والمصلحة الفعلية، والمصلحة المشروعة، والترميز، وإخفاء الهوية، والموافقة الصريحة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.486638+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 24",
          "label": "Personal Data Breach Notification",
          "label_ar": "الإشعار بانتهاك البيانات الشخصية",
          "summary": "The Controller must notify SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the data subject; affected data subjects are notified without undue delay.",
          "summary_ar": "يجب على جهة التحكم إشعار سدايا خلال 72 ساعة من علمها بالانتهاك الذي قد يضر بالبيانات الشخصية أو بصاحبها، وإشعار أصحاب البيانات المتأثرين دون تأخير غير مبرر.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-06-23T23:51:17.066942+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 2",
          "label": "Personal or Family Use",
          "label_ar": "الاستخدام الشخصي أو العائلي",
          "summary": "Excludes from the Law's scope an individual's Processing of Personal Data for purposes not exceeding personal or family use, defined as Processing within a family or limited social circle. Publishing data to the public, disclosure beyond that circle, or professional, commercial, or non-profit use is not covered.",
          "summary_ar": "تستثني من نطاق تطبيق النظام معالجة الفرد للبيانات الشخصية لأغراض لا تتجاوز الاستخدام الشخصي أو العائلي، وتعرّفه بأنه المعالجة داخل الإطار العائلي أو الاجتماعي المحدود، ولا يُعد منه نشر البيانات للعموم أو الإفصاح عنها خارج هذا النطاق أو استخدامها لأغراض مهنية أو تجارية أو غير ربحية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.520283+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 25",
          "label": "Data Protection Impact Assessment",
          "label_ar": "تقييم الأثر على حماية البيانات",
          "summary": "Specifies the processing activities that require an impact assessment, including sensitive data, large-scale processing, vulnerable data subjects, new technologies and automated decision-making.",
          "summary_ar": "يحدد أنشطة المعالجة التي تستوجب إجراء تقييم للأثر، ومنها البيانات الحساسة والمعالجة واسعة النطاق وأصحاب البيانات الأكثر عرضة والتقنيات الحديثة واتخاذ القرارات الآلية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-08-12T09:46:21.416914+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 3",
          "label": "General Provisions for Data Subject Rights",
          "label_ar": "الأحكام العامة لحقوق صاحب البيانات الشخصية",
          "summary": "Requires the Controller to act on data subject rights requests within 30 days, extendable by a further 30 days with notice, verify the requester's identity, and document all requests. Repetitive, manifestly unfounded, or disproportionate requests may be refused with reasons; legal guardians exercise rights for those lacking capacity.",
          "summary_ar": "توجب على جهة التحكم تنفيذ طلبات صاحب البيانات الشخصية المتعلقة بحقوقه خلال (30) يوماً، قابلة للتمديد (30) يوماً إضافية مع إشعاره، والتحقق من هوية مقدم الطلب، وتوثيق جميع الطلبات. ويجوز رفض الطلبات المتكررة أو غير المبررة أو التي تتطلب جهوداً غير متناسبة مع بيان السبب، ويمارس الولي الحقوق نيابةً عن فاقدي الأهلية كلياً أو جزئياً.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.551854+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 32",
          "label": "Data Protection Officer",
          "label_ar": "مسؤول حماية البيانات",
          "summary": "Lists the processing that requires appointing a DPO (public bodies processing at scale, regular and systematic monitoring, core processing of sensitive data); the appointment is documented and notified to SDAIA.",
          "summary_ar": "يحدد حالات المعالجة التي تستوجب تعيين مسؤول لحماية البيانات (الجهات العامة، والمراقبة المنتظمة والممنهجة، ومعالجة البيانات الحساسة)، ويُوثَّق التعيين ويُبلَّغ به سدايا.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-06-23T23:51:17.066942+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 33",
          "label": "Records of Processing Activities (RoPA)",
          "label_ar": "سجل أنشطة المعالجة",
          "summary": "The Controller maintains a written record of processing activities during processing and for five years afterwards, kept accurate and produced to SDAIA on request. (Being simplified under the pending IR amendments.)",
          "summary_ar": "تحتفظ جهة التحكم بسجل مكتوب لأنشطة المعالجة أثناء المعالجة ولمدة خمس سنوات بعدها، محدَّثاً ويُقدَّم لسدايا عند الطلب. (يجري تبسيطه ضمن تعديلات اللائحة المرتقبة.)",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-06-23T23:51:17.066942+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 5",
          "label": "Right of Access",
          "label_ar": "حق الاطلاع على البيانات الشخصية",
          "summary": "Grants the data subject the right to access their Personal Data held by the Controller, either on request or through a direct-access channel, provided access does not adversely affect others' rights such as intellectual property or trade secrets, and no Personal Data identifying another individual is disclosed.",
          "summary_ar": "تمنح صاحب البيانات الشخصية حق الاطلاع على بياناته الشخصية المتوفرة لدى جهة التحكم، سواء بناءً على طلب أو عبر قناة تتيح الاطلاع المباشر، على ألا يؤثر ذلك سلباً في حقوق الآخرين كحقوق الملكية الفكرية أو الأسرار التجارية، ومع ضمان عدم الإفصاح عن بيانات شخصية تحدد هوية فرد آخر.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.585692+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 34",
          "label": "National Register of Controllers",
          "label_ar": "السجل الوطني لجهات التحكم",
          "summary": "Sets the requirements for registering controllers in the national register, distinct from the RoPA in Art. 33.",
          "summary_ar": "يحدد متطلبات تسجيل جهات التحكم في السجل الوطني، ويختلف عن سجل أنشطة المعالجة في المادة 33.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-08-12T09:46:21.47808+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 36",
          "label": "Auditing and Controlling",
          "label_ar": "التدقيق والرقابة",
          "summary": "Audits and checks of personal-data processing to ensure the entity properly protects personal data. (This, not Art. 24/25/33, is the audit obligation.)",
          "summary_ar": "تدقيق ومراجعة معالجة البيانات الشخصية للتأكد من أن الجهة تحمي البيانات الشخصية على نحو سليم. (هذه، وليست المواد 24/25/33، هي مادة التدقيق.)",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-08-12T09:46:21.542018+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 6",
          "label": "Right to Request Data Copy",
          "label_ar": "حق طلب الحصول على نسخة من البيانات",
          "summary": "Entitles the data subject to request a copy of their Personal Data in a readable and clear format, provided in a commonly used electronic format or, if feasible, a printed hard copy, without adversely affecting others' rights or disclosing Personal Data that identifies another individual.",
          "summary_ar": "تخوّل صاحب البيانات الشخصية طلب الحصول على نسخة من بياناته الشخصية بصيغة واضحة ومقروءة، تُقدَّم بصيغة إلكترونية شائعة الاستخدام أو نسخة ورقية مطبوعة متى كان ذلك ممكناً، دون المساس بحقوق الآخرين أو الإفصاح عن بيانات شخصية تحدد هوية فرد آخر.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.618065+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 7",
          "label": "Right to Request Correction",
          "label_ar": "حق طلب تصحيح البيانات الشخصية",
          "summary": "Allows the data subject to obtain restriction of Processing while the accuracy of contested Personal Data is verified. The Controller may request supporting documents, which must be destroyed once verification is complete, and must notify parties to whom the data was previously disclosed after correction, without undue delay.",
          "summary_ar": "تتيح لصاحب البيانات الشخصية تقييد المعالجة خلال فترة التحقق من دقة البيانات الشخصية المعترض عليها. ويجوز لجهة التحكم طلب مستندات مؤيدة على أن تُتلف فور اكتمال التحقق، وعليها إشعار الجهات التي سبق الإفصاح لها عن البيانات بعد تصحيحها دون تأخير غير مبرر.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.653554+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 8",
          "label": "Right to Request Destruction",
          "label_ar": "حق طلب إتلاف البيانات الشخصية",
          "summary": "Obliges the Controller to destroy Personal Data upon the data subject's request, when no longer necessary for the collection purpose, on withdrawal of consent where consent is the sole legal basis, or if processed unlawfully. All copies including backups must be destroyed and recipients notified, subject to Article 18 of the Law.",
          "summary_ar": "تلزم جهة التحكم بإتلاف البيانات الشخصية بناءً على طلب صاحب البيانات الشخصية، أو عند انتفاء الحاجة إليها لتحقيق غرض جمعها، أو عند سحب الموافقة إذا كانت الأساس النظامي الوحيد للمعالجة، أو إذا عُولجت بطريقة غير مشروعة، مع إتلاف جميع النسخ بما فيها النسخ الاحتياطية وإشعار الجهات التي أُفصح لها عنها، دون إخلال بالمادة (18) من النظام.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.684537+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 9",
          "label": "Anonymisation",
          "label_ar": "إخفاء الهوية",
          "summary": "Sets conditions for anonymising Personal Data: the Controller must ensure re-identification is impossible, assess the impact and re-identification risk, apply and update organisational, administrative, and technical measures in light of technological developments, and evaluate the effectiveness of the techniques used. Anonymised data is no longer considered Personal Data.",
          "summary_ar": "تحدد ضوابط إخفاء هوية البيانات الشخصية؛ إذ يجب على جهة التحكم ضمان استحالة إعادة تحديد هوية صاحب البيانات الشخصية، وتقييم الأثر واحتمالية إعادة تحديد الهوية، واتخاذ التدابير التنظيمية والإدارية والتقنية اللازمة وتحديثها وفق التطورات التقنية، وتقييم فعالية التقنيات المطبقة. ولا تُعد البيانات بعد إخفاء الهوية بيانات شخصية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.71763+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 10",
          "label": "Means of Communication",
          "label_ar": "وسائل التواصل",
          "summary": "Requires the Controller to provide appropriate means for handling data subject rights requests. The data subject may choose among the options made available, including e-mail, text messages, the national address, electronic applications, or any other lawful communication means provided by the Controller for this purpose.",
          "summary_ar": "توجب على جهة التحكم توفير الوسائل المناسبة لمعالجة الطلبات المتعلقة بحقوق صاحب البيانات الشخصية، وله الاختيار من بين الخيارات المتاحة، ومنها البريد الإلكتروني، والرسائل النصية، والعنوان الوطني، والتطبيقات الإلكترونية، أو أي وسيلة تواصل نظامية أخرى توفرها جهة التحكم لهذا الغرض.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.88122+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 11",
          "label": "Consent Conditions",
          "label_ar": "شروط الموافقة",
          "summary": "Sets conditions for valid consent: freely given without misleading methods, for clear and specific purposes explained in advance, given by a person with full legal capacity, documented verifiably, and obtained separately for each Processing purpose. Explicit consent is required for Sensitive Data, Credit Data, and solely automated decision-making.",
          "summary_ar": "تحدد شروط الموافقة الصحيحة: أن تصدر بحرية دون أساليب مضللة، ولأغراض واضحة ومحددة تُوضَّح مسبقاً، وأن تصدر ممن يتمتع بالأهلية النظامية الكاملة، وأن تُوثَّق بوسائل تتيح التحقق منها مستقبلاً، وأن تكون موافقة مستقلة لكل غرض من أغراض المعالجة. وتُشترط الموافقة الصريحة لمعالجة البيانات الحساسة والبيانات الائتمانية والقرارات المبنية كلياً على المعالجة الآلية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.915369+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 12",
          "label": "Consent Withdrawal",
          "label_ar": "سحب الموافقة",
          "summary": "Confirms the data subject may withdraw consent at any time. Withdrawal must be as easy as giving consent, with procedures established in advance. The Controller must then cease Processing without undue delay and notify recipients to destroy the data; prior Processing and Processing on other legal bases remain unaffected.",
          "summary_ar": "تؤكد حق صاحب البيانات الشخصية في سحب موافقته في أي وقت، على أن يكون السحب بسهولة منحها أو أيسر، مع وضع إجراءات السحب مسبقاً. وعلى جهة التحكم التوقف عن المعالجة دون تأخير غير مبرر وإشعار من أُفصح لهم عن البيانات بطلب إتلافها، دون أن يؤثر السحب في مشروعية المعالجة السابقة أو المعالجة المستندة إلى أساس نظامي آخر.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.948092+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 13",
          "label": "Legal Guardian",
          "label_ar": "الولي الشرعي",
          "summary": "Regulates how the legal guardian of a data subject lacking full or partial legal capacity exercises rights and consents to Processing in the subject's best interests. The Controller must verify guardianship validity, ensure the guardian's consent causes no harm, and let the data subject exercise rights upon reaching legal capacity.",
          "summary_ar": "تنظم قيام الولي الشرعي لصاحب البيانات الشخصية فاقد الأهلية كلياً أو جزئياً بممارسة حقوقه والموافقة على معالجة بياناته بما يحقق مصلحته الفضلى. وعلى جهة التحكم التحقق من صحة الولاية، وضمان ألا تُلحق موافقة الولي ضرراً بمصالح صاحب البيانات، وتمكينه من ممارسة حقوقه متى اكتسب الأهلية النظامية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:32.983386+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 14",
          "label": "Processing for Actual Interest",
          "label_ar": "المعالجة لتحقيق المصلحة الفعلية",
          "summary": "When Processing Personal Data to serve the data subject's Actual Interest, the Controller must retain evidence demonstrating both that the actual interest exists and that it is not possible to contact or communicate with the data subject.",
          "summary_ar": "عند معالجة البيانات الشخصية لتحقيق مصلحة فعلية لصاحب البيانات الشخصية، يجب على جهة التحكم الاحتفاظ بما يُثبت قيام تلك المصلحة وتعذُّر الاتصال أو التواصل مع صاحب البيانات الشخصية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.015234+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 15",
          "label": "Collecting Data from Third Parties",
          "label_ar": "جمع البيانات من طرف ثالث",
          "summary": "Governs Processing of Personal Data collected from sources other than the data subject: Processing must be necessary, proportionate to the purpose, and must not affect the data subject's rights and interests. Collection from publicly available sources must be lawful, and the Regulation's anonymisation provisions apply where relevant.",
          "summary_ar": "تنظم معالجة البيانات الشخصية المجموعة من مصادر غير صاحب البيانات الشخصية مباشرةً؛ فيجب أن تكون المعالجة ضرورية ومتناسبة مع الغرض المحدد، وألا تؤثر في حقوق صاحب البيانات ومصالحه، مع التحقق من مشروعية الجمع من المصادر المتاحة للعموم، ومراعاة أحكام إخفاء الهوية الواردة في اللائحة عند الاقتضاء.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.04963+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 16",
          "label": "Processing for Legitimate Interest",
          "label_ar": "المعالجة لتحقيق المصلحة المشروعة",
          "summary": "Permits Controllers other than Public Entities to process Personal Data for a Legitimate Interest, provided the purpose is lawful, interests are balanced against the data subject's rights, no Sensitive Data is involved, and Processing is within reasonable expectations. A documented prior assessment is required, with modification if harm is indicated.",
          "summary_ar": "تجيز لجهات التحكم - عدا الجهات العامة - معالجة البيانات الشخصية لتحقيق مصلحة مشروعة، بشرط ألا يخالف الغرض أنظمة المملكة، وتحقيق الموازنة بين مصلحة جهة التحكم وحقوق صاحب البيانات الشخصية ومصالحه، وألا تشمل المعالجة بيانات حساسة، وأن تكون ضمن التوقعات المعقولة لصاحب البيانات. ويلزم إجراء تقييم موثق قبل المعالجة، وتعديل المعالجة أو الاستناد إلى أساس آخر إذا تبين احتمال الضرر.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.0823+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 17",
          "label": "Processor Selection",
          "label_ar": "اختيار جهة المعالجة",
          "summary": "Requires the Controller to select Processors offering sufficient guarantees and to conclude agreements covering purpose, data categories, duration, breach notification, and subcontractors. The Controller must issue instructions and periodically assess compliance; a Processor breaching instructions is treated as a Controller, and subcontracting requires guarantees and the Controller's prior acceptance.",
          "summary_ar": "توجب على جهة التحكم اختيار جهة معالجة تقدم ضمانات كافية لحماية البيانات الشخصية، وأن يتضمن الاتفاق بينهما الغرض من المعالجة وفئات البيانات ومدتها والالتزام بالإشعار عن حوادث تسرب البيانات وتحديد المتعاقدين من الباطن. وعلى جهة التحكم إصدار تعليمات واضحة وتقييم امتثال جهة المعالجة دورياً، وتُعد جهة المعالجة المخالفة للتعليمات أو الاتفاق جهة تحكم مسؤولة مباشرةً، ويشترط للتعاقد من الباطن ضمانات كافية وقبول مسبق من جهة التحكم.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.115378+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 18",
          "label": "Processing Beyond Original Purpose",
          "label_ar": "المعالجة لغرض مغاير لغرض الجمع",
          "summary": "Applies when Personal Data is processed for a purpose other than the one for which it was collected: the Controller must clearly define the new purposes, record them in Processing activity records, document data-scoping procedures such as data maps, and limit Processing to the minimum data necessary.",
          "summary_ar": "تسري عند معالجة البيانات الشخصية لغرض غير الغرض الذي جُمعت من أجله؛ إذ يجب على جهة التحكم تحديد أغراض المعالجة بوضوح ودقة، وتدوينها في سجلات أنشطة معالجة البيانات الشخصية، وتوثيق إجراءات تحديد نطاق البيانات محل المعالجة بوسائل منها خرائط البيانات، وقصر الجمع والمعالجة على الحد الأدنى اللازم لتحقيق الغرض.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.147343+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 19",
          "label": "Data Minimisation",
          "label_ar": "الحد الأدنى من البيانات",
          "summary": "Requires the Controller to collect only the minimum Personal Data necessary to achieve the Processing purpose, using appropriate means such as data maps to link each collected item to a purpose, to avoid collecting unnecessary data, and to retain only the minimal data needed for the purpose.",
          "summary_ar": "توجب على جهة التحكم الاقتصار على جمع الحد الأدنى من البيانات الشخصية اللازمة لتحقيق غرض المعالجة، باستخدام وسائل مناسبة منها خرائط البيانات التي تربط كل بيان مجموع بغرض المعالجة، وتجنب جمع بيانات غير ضرورية، والاحتفاظ بالحد الأدنى من البيانات اللازمة لتحقيق الغرض.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.179068+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 20",
          "label": "Disclosure of Personal Data",
          "label_ar": "الإفصاح عن البيانات الشخصية",
          "summary": "Sets controls for disclosing Personal Data, including data from publicly available sources: disclosure must relate to a specific, clear purpose, protect privacy, and be limited to the minimum necessary. Disclosure requests from public authorities must be documented, third-party data safeguarded through balancing and pseudonymisation, and all disclosure operations recorded with dates, methods, and purposes.",
          "summary_ar": "تضع ضوابط الإفصاح عن البيانات الشخصية بما فيها البيانات المجموعة من مصادر متاحة للعموم؛ فيجب أن يرتبط الإفصاح بغرض محدد وواضح، مع العناية اللازمة بحماية خصوصية صاحب البيانات الشخصية، وقصره على الحد الأدنى اللازم. ويجب توثيق طلبات الإفصاح المقدمة من الجهات العامة، وحماية بيانات الغير بالموازنة بين الحقوق والترميز حيثما أمكن، وتدوين عمليات الإفصاح وتواريخها ووسائلها وأغراضها في سجلات أنشطة المعالجة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.211167+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 21",
          "label": "Public Interest Processing Controls",
          "label_ar": "ضوابط المعالجة لأغراض المصلحة العامة",
          "summary": "Applies when a Public Entity collects Personal Data indirectly, processes it for a new purpose, or requests disclosure to achieve a public interest. The entity must ensure necessity for a clearly defined public interest within its mandate, limit potential damage, record the operations, and process only the minimum data.",
          "summary_ar": "تسري عندما تجمع جهة عامة بيانات شخصية من غير صاحبها مباشرةً، أو تعالجها لغرض مغاير لغرض جمعها، أو تطلب الإفصاح عنها لتحقيق مصلحة عامة؛ إذ يجب التحقق من ضرورة ذلك لتحقيق مصلحة عامة محددة بوضوح ترتبط باختصاص الجهة، واتخاذ تدابير مناسبة للحد من الضرر المحتمل، وتدوين تلك العمليات في سجلات أنشطة المعالجة، والاقتصار على الحد الأدنى من البيانات.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.398006+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 22",
