{
  "meta": {
    "source": "https://www.wadiraksa.com",
    "license": "CC BY 4.0 — attribute Wadira (https://www.wadiraksa.com)",
    "generated_at": "2026-07-27T23:58:32.877Z",
    "data_updated_at": "2026-07-27",
    "counts": {
      "frameworks": 8,
      "authorities": 6,
      "instruments": 86,
      "provisions": 98
    }
  },
  "tiers": [
    {
      "tier": 0,
      "label": "Foundational — Sharia & Basic Law",
      "label_ar": "تأسيسي — الشريعة والنظام الأساسي للحكم"
    },
    {
      "tier": 1,
      "label": "Primary law — niẓām (Royal Decree, M/…)",
      "label_ar": "التشريع الأساسي — نظام (مرسوم ملكي، م/…)"
    },
    {
      "tier": 2,
      "label": "Cabinet instruments — CoM Resolution",
      "label_ar": "أدوات مجلس الوزراء — قرار مجلس الوزراء"
    },
    {
      "tier": 3,
      "label": "Implementing & executive regulation",
      "label_ar": "اللائحة التنفيذية واللوائح التنظيمية"
    },
    {
      "tier": 4,
      "label": "Rules, controls & standards",
      "label_ar": "القواعد والضوابط والمعايير"
    },
    {
      "tier": 5,
      "label": "Guidelines & circulars",
      "label_ar": "الإرشادات والتعاميم"
    }
  ],
  "frameworks": [
    {
      "slug": "constitutional",
      "name": "Constitutional foundation",
      "name_ar": "الأساس الدستوري",
      "description": "The Basic Law of Governance and the foundational instruments the regime rests on.",
      "description_ar": "النظام الأساسي للحكم والأدوات التأسيسية التي يقوم عليها المنظومة."
    },
    {
      "slug": "pdpl",
      "name": "Personal Data Protection (PDPL)",
      "name_ar": "حماية البيانات الشخصية (PDPL)",
      "description": "Saudi Arabia's data-protection regime — the PDPL, its Implementing Regulation, and the rules and guidelines beneath them.",
      "description_ar": "منظومة حماية البيانات في المملكة العربية السعودية — نظام حماية البيانات الشخصية (PDPL) ولائحته التنفيذية والقواعد والإرشادات المنبثقة عنها."
    },
    {
      "slug": "data-management-and-governance",
      "name": "Data Management & Governance",
      "name_ar": "إدارة البيانات وحوكمتها",
      "description": "Saudi Arabia's national data-management and governance regime — the NDMO data-management standards and domains, the national data policies on classification, sharing, open data, freedom of information and monetisation, and the National Data Index.",
      "description_ar": "منظومة إدارة البيانات وحوكمتها الوطنية في المملكة العربية السعودية — معايير ومجالات إدارة البيانات الصادرة عن المكتب الوطني لإدارة البيانات (NDMO)، والسياسات الوطنية للبيانات المتعلقة بالتصنيف والمشاركة والبيانات المفتوحة وحرية المعلومات وتوليد الإيرادات، والمؤشر الوطني للبيانات."
    },
    {
      "slug": "cyber",
      "name": "Cybersecurity",
      "name_ar": "الأمن السيبراني",
      "description": "The Anti-Cyber Crime Law and the National Cybersecurity Authority's controls and frameworks (ECC, CCC and more).",
      "description_ar": "نظام مكافحة الجرائم المعلوماتية وضوابط الهيئة الوطنية للأمن السيبراني وأطرها (الضوابط الأساسية للأمن السيبراني ECC وضوابط الأمن السيبراني للحوسبة السحابية CCC وغيرها)."
    },
    {
      "slug": "financial",
      "name": "Financial services",
      "name_ar": "الخدمات المالية",
      "description": "SAMA and CMA laws, frameworks and rules governing banks and capital-market institutions.",
      "description_ar": "أنظمة البنك المركزي السعودي (SAMA) وهيئة السوق المالية (CMA) وأطرهما وقواعدهما التي تحكم البنوك ومؤسسات السوق المالية."
    },
    {
      "slug": "ai",
      "name": "Artificial Intelligence",
      "name_ar": "الذكاء الاصطناعي",
      "description": "SDAIA's AI laws, frameworks and guidelines, including generative-AI and deepfakes guidance.",
      "description_ar": "أنظمة الذكاء الاصطناعي وأطره وإرشاداته الصادرة عن الهيئة السعودية للبيانات والذكاء الاصطناعي (SDAIA)، بما في ذلك إرشادات الذكاء الاصطناعي التوليدي والتزييف العميق."
    },
    {
      "slug": "telecom",
      "name": "Telecommunications & Cloud",
      "name_ar": "الاتصالات والحوسبة السحابية",
      "description": "CST's cloud-computing and telecom regulatory framework and licensing.",
      "description_ar": "الإطار التنظيمي للحوسبة السحابية والاتصالات والترخيص الصادر عن هيئة الاتصالات والفضاء والتقنية (CST)."
    },
    {
      "slug": "health",
      "name": "Health data",
      "name_ar": "البيانات الصحية",
      "description": "Health-sector data-protection rules and standards.",
      "description_ar": "قواعد ومعايير حماية البيانات في القطاع الصحي."
    }
  ],
  "authorities": [
    {
      "slug": "sdaia",
      "acronym": "SDAIA / NDMO",
      "name": "Saudi Data & AI Authority / National Data Management Office",
      "name_ar": "الهيئة السعودية للبيانات والذكاء الاصطناعي / مكتب إدارة البيانات الوطنية",
      "short_desc": "National authority for data & AI; the PDPL regulator and — via the NDMO — government data governance.",
      "short_desc_ar": "الجهة الوطنية للبيانات والذكاء الاصطناعي؛ الجهة المنظِّمة لنظام حماية البيانات الشخصية (PDPL)، ومن خلال مكتب إدارة البيانات الوطنية (NDMO)، حوكمة البيانات الحكومية."
    },
    {
      "slug": "nca",
      "acronym": "NCA",
      "name": "National Cybersecurity Authority",
      "name_ar": "الهيئة الوطنية للأمن السيبراني",
      "short_desc": "National cybersecurity regulator; ECC/CCC and related controls across government, CNI and cloud.",
      "short_desc_ar": "الجهة الوطنية المنظِّمة للأمن السيبراني؛ الضوابط الأساسية للأمن السيبراني (ECC) وضوابط الأمن السيبراني للحوسبة السحابية (CCC) وما يتصل بها من ضوابط تشمل الجهات الحكومية والبنى التحتية الوطنية الحساسة والحوسبة السحابية."
    },
    {
      "slug": "sama",
      "acronym": "SAMA",
      "name": "Saudi Central Bank",
      "name_ar": "البنك المركزي السعودي",
      "short_desc": "Central bank; its Cyber Security Framework is mandatory for licensed financial institutions.",
      "short_desc_ar": "البنك المركزي؛ إطار الأمن السيبراني الصادر عنه إلزامي للمؤسسات المالية المرخّصة."
    },
    {
      "slug": "cst",
      "acronym": "CST",
      "name": "Communications, Space & Technology Commission",
      "name_ar": "هيئة الاتصالات والفضاء والتقنية",
      "short_desc": "Telecom/ICT, cloud and space regulator; CSP tiers and government data localisation.",
      "short_desc_ar": "الجهة المنظِّمة لقطاعات الاتصالات وتقنية المعلومات والحوسبة السحابية والفضاء؛ تصنيف مزوّدي الخدمات السحابية وتوطين البيانات الحكومية."
    },
    {
      "slug": "cma",
      "acronym": "CMA",
      "name": "Capital Market Authority",
      "name_ar": "هيئة السوق المالية",
      "short_desc": "Capital market regulator; cybersecurity guidelines for Capital Market Institutions (~188), not issuers.",
      "short_desc_ar": "الجهة المنظِّمة للسوق المالية؛ إرشادات الأمن السيبراني لمؤسسات السوق المالية (نحو 188 مؤسسة)، وليس الجهات المُصدِرة."
    },
    {
      "slug": "moh",
      "acronym": "MOH",
      "name": "Ministry of Health",
      "name_ar": "وزارة الصحة",
      "short_desc": "Health regulator; health data is PDPL-sensitive, with HIE policies and health data rules.",
      "short_desc_ar": "الجهة المنظِّمة لقطاع الصحة؛ البيانات الصحية بيانات حساسة بموجب نظام حماية البيانات الشخصية (PDPL)، مع سياسات تبادل المعلومات الصحية وقواعد البيانات الصحية."