          "label": "Correction of Personal Data",
          "label_ar": "تصحيح البيانات الشخصية",
          "summary": "Details the Controller's correction duties: correcting inaccurate data, completing incomplete data, and updating outdated data. The Controller must verify accuracy, notify prior recipients and the data subject, document updates, suspend Processing where inaccurate data may cause harm, and maintain policies and periodic reviews of data accuracy.",
          "summary_ar": "تفصّل واجبات جهة التحكم في التصحيح، ويشمل تصحيح البيانات غير الصحيحة وإكمال الناقصة وتحديث القديمة. وعليها التحقق من دقة البيانات وسلامتها، وإشعار من سبق الإفصاح لهم عنها وإشعار صاحب البيانات الشخصية عند اكتمال التصحيح، وتوثيق التحديثات، وتعليق المعالجة إذا كان من شأن البيانات غير الدقيقة إلحاق ضرر بصاحبها، ووضع سياسات داخلية ومراجعة دورية لدقة البيانات وحداثتها.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.432094+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 23",
          "label": "Information Security",
          "label_ar": "أمن المعلومات",
          "summary": "Requires the Controller to take organisational, administrative, and technical measures to secure Personal Data and protect privacy, including security measures limiting breach risks and adopting the controls, standards, and rules of the National Cybersecurity Authority, or recognised cybersecurity best practices where those rules are not mandatory for the Controller.",
          "summary_ar": "توجب على جهة التحكم اتخاذ التدابير التنظيمية والإدارية والتقنية اللازمة لضمان أمن البيانات الشخصية وخصوصية أصحابها، بما في ذلك تطبيق التدابير الأمنية والتقنية للحد من مخاطر تسرب البيانات، واعتماد الضوابط والمعايير والقواعد الصادرة عن الهيئة الوطنية للأمن السيبراني، أو أفضل الممارسات والمعايير المعتمدة في الأمن السيبراني إذا لم تكن جهة التحكم ملزمة بها.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.470196+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 26",
          "label": "Processing Health Data",
          "label_ar": "معالجة البيانات الصحية",
          "summary": "Obliges the Controller to protect Health Data through organisational, technical, and administrative measures, adopting requirements of health and insurance regulators, embedding the Law in internal policies, segregating staff responsibilities with tiered access, documenting all Processing stages, binding Processors contractually, and limiting Processing to the minimum needed for healthcare or health insurance.",
          "summary_ar": "تلزم جهة التحكم بحماية البيانات الصحية عبر تدابير تنظيمية وتقنية وإدارية، تشمل اعتماد المتطلبات والضوابط الصادرة عن وزارة الصحة والمجلس الصحي السعودي والبنك المركزي السعودي ومجلس الضمان الصحي والجهات ذات العلاقة، وتضمين أحكام النظام ولوائحه في السياسات الداخلية، وتوزيع المهام والمسؤوليات بما يمنع تداخل الاختصاصات مع تفاوت مستويات الوصول، وتوثيق جميع مراحل المعالجة، وإلزام جهات المعالجة تعاقدياً، وقصر معالجة البيانات الصحية على الحد الأدنى اللازم لتقديم الخدمات الصحية أو برامج التأمين الصحي.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.50452+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 27",
          "label": "Processing Credit Data",
          "label_ar": "معالجة البيانات الائتمانية",
          "summary": "Requires the Controller, without prejudice to the Credit Information Law, to protect Credit Data from unauthorised use, access, or disclosure by adopting requirements of the Saudi Central Bank and relevant authorities, and to obtain the data subject's consent and notify them of any request to disclose their Credit Data.",
          "summary_ar": "توجب على جهة التحكم - دون إخلال بنظام المعلومات الائتمانية - حماية البيانات الائتمانية من الاستخدام أو الوصول أو الإفصاح غير المصرح به، باعتماد المتطلبات والضوابط الصادرة عن البنك المركزي السعودي والجهات ذات العلاقة، والحصول على موافقة صاحب البيانات الشخصية وإشعاره عند أي طلب للإفصاح عن بياناته الائتمانية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.53645+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 28",
          "label": "Advertising and Awareness Materials",
          "label_ar": "المواد الإعلانية أو التوعوية",
          "summary": "Regulates sending advertising or awareness materials: prior consent of the targeted recipient is required absent previous interaction, consent must be free, specific, and documented, the sender's identity must be clearly stated, and recipients must be able to halt such materials easily, immediately, and free of charge.",
          "summary_ar": "تنظم إرسال المواد الإعلانية أو التوعوية؛ إذ يجب الحصول على موافقة المستهدف مسبقاً عند عدم وجود تعامل سابق مع جهة التحكم، وأن تكون الموافقة حرة ومحددة وموثقة بما يتيح التحقق منها، مع الإفصاح بوضوح عن هوية المرسل، وتوفير آلية تمكّن المستهدف من إيقاف استقبال تلك المواد بسهولة وبشكل فوري ودون مقابل.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.569519+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 29",
          "label": "Direct Marketing",
          "label_ar": "التسويق المباشر",
          "summary": "Requires the Controller, before Processing Personal Data for Direct Marketing, to obtain the data subject's consent and provide a mechanism to halt marketing material that is as simple as giving consent. The sender's identity must be clearly disclosed, and marketing must stop without undue delay upon consent withdrawal.",
          "summary_ar": "توجب على جهة التحكم قبل معالجة البيانات الشخصية لأغراض التسويق المباشر الحصول على موافقة صاحب البيانات الشخصية، وتوفير آلية لإيقاف استقبال المواد التسويقية لا تقل سهولةً عن إجراءات منح الموافقة، مع الإفصاح بوضوح عن هوية المرسل، والتوقف عن إرسال المواد التسويقية دون تأخير غير مبرر عند سحب الموافقة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.607212+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 30",
          "label": "Scientific, Research or Statistical Purposes",
          "label_ar": "الأغراض العلمية أو البحثية أو الإحصائية",
          "summary": "Governs collecting or Processing Personal Data for scientific, research, or statistical purposes without the data subject's consent: purposes must be clearly specified in Processing records, only the minimum necessary data collected, data pseudonymised where the purposes can still be fulfilled, and any negative impact on the data subject's rights avoided.",
          "summary_ar": "تنظم جمع البيانات الشخصية أو معالجتها لأغراض علمية أو بحثية أو إحصائية دون موافقة صاحب البيانات الشخصية؛ إذ يجب تحديد تلك الأغراض بوضوح ودقة في سجلات أنشطة المعالجة، والاقتصار على الحد الأدنى اللازم من البيانات، وترميز البيانات محل المعالجة متى أمكن تحقيق الأغراض بذلك، واتخاذ التدابير اللازمة لضمان عدم تأثير المعالجة سلباً في حقوق صاحب البيانات ومصالحه.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.643061+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 31",
          "label": "Photographing or Copying Official Documents",
          "label_ar": "تصوير الوثائق الرسمية أو نسخها",
          "summary": "Prohibits the Controller from photographing or copying official documents issued by Public Entities that identify data subjects, except at the request of a public competent authority or to fulfil a legal requirement. Such documents must be protected and destroyed once their purpose ends, unless retention is legally required.",
          "summary_ar": "تحظر على جهة التحكم تصوير الوثائق الرسمية الصادرة عن الجهات العامة التي تكشف هوية صاحب البيانات الشخصية أو نسخها، إلا بناءً على طلب من جهة عامة مختصة أو استيفاءً لمتطلب نظامي. ويجب توفير الحماية اللازمة لتلك الوثائق وإتلافها فور انتهاء الغرض من الحصول عليها ما لم يوجد متطلب نظامي يقضي بالاحتفاظ بها.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.675416+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 35",
          "label": "Accreditation Bodies",
          "label_ar": "جهات الاعتماد",
          "summary": "Tasks the competent authority with issuing regulatory rules for licensing entities that grant accreditation certificates to Controllers and Processors under Article 33 of the Law, and with coordinating with the Digital Government Authority on licensing entities that provide such services on behalf of government entities.",
          "summary_ar": "تُسند إلى الجهة المختصة إصدار القواعد المنظمة للترخيص للجهات التي تصدر شهادات الاعتماد لجهات التحكم وجهات المعالجة وفقاً للمادة (33) من النظام، والتنسيق مع هيئة الحكومة الرقمية فيما يتعلق بالترخيص للجهات التي تقدم هذه الخدمات نيابةً عن الجهات الحكومية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.713338+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 37",
          "label": "Submitting and Processing Complaints",
          "label_ar": "تقديم الشكاوى ومعالجتها",
          "summary": "Allows a data subject to file a complaint with the competent authority within 90 days of the incident or of becoming aware of it, with late complaints admissible for reasonable causes. The authority must register, examine, and act on complaints and inform the complainant of the outcome.",
          "summary_ar": "تجيز لصاحب البيانات الشخصية تقديم شكوى إلى الجهة المختصة خلال مدة لا تتجاوز (90) يوماً من تاريخ وقوع الحادثة أو العلم بها، مع جواز قبول الشكاوى المتأخرة لأسباب معقولة. وتتولى الجهة المختصة استقبال الشكاوى وقيدها في سجل مخصص ودراستها واتخاذ الإجراءات اللازمة بشأنها وإبلاغ مقدم الشكوى بالنتيجة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.747699+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 38",
          "label": "Publication and Enforcement",
          "label_ar": "النشر والنفاذ",
          "summary": "Provides that the Regulation shall be published in the official gazette and on the competent authority's official website, and shall come into force from the date of the Law's enforcement.",
          "summary_ar": "تقضي بنشر اللائحة التنفيذية في الجريدة الرسمية وفي الموقع الإلكتروني الرسمي للجهة المختصة، وبأن يُعمل بها من تاريخ العمل بالنظام.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.927302+00:00"
        }
      ]
    },
    {
      "slug": "freedom-of-information-policy",
      "name": "Freedom of Information Policy",
      "name_ar": "سياسة حرية المعلومات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Government freedom-of-information policy.",
      "summary_ar": "السياسة الحكومية لحرية المعلومات.",
      "type": "Instrument",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/FreedomOfInformationPolicy.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/freedom-of-information-policy",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "transfer-regulation",
      "name": "Regulation on Personal Data Transfer Outside KSA",
      "name_ar": "لائحة نقل البيانات الشخصية خارج المملكة العربية السعودية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Regulation on Personal Data Transfer Outside the Kingdom operationalises PDPL Article 29. First issued in September 2023, it was reissued as **version 2.0 in September 2024**, and SDAIA published Standard Contractual Clauses and a transfer risk-assessment guideline to support it.\n\n**How transfers work.** A transfer or disclosure outside the Kingdom needs a permitted purpose: the Law's purposes (a Kingdom treaty obligation, the Kingdom's interests, an obligation the data subject is party to) extended by Article 2 to central processing operations, providing a service or benefit to the data subject, and scientific research. SDAIA is to publish and review, every four years or as needed, a list of countries and organisations providing an adequate level of protection (Art. 3); pending that list, transfers rely in practice on Article 4's exemptions, which require **appropriate safeguards**: SDAIA's Standard Contractual Clauses, Binding Common Rules for corporate groups, or an accreditation certificate. The Law and Regulation continue to apply to any onward transfer (Art. 5), exemptions lapse if safeguards fail (Art. 6), and a documented **risk assessment** is required before transfers under the exemptions and for continuous or large-scale transfers of sensitive data (Art. 7).\n\n## Frequently asked questions\n\n**Do we need SDAIA's approval for each transfer?**\n\nNo. There is no per-transfer approval requirement. The controller must have a permitted purpose (PDPL Art. 29; Transfer Regulation Art. 2), meet the conditions or fall within an Article 4 exemption backed by appropriate safeguards, and document a risk assessment where Article 7 requires one.\n\n**Is there a Saudi adequacy list?**\n\nArticle 3 directs the competent authority to publish a list of countries and international organisations with an adequate level of protection, reviewed every four years or as necessary. As of mid-2026 no list had been published, so transfers in practice proceed under the Article 4 exemptions with appropriate safeguards.\n\n**Which safeguards are recognised?**\n\nArticle 4 recognises three: Standard Contractual Clauses issued by SDAIA (published September 2024), Binding Common Rules for transfers within a corporate group, and accreditation certificates issued by licensed bodies. EU-style SCCs are not a recognised Saudi safeguard.\n\n**When is a transfer risk assessment mandatory?**\n\nArticle 7 requires one before transferring or disclosing personal data under the Article 4 exemptions, and whenever sensitive data is transferred on a continuous or wide-scale basis. The assessment covers the purpose and legal basis, the nature and scope of the transfer, the safeguards applied, data minimisation, the potential effects and their likelihood, and mitigation measures.",
      "summary_ar": "تضع لائحة نقل البيانات الشخصية إلى خارج المملكة المادة (29) من نظام حماية البيانات الشخصية موضع التطبيق العملي. وقد صدرت اللائحة أول مرة في سبتمبر 2023، ثم أُعيد إصدارها **بالإصدار 2.0 في سبتمبر 2024**، ونشرت سدايا البنود التعاقدية القياسية ودليلًا استرشاديًا لتقييم مخاطر النقل دعمًا لتطبيقها.\n\n**آلية النقل.** يتطلب نقل البيانات الشخصية إلى خارج المملكة أو الإفصاح عنها لجهة خارجها وجود غرض مسموح به، فالأغراض المقررة في النظام (تنفيذ التزام بموجب اتفاقية تكون المملكة طرفًا فيها، أو خدمة مصالح المملكة، أو تنفيذ التزام يكون صاحب البيانات الشخصية طرفًا فيه) وسّعتها المادة (2) لتشمل عمليات المعالجة المركزية، وتقديم خدمة أو منفعة لصاحب البيانات الشخصية، والبحث العلمي. وعلى سدايا أن تنشر وتراجع، كل أربع سنوات أو كلما دعت الحاجة، قائمة بالدول والمنظمات التي توفر مستوى مناسبًا من الحماية (المادة (3))؛ وإلى حين صدور تلك القائمة تستند عمليات النقل عمليًا إلى الاستثناءات الواردة في المادة (4)، التي تشترط **ضمانات مناسبة**: البنود التعاقدية القياسية الصادرة عن سدايا، أو القواعد المشتركة الملزمة لمجموعات الشركات، أو شهادة اعتماد. ويظل النظام واللائحة ساريين على أي نقل لاحق للبيانات (المادة (5))، وتسقط الاستثناءات متى اختلت الضمانات (المادة (6))، ويلزم إجراء **تقييم مخاطر** موثق قبل عمليات النقل المستندة إلى الاستثناءات، وكذلك في حالات النقل المستمر أو الواسع النطاق للبيانات الحساسة (المادة (7)).\n\n## الأسئلة الشائعة\n\n**هل نحتاج إلى موافقة سدايا على كل عملية نقل؟**\n\nلا. لا يوجد اشتراط للحصول على موافقة لكل عملية نقل على حدة. وإنما يجب على جهة التحكم أن يتوافر لديها غرض مسموح به (المادة (29) من نظام حماية البيانات الشخصية؛ والمادة (2) من لائحة نقل البيانات الشخصية إلى خارج المملكة)، وأن تستوفي الشروط المقررة أو تندرج ضمن أحد الاستثناءات الواردة في المادة (4) مدعومًا بضمانات مناسبة، وأن توثق تقييمًا للمخاطر متى أوجبته المادة (7).\n\n**هل توجد قائمة سعودية بالدول ذات مستوى الحماية المناسب؟**\n\nتوجب المادة (3) على الجهة المختصة نشر قائمة بالدول والمنظمات الدولية التي توفر مستوى مناسبًا من الحماية، على أن تُراجَع كل أربع سنوات أو عند الاقتضاء. وحتى منتصف عام 2026 لم تكن أي قائمة قد نُشرت؛ ولذلك تجري عمليات النقل عمليًا استنادًا إلى الاستثناءات الواردة في المادة (4) مع توافر الضمانات المناسبة.\n\n**ما الضمانات المعترف بها؟**\n\nتعترف المادة (4) بثلاث ضمانات: البنود التعاقدية القياسية الصادرة عن سدايا (نُشرت في سبتمبر 2024)، والقواعد المشتركة الملزمة لعمليات النقل داخل مجموعة الشركات الواحدة، وشهادات الاعتماد الصادرة عن الجهات المرخص لها. أما البنود التعاقدية القياسية على النمط الأوروبي فلا تُعد ضمانة معترفًا بها في المملكة.\n\n**متى يكون تقييم مخاطر النقل إلزاميًا؟**\n\nتوجب المادة (7) إجراء التقييم قبل نقل البيانات الشخصية أو الإفصاح عنها بموجب الاستثناءات الواردة في المادة (4)، وكذلك كلما جرى نقل بيانات حساسة بصورة مستمرة أو على نطاق واسع. ويغطي التقييم الغرض والأساس النظامي، وطبيعة عملية النقل ونطاقها، والضمانات المطبقة، والاقتصار على الحد الأدنى من البيانات، والآثار المحتملة ومدى احتمال وقوعها، وتدابير التخفيف منها.",
      "type": "Implementing Regulation",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "pdpl-law",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/RegulationonPersonalDataEN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/transfer-regulation",
      "date_note": "Updated 2024",
      "date_note_ar": "محدَّثة 2024",
      "provisions": [
        {
          "kind": "article",
          "code": "Art. 1",
          "label": "Definitions",
          "label_ar": "التعريفات",
          "summary": "Adopts the definitions of Article 1 of the Personal Data Protection Law and defines terms specific to this Regulation, including Appropriate Safeguards, Operational Processes, Standard Contractual Clauses, and Binding Common Rules applicable to transfers of personal data outside the Kingdom.",
          "summary_ar": "تعتمد التعريفات الواردة في المادة الأولى من نظام حماية البيانات الشخصية، وتحدد معاني مصطلحات خاصة بهذه اللائحة، منها الضمانات المناسبة، والعمليات التشغيلية، والبنود التعاقدية القياسية، والقواعد المشتركة الملزمة، فيما يتعلق بنقل البيانات الشخصية إلى خارج المملكة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.965158+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 2",
          "label": "Other Purposes for Transfer",
          "label_ar": "أغراض أخرى لنقل البيانات",
          "summary": "Specifies additional purposes for transferring or disclosing personal data to a party outside the Kingdom under Article 29 of the Law, including performing central processing operations necessary for the controller's activities, providing a service or benefit to the data subject, and conducting scientific research and studies.",
          "summary_ar": "تحدد أغراضاً أخرى لنقل البيانات الشخصية أو الإفصاح عنها لجهة خارج المملكة وفقاً للمادة (29) من النظام، ومنها تنفيذ العمليات اللازمة للمعالجة المركزية بما يمكّن جهة التحكم من مزاولة نشاطها، وتقديم خدمة أو منفعة لصاحب البيانات الشخصية، وإجراء البحوث والدراسات العلمية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:33.998438+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 3",
          "label": "Adequacy Assessment",
          "label_ar": "تقييم مستوى الحماية خارج المملكة",
          "summary": "Requires the competent authority to publish, and review every four years or as necessary, a list of countries and international organisations providing an adequate level of personal data protection, based on criteria including legislation, supervisory bodies, and cooperation. The authority may amend the list or suspend transfers; the standards also apply to cities, special economic zones, and global trade centres.",
          "summary_ar": "توجب على الجهة المختصة نشر قائمة بالدول والمنظمات الدولية التي توفر مستوى مناسباً لحماية البيانات الشخصية ومراجعتها كل أربع سنوات أو عند الحاجة، وفق معايير منها وجود تنظيمات لحماية البيانات، وجهة إشرافية معنية بإنفاذها، واستعدادها للتعاون مع الجهة المختصة. ويجوز للجهة المختصة تعديل القائمة أو تعليق النقل، وتسري المعايير أيضاً على المدن والمناطق الاقتصادية الخاصة والمراكز التجارية العالمية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:34.034687+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 4",
          "label": "Exemptions and Appropriate Safeguards",
          "label_ar": "حالات الإعفاء والضمانات المناسبة",
          "summary": "Exempts controllers, in defined cases, from the adequacy and data-minimisation conditions of Article 29 of the Law, provided appropriate safeguards apply: standard contractual clauses, binding common rules, or accreditation certificates. Cases cover public-body agreements, limited transfers, multinational central operations, services to data subjects, and scientific research; the competent authority may review the safeguards every two years or as necessary.",
          "summary_ar": "تعفي جهة التحكم في حالات محددة من شرطي توفر المستوى المناسب من الحماية والحد الأدنى من البيانات المنصوص عليهما في المادة (29) من النظام أو من أحدهما، شريطة تطبيق ضمانات مناسبة تشمل البنود التعاقدية القياسية أو القواعد المشتركة الملزمة أو شهادات الاعتماد. وتشمل الحالات الاتفاقيات بين الجهات العامة، والنقل غير المتكرر المحدود، والعمليات المركزية لمجموعات الكيانات متعددة الجنسيات، وتقديم خدمة أو منفعة لصاحب البيانات الشخصية، والبحث العلمي، مع مراجعة الجهة المختصة لكفاية الضمانات كل سنتين أو عند الحاجة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:34.071514+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 5",
          "label": "Subsequent Transfers of Personal Data",
          "label_ar": "النقل اللاحق للبيانات الشخصية",