    }
  ],
  "instruments": [
    {
      "slug": "basic-law-governance",
      "name": "Basic Law of Governance (Arts 37 & 40)",
      "name_ar": "النظام الأساسي للحكم (المادتان 37 و40)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Basic Law of Governance — Articles 37 (sanctity of the home) and 40 (privacy of communications) anchor the privacy framework.",
      "summary_ar": "النظام الأساسي للحكم — تُرسي المادتان 37 (حرمة المساكن) و40 (سرّية المراسلات) ركيزة إطار الخصوصية.",
      "type": "Law",
      "tier": 0,
      "legal_status": "Foundational",
      "framework": "constitutional",
      "authority": null,
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/basic-law-governance",
      "date_note": "Royal Order A/90, 1992",
      "date_note_ar": "الأمر الملكي أ/90، 1992",
      "provisions": []
    },
    {
      "slug": "sharia",
      "name": "Sharia (Qur'an & Sunnah)",
      "name_ar": "الشريعة الإسلامية (القرآن والسنة)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Sharia principles — including tajassus (prohibition on spying), satr (concealment), amanah (trust) and the sanctity of the home — form the backdrop to privacy norms.",
      "summary_ar": "مبادئ الشريعة الإسلامية — ومنها التجسّس (النهي عن التجسّس) والستر والأمانة وحرمة المسكن — تشكّل الخلفية التي تستند إليها معايير الخصوصية.",
      "type": "Framework",
      "tier": 0,
      "legal_status": "Foundational",
      "framework": "constitutional",
      "authority": null,
      "parent": null,
      "in_library": false,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/sharia",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "global-ai-hub-law",
      "name": "Global AI Hub Law",
      "name_ar": "نظام المركز العالمي للذكاء الاصطناعي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "A draft law to position Saudi Arabia as a global AI hub, issued by the Communications, Space & Technology Commission (CST) for public consultation on 14 April 2025. It remains a draft as of mid-2026; the competent authority is to be designated by the Council of Ministers.",
      "summary_ar": "مشروع نظام يهدف إلى ترسيخ مكانة المملكة العربية السعودية بوصفها مركزًا عالميًا للذكاء الاصطناعي، طرحته هيئة الاتصالات والفضاء والتقنية (CST) للاستطلاع العام في 14 أبريل 2025. ولا يزال مشروعًا حتى منتصف عام 2026، على أن يُحدِّد مجلس الوزراء الجهة المختصة.",
      "type": "Law",
      "tier": 1,
      "legal_status": "Draft",
      "framework": "ai",
      "authority": "CST",
      "parent": null,
      "in_library": false,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/global-ai-hub-law",
      "date_note": "Public consultation closed 14 May 2025 — not enacted; no public text available.",
      "date_note_ar": "أُغلقت المشاورة العامة في 14 مايو 2025 — لم يُسَنّ بعد؛ لا يتوفر نص علني.",
      "provisions": []
    },
    {
      "slug": "anti-cyber-crime-law",
      "name": "Anti-Cyber Crime Law",
      "name_ar": "نظام مكافحة الجرائم المعلوماتية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Anti-Cyber Crime Law (M/17, 2007) — Articles 3 & 6 are central to interception/surveillance offences. Applies to all.",
      "summary_ar": "نظام مكافحة الجرائم المعلوماتية (M/17، 2007) — تُعدّ المادتان 3 و6 محوريتين في جرائم الاعتراض/المراقبة. وينطبق على الجميع.",
      "type": "Law",
      "tier": 1,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/anti-cyber-crime-law",
      "date_note": "Royal Decree M/17, 2007",
      "date_note_ar": "مرسوم ملكي م/17، 2007",
      "provisions": []
    },
    {
      "slug": "the-capital-market-law",
      "name": "The Capital Market Law",
      "name_ar": "نظام السوق المالية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Law",
      "tier": 1,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "CMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/the-capital-market-law",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "pdpl-law",
      "name": "Personal Data Protection Law (PDPL)",
      "name_ar": "نظام حماية البيانات الشخصية (PDPL)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Personal Data Protection Law (PDPL) is Saudi Arabia's first comprehensive data-protection statute — issued by Royal Decree M/19 (9/2/1443H, 16 September 2021), published in the Umm al-Qura Official Gazette on 24 September 2021, amended by Royal Decree M/148 (27 March 2023), and in force since 14 September 2023, with SDAIA's compliance grace period ending 14 September 2024. The Saudi Data & Artificial Intelligence Authority (SDAIA) supervises implementation as the competent authority (Art. 30).\n\n**Who it applies to.** The Law covers any processing of personal data in the Kingdom and — notably — processing of Saudi residents' data by parties outside the Kingdom (Art. 2). It extends to data of the deceased where it could identify them or a family member; purely personal or family use is excluded.\n\n**How it regulates.** Processing rests on consent by default (Art. 5), with exceptions including the data subject's actual interest, another law or prior agreement, public-entity security or judicial requirements, and the controller's legitimate interest for non-sensitive data (Arts. 6, 10, 15). Data subjects can be informed, access, obtain a copy, correct and destroy their data (Art. 4). Controllers must publish a privacy policy (Art. 12), verify accuracy (Art. 14), secure data (Art. 19), notify breaches (Art. 20 — 72 hours to SDAIA under the Implementing Regulation), conduct impact assessments (Art. 22) and keep records of processing (Art. 31). Cross-border transfers are permitted for defined purposes subject to safeguards (Art. 29, detailed in the Transfer Regulation).\n\n**Penalties.** Disclosing sensitive data with intent to harm or for personal gain is a criminal offence — up to two years' imprisonment and/or a SAR 3,000,000 fine, prosecuted by the Public Prosecution (Art. 35). Any other violation draws a warning or a fine up to SAR 5,000,000, doubled for repeat violations, imposed by SDAIA violation committees with appeal to the competent court (Art. 36). Courts may order confiscation and publication of judgments (Art. 38), and injured individuals may claim compensation (Art. 40).\n\n## Frequently asked questions\n\n**Does the Saudi PDPL apply to companies outside Saudi Arabia?**\n\nYes. Article 2 extends the Law to any processing of the personal data of individuals residing in the Kingdom by parties outside it, and Article 33 directs the competent authority to set mechanisms for monitoring and enforcing compliance by controllers and processors abroad.\n\n**Is consent always required to process personal data?**\n\nNo. Consent is the default legal basis (Art. 5), but Articles 6, 10 and 15 permit processing without it — including for the data subject's actual interest where contact is impossible or difficult, under another law or a prior agreement with the data subject, for public-entity security or judicial purposes, and for the controller's legitimate interest provided no sensitive data is processed.\n\n**What are the penalties for violating the PDPL?**\n\nUnlawful disclosure of sensitive data with intent to harm or for personal benefit carries up to two years' imprisonment and/or SAR 3 million (Art. 35). Other violations carry a warning or a fine up to SAR 5 million, doubled for repeat violations (Art. 36), plus possible confiscation and publication of the judgment (Art. 38) and civil compensation (Art. 40).\n\n**When did the PDPL come into force?**\n\nThe Law took effect on 14 September 2023 — 720 days after Official Gazette publication (Art. 43) — and SDAIA's transition period for full compliance ended on 14 September 2024. The Implementing Regulation accompanied it, and the Transfer Regulation was reissued as version 2.0 in September 2024.",