          "summary": "Provides that the Law and its Regulations continue to apply to any subsequent transfer of personal data that has already been transferred or disclosed to a party outside the Kingdom, without prejudice to Articles 8 and 15 of the Law and Article 17 of the Implementing Regulation.",
          "summary_ar": "تقضي باستمرار سريان النظام ولوائحه على عمليات النقل اللاحق للبيانات الشخصية التي سبق نقلها أو الإفصاح عنها لجهة خارج المملكة، وذلك دون إخلال بأحكام المادتين (8) و(15) من النظام والمادة (17) من اللائحة التنفيذية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:34.106022+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 6",
          "label": "Revocation of Exemption",
          "label_ar": "إلغاء الإعفاء",
          "summary": "Terminates exemptions granted under Article 4 of the Regulation where the controller fails to implement the appropriate safeguards or the competent authority finds those safeguards inadequate in a specific case. The controller must then halt the transfer or disclosure and notify the entities that received the personal data.",
          "summary_ar": "تقضي بعدم سريان أي من الإعفاءات الممنوحة وفقاً للمادة (4) من اللائحة إذا أخفقت جهة التحكم في تطبيق الضمانات المناسبة، أو إذا قررت الجهة المختصة عدم كفاية تلك الضمانات في حالة معينة. وعلى جهة التحكم عندئذٍ إيقاف النقل أو الإفصاح وإشعار الجهات التي نُقلت إليها البيانات الشخصية أو أُفصح لها عنها.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:34.140512+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 7",
          "label": "Risk Assessment for Transfers",
          "label_ar": "تقييم مخاطر النقل",
          "summary": "Requires the controller to conduct a risk assessment before transferring or disclosing personal data outside the Kingdom under Article 4 exemptions, or when transferring sensitive data continuously or widely. The assessment covers purpose, legal basis, nature and scope, safeguards, data minimisation, potential effects and their likelihood, and mitigation measures.",
          "summary_ar": "توجب على جهة التحكم إجراء تقييم للمخاطر قبل نقل البيانات الشخصية أو الإفصاح عنها لجهة خارج المملكة في حالات الإعفاء وفقاً للمادة (4) من اللائحة، وعند نقل البيانات الحساسة بصفة مستمرة أو واسعة النطاق. ويشمل التقييم الغرض والأساس النظامي، ووصف طبيعة النقل ونطاقه الجغرافي، والضمانات المناسبة ومدى كفايتها، وتدابير الاقتصار على الحد الأدنى من البيانات، والآثار المادية والمعنوية المحتملة واحتمالية وقوعها، والتدابير اللازمة لمنع المخاطر أو الحد من آثارها.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:34.171962+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 8",
          "label": "Guides and Guidelines",
          "label_ar": "الأدلة والإرشادات",
          "summary": "Directs the competent authority to issue guides and guidelines related to the provisions of this Regulation on the transfer of personal data outside the Kingdom.",
          "summary_ar": "تقضي بأن تصدر الجهة المختصة الأدلة والإرشادات المتعلقة بالأحكام الواردة في هذه اللائحة الخاصة بنقل البيانات الشخصية إلى خارج المملكة.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:34.20475+00:00"
        },
        {
          "kind": "article",
          "code": "Art. 9",
          "label": "Entry into Force",
          "label_ar": "النفاذ",
          "summary": "The Regulation enters into force on the date of its publication in the Official Gazette.",
          "summary_ar": "يُعمل باللائحة من تاريخ نشرها في الجريدة الرسمية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-07-13T23:23:34.237852+00:00"
        }
      ]
    },
    {
      "slug": "data-classification-policy",
      "name": "Data Classification Policy",
      "name_ar": "سياسة تصنيف البيانات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NDMO national data-classification policy (Top Secret / Secret / Confidential / Public).",
      "summary_ar": "سياسة التصنيف الوطنية للبيانات الصادرة عن مكتب إدارة البيانات الوطني NDMO (سري للغاية / سري / مقيّد / عام).",
      "type": "Standard",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/DataClassificationPolicy.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/data-classification-policy",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "open-data-policy",
      "name": "Open Data Policy",
      "name_ar": "سياسة البيانات المفتوحة",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NDMO open-data policy for government entities.",
      "summary_ar": "سياسة البيانات المفتوحة الصادرة عن مكتب إدارة البيانات الوطني NDMO للجهات الحكومية.",
      "type": "Instrument",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/OpenDataPolicy.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/open-data-policy",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "dpo-appointment-rules",
      "name": "Rules for Appointing a DPO",
      "name_ar": "قواعد تعيين مسؤول حماية البيانات (DPO)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Rules on when and how to appoint a Data Protection Officer. May be folded into the amended Implementing Regulation.",
      "summary_ar": "قواعد بشأن متى وكيف يُعيَّن مسؤول حماية البيانات (DPO). وقد تُدمَج ضمن اللائحة التنفيذية المعدّلة.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/RulesforAppointingPersonalDataProtectionOfficer.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/dpo-appointment-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ecc",
      "name": "Essential Cybersecurity Controls (ECC-2:2024)",
      "name_ar": "الضوابط الأساسية للأمن السيبراني (ECC-2:2024)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The NCA's baseline cybersecurity controls: 108 controls across 4 domains.",
      "summary_ar": "الضوابط الأساسية للأمن السيبراني الصادرة عن NCA: 108 ضابطًا موزّعة على 4 مجالات.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": "https://nca.gov.sa/en/regulatory-documents/controls-list/ecc/",
      "wadira_url": "https://www.wadiraksa.com/instrument/ecc",
      "date_note": "ECC-2:2024",
      "date_note_ar": "ECC-2:2024",
      "provisions": []
    },
    {
      "slug": "hie-policies",
      "name": "Health Information Exchange (HIE) Policies",
      "name_ar": "سياسات تبادل المعلومات الصحية (HIE)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "MOH policies for health information exchange.",
      "summary_ar": "سياسات وزارة الصحة (MOH) لتبادل المعلومات الصحية.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "health",
      "authority": "MOH",
      "parent": null,
      "in_library": true,
      "official_url": "https://nhic.gov.sa/standards/Policies/IS0303-Saudi-Health-Information-Exchange-Policies-v1.0.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/hie-policies",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "nca-cybersecurity-toolkits",
      "name": "NCA Cybersecurity Toolkits",
      "name_ar": "أدوات الأمن السيبراني الصادرة عن NCA",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The NCA Cybersecurity Toolkits are a library of template documents published by the National Cybersecurity Authority to help organisations build the documentary backbone of a cybersecurity programme. Their stated objectives are to raise organisations' cybersecurity efficiency, reduce cyber risks and enhance cyber readiness.\n\nThe toolkits consist of templates for policies, standards, procedures and governance documents, offered in editable Word and PDF formats. They include a cybersecurity organisational structure template, a cybersecurity strategy and roadmap, and policy templates spanning the NCA's control domains, among them asset management, identity and access management, network and server security, cryptography, malware protection, event-log monitoring, incident and threat management, business continuity, risk management, review and audit, third-party cybersecurity, cloud computing and hosting, operational technology and secure development, together with matching standards, checklists and governance forms. They give organisations a consistent starting point for implementing NCA control sets such as the ECC.",
      "summary_ar": "أدوات الأمن السيبراني الصادرة عن الهيئة الوطنية للأمن السيبراني هي مكتبة من النماذج المُعدّة لمساعدة الجهات على بناء الأساس الوثائقي لبرنامج الأمن السيبراني. وتتمثل أهدافها المعلنة في تمكين الجهات من رفع كفاءتها في الأمن السيبراني، وتقليل المخاطر السيبرانية، وتعزيز الجاهزية السيبرانية.\n\nتتكوّن الأدوات من نماذج للسياسات والمعايير والإجراءات ووثائق الحوكمة، متاحة بصيغتي Word القابلة للتحرير وPDF. وتشمل نموذج الهيكل التنظيمي للأمن السيبراني، ونموذج استراتيجية الأمن السيبراني وخارطة طريقها، ونماذج سياسات تمتد عبر مجالات ضوابط الهيئة، ومنها إدارة الأصول، وإدارة هويات الدخول والصلاحيات، وأمن الشبكات والخوادم، والتشفير، والحماية من البرمجيات الضارة، ومراقبة سجلات الأحداث، وإدارة الحوادث والتهديدات، واستمرارية الأعمال، وإدارة المخاطر، والمراجعة والتدقيق، والأمن السيبراني المتعلق بالأطراف الخارجية، والحوسبة السحابية والاستضافة، والتقنيات التشغيلية، والتطوير الآمن، إلى جانب معايير مماثلة وقوائم تحقق ونماذج حوكمة. وتوفر هذه الأدوات للجهات نقطة انطلاق متسقة لتطبيق مجموعات ضوابط الهيئة مثل الضوابط الأساسية للأمن السيبراني (ECC).",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/nca-cybersecurity-toolkits",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ai-adoption-framework",
      "name": "AI Adoption Framework",
      "name_ar": "إطار تبنّي الذكاء الاصطناعي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Framework for AI adoption.",
      "summary_ar": "إطار لتبنّي الذكاء الاصطناعي.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/AIAdoptionFramework.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/ai-adoption-framework",
      "date_note": "2024",
      "date_note_ar": "2024",
      "provisions": []
    },
    {
      "slug": "ndi",
      "name": "National Data Index (NDI)",
      "name_ar": "المؤشر الوطني للبيانات (NDI)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **National Data Index (NDI)** is SDAIA's dynamic, results-oriented monitoring and evaluation index that assesses government entities across three lenses:\n\n- **DM Maturity**: how well an entity applies best practices across **14 data-management domains** (people, technology, processes), with improvement recommendations.\n- **DM & PDP Standards Compliance**: adoption and implementation of the NDMO Data Management and Personal Data Protection Standards.\n- **Operational Excellence (OE)**: progress in using the National Data Platforms across **6 DM domains**.\n\nAssessments are measured and audited periodically via the NDI platform. The NDI supports Vision 2030 by strengthening data governance, data quality, lifecycle management, compliance reporting and a data-driven culture across the Kingdom.",
      "summary_ar": "**المؤشر الوطني للبيانات (NDI)** هو مؤشر الرصد والتقييم الديناميكي والموجَّه نحو النتائج التابع لـSDAIA، والذي يقيّم الجهات الحكومية عبر ثلاثة محاور:\n\n- **نضج إدارة البيانات**: مدى تطبيق الجهة للممارسات المثلى عبر **14 مجالًا من مجالات إدارة البيانات** (الأشخاص والتقنية والعمليات)، مع توصيات للتحسين.\n- **الامتثال لمعايير إدارة البيانات وحماية البيانات الشخصية**: تبنّي وتطبيق معايير إدارة البيانات وحماية البيانات الشخصية الصادرة عن مكتب إدارة البيانات الوطني NDMO.\n- **التميّز التشغيلي (OE)**: التقدّم في الاستفادة من المنصات الوطنية للبيانات عبر **6 من مجالات إدارة البيانات**.\n\nتُقاس عمليات التقييم وتُدقَّق دوريًا عبر منصة المؤشر الوطني للبيانات NDI. ويدعم المؤشر رؤية 2030 من خلال تعزيز حوكمة البيانات وجودة البيانات وإدارة دورة حياتها وإعداد تقارير الامتثال وترسيخ ثقافة قائمة على البيانات في جميع أنحاء المملكة.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/ndi",
      "date_note": null,
      "date_note_ar": null,
      "provisions": [
        {
          "kind": "section",
          "code": "Compliance",
          "label": "Compliance",
          "label_ar": "الالتزام",
          "summary": "Adherence to the NDMO Data Management & PDP specifications, assessed in phases. The NDI scores entities against the NDMO specifications, it does not define its own specification codes.",
          "summary_ar": "مدى الالتزام بمواصفات إدارة البيانات وحماية البيانات الشخصية الصادرة عن NDMO، ويُقيَّم على مراحل. يقيس المؤشر الجهات وفق مواصفات NDMO ولا يضع رموز مواصفات خاصة به.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-08-12T09:46:22.05877+00:00"
        },
        {
          "kind": "section",
          "code": "Maturity",
          "label": "Data Management Maturity (0–5)",
          "label_ar": "النضج (0–5)",
          "summary": "Maturity of data-management practice across the domains on a 0–5 scale (Absence of Capabilities → Pioneer), assessed via a questionnaire on the National Data Governance Platform.",
          "summary_ar": "نضج ممارسات إدارة البيانات عبر المجالات على مقياس 0–5 (غياب القدرات ← الريادة)، عبر استبيان على منصة حوكمة البيانات الوطنية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-06-23T23:51:17.066942+00:00"
        },
        {
          "kind": "section",
          "code": "Operational Excellence",
          "label": "Operational Excellence",
          "label_ar": "التميّز التشغيلي",
          "summary": "Efficiency and effectiveness of data operations, drawn from national data platforms.",
          "summary_ar": "كفاءة وفعالية عمليات البيانات، مستمدة من منصات البيانات الوطنية.",
          "parent": null,
          "official_anchor": null,
          "updated_at": "2026-06-23T23:51:17.066942+00:00"
        }
      ]
    },
    {
      "slug": "national-register-controllers",
      "name": "Rules Governing the National Register of Controllers",
      "name_ar": "قواعد تنظيم السجل الوطني للمتحكمين",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Rules for the national register of data controllers.",
      "summary_ar": "قواعد السجل الوطني لجهات التحكم في البيانات.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/TheRulesGoverningTheNationalRegisterOfControllersWithinTheKingdomPublicEN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/national-register-controllers",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "crf",
      "name": "Cybersecurity Regulatory Framework (CRF)",
      "name_ar": "الإطار التنظيمي للأمن السيبراني (CRF)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "CST cybersecurity regulatory framework for the ICT sector.",
      "summary_ar": "الإطار التنظيمي للأمن السيبراني الصادر عن هيئة الاتصالات والفضاء والتقنية (CST) لقطاع تقنية المعلومات والاتصالات.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "telecom",
      "authority": "CST",
      "parent": null,
      "in_library": true,
      "official_url": "https://www.cst.gov.sa/en/regulations-and-licenses/regulations/Document-413",
      "wadira_url": "https://www.wadiraksa.com/instrument/crf",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "health-data-rules",
      "name": "MOH Data Governance Policy",
      "name_ar": "سياسة حوكمة البيانات بوزارة الصحة (MOH)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "MOH rules for managing health data; health data is PDPL-sensitive.",
      "summary_ar": "قواعد وزارة الصحة (MOH) لإدارة البيانات الصحية؛ وتُعدّ البيانات الصحية بيانات حساسة بموجب نظام حماية البيانات الشخصية (PDPL).",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "health",
      "authority": "MOH",
      "parent": null,
      "in_library": true,
      "official_url": "https://www.moh.gov.sa/Ministry/OpenData/Documents/Data-Governance-Policy.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/health-data-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "sccs",
      "name": "Standard Contractual Clauses (SCCs)",
      "name_ar": "الشروط التعاقدية النموذجية (SCCs)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "SDAIA-issued standard contractual clauses for cross-border transfers.",
      "summary_ar": "بنود تعاقدية معيارية صادرة عن SDAIA لعمليات نقل البيانات عبر الحدود.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "transfer-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/StandardContractualClausesForPersonalDataTransferEN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/sccs",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ccc",
      "name": "Cloud Cybersecurity Controls (CCC-2:2024)",
      "name_ar": "ضوابط الأمن السيبراني للحوسبة السحابية (CCC-2:2024)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NCA controls for cloud service providers and their tenants.",
      "summary_ar": "ضوابط صادرة عن NCA لمزوّدي الخدمات السحابية ومستفيديها.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/ccc",
      "date_note": "CCC-2:2024",
      "date_note_ar": "CCC-2:2024",
      "provisions": []
    },
    {
      "slug": "cst-licensing",
      "name": "CST Licensing",
      "name_ar": "التراخيص الصادرة عن CST",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "CST telecom / ICT and cloud licensing.",
      "summary_ar": "تراخيص هيئة الاتصالات والفضاء والتقنية (CST) للاتصالات وتقنية المعلومات والخدمات السحابية.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "telecom",
      "authority": "CST",
      "parent": null,
      "in_library": false,
      "official_url": "https://www.cst.gov.sa/en/regulations-and-licenses",
      "wadira_url": "https://www.wadiraksa.com/instrument/cst-licensing",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "sama-outsourcing-rules",
      "name": "SAMA Rules on Outsourcing (Circular 2389)",
      "name_ar": "قواعد SAMA بشأن الإسناد إلى أطراف خارجية (التعميم 2389)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "SAMA rules governing outsourcing by regulated entities.",
      "summary_ar": "قواعد البنك المركزي السعودي (SAMA) المنظِّمة للإسناد (التعهيد) من قِبل الجهات الخاضعة للإشراف.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": "https://rulebook.sama.gov.sa/en/rules-outsourcing",
      "wadira_url": "https://www.wadiraksa.com/instrument/sama-outsourcing-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ndi-operational-excellence-oe",
      "name": "NDI: Operational Excellence (OE)",
      "name_ar": "المؤشر الوطني للبيانات (NDI): التميز التشغيلي (OE)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "**Operational Excellence (OE)** is one of the three components of SDAIA's National Data Index (NDI), alongside Compliance and Maturity. Where those components assess what entities say they do, OE measures **actual performance**: the efficiency and effectiveness of a government entity's data-management operations, computed from telemetry on the SDAIA-operated **National Data Platforms**: the Government Service Bus, National Data Lake, Collaborative Data Labs, Data Marketplace, National Data Catalog and Reference Data Platform.\n\nThe document defines the OE calculation approach and its measurable metrics across **six data-management domains**: Data Sharing and Interoperability, Open Data, Data Catalog and Metadata, Reference and Master Data Management, Data Quality and Data Operations. Each metric has a defined structure, thresholds and ranges; performance targets are set by SDAIA, with each entity responsible for meeting and following up on them.\n\nFirst issued in October 2023, the specification evolves rapidly: the hosted version 5.0 (October 2025) adds new sharing and quality metrics and updates the score equation, so the metric set should be treated as a living instrument.",
      "summary_ar": "**التميز التشغيلي (OE)** هو أحد المكوّنات الثلاثة للمؤشر الوطني للبيانات (NDI) الصادر عن سدايا، إلى جانب الالتزام والنضج. فبينما تقيس تلك المكوّنات ما تقرره الجهات عن نفسها، يقيس التميز التشغيلي **الأداء الفعلي**: أي كفاءة وفاعلية عمليات إدارة البيانات لدى الجهة الحكومية، محسوبةً من البيانات الملتقطة عبر **المنصات الوطنية للبيانات** التي تديرها سدايا: قناة التكامل الحكومية، وبحيرة البيانات الوطنية، ومختبرات البيانات التعاونية، وسوق البيانات، والفهرس الوطني للبيانات، ومنصة البيانات المرجعية.\n\nوتحدد الوثيقة منهجية احتساب التميز التشغيلي ومقاييسه القابلة للقياس عبر **ستة مجالات لإدارة البيانات**: مشاركة البيانات وقابلية التشغيل البيني، والبيانات المفتوحة، وفهرسة البيانات والبيانات الوصفية، وإدارة البيانات المرجعية والرئيسة، وجودة البيانات، وعمليات البيانات. ولكل مقياس بنية محددة وحدود ونطاقات؛ وتضع سدايا مستهدفات الأداء، وتتولى كل جهة مسؤولية تحقيقها ومتابعتها.\n\nوقد صدرت الوثيقة أول مرة في أكتوبر 2023، وتطورت بوتيرة متسارعة، إذ يضيف الإصدار الخامس المستضاف هنا (أكتوبر 2025) مقاييس جديدة للمشاركة والجودة ويحدّث معادلة الاحتساب، لذا ينبغي التعامل مع مجموعة المقاييس بوصفها أداة حية.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/ndi-operational-excellence-oe",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ndi-operational-excellence-faqs",
      "name": "NDI: Operational Excellence FAQs",