      "summary_ar": "يُعد نظام حماية البيانات الشخصية أول نظام شامل لحماية البيانات في المملكة العربية السعودية — فقد صدر بالمرسوم الملكي رقم (م/19) (9/2/1443هـ، 16 سبتمبر 2021)، ونُشر في جريدة أم القرى الرسمية في 24 سبتمبر 2021، وعُدِّل بالمرسوم الملكي رقم (م/148) بتاريخ 27 مارس 2023، وأصبح نافذًا اعتبارًا من 14 سبتمبر 2023، مع انتهاء المهلة التصحيحية للامتثال التي منحتها سدايا في 14 سبتمبر 2024. وتتولى الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا) الإشراف على تنفيذ النظام بوصفها الجهة المختصة (المادة (30)).\n\n**نطاق التطبيق.** يسري النظام على أي معالجة للبيانات الشخصية تجري داخل المملكة، كما يسري — وهو أمر جدير بالملاحظة — على معالجة البيانات الشخصية للمقيمين في المملكة من قِبل جهات خارج المملكة (المادة (2)). ويمتد النظام ليشمل بيانات المتوفين إذا كان من شأنها أن تؤدي إلى التعرف عليهم أو على أحد أفراد أسرهم؛ ويُستثنى من نطاقه الاستخدام الشخصي أو العائلي المحض.\n\n**كيفية التنظيم.** تقوم المعالجة على الموافقة بوصفها الأصل العام (المادة (5))، مع استثناءات تشمل تحقيق مصلحة فعلية لصاحب البيانات الشخصية، أو الاستناد إلى نظام آخر أو اتفاق سابق، أو المتطلبات الأمنية أو القضائية للجهات العامة، أو المصلحة المشروعة لجهة التحكم فيما لا يتصل بالبيانات الحساسة (المواد (6) و(10) و(15)). ولصاحب البيانات الشخصية الحق في العلم بمعالجة بياناته، والاطلاع عليها، والحصول على نسخة منها، وتصحيحها، وإتلافها (المادة (4)). ويجب على جهة التحكم نشر سياسة الخصوصية (المادة (12))، والتحقق من دقة البيانات (المادة (14))، وحماية البيانات (المادة (19))، والإشعار عن حوادث تسرب البيانات (المادة (20) — خلال (72) ساعة إلى سدايا بموجب اللائحة التنفيذية)، وإجراء تقييم الأثر (المادة (22))، والاحتفاظ بسجلات أنشطة المعالجة (المادة (31)). ويجوز نقل البيانات إلى خارج المملكة لأغراض محددة مع مراعاة الضمانات المقررة (المادة (29)، وتفصّلها لائحة نقل البيانات الشخصية إلى خارج المملكة).\n\n**العقوبات.** يُعد إفشاء البيانات الحساسة بقصد الإضرار بصاحبها أو بقصد تحقيق منفعة شخصية جريمة جنائية — عقوبتها السجن مدة لا تزيد على سنتين وغرامة لا تزيد على (3,000,000) ريال أو إحدى هاتين العقوبتين، وتتولى النيابة العامة الادعاء في شأنها (المادة (35)). وتستوجب أي مخالفة أخرى الإنذار أو غرامة لا تزيد على (5,000,000) ريال، تُضاعف في حال تكرار المخالفة، وتوقعها لجان النظر في المخالفات لدى سدايا مع جواز التظلم أمام المحكمة المختصة (المادة (36)). ويجوز للمحكمة الحكم بالمصادرة ونشر الأحكام (المادة (38))، ولمن لحقه ضرر المطالبة بالتعويض (المادة (40)).\n\n## الأسئلة الشائعة\n\n**هل يسري نظام حماية البيانات الشخصية السعودي على الشركات خارج المملكة العربية السعودية؟**\n\nنعم. تمد المادة (2) نطاق سريان النظام ليشمل أي معالجة للبيانات الشخصية الخاصة بالأفراد المقيمين في المملكة من قِبل جهات خارجها، وتقضي المادة (33) بأن تضع الجهة المختصة آليات لمراقبة امتثال جهات التحكم وجهات المعالجة خارج المملكة وإنفاذ ذلك الامتثال.\n\n**هل تُشترط الموافقة دائمًا لمعالجة البيانات الشخصية؟**\n\nلا. الموافقة هي الأساس النظامي الأصل للمعالجة (المادة (5))، غير أن المواد (6) و(10) و(15) تجيز المعالجة من دونها — بما في ذلك تحقيق مصلحة فعلية لصاحب البيانات الشخصية متى كان الاتصال به مستحيلًا أو صعبًا، أو الاستناد إلى نظام آخر أو اتفاق سابق مع صاحب البيانات الشخصية، أو الأغراض الأمنية أو القضائية للجهات العامة، أو تحقيق المصلحة المشروعة لجهة التحكم شريطة عدم معالجة أي بيانات حساسة.\n\n**ما العقوبات المترتبة على مخالفة نظام حماية البيانات الشخصية؟**\n\nيعاقَب على الإفشاء غير المشروع للبيانات الحساسة بقصد الإضرار أو تحقيق منفعة شخصية بالسجن مدة لا تزيد على سنتين وغرامة لا تزيد على (3,000,000) ريال أو بإحدى هاتين العقوبتين (المادة (35)). وتستوجب المخالفات الأخرى الإنذار أو غرامة لا تزيد على (5,000,000) ريال تُضاعف في حال تكرار المخالفة (المادة (36))، إضافة إلى إمكانية الحكم بالمصادرة ونشر الحكم (المادة (38)) والتعويض المدني (المادة (40)).\n\n**متى دخل نظام حماية البيانات الشخصية حيز النفاذ؟**\n\nدخل النظام حيز النفاذ في 14 سبتمبر 2023 — أي بعد (720) يومًا من نشره في الجريدة الرسمية (المادة (43)) — وانتهت الفترة الانتقالية التي حددتها سدايا للامتثال الكامل في 14 سبتمبر 2024. وقد صاحبت النظامَ اللائحةُ التنفيذية، وأُعيد إصدار لائحة نقل البيانات الشخصية إلى خارج المملكة بالإصدار 2.0 في سبتمبر 2024.",
      "type": "Law",
      "tier": 1,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/PersonalDataProtectionLaw.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/pdpl-law",
      "date_note": "M/19 (2021), amended M/148 (2023); in force 14 Sep 2023",
      "date_note_ar": "م/19 (2021)، المعدّل م/148 (2023)؛ ساري المفعول في 14 سبتمبر 2023",
      "provisions": [
        {
          "kind": "article",
          "code": "Art. 1",
          "label": "Definitions",
          "label_ar": "التعريفات",
          "summary": "Definitional article setting out nineteen terms used throughout the Law, including Personal Data, Processing, Collection, Disclosure, Transfer, Sensitive Data, Genetic Data, Health Data, Credit Data, Data Subject, Public Entity, Controller, Processor and the Competent Authority, whose meanings apply unless the context requires otherwise.",
          "summary_ar": "مادة تعريفية تحدد تسعة عشر مصطلحًا مستخدمًا في النظام، منها البيانات الشخصية والمعالجة والجمع والإفصاح والنقل والبيانات الحساسة والبيانات الوراثية والبيانات الصحية والبيانات الائتمانية وصاحب البيانات الشخصية والجهة العامة وجهة التحكم وجهة المعالجة والجهة المختصة، وتسري هذه المعاني ما لم يقتضِ السياق خلاف ذلك.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 2",
          "label": "Scope of Application",
          "label_ar": "نطاق سريان النظام",
          "summary": "Defines the Law's scope: it applies to any Processing of Personal Data in the Kingdom, including Processing of residents' data by parties outside the Kingdom, and to deceased persons' data if it would identify them or a family member. Purely personal or family use is excluded unless published or disclosed; the Regulations define such use.",
          "summary_ar": "تحدد نطاق سريان النظام؛ إذ يسري على أي معالجة للبيانات الشخصية تتم في المملكة بأي وسيلة، بما في ذلك معالجة بيانات المقيمين فيها من أي جهة خارج المملكة، ويشمل بيانات المتوفين إذا كانت تؤدي إلى تحديد هويتهم أو هوية أحد أفراد أسرهم تحديدًا. ويُستثنى الاستخدام الشخصي أو العائلي ما لم تُنشر البيانات أو يُفصح عنها للغير، وتحدد اللوائح هذا الاستخدام.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 3",
          "label": "Relationship With Other Laws",
          "label_ar": "العلاقة بالأنظمة الأخرى",
          "summary": "States that the Law's provisions and procedures do not prejudice any provision that grants a right to the Data Subject or confers better protection of Personal Data under any other law or an international agreement to which the Kingdom is a party.",
          "summary_ar": "تنص على أن ما تضمنه النظام من أحكام وإجراءات لا يخل بأي حكم يمنح صاحب البيانات الشخصية حقًا أو يقرر حماية أفضل للبيانات الشخصية بموجب أي نظام آخر أو اتفاقية دولية تكون المملكة طرفًا فيها.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 5",
          "label": "Consent and Withdrawal",
          "label_ar": "الموافقة وسحبها",
          "summary": "Prohibits Processing Personal Data or changing the Processing purpose without the Data Subject's consent, except in cases stated in the Law. The Regulations set consent conditions, cases requiring explicit consent, and legal-guardian consent where capacity is lacking. Consent may be withdrawn at any time, subject to controls in the Regulations.",
          "summary_ar": "تحظر معالجة البيانات الشخصية أو تغيير الغرض من معالجتها دون موافقة صاحبها إلا في الحالات التي نص عليها النظام. وتحدد اللوائح شروط الموافقة والحالات التي يجب أن تكون فيها صريحة والأحكام المتعلقة بموافقة الولي إذا كان صاحب البيانات فاقد الأهلية أو ناقصها. ولصاحب البيانات سحب موافقته في أي وقت وفق الضوابط التي تحددها اللوائح.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 6",
          "label": "Exceptions to Consent Requirement",
          "label_ar": "حالات الاستثناء من الموافقة",
          "summary": "Lists four cases where Processing does not require consent: it serves the Data Subject's actual interests and contacting them is impossible or difficult; it is pursuant to another law or a prior agreement with the Data Subject; a Public Entity requires it for security or judicial purposes; or the Controller's legitimate interest, excluding Sensitive Data.",
          "summary_ar": "تعدد أربع حالات لا تخضع فيها المعالجة للموافقة: إذا حققت مصلحة فعلية لصاحب البيانات وتعذر الاتصال به أو صعب؛ أو كانت بموجب نظام آخر أو تنفيذًا لاتفاق سابق يكون طرفًا فيه؛ أو كانت جهة التحكم جهة عامة وتطلبتها أغراض أمنية أو متطلبات قضائية؛ أو كانت لازمة لمصلحة مشروعة لجهة التحكم دون معالجة بيانات حساسة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 7",