      "name_ar": "المؤشر الوطني للبيانات (NDI): الأسئلة الشائعة حول التميز التشغيلي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **Operational Excellence (OE) Support Handbook** is SDAIA's question-and-answer companion to the Operational Excellence component of the National Data Index. First issued in March 2024 and revised regularly (the hosted version 5.0 dates from October 2025), it exists because the OE metrics are computed from live telemetry on the National Data Platforms, and entities need practical clarity on how the numbers are produced.\n\nAfter a short glossary of the platform ecosystem (Government Service Bus, National Data Bank, National Data Lake, National Data Catalog, Data Marketplace, Open Data Platform, Reference Data Management Platform and others), the Handbook answers recurring questions in two parts: the **OE component itself** (how it fits within the NDI alongside Compliance and Maturity, and how the score is assembled) and the **data-domain metrics**, walking through the measures for data sharing, open data, cataloguing, reference data, quality and operations.\n\nIt introduces no new obligations: it complements the main OE specification with context and practical insights, and should be read together with it.",
      "summary_ar": "**الدليل المساند للتميز التشغيلي (OE)** هو المرجع التوضيحي الصادر عن سدايا بصيغة سؤال وجواب لمكوّن التميز التشغيلي في المؤشر الوطني للبيانات. صدر أول مرة في مارس 2024 ويُحدَّث دورياً، والإصدار الخامس المستضاف هنا مؤرخ في أكتوبر 2025، وقد وُجد لأن مقاييس التميز التشغيلي تُحتسب من بيانات حية على المنصات الوطنية للبيانات، وتحتاج الجهات إلى وضوح عملي حول كيفية إنتاج هذه الأرقام.\n\nوبعد مسردٍ موجز لمنظومة المنصات (قناة التكامل الحكومية، وبنك البيانات الوطني، وبحيرة البيانات الوطنية، والفهرس الوطني للبيانات، وسوق البيانات، ومنصة البيانات المفتوحة، ومنصة إدارة البيانات المرجعية وغيرها)، يجيب الدليل عن الأسئلة المتكررة في قسمين: **مكوّن التميز التشغيلي ذاته**، وكيف يندرج ضمن المؤشر الوطني للبيانات إلى جانب الالتزام والنضج، وكيف تُجمَّع الدرجة، و**مقاييس مجالات البيانات**، متناولاً مقاييس مشاركة البيانات والبيانات المفتوحة والفهرسة والبيانات المرجعية والجودة والعمليات.\n\nولا يُنشئ الدليل التزامات جديدة: فهو يُكمل وثيقة التميز التشغيلي الرئيسة بالسياق والرؤى العملية، وينبغي قراءته معها.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/ndi-operational-excellence-faqs",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "financial-consumer-protection-principles-and-rules",
      "name": "Financial Consumer Protection Principles and Rules",
      "name_ar": "مبادئ وقواعد حماية المستهلك المالي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **Financial Consumer Protection Principles and Rules**, issued by the Saudi Central Bank in 1444H (2022), are SAMA's binding conduct framework for all financial institutions it licenses. They rest on Article 4(9) of the Saudi Central Bank Law, SAMA's power to issue consumer-protection instructions, reinforced by the banking, insurance, finance-companies, credit-information and payments statutes.\n\nIt sets out **ten consumer-protection principles** (equitable and fair treatment; disclosure and transparency; education and awareness; behaviour and work ethic; protection against fraud and misuse; **protection of data and information privacy**; complaints handling; competition; outsourcing; and conflict of interest), followed by general and sector-specific conduct rules.\n\nPrinciple 6 is the data hook: institutions must protect the privacy of consumers' financial, credit, insurance and personal information through mechanisms that encompass **all rights under the Personal Data Protection Law**, backed by control systems. It thus operationalises the PDPL inside SAMA's supervisory perimeter, alongside SAMA's 2021 circular directing institutions to gap-assess against the PDPL.",
      "summary_ar": "**مبادئ وقواعد حماية عملاء المؤسسات المالية**، الصادرة عن البنك المركزي السعودي عام 1444هـ (2022)، هي إطار السلوك المُلزم الذي تفرضه ساما على جميع المؤسسات المالية المرخصة منها. وتستند إلى الفقرة (9) من المادة الرابعة من نظام البنك المركزي السعودي، صلاحية ساما في وضع التعليمات اللازمة لحماية عملاء المؤسسات المالية، معززةً بأنظمة البنوك والتأمين وشركات التمويل والمعلومات الائتمانية والمدفوعات.\n\nوتحدد الوثيقة **عشرة مبادئ لحماية العملاء**: المعاملة العادلة والمنصفة؛ والإفصاح والشفافية؛ والتثقيف والتوعية؛ والسلوك وأخلاقيات العمل؛ والحماية من الاحتيال وسوء الاستخدام؛ و**حماية خصوصية البيانات والمعلومات**؛ ومعالجة الشكاوى؛ والمنافسة؛ والإسناد إلى طرف ثالث؛ وتعارض المصالح، تليها قواعد سلوك عامة وأخرى خاصة بكل قطاع.\n\nويمثّل المبدأ السادس نقطة الارتباط بالبيانات: إذ يجب على المؤسسات حماية خصوصية المعلومات المالية والائتمانية والتأمينية والشخصية لعملائها عبر آليات تشمل **جميع الحقوق الواردة في نظام حماية البيانات الشخصية**، مدعومةً بأنظمة رقابية رفيعة المستوى. وبذلك تُفعِّل هذه المبادئ نظام حماية البيانات الشخصية داخل النطاق الرقابي لساما، إلى جانب تعميم ساما الصادر عام 2021 الذي وجّه المؤسسات إلى إجراء تقييم للفجوات مقابل النظام.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/financial-consumer-protection-principles-and-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "secondary-use-rules",
      "name": "Rules for Secondary Use of Data",
      "name_ar": "قواعد الاستخدام الثانوي للبيانات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "General rules governing the secondary use of data.",
      "summary_ar": "القواعد العامة المنظِّمة للاستخدام الثانوي للبيانات.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/GeneralRulesForSecondaryUseOfData_EN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/secondary-use-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "bcrs",
      "name": "Binding Common Rules (BCRs)",
      "name_ar": "القواعد الملزِمة المشتركة (BCRs)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Binding common rules as an intra-group transfer mechanism.",
      "summary_ar": "قواعد مُلزِمة مشتركة بوصفها آلية لنقل البيانات داخل المجموعة الواحدة.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "transfer-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/CommonRulesBCRForPersonalDataTransferEN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/bcrs",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cscc",
      "name": "Critical Systems Cybersecurity Controls",
      "name_ar": "ضوابط الأمن السيبراني للأنظمة الحساسة",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NCA controls for organisations operating critical national systems.",
      "summary_ar": "ضوابط صادرة عن NCA للجهات التي تشغّل أنظمة وطنية حسّاسة.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cscc",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "accreditation-certificate-rules",
      "name": "Rules Governing Issuance of Accreditation Certificates",
      "name_ar": "قواعد تنظيم إصدار شهادات الاعتماد",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Rules governing issuance and accreditation of certificates for controllers and processors.",
      "summary_ar": "قواعد إصدار شهادات الاعتماد لجهات التحكم وجهات المعالجة.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/RulesGoverningIssuanceAccreditationCertificatesControllersProcessers.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/accreditation-certificate-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cyber-resilience-fundamental-requirements-crfr",
      "name": "Cyber Resilience Fundamental Requirements (CRFR)",
      "name_ar": "المتطلبات الأساسية للمرونة السيبرانية (CRFR)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **Cyber Resilience Fundamental Requirements (CRFR)**, issued by the Saudi Central Bank in January 2022 (version 1.0), set the minimum cyber-resilience bar for entities **entering the financial sector**: applicants intending to qualify for SAMA's Regulatory Sandbox and/or seeking a licence to operate in the Kingdom.\n\nThe CRFR act as a catalyst for meeting SAMA's minimum cyber-resilience licensing requirements. They are explicitly **not a substitute** for SAMA's full Cyber Security Framework and Business Continuity Management framework, with which entities must comply once licensed, and are to be read alongside the Regulatory Sandbox Framework.\n\nThe control requirements follow a risk-based approach across **three domains** (Cyber Security Leadership and Governance; Cyber Security Operations and Technology; and Resilience), with compliance verified through entity self-assessment and SAMA audit. In practice the CRFR are the first SAMA cyber instrument a fintech encounters: a compact set of fundamentals bridging the gap between an unregulated start-up and the full CSF obligations that apply after licensing.",
      "summary_ar": "**المتطلبات الأساسية للمرونة السيبرانية (CRFR)**، الصادرة عن البنك المركزي السعودي في يناير 2022 (الإصدار 1.0)، تضع الحد الأدنى من متطلبات المرونة السيبرانية للجهات **الداخلة إلى القطاع المالي**، أي المتقدمين الراغبين في التأهل لبيئة ساما التجريبية التشريعية و/أو الساعين للحصول على ترخيص لمزاولة النشاط في المملكة.\n\nوتعمل هذه المتطلبات كأداة تمكينية لاستيفاء الحد الأدنى من متطلبات الترخيص المتعلقة بالمرونة السيبرانية لدى ساما. وهي صراحةً **ليست بديلاً** عن إطار الأمن السيبراني وإطار إدارة استمرارية الأعمال الصادرين عن ساما، اللذين يجب على الجهات الالتزام بهما بعد الترخيص، كما يجب قراءتها جنباً إلى جنب مع إطار البيئة التجريبية التشريعية.\n\nوتتبع متطلبات الضبط منهجية قائمة على المخاطر عبر **ثلاثة مجالات**: قيادة وحوكمة الأمن السيبراني؛ وعمليات وتقنية الأمن السيبراني؛ والمرونة، ويُتحقق من الالتزام بها عبر التقييم الذاتي للجهة وتدقيق ساما. وعملياً تُعد هذه المتطلبات أول أداة سيبرانية من ساما تواجه شركات التقنية المالية: مجموعة مقتضبة من الأساسيات تسد الفجوة بين شركة ناشئة غير مرخصة والتزامات إطار الأمن السيبراني الكاملة التي تسري بعد الترخيص.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cyber-resilience-fundamental-requirements-crfr",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "controller-auditing-rules",
      "name": "Rules for Auditing & Inspecting Controllers and Processors",
      "name_ar": "قواعد تدقيق المتحكمين والمعالجين وتفتيشهم",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Rules for auditing and inspecting controllers/processors and their processing activities.",
      "summary_ar": "قواعد تدقيق وتفتيش جهات التحكم/جهات المعالجة وأنشطة المعالجة لديها.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/CertificatesControllersProcessorsAuditingInspectionPersonalDataProcessingActivities.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/controller-auditing-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "otcc",
      "name": "Operational Technology Cybersecurity Controls",
      "name_ar": "ضوابط الأمن السيبراني للتقنية التشغيلية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NCA controls for OT / ICS environments.",
      "summary_ar": "ضوابط صادرة عن NCA لبيئات التقنية التشغيلية (OT) وأنظمة التحكم الصناعي (ICS).",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/otcc",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "committee-working-rules",
      "name": "Committee Working Rules",
      "name_ar": "قواعد عمل اللجنة",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Working rules of the relevant data-protection committee.",
      "summary_ar": "قواعد عمل لجنة حماية البيانات المختصة.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/CommitteeWorkingRules.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/committee-working-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "dcc",
      "name": "Data Cybersecurity Controls",
      "name_ar": "ضوابط الأمن السيبراني للبيانات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NCA controls for protecting data through its lifecycle.",
      "summary_ar": "ضوابط صادرة عن NCA لحماية البيانات عبر دورة حياتها.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/dcc",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ncs",
      "name": "National Cryptographic Standards",
      "name_ar": "المعايير الوطنية للتشفير",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NCA cryptographic standards.",
      "summary_ar": "المعايير التشفيرية الصادرة عن NCA.",
      "type": "Standard",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/ncs",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "sama-4725",
      "name": "SAMA 4725",
      "name_ar": "SAMA 4725",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "**SAMA Circular No. 43045328 (19/5/1443H, December 2021)** is the Saudi Central Bank's directive bringing the Personal Data Protection Law into its supervisory perimeter. Addressed to **all financial institutions subject to SAMA supervision**, its subject line is the PDPL (Royal Decree M/19, 9/2/1443H) together with the policies, controls and rules on data governance issued by SDAIA under Council of Ministers Resolution No. 292 (27/4/1441H).\n\nNoting that some of those instruments bind its supervised institutions, SAMA directs each to:\n\n1. **Review its approved internal policies and procedures** and confirm, or amend, their alignment with the PDPL within the statutory compliance period, and with the SDAIA/NDMO data-governance policies and controls (published at sdaia.gov.sa/ndmo).\n2. **Perform a gap analysis** against the Law and those instruments, and set a board-approved, time-bound remediation plan.\n\nThe circular took effect from its date and was signed by the Deputy Governor for Supervision. It is the key bridge instrument between SDAIA's data regime and SAMA's financial-sector rulebook; the hosted document is the original Arabic circular.",
      "summary_ar": "**تعميم البنك المركزي السعودي رقم 43045328 وتاريخ 19/5/1443هـ (ديسمبر 2021)** هو التوجيه الذي أدخل به البنك المركزي نظامَ حماية البيانات الشخصية في نطاقه الرقابي. وهو موجَّه إلى **جميع المؤسسات المالية الخاضعة لإشراف ورقابة البنك المركزي**، وموضوعه نظام حماية البيانات الشخصية (المرسوم الملكي م/19 وتاريخ 9/2/1443هـ) والسياسات والضوابط والقواعد الصادرة عن الهيئة السعودية للبيانات والذكاء الاصطناعي في شأن حوكمة البيانات استناداً إلى قرار مجلس الوزراء رقم (292) وتاريخ 27/4/1441هـ.\n\nوإذ يشير التعميم إلى أن نطاق الإلزام في تطبيق بعض هذه الأدوات يشمل المؤسسات المالية الخاضعة لإشرافه، يوجّه البنك المركزي كل مؤسسة إلى أمرين:\n\n1. **مراجعة السياسات والإجراءات الداخلية المعتمدة** والتأكد من توافقها و/أو تعديلها بما يتسق مع نظام حماية البيانات الشخصية خلال الفترة المحددة نظاماً للالتزام، ومع سياسات وضوابط حوكمة البيانات الصادرة عن الهيئة (المتاحة عبر sdaia.gov.sa/ndmo).\n2. **تقييم الفجوات التنظيمية** مقابل النظام وتلك الأدوات، ووضع خطة زمنية لتصحيحها وعرضها على مجلس الإدارة لاعتمادها.\n\nوقد سرى التعميم اعتباراً من تاريخه، ووقّعه وكيل المحافظ للرقابة. ويُعد هذا التعميم أداة الربط الرئيسة بين منظومة البيانات لدى سدايا ومنظومة القطاع المالي التنظيمية لدى ساما. والوثيقة المستضافة هي التعميم العربي الأصلي.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/sama-4725",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "national-occupational-standard-framework-for-data-ai",
      "name": "National Occupational Standard Framework for Data & AI",
      "name_ar": "الإطار الوطني للمعايير المهنية للبيانات والذكاء الاصطناعي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **National Occupational Standard Framework for Data & Artificial Intelligence** (SDAIA, 2025) is the Kingdom's baseline reference for what data and AI professionals actually do. Issued under SDAIA's mandate as the national competent authority for data and AI (Royal Order A/471, 29/12/1440H), it aims to standardise and improve occupational practice and to anchor the human-capital side of Saudi Arabia's data and AI ambitions.\n\nIts core is a classification of the field: data and AI occupations are organised into **five classifications, ten specialty areas and sixteen occupations**, each documented in a **job card** setting out the occupation's key tasks and the skills, knowledge and abilities required to perform them. The methodology chapters explain how the classification was built from expert analysis, and an annex completes the reference.\n\nThe framework is guidance rather than binding regulation. It is written for professionals, employers and decision-makers who recruit, develop or certify data and AI talent, and pairs with the Saudi Academic Framework for AI Qualifications, which addresses the education pipeline feeding these occupations.",
      "summary_ar": "**الإطار الوطني للمعايير المهنية للبيانات والذكاء الاصطناعي** (سدايا، 2025) هو المرجع الأساسي في المملكة لما يؤديه فعلياً المتخصصون في البيانات والذكاء الاصطناعي. صدر بموجب اختصاص سدايا بوصفها الجهة الوطنية المختصة بالبيانات والذكاء الاصطناعي (الأمر الملكي أ/471 وتاريخ 29/12/1440هـ)، وغايته توحيد الممارسات المهنية وتحسينها، وترسيخ شق رأس المال البشري في طموحات المملكة في البيانات والذكاء الاصطناعي.\n\nويقوم جوهره على تصنيف للقطاع: إذ تُنظَّم مهن البيانات والذكاء الاصطناعي في **خمسة تصنيفات وعشرة مجالات تخصصية وست عشرة مهنة**، توثَّق كل منها في **بطاقة وظيفية** تحدد المهام الرئيسة للمهنة والمهارات والمعارف والقدرات اللازمة لأدائها. وتشرح فصول المنهجية كيفية بناء التصنيف من تحليل مدخلات الخبراء، ويكتمل المرجع بملحق.\n\nوالإطار إرشادي وليس تنظيماً مُلزماً. وهو موجَّه للمتخصصين وأصحاب العمل وصنّاع القرار الذين يستقطبون كفاءات البيانات والذكاء الاصطناعي أو يطورونها أو يعتمدونها، ويتكامل مع الإطار الأكاديمي السعودي لمؤهلات الذكاء الاصطناعي الذي يعالج مسار التعليم الرافد لهذه المهن.",
      "type": "Standard",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/File0002.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/national-occupational-standard-framework-for-data-ai",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "sama-cyber-security-framework-csf",
      "name": "SAMA Cyber Security Framework (CSF)",
      "name_ar": "إطار الأمن السيبراني الصادر عن SAMA (CSF)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **SAMA Cyber Security Framework (CSF)**, version 1.0 of May 2017, is the Saudi Central Bank's sector-wide cyber-security baseline for its regulated \"Member Organisations\": all banks, insurance and reinsurance companies, financing companies, credit bureaus and financial-market infrastructure operating in Saudi Arabia.\n\nPrinciple-based and risk-oriented, it prescribes cyber-security principles and objectives across **four domains** (Cyber Security Leadership and Governance; Cyber Security Risk Management and Compliance; Cyber Security Operations and Technology; and Third-Party Cyber Security), each broken into sub-domains with mandated control considerations, covering information assets from electronic records to technical infrastructure.\n\nImplementation is measured against a **six-level maturity model (0–5)** through periodic self-assessment reviewed and audited by SAMA; where a control cannot be implemented, entities may apply compensating controls and request a formal waiver. The Framework is mandated and maintained by SAMA under the supervisory powers of the Saudi Central Bank Law; for licence applicants it is preceded by the Cyber Resilience Fundamental Requirements.",
      "summary_ar": "**إطار الأمن السيبراني الصادر عن ساما**، بإصداره الأول في مايو 2017، هو خط الأساس القطاعي للأمن السيبراني الذي يضعه البنك المركزي السعودي على «المنظمات الأعضاء» الخاضعة لرقابته: جميع البنوك وشركات التأمين وإعادة التأمين وشركات التمويل وشركات المعلومات الائتمانية والبنية التحتية للسوق المالية العاملة في المملكة.\n\nويقوم الإطار على منهجية المبادئ (المنهجية القائمة على المخاطر): إذ يحدد مبادئ وأهدافاً للأمن السيبراني عبر **أربعة مجالات**: قيادة وحوكمة الأمن السيبراني؛ وإدارة مخاطر الأمن السيبراني والالتزام؛ وعمليات وتقنية الأمن السيبراني؛ والأمن السيبراني للأطراف الثالثة، تتفرع إلى مجالات فرعية تتضمن اعتبارات ضبط مُلزمة. ويغطي الإطار المعلومات الإلكترونية والورقية والتطبيقات وقواعد البيانات والأجهزة والبنية التحتية التقنية.\n\nويُقاس التطبيق وفق **نموذج نضج من ستة مستويات (0–5)** عبر تقييم ذاتي دوري تراجعه ساما وتدقّقه؛ وحيثما تعذّر تطبيق ضابطٍ ما، يمكن للمنشأة تطبيق ضوابط تعويضية وطلب إعفاء رسمي. والإطار مُلزم تصدره وتحدّثه ساما استناداً إلى صلاحياتها الرقابية بموجب نظام البنك المركزي السعودي؛ وتسبقه المتطلبات الأساسية للمرونة السيبرانية بالنسبة لطالبي الترخيص.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/sama-cyber-security-framework-csf",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ncnicc",
      "name": "Non-Critical National Infrastructure Cybersecurity Controls (NCNICC-1:2025)",
      "name_ar": "ضوابط الأمن السيبراني للبنى التحتية الوطنية غير الحساسة (NCNICC-1:2025)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Non-Critical National Infrastructure Cybersecurity Controls (NCNICC-1:2025) are the National Cybersecurity Authority's cybersecurity baseline for private-sector entities that are not classified as Critical National Infrastructure. They extend the NCA's ECC-derived control model to these entities across governance, defence and third-party/cloud domains. The controls are split into Category A (65 controls, for larger entities) and Category B (26 controls, for smaller entities).",
      "summary_ar": "ضوابط الأمن السيبراني للبنى التحتية الوطنية غير الحساسة (NCNICC-1:2025) هي الحد الأدنى من متطلبات الأمن السيبراني الذي تفرضه الهيئة الوطنية للأمن السيبراني على منشآت القطاع الخاص التي لا تُصنَّف ضمن البنى التحتية الوطنية الحساسة. وتوسّع هذه الضوابط نموذج الضوابط المشتق من الضوابط الأساسية للأمن السيبراني (ECC) ليشمل هذه المنشآت عبر مجالات الحوكمة والدفاع والأطراف الثالثة والحوسبة السحابية. وتنقسم إلى الفئة (أ) (65 ضابطًا للمنشآت الأكبر) والفئة (ب) (26 ضابطًا للمنشآت الأصغر).",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": "https://nca.gov.sa/en/regulatory-documents/",
      "wadira_url": "https://www.wadiraksa.com/instrument/ncnicc",