          "label": "Consent Not a Service Condition",
          "label_ar": "عدم اشتراط الموافقة لتقديم الخدمة",
          "summary": "Provides that consent to Processing may not be made a condition for providing a service or benefit, unless the service or benefit is directly related to the Personal Data Processing for which the consent is given.",
          "summary_ar": "تقضي بأنه لا يجوز أن تكون الموافقة على المعالجة شرطًا لتقديم خدمة أو الحصول على مزية، ما لم تكن الخدمة أو المزية مرتبطة ارتباطًا مباشرًا بمعالجة البيانات الشخصية التي تُمنح الموافقة من أجلها.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 4",
          "label": "Data Subject Rights",
          "label_ar": "حقوق صاحب البيانات",
          "summary": "The data subject's rights: to be informed, to access their data, to obtain a copy in a readable format, to request correction/completion/update, and to request destruction.",
          "summary_ar": "حقوق صاحب البيانات: الحق في العلم، والوصول إلى بياناته، والحصول على نسخة بصيغة مقروءة، وطلب تصحيحها أو إكمالها أو تحديثها، وطلب إتلافها.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 8",
          "label": "Processor Selection and Oversight",
          "label_ar": "اختيار جهة المعالجة والرقابة عليها",
          "summary": "Requires the Controller to select only Processors that provide sufficient guarantees to implement the Law and Regulations, and to monitor their compliance. The Controller remains responsible towards the Data Subject and the Competent Authority. The Regulations govern related matters, including subsequent contracts concluded by the Processor.",
          "summary_ar": "توجب على جهة التحكم ألا تختار إلا جهات معالجة تقدم الضمانات اللازمة لتطبيق أحكام النظام واللوائح، وأن تراقب التزامها بها. وتظل جهة التحكم مسؤولة تجاه صاحب البيانات الشخصية والجهة المختصة. وتحدد اللوائح الأحكام اللازمة في هذا الشأن، بما فيها الأحكام المتعلقة بالعقود اللاحقة التي تبرمها جهة المعالجة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 20",
          "label": "Breach Notification (duty)",
          "label_ar": "الإبلاغ عن الانتهاك (الالتزام)",
          "summary": "Imposes the duty to notify the Competent Authority and affected data subjects of a personal-data breach. The Law sets no fixed deadline — the 72-hour timeline is set by IR Art. 24.",
          "summary_ar": "يفرض واجب إشعار الجهة المختصة وأصحاب البيانات المتأثرين بانتهاك البيانات الشخصية. ولا يحدد النظام مهلة؛ ومهلة الـ72 ساعة مقررة في المادة 24 من اللائحة التنفيذية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 9",
          "label": "Restrictions on Access Right",
          "label_ar": "قيود حق الاطلاع",
          "summary": "Permits the Controller to set time frames for exercising the right of access and to limit that right where necessary to protect the Data Subject or others from harm, or where a Public Entity requires it for security, legal or judicial reasons. Access must be prevented in the situations listed in Article 16.",
          "summary_ar": "تجيز لجهة التحكم وضع أطر زمنية لممارسة حق الاطلاع على البيانات الشخصية وتقييد هذا الحق إذا كان ذلك لازمًا لحماية صاحب البيانات أو غيره من أي ضرر، أو إذا كانت جهة التحكم جهة عامة واقتضت ذلك أغراض أمنية أو نظام آخر أو متطلبات قضائية. ويجب منع الاطلاع في الحالات الواردة في المادة السادسة عشرة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 22",
          "label": "Impact Assessment",
          "label_ar": "تقييم الأثر",
          "summary": "The Controller shall conduct an impact assessment for any product or service involving personal-data processing, in accordance with the Regulations (detailed in IR Art. 25).",
          "summary_ar": "تُجري جهة التحكم تقييماً للأثر لأي منتج أو خدمة تتضمن معالجة بيانات شخصية، وفقاً للائحة (مفصَّلة في المادة 25 من اللائحة التنفيذية).",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 31",
          "label": "Records of Processing (Law)",