      "date_note": "Issued by the NCA (NCNICC-1:2025), published January 2026",
      "date_note_ar": "صادرة عن الهيئة الوطنية للأمن السيبراني (NCNICC-1:2025)، نُشرت في يناير 2026",
      "provisions": []
    },
    {
      "slug": "saudi-academic-framework-for-ai-qualifications",
      "name": "Saudi Academic Framework for AI Qualifications",
      "name_ar": "الإطار الأكاديمي السعودي لمؤهلات الذكاء الاصطناعي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **Saudi Academic Framework for AI Qualifications (Education Intelligence)** (SDAIA, 2025) is the Kingdom's reference for developing, evaluating and accrediting higher-education programmes in artificial intelligence. It positions itself as the trusted national benchmark for AI education, designed to stay flexible in a fast-moving field.\n\nThe framework has four chapters. **Benchmarks** surveys the Kingdom's existing specialised frameworks and prominent local and international educational institutions. **AI Qualifications in the Kingdom** maps the qualifications awarded in Saudi Arabia to the National Qualifications Framework and the Saudi Standard Classification of Educational Levels, from associate diploma up to doctoral level (NQF Level 8). **Learning Outcomes** defines the general outcomes expected of graduates at each qualification level, and **Knowledge Units** details the curricular building blocks.\n\nIt is guidance for universities, training institutions and accreditation bodies rather than binding regulation, and complements the National Occupational Standard Framework for Data & AI, which describes the occupations these qualifications feed.",
      "summary_ar": "**الإطار الأكاديمي السعودي لمؤهلات الذكاء الاصطناعي (ذكاء التعليم)** (سدايا، 2025) هو مرجع المملكة لتطوير برامج التعليم العالي في الذكاء الاصطناعي وتقييمها واعتمادها. ويقدّم نفسه بوصفه المرجع الوطني الموثوق لتعليم الذكاء الاصطناعي، وصُمم ليحافظ على مرونته في مجال سريع التطور.\n\nويتكون الإطار من أربعة فصول: **المعايير المرجعية** يستعرض الأطر التخصصية القائمة في المملكة وأبرز المؤسسات التعليمية المحلية والعالمية. و**مؤهلات الذكاء الاصطناعي في المملكة** يربط المؤهلات الممنوحة في السعودية بالإطار الوطني للمؤهلات والتصنيف السعودي الموحد للمستويات والتخصصات التعليمية، من الدبلوم المشارك وصولاً إلى مستوى الدكتوراه (المستوى الثامن في الإطار الوطني للمؤهلات). و**مخرجات التعلم** يحدد المخرجات العامة المتوقعة من الخريجين في كل مستوى تأهيلي، بينما يفصّل **وحدات المعرفة** اللبنات المنهجية للمقررات.\n\nوالإطار إرشادي موجَّه للجامعات ومؤسسات التدريب وجهات الاعتماد وليس تنظيماً مُلزماً، ويتكامل مع الإطار الوطني للمعايير المهنية للبيانات والذكاء الاصطناعي الذي يصف المهن التي ترفدها هذه المؤهلات.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/File0003.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/saudi-academic-framework-for-ai-qualifications",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cybersecurity-organizational-structure-template",
      "name": "Cybersecurity Organizational Structure Template",
      "name_ar": "نموذج الهيكل التنظيمي للأمن السيبراني",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Cybersecurity Organizational Structure Template is one of the National Cybersecurity Authority's toolkit templates, an illustrative model that organisations customise to establish and document their cybersecurity function. It supports the requirement, anchored in Royal Decree No. 37140 (14/8/1438H) and reflected in NCA control sets such as the ECC, that the cybersecurity function be independent of the information technology function and report to the head of the organisation or their delegate, with the standing to influence key cybersecurity decisions.\n\nThe template covers cybersecurity governance arrangements, the individuals within the organisational structure, the structure of the cybersecurity function itself, roles and responsibilities, and update, review and compliance provisions, together with document-approval and version-control scaffolding. The NCA presents it strictly as an illustrative example: each organisation must adapt it to its business and applicable legislative and regulatory requirements and obtain approval from its authorising official. It sits within the wider NCA Cybersecurity Toolkits alongside policy, standard and procedure templates.",
      "summary_ar": "نموذج الهيكل التنظيمي للأمن السيبراني هو أحد نماذج أدوات الأمن السيبراني الصادرة عن الهيئة الوطنية للأمن السيبراني، وهو نموذج استرشادي تُخصّصه الجهات لإنشاء الإدارة المعنية بالأمن السيبراني لديها وتوثيقها. ويدعم النموذج المتطلب المستند إلى الأمر الملكي رقم 37140 وتاريخ 14/8/1438هـ، والمنعكس في ضوابط الهيئة مثل الضوابط الأساسية للأمن السيبراني (ECC)، بأن تكون الإدارة المعنية بالأمن السيبراني مستقلة عن إدارة تقنية المعلومات وأن ترتبط برئيس الجهة أو من ينيبه، مع تمكينها من التأثير في القرارات الرئيسة للأمن السيبراني.\n\nويغطي النموذج ترتيبات حوكمة الأمن السيبراني، والأفراد ضمن الهيكل التنظيمي، وهيكل الإدارة المعنية بالأمن السيبراني ذاتها، والأدوار والمسؤوليات، وأحكام التحديث والمراجعة والالتزام، إضافة إلى جداول اعتماد الوثيقة وضبط الإصدارات. وتؤكد الهيئة أنه مثال استرشادي بحت: إذ يجب على كل جهة تكييفه بما يتوافق مع طبيعة أعمالها والمتطلبات التشريعية والتنظيمية ذات العلاقة، واعتماده من صاحب الصلاحية لديها. ويندرج النموذج ضمن أدوات الأمن السيبراني الأوسع للهيئة إلى جانب نماذج السياسات والمعايير والإجراءات.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cybersecurity-organizational-structure-template",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "regulatory-framework-for-licensing-managed-security-oper",
      "name": "Regulatory Framework for Licensing Managed Security Operations Centre Services (RFMSOC-1:2024)",
      "name_ar": "الإطار التنظيمي لترخيص خدمات مراكز العمليات الأمنية المُدارة (RFMSOC-1:2024)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Regulatory Framework for Licensing Managed Security Operations Centre (MSOC) Services (RFMSOC-1:2024) is the National Cybersecurity Authority's licensing regime for providers of managed security operations centre services in the Kingdom, published as a public (TLP: White) document; the Arabic version is the binding text.\n\nThe framework sets out its objectives and scope, then the provisions for licensing MSOC services (obtaining, maintaining, renewing and transferring a licence), followed by service-provider obligations, rules on subcontracting MSOC services, and the requirements for individuals to obtain a qualification certificate to work in an MSOC, with general provisions and appendices. Its definitions cover security operations centres, MSOC services, beneficiaries, service providers, cloud computing service providers and MSOC analysts. It pairs with the National Policy for Managed Security Operations Centres (NPMSOC-1:2024), which governs how beneficiary organisations use such services.",
      "summary_ar": "الإطار التنظيمي لترخيص خدمات مراكز عمليات الأمن السيبراني المُدارة (RFMSOC-1:2024) هو نظام الترخيص الذي وضعته الهيئة الوطنية للأمن السيبراني لمقدّمي خدمات مراكز عمليات الأمن السيبراني المُدارة في المملكة، وقد نُشر وثيقةً عامة (TLP: أبيض)؛ والنسخة العربية هي النص المُلزم.\n\nيعرض الإطار أهدافه ونطاقه، ثم أحكام ترخيص خدمات المراكز المُدارة، من الحصول على الترخيص والمحافظة عليه وتجديده ونقله، تليها التزامات مقدّم الخدمة، وقواعد التعاقد من الباطن على خدمات المراكز المُدارة، ومتطلبات حصول الأفراد على شهادة تأهيل للعمل في هذه المراكز، إضافة إلى الأحكام العامة والملاحق. وتشمل تعريفاته مراكز عمليات الأمن السيبراني، وخدمات المراكز المُدارة، والمستفيدين، ومقدّمي الخدمة، ومقدّمي خدمات الحوسبة السحابية، ومحلّلي المراكز المُدارة. ويقترن الإطار بالسياسة الوطنية لمراكز عمليات الأمن السيبراني المُدارة (NPMSOC-1:2024) التي تنظّم كيفية استفادة الجهات من تلك الخدمات.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/regulatory-framework-for-licensing-managed-security-oper",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "saudi-cybersecurity-higher-education-framework-scyber-ed",
      "name": "Saudi Cybersecurity Higher Education Framework (SCyber-Edu-1:2020)",
      "name_ar": "الإطار السعودي للتعليم العالي في الأمن السيبراني (SCyber-Edu-1:2020)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Saudi Cybersecurity Higher Education Framework (SCyber-Edu-1:2020) is the National Cybersecurity Authority's framework for cybersecurity degree programmes, issued in October 2020 (version 1.0) and developed in cooperation with the Ministry of Education and the Education and Training Evaluation Commission. It can be applied to cybersecurity degree programmes offered by public and private higher-education institutions in Saudi Arabia.\n\nThe framework defines seven programme levels (intermediate diploma, bachelor (cybersecurity track), bachelor (cybersecurity major), higher diplomas for IT and non-IT backgrounds, master's and doctoral) and for each sets programme descriptors, admission requirements and the core and elective knowledge units to be covered. The knowledge units span foundations such as cybersecurity principles, basic cryptography, networking and operating systems through to advanced and specialised topics including digital forensics, industrial control systems and machine learning. An accompanying alignment guide takes institutions through mapping their programmes to the framework.",
      "summary_ar": "الإطار السعودي للتعليم العالي في الأمن السيبراني (SCyber-Edu-1:2020) هو الإطار الذي وضعته الهيئة الوطنية للأمن السيبراني للبرامج الأكاديمية في الأمن السيبراني، وصدر في أكتوبر 2020 (الإصدار 1.0) وطُوّر بالتعاون مع وزارة التعليم وهيئة تقويم التعليم والتدريب. ويمكن تطبيقه على البرامج الأكاديمية في الأمن السيبراني التي تقدّمها مؤسسات التعليم العالي الحكومية والأهلية في المملكة العربية السعودية.\n\nيحدد الإطار سبعة مستويات للبرامج: الدبلوم المتوسط، والبكالوريوس (مسار الأمن السيبراني)، والبكالوريوس (تخصص الأمن السيبراني)، والدبلومين العاليين لخلفيتي تقنية المعلومات وغير تقنية المعلومات، والماجستير، والدكتوراه، ويضع لكل مستوى توصيف البرنامج ومتطلبات القبول ووحدات المعرفة الأساسية والاختيارية الواجب تغطيتها. وتمتد وحدات المعرفة من الأساسيات مثل مبادئ الأمن السيبراني وأساسيات التشفير والشبكات وأنظمة التشغيل، إلى موضوعات متقدمة ومتخصصة تشمل التحقيق الجنائي الرقمي وأنظمة التحكم الصناعي وتعلّم الآلة. ويصاحب الإطارَ دليلُ مواءمة يرشد المؤسسات إلى كيفية مواءمة برامجها معه.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/saudi-cybersecurity-higher-education-framework-scyber-ed",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "guide-to-critical-systems-cybersecurity-controls-cscc-im",
      "name": "Guide to Critical Systems Cybersecurity Controls (CSCC) Implementation",
      "name_ar": "دليل تطبيق ضوابط الأمن السيبراني للأنظمة الحساسة (CSCC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Guide to Cybersecurity Controls for Critical Systems (CSCC) Implementation (GCSCC-1:2023) is the National Cybersecurity Authority's public implementation guide for the Critical Systems Cybersecurity Controls, helping in-scope organisations translate the controls into practice.\n\nIt opens with the components and architecture of the CSCC across their four domains (cybersecurity governance, cybersecurity defence, cybersecurity resilience, and third-party and cloud computing cybersecurity), with subdomains ranging from cybersecurity strategy, risk management and periodic review and audit through identity and access management, cryptography, penetration testing and vulnerability management to business-continuity resilience and cloud-hosting security. General implementation guidance is followed by guidance under each domain in turn. The CSCC themselves build on the NCA's Essential Cybersecurity Controls (ECC) baseline, tightening requirements for the critical national systems whose compromise would carry the greatest impact; the guide is part of the NCA's series of implementation guides for its control sets.",
      "summary_ar": "دليل تطبيق ضوابط الأمن السيبراني للأنظمة الحساسة (GCSCC-1:2023) هو دليل التطبيق العام الصادر عن الهيئة الوطنية للأمن السيبراني لضوابط الأمن السيبراني للأنظمة الحساسة، لمساعدة الجهات المشمولة على ترجمة الضوابط إلى ممارسة عملية.\n\nيستهل الدليل بعرض مكوّنات ضوابط الأنظمة الحساسة وبنيتها عبر مجالاتها الرئيسة الأربعة: حوكمة الأمن السيبراني، وتعزيز الأمن السيبراني، وصمود الأمن السيبراني، والأمن السيبراني المتعلق بالأطراف الخارجية والحوسبة السحابية، بمجالات فرعية تمتد من استراتيجية الأمن السيبراني وإدارة المخاطر والمراجعة والتدقيق الدوريين، مرورًا بإدارة هويات الدخول والصلاحيات والتشفير واختبار الاختراق وإدارة الثغرات، وصولًا إلى صمود استمرارية الأعمال وأمن الحوسبة السحابية والاستضافة. وتُتبع الإرشادات العامة للتطبيق بإرشادات تفصيلية تحت كل مجال على حدة. وتبني ضوابط الأنظمة الحساسة ذاتها على الحد الأدنى المقرر في الضوابط الأساسية للأمن السيبراني (ECC)، بتشديد المتطلبات على الأنظمة الوطنية الحساسة التي يكون لاختراقها الأثر الأكبر؛ ويُعد الدليل جزءًا من سلسلة أدلة التطبيق الصادرة عن الهيئة لمجموعات ضوابطها.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-critical-systems-cybersecurity-controls-cscc-im",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "operational-technology-cybersecurity-controls-methodolog",
      "name": "Operational Technology Cybersecurity Controls: Methodology & Mapping Annex",
      "name_ar": "ضوابط الأمن السيبراني للتقنية التشغيلية: ملحق المنهجية والمواءمة",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Operational Technology Cybersecurity Controls Methodology and Mapping Annex (OTCCMM-1:2022) is a National Cybersecurity Authority annex explaining how the Operational Technology Cybersecurity Controls (OTCC-1:2022) were designed and how they relate to other standards. The OTCC are an extension of the Essential Cybersecurity Controls (ECC): applicable organisations comply with the ECC first, then with the additional OT-specific controls.\n\nThe annex sets out the OTCC design principles and methodology, the main domains and subdomains, and how controls and subcontrols are assigned to levels, and it details the relationship between the OTCC and ECC Domain 5. It also maps the controls to the international references used in their development, including the ISA/IEC 62443 series on security for industrial automation and control systems (62443-2-1, 62443-3-2 and 62443-3-3), the NIST Cybersecurity Framework and NIST Special Publication 800-53. It accompanies the OTCC and their separate implementation guide (GOTCC-1:2023).",
      "summary_ar": "ملحق منهجية ضوابط الأمن السيبراني للتقنيات التشغيلية ومواءمتها (OTCCMM-1:2022) هو ملحق صادر عن الهيئة الوطنية للأمن السيبراني يشرح كيفية تصميم ضوابط الأمن السيبراني للتقنيات التشغيلية (OTCC-1:2022) وعلاقتها بالمعايير الأخرى. وتُعد هذه الضوابط امتدادًا للضوابط الأساسية للأمن السيبراني (ECC): إذ تلتزم الجهات المشمولة بالضوابط الأساسية أولًا، ثم بالضوابط الإضافية الخاصة بالتقنيات التشغيلية.\n\nيعرض الملحق مبادئ تصميم الضوابط ومنهجيتها، ومجالاتها الرئيسة والفرعية، وكيفية إسناد الضوابط والضوابط الفرعية إلى مستويات، ويفصّل العلاقة بين ضوابط التقنيات التشغيلية والمجال الخامس من الضوابط الأساسية. كما يوائم الضوابط مع المراجع الدولية المستخدمة في تطويرها، ومنها سلسلة ISA/IEC 62443 الخاصة بأمن أنظمة التحكم والأتمتة الصناعية (62443-2-1 و62443-3-2 و62443-3-3)، وإطار الأمن السيبراني الصادر عن المعهد الوطني الأمريكي للمعايير والتقنية (NIST CSF)، والمنشور الخاص NIST SP 800-53. ويصاحب الملحقُ الضوابطَ ودليلَ تطبيقها المستقل (GOTCC-1:2023).",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/operational-technology-cybersecurity-controls-methodolog",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "national-policy-for-managed-security-operations-centres-",
      "name": "National Policy for Managed Security Operations Centres (NPMSOC-1:2024)",
      "name_ar": "السياسة الوطنية لمراكز العمليات الأمنية المُدارة (NPMSOC-1:2024)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The National Policy for Managed Security Operations Centres (NPMSOC-1:2024) is a National Cybersecurity Authority policy on the use and provision of managed security operations centre (MSOC) services in the Kingdom, published as a public (TLP: White) document; the Arabic version is the binding text.\n\nThe policy is organised into definitions (covering critical national infrastructure, security operations centres, MSOC services, beneficiaries and service providers), followed by policy objectives, scope, the policy clauses themselves, compliance procedures and general provisions, with an appendix listing MSOC services. It frames how beneficiary organisations engage third-party providers to monitor and operate their security operations capabilities. It operates alongside the Regulatory Framework for Licensing Managed Security Operations Centre Services (RFMSOC-1:2024), which sets the licensing and qualification requirements for providers delivering those services.",
      "summary_ar": "السياسة الوطنية لمراكز عمليات الأمن السيبراني المُدارة (NPMSOC-1:2024) هي سياسة صادرة عن الهيئة الوطنية للأمن السيبراني بشأن استخدام خدمات مراكز عمليات الأمن السيبراني المُدارة (MSOC) وتقديمها في المملكة، ونُشرت وثيقةً عامة (TLP: أبيض)؛ والنسخة العربية هي النص المُلزم.\n\nتنتظم السياسة في تعريفات تشمل البنى التحتية الوطنية الحساسة، ومراكز عمليات الأمن السيبراني، وخدمات المراكز المُدارة، والمستفيدين، ومقدّمي الخدمة، تليها أهداف السياسة ونطاقها، ثم بنود السياسة ذاتها، وإجراءات الالتزام بها، والأحكام العامة، مع ملحق يورد خدمات المراكز المُدارة. وتؤطّر السياسة كيفية استعانة الجهات المستفيدة بمقدّمي خدمات من الأطراف الخارجية لمراقبة قدراتها في عمليات الأمن وتشغيلها. وتعمل السياسة جنبًا إلى جنب مع الإطار التنظيمي لترخيص خدمات مراكز عمليات الأمن السيبراني المُدارة (RFMSOC-1:2024)، الذي يحدد متطلبات الترخيص والتأهيل لمقدّمي تلك الخدمات.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/national-policy-for-managed-security-operations-centres-",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "organizations-social-media-accounts-cybersecurity-contro",
      "name": "Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC-1:2021)",
      "name_ar": "ضوابط الأمن السيبراني لحسابات الجهات على وسائل التواصل الاجتماعي (OSMACC-1:2021)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Organizations' Social Media Accounts Cybersecurity Controls (OSMACC-1:2021) are the National Cybersecurity Authority's minimum cybersecurity requirements for the safe official use of social networks, developed in response to rising theft, misuse and impersonation of organisations' accounts.\n\nThe controls apply to government organisations in the Kingdom (ministries, authorities, establishments and related companies) and to private-sector organisations that own, operate or host sensitive national infrastructure; the NCA encourages all other organisations to adopt them. They comprise 3 main domains, 12 subdomains, 15 main controls and 38 subcontrols, aligned with the Essential Cybersecurity Controls (ECC): continuous ECC compliance is a prerequisite, and compliance, required under item 3 of Article 10 of the NCA's mandate, is assessed through means such as self-assessment and on-site audits. A separate NCA guide (GOSMACC-1:2023) supports implementation.",
      "summary_ar": "ضوابط الأمن السيبراني لحسابات التواصل الاجتماعي للجهات (OSMACC-1:2021) هي الحد الأدنى من متطلبات الأمن السيبراني التي وضعتها الهيئة الوطنية للأمن السيبراني لتمكين الاستخدام الرسمي الآمن لشبكات التواصل الاجتماعي، وقد طُوّرت استجابةً لتزايد جرائم سرقة حسابات الجهات وإساءة استخدامها وانتحال هويتها.\n\nتسري الضوابط على الجهات الحكومية في المملكة، من وزارات وهيئات ومؤسسات وما يرتبط بها من شركات، وعلى جهات القطاع الخاص التي تمتلك بنى تحتية وطنية حساسة أو تشغّلها أو تستضيفها؛ وتشجع الهيئة سائر الجهات الأخرى على تبنّيها. وتتكوّن الضوابط من 3 مجالات رئيسة و12 مجالًا فرعيًا و15 ضابطًا رئيسًا و38 ضابطًا فرعيًا، وهي مواءَمة مع الضوابط الأساسية للأمن السيبراني (ECC): إذ يُعد الالتزام المستمر بالضوابط الأساسية شرطًا مسبقًا، ويُقيَّم الالتزام، المطلوب بموجب الفقرة الثالثة من المادة العاشرة من تنظيم الهيئة، بوسائل منها التقييم الذاتي والتدقيق الميداني. ويدعم التطبيقَ دليلٌ مستقل صادر عن الهيئة (GOSMACC-1:2023).",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/organizations-social-media-accounts-cybersecurity-contro",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "saudi-cybersecurity-workforce-framework-scywf-1-2020",
      "name": "Saudi Cybersecurity Workforce Framework (SCyWF-1:2020)",
      "name_ar": "الإطار السعودي لكوادر الأمن السيبراني (SCyWF-1:2020)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Saudi Cybersecurity Workforce Framework (SCyWF-1:2020) is the National Cybersecurity Authority's reference model for categorising cybersecurity work in Saudi Arabia, issued under the NCA's mandate (Royal Order 6801 of 1439H) to build the national cybersecurity workforce, participate in developing education and training programmes and prepare professional standards.\n\nThe framework organises cybersecurity work into five categories (Cybersecurity Architecture, Research and Development; Leadership and Workforce Development; Governance, Risk, Compliance and Laws; Protection and Defence; and Industrial Control Systems and Operational Technologies), comprising twelve specialty areas and forty job roles, each defined by its tasks, knowledge, skills and abilities (TKSAs). The taxonomy adapts the US NICE framework to Saudi workforce demand. Organisations are recommended to adopt it, customising it to their needs, to align workforce structures, recruitment and training with national frameworks; its job roles are included in the Saudi Standard Classification of Occupations, and a separate alignment guide supports mapping existing job titles to SCyWF roles.",
      "summary_ar": "الإطار السعودي لكوادر الأمن السيبراني (SCyWF-1:2020) هو النموذج المرجعي الذي وضعته الهيئة الوطنية للأمن السيبراني لتصنيف العمل في مجال الأمن السيبراني في المملكة العربية السعودية، وقد صدر في إطار اختصاص الهيئة (الأمر الملكي رقم 6801 لعام 1439هـ) ببناء الكوادر الوطنية للأمن السيبراني والمشاركة في تطوير برامج التعليم والتدريب وإعداد المعايير المهنية.\n\nينظّم الإطار العمل في الأمن السيبراني ضمن خمس فئات: هندسة الأمن السيبراني والبحث والتطوير؛ والقيادة وتنمية الكوادر؛ والحوكمة والمخاطر والالتزام والقوانين؛ والحماية والدفاع؛ وأنظمة التحكم الصناعي والتقنيات التشغيلية، تضم اثني عشر مجال تخصص وأربعين دورًا وظيفيًا، يُعرَّف كل منها بمهامه ومعارفه ومهاراته وقدراته (TKSAs). ويكيّف هذا التصنيف إطار NICE الأمريكي بما يلائم احتياجات سوق العمل السعودي. ويوصى بأن تتبنى الجهات الإطار، مع تخصيصه وفق احتياجاتها، لمواءمة هياكل كوادرها واستقطابها وتدريبها مع الأطر الوطنية؛ وقد أُدرجت أدواره الوظيفية في التصنيف السعودي الموحد للمهن، ويدعم دليلُ مواءمة مستقل ربطَ المسميات الوظيفية القائمة بأدوار الإطار.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/saudi-cybersecurity-workforce-framework-scywf-1-2020",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "telework-cybersecurity-controls-tcc",
      "name": "Telework Cybersecurity Controls (TCC)",
      "name_ar": "ضوابط الأمن السيبراني للعمل عن بُعد (TCC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Telework Cybersecurity Controls (TCC-1:2021) are the National Cybersecurity Authority's minimum cybersecurity requirements for enabling organisations to operate telework securely, complementing the Essential Cybersecurity Controls (ECC) and taking the Critical Systems Cybersecurity Controls (CSCC) into account where critical systems are used in telework.\n\nThe controls apply to government organisations in the Kingdom and to private-sector organisations owning, operating or hosting critical national infrastructure; the NCA encourages all other organisations to adopt them, and any in-scope organisation that allows telework must comply with all applicable controls. The TCC comprise 3 main domains (cybersecurity governance, cybersecurity defence, and third-party and cloud computing cybersecurity), with 16 subdomains, 21 main controls and 42 subcontrols. Continuous ECC compliance is a prerequisite; compliance is mandated under item 3 of Article 10 of the NCA's mandate and Royal Decree 57231 (10/11/1439H), and is assessed through self-assessment and external compliance assessment. A separate guide (GTCC-1:2023) supports implementation.",
      "summary_ar": "ضوابط الأمن السيبراني للعمل عن بُعد (TCC-1:2021) هي الحد الأدنى من متطلبات الأمن السيبراني التي وضعتها الهيئة الوطنية للأمن السيبراني لتمكين الجهات من ممارسة العمل عن بُعد بطريقة آمنة، وهي مكمّلة للضوابط الأساسية للأمن السيبراني (ECC)، مع مراعاة ضوابط الأمن السيبراني للأنظمة الحساسة (CSCC) عند استخدام أنظمة حساسة في العمل عن بُعد.\n\nتسري الضوابط على الجهات الحكومية في المملكة وعلى جهات القطاع الخاص التي تمتلك بنى تحتية وطنية حساسة أو تشغّلها أو تستضيفها؛ وتشجع الهيئة سائر الجهات على تبنّيها، ويجب على كل جهة مشمولة تسمح بالعمل عن بُعد الالتزام بجميع الضوابط المنطبقة عليها. وتتكوّن الضوابط من 3 مجالات رئيسة: حوكمة الأمن السيبراني، وتعزيز الأمن السيبراني، والأمن السيبراني المتعلق بالأطراف الخارجية والحوسبة السحابية، تضم 16 مجالًا فرعيًا و21 ضابطًا رئيسًا و42 ضابطًا فرعيًا. ويُعد الالتزام المستمر بالضوابط الأساسية شرطًا مسبقًا؛ والالتزام واجب بموجب الفقرة الثالثة من المادة العاشرة من تنظيم الهيئة والأمر الملكي رقم 57231 وتاريخ 10/11/1439هـ، ويُقيَّم عبر التقييم الذاتي وتقييم الالتزام الخارجي. ويدعم التطبيقَ دليلٌ مستقل (GTCC-1:2023).",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/telework-cybersecurity-controls-tcc",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "data-sharing-guideline",
      "name": "Data Sharing Guideline",
      "name_ar": "دليل مشاركة البيانات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on data-sharing arrangements.",
      "summary_ar": "إرشادات بشأن ترتيبات مشاركة البيانات.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/DataSharingPolicyEN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/data-sharing-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cma-cyber-guidelines",
      "name": "CMA Cybersecurity Guidelines",
      "name_ar": "إرشادات الأمن السيبراني الصادرة عن CMA",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Non-binding but examined at licensing; cloud must be in KSA.",
      "summary_ar": "غير ملزمة لكنها تُفحَص عند الترخيص؛ ويجب أن تكون الخدمات السحابية داخل المملكة العربية السعودية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "financial",
      "authority": "CMA",
      "parent": null,
      "in_library": true,
      "official_url": "https://cma.gov.sa/en/RulesRegulations/Guides/Documents/Cyber_Security_en.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/cma-cyber-guidelines",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "privacy-policy-guideline",
      "name": "Privacy Policy (Notice) Guideline",
      "name_ar": "دليل سياسة الخصوصية (الإشعار)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on drafting privacy notices.",
      "summary_ar": "إرشادات بشأن صياغة إشعارات الخصوصية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/PrivacyPolicyGuideline.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/privacy-policy-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ai-ethics-principles",
      "name": "AI Ethics Principles",
      "name_ar": "مبادئ أخلاقيات الذكاء الاصطناعي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "SDAIA's AI Ethics Principles (2023).",
      "summary_ar": "مبادئ أخلاقيات الذكاء الاصطناعي الصادرة عن SDAIA (2023).",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/ai-principles.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/ai-ethics-principles",
      "date_note": "2023",
      "date_note_ar": "2023",
      "provisions": []
    },
    {
      "slug": "cst-guide-for-cloud-computing-service-providers",
      "name": "CST Guide for Cloud Computing Service Providers",
      "name_ar": "دليل CST لمقدمي خدمات الحوسبة السحابية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **Guide for Cloud Computing Service Providers** (Fifth Version, October 2023) is the Communications, Space & Technology Commission's manual for registering as a cloud service provider (CSP) under the **Cloud Computing Services Provisioning Regulations**, grounded in the Telecommunication and Information Technology Act (Royal Decree M/106, 2/11/1443H).\n\nRegistration is required of any provider exercising **direct or effective control over a data centre or the critical infrastructure of a cloud computing system** hosted and used in the Kingdom. Applications go through CST's electronic platform, describing the applicant's business, services, cloud systems and data centres, including any **foreign data-centre locations** used to process Saudi subscribers' content, which CST may refuse.\n\nProviders register in **Class A, Class B or Category C**, evidenced by escalating facility certifications (Tier 2 or ISO/IEC 27001; Tier 3; further approvals for Category C), and must comply with the National Cybersecurity Authority's controls. Submissions are in Arabic; CST decides within 15 working days; registration lasts **three years**, renewable, with registered CSPs published on CST's website.",
      "summary_ar": "**دليل مقدمي خدمات الحوسبة السحابية** (الإصدار الخامس، أكتوبر 2023) هو الدليل العملي الصادر عن هيئة الاتصالات والفضاء والتقنية للتسجيل بوصفه مقدم خدمات حوسبة سحابية بموجب **تنظيمات تقديم خدمات الحوسبة السحابية**، المستندة بدورها إلى نظام الاتصالات وتقنية المعلومات (المرسوم الملكي م/106 وتاريخ 2/11/1443هـ).\n\nويلزم التسجيل كلَّ مقدم خدمة يمارس **سيطرة مباشرة أو فعلية على مركز بيانات أو على البنية التحتية الحساسة لنظام حوسبة سحابية** مستضاف ومستخدم في المملكة. وتُقدَّم الطلبات عبر المنصة الإلكترونية للهيئة، ويجب أن تتضمن وصفاً لنشاط المتقدم وخدماته وأنظمته السحابية ومراكز بياناته، بما في ذلك **مواقع مراكز البيانات في الخارج** المستخدمة في معالجة محتوى المشتركين في المملكة، والتي يحق للهيئة رفض أيٍّ منها.\n\nويسجَّل مقدمو الخدمة في **الفئة (أ) أو الفئة (ب) أو الفئة (ج)**، بإثباتات تصاعدية لاعتماد المنشآت (شهادة المستوى الثاني أو ISO/IEC 27001 للفئة أ؛ والمستوى الثالث للفئة ب؛ ومتطلبات الفئة ب مع موافقات إضافية للفئة ج)، مع الالتزام بضوابط الهيئة الوطنية للأمن السيبراني. وتُقدَّم المتطلبات باللغة العربية؛ وتبتّ الهيئة خلال 15 يوم عمل؛ ومدة التسجيل **ثلاث سنوات** قابلة للتجديد، وتنشر الهيئة قائمة المسجلين على موقعها.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "telecom",
      "authority": "CST",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cst-guide-for-cloud-computing-service-providers",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cybersecurity-guidelines-for-internet-of-things-cgiot-1-",
      "name": "Cybersecurity Guidelines for Internet of Things (CGIoT-1:2024)",
      "name_ar": "إرشادات الأمن السيبراني لإنترنت الأشياء (CGIoT-1:2024)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Cybersecurity Guidelines for Internet of Things (CGIoT-1:2024) are National Cybersecurity Authority guidance on securing Internet of Things technologies, published as a public (TLP: White) document.\n\nThe guidelines follow the domain model familiar from the NCA's control sets, organised into four main domains (cybersecurity governance, cybersecurity defence, cybersecurity resilience, and third-party and cloud computing cybersecurity), each broken into subdomains containing individual guidelines, with a coding scheme identifying each guideline by main domain, subdomain and number. As guidance rather than binding controls, they help organisations adopting IoT devices and services address risks across governance arrangements, defensive measures, resilience, and dependencies on third parties and cloud services. They sit alongside the NCA's binding control sets, such as the Essential Cybersecurity Controls (ECC), which remain the compliance baseline for in-scope entities.",
      "summary_ar": "إرشادات الأمن السيبراني لإنترنت الأشياء (CGIoT-1:2024) هي إرشادات صادرة عن الهيئة الوطنية للأمن السيبراني بشأن تأمين تقنيات إنترنت الأشياء، ونُشرت وثيقةً عامة (TLP: أبيض).\n\nتتبع الإرشادات نموذج المجالات المعهود في مجموعات ضوابط الهيئة، إذ تنتظم في أربعة مجالات رئيسة: حوكمة الأمن السيبراني، وتعزيز الأمن السيبراني، وصمود الأمن السيبراني، والأمن السيبراني المتعلق بالأطراف الخارجية والحوسبة السحابية، يتفرع كل منها إلى مجالات فرعية تتضمن إرشادات مفردة، مع منهجية ترميز تحدد كل إرشاد برقم المجال الرئيس والمجال الفرعي ورقم الإرشاد. وبوصفها إرشادات لا ضوابط مُلزمة، فهي تساعد الجهات التي تتبنى أجهزة إنترنت الأشياء وخدماتها على معالجة المخاطر عبر ترتيبات الحوكمة والتدابير الدفاعية والصمود والاعتماد على الأطراف الخارجية والخدمات السحابية. وتقوم إلى جانب مجموعات الضوابط المُلزمة الصادرة عن الهيئة، مثل الضوابط الأساسية للأمن السيبراني (ECC)، التي تبقى الحد الأدنى للالتزام لدى الجهات المشمولة.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cybersecurity-guidelines-for-internet-of-things-cgiot-1-",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "genai-guidelines-gov",
      "name": "Generative AI Guidelines: Government & Public",
      "name_ar": "إرشادات الذكاء الاصطناعي التوليدي: الجهات الحكومية والعموم",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on generative AI for government and the public.",
      "summary_ar": "إرشادات بشأن الذكاء الاصطناعي التوليدي للجهات الحكومية والجمهور.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/GenAIGuidelinesForGovernmentENCompressed.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/genai-guidelines-gov",
      "date_note": "2024",
      "date_note_ar": "2024",
      "provisions": []
    },
    {
      "slug": "registration-guide-in-the-qualifying-category",
      "name": "Registration Guide in the Qualifying Category",
      "name_ar": "دليل التسجيل في فئة التأهيل",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **Registration Guide in the Qualifying Category** (CST, October 2023) opens a transitional path into the Saudi cloud market. The **Qualifying Category** lets an entity intending to provide cloud services through a Kingdom data centre, but not yet meeting all requirements of the basic registration categories (A/B/C) under the Cloud Computing Services Provisioning Regulations, register and operate while it works towards them.\n\nThe trade-off is a restricted scope: qualifying-category registrants may serve **individuals and the private sector only**; the government and financial sectors are off-limits during registration. Mandatory requirements include an Arabic application, an undertaking of compliance, the named Kingdom data centre to be used, a plan for achieving the basic-category requirements and compliance with the National Cybersecurity Authority's controls; CST may exempt applicants such as mega data-centre projects.\n\nRegistration is applied for through CST's cloud portal, issued electronically, and valid for **one year**. The Guide sits under the Telecommunication and Information Technology Act (Royal Decree M/106) and complements the main CSP registration guide.",
      "summary_ar": "**دليل التسجيل في الفئة التأهيلية لتقديم خدمات الحوسبة السحابية** (هيئة الاتصالات والفضاء والتقنية، أكتوبر 2023) يفتح مساراً انتقالياً لدخول سوق الحوسبة السحابية السعودية. إذ تتيح **الفئة التأهيلية** للمنشأة الراغبة في تقديم خدمات حوسبة سحابية عبر مركز بيانات في المملكة، دون أن تستوفي بعد جميع متطلبات فئات التسجيل الأساسية (أ/ب/ج) بموجب تنظيمات تقديم خدمات الحوسبة السحابية، أن تسجَّل وتعمل ريثما تستكمل تلك المتطلبات.\n\nومقابل ذلك يُقيَّد نطاق الخدمة: فلا يجوز للمسجلين في الفئة التأهيلية تقديم الخدمة إلا **للأفراد والقطاع الخاص فقط**، ويُحظر عليهم خدمة القطاع الحكومي أو القطاع المالي خلال مدة تسجيلهم. وتشمل المتطلبات الإلزامية تقديم الطلب باللغة العربية، وتعهداً بالالتزام، وتحديد مركز البيانات في المملكة المزمع استخدامه، وخطة لاستيفاء متطلبات الفئة الأساسية، والالتزام بضوابط الهيئة الوطنية للأمن السيبراني؛ وللهيئة إعفاء من تراه، كمشاريع مراكز البيانات العملاقة.\n\nويُقدَّم طلب التسجيل عبر بوابة الحوسبة السحابية على موقع الهيئة، وتصدر الشهادة إلكترونياً وتسري لمدة **سنة واحدة**. ويُنفِّذ الدليل نظام الاتصالات وتقنية المعلومات (المرسوم الملكي م/106 وتاريخ 2/11/1443هـ) ويُكمل الدليل الرئيس لتسجيل مقدمي الخدمات السحابية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "telecom",
      "authority": "CST",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/registration-guide-in-the-qualifying-category",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "guide-to-organizations-social-media-accounts-cybersecuri",
      "name": "Guide to Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC) Implementation",
      "name_ar": "دليل تطبيق ضوابط الأمن السيبراني لحسابات الجهات على وسائل التواصل الاجتماعي (OSMACC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Guide to Organizations' Social Media Accounts Cybersecurity Controls Implementation (GOSMACC-1:2023) is the National Cybersecurity Authority's public implementation guide for the Organizations' Social Media Accounts Cybersecurity Controls (OSMACC-1:2021), which set the minimum requirements for organisations' safe official use of social networks.\n\nThe guide presents the OSMACC domains and subdomains: cybersecurity governance (policies and procedures, risk management, human resources, and awareness and training), cybersecurity defence (asset management, identity and access management, protection of information systems and processing facilities, mobile-device security, data and information protection, event-log monitoring, and incident and threat management) and third-party cybersecurity, then provides a general implementation guideline followed by guidance under each domain. It supports the OSMACC's ECC-aligned compliance model, in which continuous compliance with the Essential Cybersecurity Controls is a prerequisite.",
      "summary_ar": "دليل تطبيق ضوابط الأمن السيبراني لحسابات التواصل الاجتماعي للجهات (GOSMACC-1:2023) هو دليل التطبيق العام الصادر عن الهيئة الوطنية للأمن السيبراني لضوابط الأمن السيبراني لحسابات التواصل الاجتماعي للجهات (OSMACC-1:2021)، التي تضع الحد الأدنى من المتطلبات للاستخدام الرسمي الآمن لشبكات التواصل الاجتماعي.\n\nيعرض الدليل المجالات الرئيسة والفرعية للضوابط: حوكمة الأمن السيبراني (السياسات والإجراءات، وإدارة المخاطر، والموارد البشرية، والتوعية والتدريب)، وتعزيز الأمن السيبراني (إدارة الأصول، وإدارة هويات الدخول والصلاحيات، وحماية أنظمة المعلومات ومرافق معالجة المعلومات، وأمن الأجهزة المحمولة، وحماية البيانات والمعلومات، ومراقبة سجلات الأحداث، وإدارة الحوادث والتهديدات)، والأمن السيبراني المتعلق بالأطراف الخارجية، ثم يقدّم إرشادًا عامًا للتطبيق تليه إرشادات تحت كل مجال. ويدعم الدليل نموذج الالتزام المواءَم مع الضوابط الأساسية للأمن السيبراني (ECC)، الذي يُعد فيه الالتزام المستمر بالضوابط الأساسية شرطًا مسبقًا.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-organizations-social-media-accounts-cybersecuri",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "payment-services-provider-regulatory-guidelines",
      "name": "Payment Services Provider Regulatory Guidelines",
      "name_ar": "الإرشادات التنظيمية لمقدمي خدمات المدفوعات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **Payment Services Provider Regulatory Guidelines**, issued by SAMA in January 2020, were the Kingdom's first dedicated regulatory framework for non-bank payment service providers, and remain useful as the definitional companion to the payments regime.\n\nArticle 1 supplies an extensive interpretation catalogue (defining account information services and providers (open-banking-style data aggregation), acquiring of payment transactions, agents, alternative delivery channels, authentication, e-money and the rest of the payments vocabulary) while Article 6 sets out the licensing pathway to SAMA for applicants across the payment-institution and e-money categories. The Guidelines also carry conduct, record-keeping and AML expectations, cross-referencing the Anti-Money Laundering Law.\n\nSAMA issued the updated **Payment Services Provider Regulations** in August 2020, which restate and supersede the substance of this framework; the Law of Payments and Payment Services (2021) later gave the sector its statutory base. The Guidelines are retained in the atlas as the origin document of the Saudi payments rulebook and the fullest glossary of its defined terms.",
      "summary_ar": "**الأدلة الإرشادية التنظيمية لمقدمي خدمات المدفوعات**، الصادرة عن ساما في يناير 2020، كانت أول إطار تنظيمي مخصص لمقدمي خدمات المدفوعات من غير البنوك في المملكة، وما تزال مفيدة بوصفها المرجع التعريفي المرافق لمنظومة المدفوعات.\n\nفالمادة الأولى تقدّم قائمة تفسيرية موسّعة (تُعرِّف خدمات معلومات الحسابات ومقدميها (تجميع البيانات على نمط الخدمات المصرفية المفتوحة)، وقبول عمليات الدفع، والوكلاء، وقنوات التقديم البديلة، والمصادقة، والنقود الإلكترونية، وسائر مفردات قطاع المدفوعات) بينما تحدد المادة السادسة مسار الترخيص لدى ساما للمتقدمين عبر فئتي مؤسسات المدفوعات ومؤسسات النقود الإلكترونية. كما تتضمن الأدلة توقعات تتعلق بالسلوك وحفظ السجلات ومكافحة غسل الأموال، مع الإحالة إلى نظام مكافحة غسل الأموال.\n\nوقد أصدرت ساما **قواعد مقدمي خدمات المدفوعات** المحدَّثة في أغسطس 2020، والتي أعادت صياغة جوهر هذا الإطار وحلّت محله؛ ثم منح نظام المدفوعات وخدماتها (2021) القطاعَ أساسه النظامي. ويُحتفظ بهذه الأدلة في الأطلس بوصفها الوثيقة المؤسِّسة لمنظومة المدفوعات السعودية وأوفى مسرد لمصطلحاتها المعرَّفة.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/payment-services-provider-regulatory-guidelines",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "destruction-anonymisation-guideline",
      "name": "Destruction / Anonymisation / Pseudonymisation Guideline",
      "name_ar": "دليل الإتلاف / إخفاء الهوية / الترميز المستعار",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on destruction, anonymisation and pseudonymisation of personal data.",
      "summary_ar": "إرشادات بشأن إتلاف البيانات الشخصية وإخفاء هويتها وإضفاء الطابع المستعار عليها.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/PersonalDataDestructionAnonymizationAndEncryptionGuideline.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/destruction-anonymisation-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "data-disclosure-guideline",
      "name": "Personal Data Disclosure Guideline",
      "name_ar": "دليل الإفصاح عن البيانات الشخصية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on lawful disclosure of personal data.",
      "summary_ar": "إرشادات بشأن الإفصاح المشروع عن البيانات الشخصية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/PersonalDataDisclosureCasesGuideline.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/data-disclosure-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "deepfakes-guidelines",
      "name": "Deepfakes Guidelines",
      "name_ar": "إرشادات التزييف العميق",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on deepfakes.",
      "summary_ar": "إرشادات بشأن التزييف العميق.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/File0001.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/deepfakes-guidelines",
      "date_note": "2024",
      "date_note_ar": "2024",
      "provisions": []
    },
    {
      "slug": "guide-to-telework-cybersecurity-controls-tcc-implementat",
      "name": "Guide to Telework Cybersecurity Controls (TCC) Implementation",
      "name_ar": "دليل تطبيق ضوابط الأمن السيبراني للعمل عن بُعد (TCC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Guide to Telework Cybersecurity Controls Implementation (GTCC-1:2023) is the National Cybersecurity Authority's public implementation guide for the Telework Cybersecurity Controls (TCC-1:2021), which set the minimum cybersecurity requirements for operating telework securely.\n\nThe guide sets out the TCC domains and subdomains: cybersecurity governance (policies and procedures, risk management, and awareness and training), cybersecurity defence (spanning asset management, identity and access management, protection of information systems and processing facilities, network security, mobile-device security, data and information protection, cryptography, backup and recovery, vulnerability management, penetration testing, event-log monitoring, and incident and threat management) and third-party and cloud computing cybersecurity, and explains the guideline's structure before giving general and then domain-by-domain implementation guidance. It supports the TCC's compliance model, under which continuous compliance with the Essential Cybersecurity Controls (ECC) is a prerequisite.",
      "summary_ar": "دليل تطبيق ضوابط الأمن السيبراني للعمل عن بُعد (GTCC-1:2023) هو دليل التطبيق العام الصادر عن الهيئة الوطنية للأمن السيبراني لضوابط الأمن السيبراني للعمل عن بُعد (TCC-1:2021)، التي تضع الحد الأدنى من متطلبات الأمن السيبراني لممارسة العمل عن بُعد بأمان.\n\nيعرض الدليل المجالات الرئيسة والفرعية للضوابط: حوكمة الأمن السيبراني (السياسات والإجراءات، وإدارة المخاطر، والتوعية والتدريب)، وتعزيز الأمن السيبراني (بما يشمل إدارة الأصول، وإدارة هويات الدخول والصلاحيات، وحماية أنظمة المعلومات ومرافق معالجة المعلومات، وأمن الشبكات، وأمن الأجهزة المحمولة، وحماية البيانات والمعلومات، والتشفير، والنسخ الاحتياطي والاسترجاع، وإدارة الثغرات، واختبار الاختراق، ومراقبة سجلات الأحداث، وإدارة الحوادث والتهديدات)، والأمن السيبراني المتعلق بالأطراف الخارجية والحوسبة السحابية، ويشرح هيكل الدليل قبل تقديم إرشادات تطبيق عامة ثم إرشادات لكل مجال على حدة. ويدعم الدليل نموذج الالتزام الخاص بالضوابط، الذي يُعد فيه الالتزام المستمر بالضوابط الأساسية للأمن السيبراني (ECC) شرطًا مسبقًا.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-telework-cybersecurity-controls-tcc-implementat",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "generative-ai-public",
      "name": "Generative AI Guidelines: Public",
      "name_ar": "إرشادات الذكاء الاصطناعي التوليدي: العموم",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on generative AI for the public.",
      "summary_ar": "إرشادات بشأن الذكاء الاصطناعي التوليدي للجمهور.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/GenerativeAIPublicEN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/generative-ai-public",
      "date_note": "2024",
      "date_note_ar": "2024",
      "provisions": []
    },
    {
      "slug": "ropa-guideline",
      "name": "Records of Processing (RoPA) Guideline",
      "name_ar": "دليل سجلّات أنشطة المعالجة (RoPA)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on maintaining records of processing activities. The RoPA form may be repealed under the amendments.",
      "summary_ar": "إرشادات بشأن الاحتفاظ بسجلات أنشطة المعالجة. وقد يُلغى نموذج سجل أنشطة المعالجة (RoPA) بموجب التعديلات.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/PersonalDataProcessingActivitiesRecordsGuideline.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/ropa-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cybersecurity-guidelines-for-e-commerce-service-provider",
      "name": "Cybersecurity Guidelines for E-commerce Service Providers (CGESP-1:2019)",
      "name_ar": "إرشادات الأمن السيبراني لمقدمي خدمات التجارة الإلكترونية (CGESP-1:2019)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Cybersecurity Guidelines for E-commerce Service Providers (CGESP-1:2019) are National Cybersecurity Authority guidance to educate and assist small and medium enterprises (SMEs) and small office/home office (SoHo) e-commerce providers in the Kingdom in securing their business, devices, data, customer accounts and payment processes, issued as the E-commerce Law sought to strengthen trust in a fast-growing market.\n\nThe guidelines were developed from a study of national and international e-commerce cybersecurity guidance, cybersecurity best practices and analysis of previous incidents targeting e-commerce providers. They are organised into seven categories: using strong authentication; protecting e-commerce systems; minimising the impact of data breaches; guarding social media accounts used in e-commerce; defending the network; continuously educating and training employees; and strengthening the internal e-commerce infrastructure. A companion instrument, the Cybersecurity Guidelines for E-commerce Consumers (CGEC-1:2019), addresses the buyer side.",
      "summary_ar": "إرشادات الأمن السيبراني لمقدّمي خدمات التجارة الإلكترونية (CGESP-1:2019) هي إرشادات صادرة عن الهيئة الوطنية للأمن السيبراني لتوعية ومساعدة المنشآت الصغيرة والمتوسطة ومنشآت المكاتب الصغيرة والمنزلية العاملة في التجارة الإلكترونية في المملكة على تأمين أعمالها وأجهزتها وبياناتها وحسابات عملائها وعمليات الدفع لديها، وقد صدرت في وقت سعى فيه نظام التجارة الإلكترونية إلى تعزيز الموثوقية في سوق سريعة النمو.\n\nطُوّرت الإرشادات استنادًا إلى دراسة للإرشادات الوطنية والدولية للأمن السيبراني في التجارة الإلكترونية، وأفضل الممارسات، وتحليل الحوادث السابقة التي استهدفت مقدّمي خدمات التجارة الإلكترونية. وتنتظم في سبع فئات: استخدام التحقق القوي من الهوية؛ وحماية أنظمة التجارة الإلكترونية؛ والحد من أثر تسريبات البيانات؛ وحماية حسابات التواصل الاجتماعي المستخدمة في التجارة الإلكترونية؛ والدفاع عن الشبكة؛ والتثقيف والتدريب المستمرين للموظفين؛ وتعزيز البنية التحتية الداخلية للتجارة الإلكترونية. وتعالج وثيقة مصاحبة، هي إرشادات الأمن السيبراني لمستهلكي التجارة الإلكترونية (CGEC-1:2019)، جانب المشتري.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cybersecurity-guidelines-for-e-commerce-service-provider",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "alignment-guide-for-the-saudi-cybersecurity-workforce-fr",
      "name": "Alignment Guide for the Saudi Cybersecurity Workforce Framework (SCyWF)",
      "name_ar": "دليل المواءمة للإطار السعودي لكوادر الأمن السيبراني (SCyWF)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Alignment Guide for the Saudi Cybersecurity Workforce Framework (SCyWF) is a National Cybersecurity Authority guide, issued in October 2020, that helps organisations map their cybersecurity jobs to the job roles defined in SCyWF-1:2020, the national framework that categorises cybersecurity work into categories, specialty areas and job roles with associated tasks, knowledge, skills and abilities.\n\nThe guide explains why entities should link every cybersecurity job title to an SCyWF job role: to identify the knowledge, skills and abilities each role requires, and to measure the qualified workforce and its demand at organisation, sector and national level. It sets out a three-step alignment mechanism: list the SCyWF job roles present in the organisation, link them to existing job titles (updating titles where needed), and handle special cases such as mapping several roles to one job where justified. The SCyWF job roles are included in the Saudi Standard Classification of Occupations approved by Cabinet Resolution No. 660 (1441H).",
      "summary_ar": "دليل المواءمة مع الإطار السعودي لكوادر الأمن السيبراني (SCyWF) هو دليل صادر عن الهيئة الوطنية للأمن السيبراني في أكتوبر 2020، يساعد الجهات على ربط وظائفها في الأمن السيبراني بالأدوار الوظيفية المحددة في الإطار (SCyWF-1:2020)، وهو الإطار الوطني الذي يصنّف العمل في الأمن السيبراني إلى فئات ومجالات تخصص وأدوار وظيفية مع ما يرتبط بها من مهام ومعارف ومهارات وقدرات.\n\nيوضح الدليل أسباب وجوب ربط كل مسمى وظيفي في الأمن السيبراني بدور وظيفي في الإطار: لتحديد المعارف والمهارات والقدرات التي يتطلبها كل دور بدقة، ولقياس الكوادر المؤهلة والطلب عليها على مستوى الجهة والقطاع والمستوى الوطني. ويعرض آلية مواءمة من ثلاث خطوات: حصر الأدوار الوظيفية للإطار الموجودة لدى الجهة، ثم ربطها بالمسميات الوظيفية القائمة (مع تحديث المسميات عند الحاجة)، ثم معالجة الحالات الخاصة مثل ربط أكثر من دور وظيفي بوظيفة واحدة عند وجود مسوّغ. وقد أُدرجت الأدوار الوظيفية للإطار في التصنيف السعودي الموحد للمهن المعتمد بقرار مجلس الوزراء رقم 660 لعام 1441هـ.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/alignment-guide-for-the-saudi-cybersecurity-workforce-fr",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "breach-incidents-guide",
      "name": "Personal Data Breach Incidents Procedural Guide",
      "name_ar": "الدليل الإجرائي لحوادث انتهاك البيانات الشخصية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Procedural guide for handling personal data breach incidents.",
      "summary_ar": "دليل إجرائي للتعامل مع حوادث انتهاك البيانات الشخصية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/PersonalDataBreachIncidents.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/breach-incidents-guide",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "guide-to-operational-technology-cybersecurity-controls-o",
      "name": "Guide to Operational Technology Cybersecurity Controls (OTCC) Implementation",
      "name_ar": "دليل تطبيق ضوابط الأمن السيبراني للتقنية التشغيلية (OTCC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Guide to Operational Technology Cybersecurity Controls (OTCC) Implementation (GOTCC-1:2023) is the National Cybersecurity Authority's public implementation guide for the Operational Technology Cybersecurity Controls, which govern the security of operational technology and industrial control system (OT/ICS) environments.\n\nThe guide describes the OTCC domains and subdomains and the structure of the guideline, then provides general implementation guidance followed by guidance under the OTCC's domains in turn, from cybersecurity governance through defence to third-party cybersecurity. The OTCC themselves extend the NCA's Essential Cybersecurity Controls (ECC): applicable organisations comply with the ECC first, then with the additional OT-specific controls. The guide is complemented by the OTCC Methodology and Mapping Annex (OTCCMM-1:2022), which explains the controls' design and their mapping to international standards such as the ISA/IEC 62443 series.",
      "summary_ar": "دليل تطبيق ضوابط الأمن السيبراني للتقنيات التشغيلية (GOTCC-1:2023) هو دليل التطبيق العام الصادر عن الهيئة الوطنية للأمن السيبراني لضوابط الأمن السيبراني للتقنيات التشغيلية، التي تنظّم أمن بيئات التقنيات التشغيلية وأنظمة التحكم الصناعي (OT/ICS).\n\nيصف الدليل المجالات الرئيسة والفرعية للضوابط وهيكل الدليل، ثم يقدّم إرشادات تطبيق عامة تليها إرشادات تحت مجالات الضوابط تباعًا، من حوكمة الأمن السيبراني مرورًا بتعزيزه وصولًا إلى الأمن السيبراني المتعلق بالأطراف الخارجية. وتُعد ضوابط التقنيات التشغيلية ذاتها امتدادًا للضوابط الأساسية للأمن السيبراني (ECC): إذ تلتزم الجهات المشمولة بالضوابط الأساسية أولًا، ثم بالضوابط الإضافية الخاصة بالتقنيات التشغيلية. ويُكمّل الدليلَ ملحقُ منهجية ضوابط الأمن السيبراني للتقنيات التشغيلية ومواءمتها (OTCCMM-1:2022)، الذي يشرح تصميم الضوابط ومواءمتها مع المعايير الدولية مثل سلسلة ISA/IEC 62443.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-operational-technology-cybersecurity-controls-o",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "transfer-nonadequate-guideline",
      "name": "Transfer to Non-Adequate Country Guideline",
      "name_ar": "دليل النقل إلى دولة غير ذات مستوى حماية ملائم",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on transfers to countries without an adequacy decision.",
      "summary_ar": "إرشادات بشأن نقل البيانات إلى الدول التي لا يتوفر بشأنها قرار بكفاية مستوى الحماية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "transfer-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/RisksTransferringDataOutsideKingdomEn.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/transfer-nonadequate-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "self-assessment-guideline",
      "name": "Self-Assessment Guideline (incl. DPO-need tool)",
      "name_ar": "دليل التقييم الذاتي (متضمنًا أداة تحديد الحاجة إلى مسؤول حماية البيانات)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Self-assessment guidance, including a tool to determine whether a DPO is required.",
      "summary_ar": "إرشادات للتقييم الذاتي، تتضمن أداة لتحديد ما إذا كان تعيين مسؤول حماية البيانات (DPO) مطلوبًا.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": false,
      "official_url": "https://dgp.sdaia.gov.sa/wps/portal/pdp/services/servicesdetails/TooltoDeterminingDataProtectionOfficer",
      "wadira_url": "https://www.wadiraksa.com/instrument/self-assessment-guideline",
      "date_note": "Tool at dgp.sdaia.gov.sa",
      "date_note_ar": "الأداة متاحة على dgp.sdaia.gov.sa",
      "provisions": []
    },
    {
      "slug": "cybersecurity-guidelines-for-e-commerce-consumers-cgec-1",
      "name": "Cybersecurity Guidelines for E-commerce Consumers (CGEC-1:2019)",
      "name_ar": "إرشادات الأمن السيبراني لمستهلكي التجارة الإلكترونية (CGEC-1:2019)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Cybersecurity Guidelines for E-commerce Consumers (CGEC-1:2019) are awareness guidance from the National Cybersecurity Authority to help consumers in Saudi Arabia shop online securely, issued against the backdrop of the Kingdom's E-commerce Law and the rapid growth of one of the region's largest e-commerce markets.\n\nThe guidelines target all consumers in the Kingdom conducting e-commerce through any channel (social media, websites or apps) on any computing device, and are intended for awareness purposes rather than binding compliance. They are organised into four categories: protecting e-commerce accounts and devices; securing e-commerce transactions; exercising caution when communicating online for e-commerce; and limiting the sharing of personal information, with detailed practical guidance under each, from anti-virus software and strong authentication to safe payment behaviour. A companion instrument, the Cybersecurity Guidelines for E-commerce Service Providers (CGESP-1:2019), addresses the seller side.",
      "summary_ar": "إرشادات الأمن السيبراني لمستهلكي التجارة الإلكترونية (CGEC-1:2019) هي إرشادات توعوية صادرة عن الهيئة الوطنية للأمن السيبراني لمساعدة المستهلكين في المملكة العربية السعودية على التسوق الإلكتروني بأمان، وقد صدرت في سياق نظام التجارة الإلكترونية في المملكة والنمو المتسارع لأحد أكبر أسواق التجارة الإلكترونية في المنطقة.\n\nتستهدف الإرشادات جميع المستهلكين في المملكة الذين يمارسون التجارة الإلكترونية عبر أي قناة، من شبكات التواصل الاجتماعي أو المواقع الإلكترونية أو التطبيقات، وباستخدام أي جهاز حاسوبي، وهي مُعدّة لأغراض التوعية لا للالتزام المُلزم. وتنتظم في أربع فئات: حماية حسابات وأجهزة التجارة الإلكترونية؛ وتأمين معاملات التجارة الإلكترونية؛ وتوخي الحذر عند التواصل عبر الإنترنت لأغراض التجارة الإلكترونية؛ والحد من مشاركة المعلومات الشخصية، مع إرشادات عملية مفصّلة تحت كل فئة، من برامج مكافحة الفيروسات والتحقق القوي من الهوية إلى سلوكيات الدفع الآمن. وتعالج وثيقة مصاحبة، هي إرشادات الأمن السيبراني لمقدّمي خدمات التجارة الإلكترونية (CGESP-1:2019)، جانب البائع.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cybersecurity-guidelines-for-e-commerce-consumers-cgec-1",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "minimum-pd-guideline",
      "name": "Minimum Personal Data Guideline",
      "name_ar": "دليل الحد الأدنى من البيانات الشخصية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on collecting the minimum personal data necessary (data minimisation).",
      "summary_ar": "إرشادات بشأن جمع الحد الأدنى اللازم من البيانات الشخصية (تقليل البيانات).",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/MinmumPDGuideline.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/minimum-pd-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "guide-to-cloud-cybersecurity-controls-ccc-implementation",
      "name": "Guide to Cloud Cybersecurity Controls (CCC) Implementation",
      "name_ar": "دليل تطبيق ضوابط الأمن السيبراني للحوسبة السحابية (CCC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Guide to Cloud Cybersecurity Controls: Cloud Service Tenants Implementation (GCCC-CST-1:2023) is the National Cybersecurity Authority's implementation guide for its Cloud Cybersecurity Controls (CCC), published to help in-scope entities meet the compliance requirements the controls impose. Its focus is the tenant side of cloud adoption: organisations that use, or plan to use, cloud computing and hosting services.\n\nThe guide presents the CCC domain and subdomain structure (spanning cybersecurity governance, defence and resilience), explains how the guideline itself is organised, and then provides implementation guidance, with a section addressed to cloud service providers and a detailed section for cloud service tenants. It complements the Cloud Cybersecurity Controls themselves, which extend the NCA's Essential Cybersecurity Controls (ECC) baseline into cloud environments, and belongs to the NCA's series of implementation guides covering the CSCC, DCC, OSMACC, OTCC and TCC control sets.",
      "summary_ar": "دليل تطبيق ضوابط الأمن السيبراني للحوسبة السحابية الخاص بمشتركي الخدمات السحابية (GCCC-CST-1:2023) هو دليل التطبيق الصادر عن الهيئة الوطنية للأمن السيبراني لضوابط الأمن السيبراني للحوسبة السحابية (CCC)، وقد نُشر لمساعدة الجهات المشمولة على استيفاء متطلبات الالتزام التي تفرضها الضوابط. ويركّز الدليل على جانب المشترك في تبنّي الحوسبة السحابية: أي الجهات التي تستخدم خدمات الحوسبة السحابية والاستضافة أو تخطط لاستخدامها.\n\nيعرض الدليل هيكل المجالات الرئيسة والفرعية لضوابط الحوسبة السحابية، بما يشمل حوكمة الأمن السيبراني وتعزيزه وصموده، ويشرح كيفية تنظيم الدليل نفسه، ثم يقدّم إرشادات التطبيق، مع قسم موجّه إلى مقدّمي الخدمات السحابية وقسم مفصّل لمشتركي الخدمات السحابية. ويُكمّل الدليلُ ضوابطَ الأمن السيبراني للحوسبة السحابية ذاتها، التي تمدّ الحد الأدنى المقرر في الضوابط الأساسية للأمن السيبراني (ECC) إلى البيئات السحابية، ويندرج ضمن سلسلة أدلة التطبيق الصادرة عن الهيئة والتي تغطي ضوابط CSCC وDCC وOSMACC وOTCC وTCC.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-cloud-cybersecurity-controls-ccc-implementation",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "data-monetization-policy",
      "name": "Data Monetisation Policy",
      "name_ar": "سياسة تحقيق العائد من البيانات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NDMO policy on monetising government data.",
      "summary_ar": "سياسة مكتب إدارة البيانات الوطني NDMO بشأن تحقيق العائد المالي من البيانات الحكومية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/DataMonetizationPolicy.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/data-monetization-policy",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "guide-to-the-pdpl-for-controllers-and-processors",
      "name": "Guide to the PDPL for Controllers and Processors",
      "name_ar": "دليل نظام حماية البيانات الشخصية (PDPL) للمتحكمين والمعالجين",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **Guide to the Saudi Personal Data Protection Law for Controllers and Processors** (Version 1.0, December 2023) is SDAIA's plain-language companion to the PDPL (Royal Decree M/19, 9/2/1443H). It is explicitly **non-binding**: the Guidance contains no rules or obligations of its own and has no status as a legal instrument; its aim is to clarify the Law and direct organisations towards compliance.\n\nThe Guide works through the PDPL's building blocks with worked scenarios: the **material scope** (what personal data is, sensitive data, data of the deceased, and the treatment of opinions, inferences, pseudonymised and anonymised data); the **territorial scope** (what counts as processing in the Kingdom, who resides in the Kingdom, and who is a party outside it); the roles of **controllers and processors**; exclusions such as personal or family use; the grace period; SDAIA's role as Competent Authority; individuals' rights; and the data-protection principles. An appendix lists **bad data-protection practices** to avoid.\n\nWithin the atlas it sits beneath the PDPL, its Implementing Regulation and the Transfer Regulation as the primary interpretive aid for day-to-day compliance work.",
      "summary_ar": "**دليل نظام حماية البيانات الشخصية السعودي لجهات التحكم والمعالجة** (الإصدار 1.0، ديسمبر 2023) هو الدليل التوضيحي الميسّر الصادر عن سدايا لنظام حماية البيانات الشخصية (المرسوم الملكي م/19 وتاريخ 9/2/1443هـ). وهو **غير مُلزم** صراحةً: فالدليل لا يتضمن قواعد أو التزامات بذاته وليست له صفة الأداة النظامية، وغايته توضيح النظام وإرشاد المنشآت نحو الالتزام به.\n\nويتناول الدليل مكوّنات النظام عبر سيناريوهات تطبيقية: **النطاق الموضوعي** (ما البيانات الشخصية، والبيانات الحساسة، وبيانات المتوفين، ومعاملة الآراء والاستنتاجات والبيانات المستعارة والمجهولة الهوية)؛ و**النطاق الإقليمي** (ما يُعد معالجةً داخل المملكة، ومن يُعد مقيماً فيها، ومن هي الأطراف خارجها)؛ وأدوار **جهات التحكم وجهات المعالجة**؛ والاستثناءات كالاستخدام الشخصي أو العائلي؛ والفترة الانتقالية؛ ودور سدايا بوصفها الجهة المختصة؛ وحقوق الأفراد؛ ومبادئ حماية البيانات. ويجمع الملحق قائمة غير حصرية **بالممارسات الخاطئة في حماية البيانات** الواجب تجنبها.\n\nويقع الدليل داخل الأطلس أسفل نظام حماية البيانات الشخصية ولائحته التنفيذية ولائحة نقل البيانات، بوصفه الأداة التفسيرية الأساسية لأعمال الالتزام اليومية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "pdpl-law",
      "in_library": true,
      "official_url": "https://dgp.sdaia.gov.sa/wps/wcm/connect/f579bc32-fda8-47bd-bc6f-66b8cb77985c/ENG-Guide+to+the+saudi+PDP+law+for+controllersprocessors.pdf?MOD=AJPERES",
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-the-pdpl-for-controllers-and-processors",
      "date_note": "December 2023",
      "date_note_ar": "ديسمبر 2023",
      "provisions": []
    },
    {
      "slug": "guide-to-data-cybersecurity-controls-dcc-implementation",
      "name": "Guide to Data Cybersecurity Controls (DCC) Implementation",
      "name_ar": "دليل تطبيق ضوابط الأمن السيبراني للبيانات (DCC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Guide to Data Cybersecurity Controls (DCC) Implementation (GDCC-1:2023) is the National Cybersecurity Authority's public implementation guide for the Data Cybersecurity Controls, intended to help in-scope organisations put the controls into effect.\n\nIt sets out the DCC's domains and subdomains (cybersecurity governance, cybersecurity defence, and third-party and cloud computing cybersecurity), covering areas such as cybersecurity in human resources, awareness and training, identity and access management, protection of information systems and processing facilities, mobile-device security, data and information protection, cryptography, secure data disposal, cybersecurity for printers, scanners and copy machines, periodic review and audit, and third-party cybersecurity. After explaining the guideline's structure it provides implementation guidance under each domain in turn. The DCC extend the NCA's Essential Cybersecurity Controls (ECC) baseline with requirements focused on protecting data across its lifecycle, and the guide belongs to the NCA's wider series of implementation guides.",
      "summary_ar": "دليل تطبيق ضوابط الأمن السيبراني للبيانات (GDCC-1:2023) هو دليل التطبيق العام الصادر عن الهيئة الوطنية للأمن السيبراني لضوابط الأمن السيبراني للبيانات، والغرض منه مساعدة الجهات المشمولة على وضع الضوابط موضع التنفيذ.\n\nيعرض الدليل المجالات الرئيسة والفرعية للضوابط: حوكمة الأمن السيبراني، وتعزيز الأمن السيبراني، والأمن السيبراني المتعلق بالأطراف الخارجية والحوسبة السحابية، ويغطي مجالات مثل الأمن السيبراني المتعلق بالموارد البشرية، والتوعية والتدريب، وإدارة هويات الدخول والصلاحيات، وحماية أنظمة المعلومات ومرافق معالجة المعلومات، وأمن الأجهزة المحمولة، وحماية البيانات والمعلومات، والتشفير، والإتلاف الآمن للبيانات، والأمن السيبراني للطابعات والماسحات وآلات النسخ، والمراجعة والتدقيق الدوريين، والأمن السيبراني المتعلق بالأطراف الخارجية. وبعد شرح هيكل الدليل، يقدّم إرشادات التطبيق تحت كل مجال على حدة. وتمدّ ضوابط الأمن السيبراني للبيانات الحد الأدنى المقرر في الضوابط الأساسية للأمن السيبراني (ECC) بمتطلبات تركّز على حماية البيانات عبر دورة حياتها، ويندرج الدليل ضمن سلسلة أدلة التطبيق الأوسع الصادرة عن الهيئة.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-data-cybersecurity-controls-dcc-implementation",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "alignment-guide-for-the-saudi-cybersecurity-higher-educa",
      "name": "Alignment Guide for the Saudi Cybersecurity Higher Education Framework (SCyber-Edu)",
      "name_ar": "دليل المواءمة للإطار السعودي للتعليم العالي في الأمن السيبراني (SCyber-Edu)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Alignment Guide for the Saudi Cybersecurity Higher Education Framework (SCyber-Edu) is issued by the National Cybersecurity Authority (NCA) to help higher-education institutions align their cybersecurity degree programmes with SCyber-Edu-1:2020, the national framework the NCA developed in cooperation with the Ministry of Education and the Education and Training Evaluation Commission.\n\nIt applies to public and private higher-education institutions in the Kingdom offering cybersecurity degree programmes. The guide sets out the framework's objectives, explains the alignment process across programme descriptors, admission requirements and core and elective knowledge units for each degree level, and provides the alignment form with step-by-step instructions for completing it. It is read alongside the Saudi Cybersecurity Higher Education Framework itself, which defines seven programme levels, from intermediate diploma through bachelor and higher diplomas to master's and doctoral degrees, and their required knowledge units.",
      "summary_ar": "دليل المواءمة مع الإطار السعودي للتعليم العالي في الأمن السيبراني (SCyber-Edu) صادر عن الهيئة الوطنية للأمن السيبراني لمساعدة مؤسسات التعليم العالي على مواءمة برامجها الأكاديمية في الأمن السيبراني مع الإطار (SCyber-Edu-1:2020)، وهو الإطار الوطني الذي طوّرته الهيئة بالتعاون مع وزارة التعليم وهيئة تقويم التعليم والتدريب.\n\nويسري الدليل على مؤسسات التعليم العالي الحكومية والأهلية في المملكة التي تقدّم برامج أكاديمية في الأمن السيبراني. ويعرض الدليل أهداف الإطار، ويشرح عملية المواءمة عبر توصيف البرامج ومتطلبات القبول ووحدات المعرفة الأساسية والاختيارية لكل مستوى أكاديمي، ويوفر نموذج المواءمة مع خطوات تعبئته. ويُقرأ جنبًا إلى جنب مع الإطار السعودي للتعليم العالي في الأمن السيبراني نفسه، الذي يحدد سبعة مستويات للبرامج، من الدبلوم المتوسط مرورًا بالبكالوريوس والدبلومات العليا وصولًا إلى الماجستير والدكتوراه، ووحدات المعرفة المطلوبة لكل منها.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/alignment-guide-for-the-saudi-cybersecurity-higher-educa",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    }
  ],
  "updates": [
    {
      "date": "2026-08-06",
      "type": "consultation",
      "title": "SDAIA consultation on PDPL licensing and accreditation guides closes",
      "title_ar": "إغلاق استطلاع سدايا حول أدلة الترخيص والاعتماد لنظام حماية البيانات",
      "summary": "SDAIA's consultation on the three draft standards guides for the PDPL compliance-services market (accreditation-certificate standards, accreditation-activities licensing, and audit-and-inspection activities licensing) closed on 6 August 2026, after the authority publicised the audit-and-inspection guide on 21 July and convened licensing stakeholders in early August. Final versions were not yet published as of 11 August 2026.",
      "summary_ar": "أُغلق في 6 أغسطس 2026 استطلاع سدايا حول الأدلة الاسترشادية الثلاثة لسوق خدمات الالتزام بنظام حماية البيانات الشخصية (دليل معايير شهادات الاعتماد، ودليل معايير ترخيص أنشطة الاعتماد، ودليل معايير ترخيص أنشطة التدقيق والفحص) بعد أن عرّفت الهيئة بدليل التدقيق والفحص في 21 يوليو وعقدت لقاءً متخصصاً مع المعنيين بالترخيص مطلع أغسطس. ولم تُنشر النسخ النهائية حتى 11 أغسطس 2026.",
      "instrument": "pdpl-law"
    },
    {
      "date": "2026-08-05",
      "type": "consultation",
      "title": "AI Cybersecurity Guidelines consultation closes; final text awaited",
      "title_ar": "إغلاق استطلاع إرشادات الأمن السيبراني للذكاء الاصطناعي بانتظار النسخة النهائية",
      "summary": "The NCA's consultation on its draft AI Cybersecurity Guidelines (covering cybersecurity governance, defence, resilience and third-party security for AI systems, including generative and agentic AI) closed on 5 August 2026. No final version had been issued as of 11 August 2026.",
      "summary_ar": "أُغلق في 5 أغسطس 2026 استطلاع الهيئة الوطنية للأمن السيبراني حول مسودة إرشادات الأمن السيبراني للذكاء الاصطناعي، التي تغطي حوكمة الأمن السيبراني والدفاع والصمود وأمن الأطراف الثالثة لأنظمة الذكاء الاصطناعي، بما في ذلك الذكاء الاصطناعي التوليدي والوكيل. ولم تصدر النسخة النهائية حتى 11 أغسطس 2026.",
      "instrument": null
    },
    {
      "date": "2026-07-24",
      "type": "consultation",
      "title": "NCA consultation on violations and penalties schedule closes",
      "title_ar": "إغلاق استطلاع الهيئة الوطنية للأمن السيبراني حول تصنيف المخالفات والعقوبات المقابلة",
      "summary": "The National Cybersecurity Authority's public consultation on the draft Cybersecurity Violations Classification and Corresponding Penalties document closed on 24 July 2026. The final classification, the first schedule to attach graduated penalties to NCA-mandated cybersecurity requirements, had not been published as of mid-August 2026.",
      "summary_ar": "أُغلق في 24 يوليو 2026 الاستطلاع العام للهيئة الوطنية للأمن السيبراني حول مسودة وثيقة تصنيف مخالفات الأمن السيبراني والعقوبات المقابلة لها. ولم يُنشر التصنيف النهائي، وهو أول جدول يربط عقوبات متدرجة بمتطلبات الأمن السيبراني الإلزامية الصادرة عن الهيئة، حتى منتصف أغسطس 2026.",
      "instrument": null
    },
    {
      "date": "2026-07-14",
      "type": "consultation",
      "title": "NCA consults on updated Saudi Cybersecurity Higher Education Framework",
      "title_ar": "الهيئة الوطنية للأمن السيبراني تستطلع الآراء حول الإطار السعودي المحدَّث للتعليم العالي في الأمن السيبراني",
      "summary": "The National Cybersecurity Authority opened a public consultation (14 July – 14 August 2026) on an updated Saudi Cybersecurity Higher Education Framework (SCyber-Edu), which sets minimum curriculum requirements, knowledge units and professional standards for undergraduate and master's cybersecurity programmes. The framework is developed with the Ministry of Education and the Education and Training Evaluation Commission.",
      "summary_ar": "أطلقت الهيئة الوطنية للأمن السيبراني استطلاعاً عاماً (14 يوليو – 14 أغسطس 2026) حول نسخة محدَّثة من الإطار السعودي للتعليم العالي في الأمن السيبراني (SCyber-Edu)، الذي يحدد الحد الأدنى لمتطلبات المناهج ووحدات المعرفة والمعايير المهنية لبرامج البكالوريوس والماجستير في الأمن السيبراني. ويُطوَّر الإطار بالتعاون مع وزارة التعليم وهيئة تقويم التعليم والتدريب.",
      "instrument": "saudi-cybersecurity-higher-education-framework-scyber-ed"
    },
    {
      "date": "2026-07-07",
      "type": "consultation",
      "title": "SDAIA consults on standards guides for the PDPL certification and audit market",
      "title_ar": null,
      "summary": "SDAIA opened a consultation (closing 6 August 2026, as reported) on three draft standards guides implementing the March-gazetted licensing rules: standards for issuing accreditation certificates to controllers and processors, for licensing personal-data audit and inspection activities, and for licensing certificate-issuance activities. They set the operating bar for the new PDPL certification and audit market, and matter to controllers seeking certificates as transfer safeguards.",
      "summary_ar": null,
      "instrument": "pdpl-law"
    },
    {
      "date": "2026-07-05",
      "type": "consultation",
      "title": "NCA consults on AI Cybersecurity Guidelines",
      "title_ar": null,
      "summary": "The National Cybersecurity Authority opened a consultation (5 July – 5 August 2026) on draft AI Cybersecurity Guidelines, its first AI-specific instrument, setting cybersecurity governance, defence, resilience and third-party requirements for organisations deploying or planning to adopt AI in the Kingdom, explicitly covering generative and agentic AI.",
      "summary_ar": null,
      "instrument": null
    },
    {
      "date": "2026-06-29",
      "type": "other",
      "title": "SDAIA committees issue further PDPL fines and warnings",
      "title_ar": null,
      "summary": "SDAIA's violation-review committees announced a further package of decisions (fines and warnings against several entities) for direct marketing without explicit consent and failing to maintain measures enabling timely responses to data-subject requests; press reports also cited 72-hour breach-notification failures and failures to appoint required DPOs. No entity names or amounts were disclosed.",
      "summary_ar": null,
      "instrument": "pdpl-law"
    },
    {
      "date": "2026-06-24",
      "type": "consultation",
      "title": "NCA consults on cybersecurity violations and penalties schedule",
      "title_ar": null,
      "summary": "The National Cybersecurity Authority opened a public consultation (24 June – 24 July 2026) on a draft classification of violations of NCA-mandated cybersecurity requirements and a corresponding penalties schedule, exercising enforcement powers under its amended statute (Royal Decree M/117). It would create the first formal penalty taxonomy behind the ECC, NCNICC and sector controls, affecting all entities subject to them.",
      "summary_ar": null,
      "instrument": null
    },
    {
      "date": "2026-06-19",
      "type": "new",
      "title": "SDAIA issues Data Revenue Generation Policy",
      "title_ar": null,
      "summary": "SDAIA published the Data Revenue Generation Policy (dated 27 April 2026, announced 19 June 2026), setting principles for government entities, and private entities holding government-sourced data, to develop revenue-generating data products and services. Products built on personal data must preserve privacy under the PDPL; open data remains free; government-to-government sharing cannot be charged. A national registry for data-product revenue generation now appears on SDAIA's National Data Governance Platform.",
      "summary_ar": null,
      "instrument": null
    },
    {
      "date": "2026-06-08",
      "type": "consultation",
      "title": "NCA consults on national incident-reporting framework (NFCISIR-1:2026)",
      "title_ar": null,
      "summary": "The National Cybersecurity Authority consulted on the draft National Framework for Cybersecurity Information Sharing and Incident Response; the consultation closed 10 July 2026. As drafted, public and private entities would report actual or suspected incidents via the national Haseen portal, follow tiered response timeframes (2/12/48/72 hours) across five severity levels, retain incident records for 15 years, and share threat intelligence under TLP. The final framework is pending.",
      "summary_ar": null,
      "instrument": null
    },
    {
      "date": "2026-04-03",
      "type": "consultation",
      "title": "SDAIA consults on draft Responsible AI Policy",
      "title_ar": null,
      "summary": "SDAIA opened a one-month public consultation (3 April – 3 May 2026) on a draft Responsible AI Policy applying to government, private and non-profit entities and individuals developing, deploying or publishing AI in the Kingdom. It moves beyond the 2023 AI Ethics Principles toward operational governance: risk-based classification, obligations for higher-risk systems, watermarking and content tracking of AI outputs, bias mitigation and performance monitoring. The final policy had not been issued as of mid-July 2026.",
      "summary_ar": null,
      "instrument": null
    },
    {
      "date": "2026-03-06",
      "type": "new",
      "title": "PDPL audit and certification licensing rules gazetted",
      "title_ar": null,
      "summary": "Two SDAIA instruments (Decisions 5135/2 and 5316, dated 16 December 2025; gazetted in Umm Al-Qura on 6 March 2026) create the PDPL compliance-services market: licences for accreditation-certificate issuers (SAR 10m capital, at least 10 qualified assessors, 3-year term) and for personal-data audit and inspection providers, plus rules for issuing controllers and processors 2-year accreditation certificates. Certificates also serve as a cross-border transfer safeguard under the Transfer Regulation.",
      "summary_ar": null,
      "instrument": "pdpl-law"
    },
    {
      "date": "2026-01-15",
      "type": "other",
      "title": "SDAIA reports 48 PDPL enforcement decisions",
      "title_ar": "سدايا تُعلن عن 48 قراراً بإنفاذ نظام حماية البيانات",
      "summary": "SDAIA's specialised committees confirmed 48 personal-data-protection violations in the first substantive enforcement wave, mostly processing without a legal basis, unauthorised disclosure, and marketing without consent. Decisions were reported in aggregate; no entities were named.",
      "summary_ar": "أكدت لجان سدايا المختصة 48 مخالفة لنظام حماية البيانات الشخصية في أول موجة إنفاذ جوهرية، معظمها معالجة دون أساس نظامي، وإفصاح غير مصرّح، وتسويق دون موافقة. ونُشرت القرارات بشكل إجمالي دون تسمية الجهات.",
      "instrument": "pdpl-law"
    },
    {
      "date": "2025-12-30",
      "type": "other",
      "title": "National Data Index: third measurement cycle launched",
      "title_ar": "المؤشر الوطني للبيانات: إطلاق الدورة الثالثة للقياس",
      "summary": "SDAIA launched the third NDI cycle, expanding measurement to 214 government entities (about +110%). The index scores data-management maturity, compliance and operational excellence via the National Data Governance Platform.",
      "summary_ar": "أطلقت سدايا الدورة الثالثة للمؤشر الوطني للبيانات، موسِّعةً القياس إلى 214 جهة حكومية (بزيادة نحو 110%). ويقيس المؤشر نضج إدارة البيانات والالتزام والتميّز التشغيلي عبر منصة حوكمة البيانات الوطنية.",
      "instrument": "ndi"
    },
    {
      "date": "2025-12-28",
      "type": "new",
      "title": "NCA issues cybersecurity controls for non-CNI private sector (NCNICC-1:2025)",
      "title_ar": null,
      "summary": "The National Cybersecurity Authority extended mandatory ECC-derived cybersecurity controls to all private-sector entities that are not critical-infrastructure operators, its largest scope expansion since the ECC. Category A entities (over 250 staff or SAR 200m revenue) face 65 controls across three domains; Category B (SMEs) face 26 controls. Compliance is continuous under Article 10(3) of the NCA statute, with no stated grace period.",
      "summary_ar": null,
      "instrument": "ncnicc"
    },
    {
      "date": "2025-12-02",
      "type": "new",
      "title": "SDAIA issues General Rules for Secondary Use of Data",
      "title_ar": null,
      "summary": "Approved by SDAIA Board Decision 22-1 (11/6/1447H) and publicised in January 2026, the General Rules govern reusing data, including personal data, beyond its original collection purpose, for research, development and public-interest uses. They cover government-to-government, government-to-private and private-to-government requests under six principles; any reuse of personal data must comply with the PDPL.",
      "summary_ar": null,
      "instrument": null
    },
    {
      "date": "2025-05-27",
      "type": "consultation",
      "title": "Third public consultation on Implementing Regulation amendments",
      "title_ar": "الاستطلاع العام الثالث لتعديلات اللائحة التنفيذية",
      "summary": "SDAIA's third public consultation (27 Apr – 27 May 2025) proposed to simplify the Implementing Regulation: folding the DPO-appointment and controller-registration rules into it, simplifying the RoPA requirement, and adding a plain-language privacy-notice clause. Not yet enacted as of mid-2026.",
      "summary_ar": "اقترح الاستطلاع العام الثالث لسدايا (27 أبريل – 27 مايو 2025) تبسيط اللائحة التنفيذية: بدمج قواعد تعيين مسؤول حماية البيانات وتسجيل جهات التحكم فيها، وتبسيط متطلب سجل المعالجة، وإضافة بند لإشعار الخصوصية بلغة واضحة. ولم تُعتمد بعدُ حتى منتصف 2026.",
      "instrument": "implementing-regulation"
    },
    {
      "date": "2025-04-23",
      "type": "consultation",
      "title": "Consultation on rules for data-protection service providers",
      "title_ar": "استطلاع حول قواعد مزوّدي خدمات حماية البيانات",
      "summary": "A parallel SDAIA consultation (closed May 2025) proposed to license firms providing PDPL consultancy, compliance technology and training, a separate instrument from the Implementing Regulation amendments.",
      "summary_ar": "اقترح استطلاع موازٍ لسدايا (أُغلق في مايو 2025) ترخيص الشركات التي تقدّم الاستشارات وتقنيات الامتثال والتدريب في مجال حماية البيانات، وهو أداة منفصلة عن تعديلات اللائحة التنفيذية.",
      "instrument": null
    },
    {
      "date": "2025-02-25",
      "type": "guidance",
      "title": "Guideline on cross-border transfer risk assessment",
      "title_ar": "دليل تقييم مخاطر النقل عبر الحدود",
      "summary": "SDAIA published a non-binding, four-phase methodology for assessing the risks of transferring personal data outside the Kingdom, with a companion risk-assessment tool on the National Data Governance Platform.",
      "summary_ar": "أصدرت سدايا منهجية غير ملزمة من أربع مراحل لتقييم مخاطر نقل البيانات الشخصية خارج المملكة، مع أداة مصاحبة لتقييم المخاطر على منصة حوكمة البيانات الوطنية.",
      "instrument": "transfer-regulation"
    }
  ]
}