          "label_ar": "سجلات المعالجة (النظام)",
          "summary": "Lists the information that a controller's records of processing activities must contain (elaborated by IR Art. 33).",
          "summary_ar": "يحدد المعلومات التي يجب أن يتضمنها سجل أنشطة المعالجة لدى جهة التحكم (تفصّلها المادة 33 من اللائحة التنفيذية).",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 10",
          "label": "Collection Sources and Purpose Limits",
          "label_ar": "مصادر الجمع وحدود الغرض",
          "summary": "Requires collecting Personal Data directly from the Data Subject and Processing it only for the Collection purpose, subject to seven exceptions: consent; publicly available data; Public Entity requirements; avoiding harm to the Data Subject or their vital interests; protecting public health, safety or lives; non-identifying storage; and the Controller's legitimate interests excluding Sensitive Data.",
          "summary_ar": "توجب جمع البيانات الشخصية من صاحبها مباشرة وقصر معالجتها على الغرض الذي جُمعت من أجله، مع سبع حالات استثنائية: الموافقة؛ والبيانات المتاحة للعموم؛ ومتطلبات الجهات العامة؛ وتفادي الإضرار بصاحب البيانات أو المساس بمصالحه الحيوية؛ وحماية الصحة العامة أو السلامة العامة أو حياة الأفراد؛ والحفظ بصورة لا تحدد الهوية؛ والمصلحة المشروعة لجهة التحكم دون معالجة بيانات حساسة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 11",
          "label": "Lawful Collection and Data Minimization",
          "label_ar": "ضوابط جمع البيانات",
          "summary": "Sets Collection standards: the purpose must relate directly to the Controller's purposes and comply with law; methods must be lawful, appropriate, direct, clear, secure and free of deception, misleading or extortion; content must be limited to the minimum necessary; and Collection must cease and collected data be destroyed when no longer needed.",
          "summary_ar": "تضع معايير للجمع: أن يكون الغرض مرتبطًا ارتباطًا مباشرًا بأغراض جهة التحكم وغير مخالف لأي نص نظامي؛ وأن تكون أساليب الجمع ووسائله نظامية ومناسبة ومباشرة وواضحة وآمنة وخالية من الخداع أو التضليل أو الابتزاز؛ وأن يقتصر المحتوى على الحد الأدنى اللازم لتحقيق الغرض؛ مع إيقاف الجمع وإتلاف ما سبق جمعه متى انتفت الحاجة إليه.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 12",
          "label": "Privacy Policy",
          "label_ar": "سياسة الخصوصية",
          "summary": "Requires the Controller to adopt a privacy policy and make it available to Data Subjects before collecting their Personal Data. The policy must state the purpose of Collection, the data collected, the means of Collection, Processing, storage and Destruction, and the Data Subject's rights and how to exercise them.",
          "summary_ar": "توجب على جهة التحكم اعتماد سياسة خصوصية وإتاحتها لأصحاب البيانات الشخصية قبل جمع بياناتهم. ويجب أن تبين السياسة الغرض من الجمع، والبيانات الشخصية المراد جمعها، ووسيلة جمعها ومعالجتها وحفظها وإتلافها، ومعلومات عن حقوق صاحب البيانات وكيفية ممارستها.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 13",
          "label": "Notice Upon Direct Collection",
          "label_ar": "الإحاطة عند الجمع المباشر",
          "summary": "Obliges the Controller, when collecting Personal Data directly, to inform the Data Subject of the legal basis, the purpose, which data is mandatory or optional, the collector's identity, recipient entities, any Transfer or Processing outside the Kingdom, consequences of not collecting, the Data Subject's rights, and other elements the Regulations specify.",
          "summary_ar": "تلزم جهة التحكم عند جمع البيانات الشخصية من صاحبها مباشرة بإحاطته بالسند النظامي للجمع، والغرض منه، وما هو إلزامي وما هو اختياري من البيانات، وهوية جهة الجمع، والجهات التي سيُفصح لها عنها، وما إذا كانت ستُنقل أو تُعالج خارج المملكة، والآثار المحتملة لعدم الجمع، وحقوقه بموجب النظام، وما تحدده اللوائح من عناصر أخرى.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 14",
          "label": "Accuracy of Personal Data",
          "label_ar": "دقة البيانات الشخصية",
          "summary": "Prohibits the Controller from Processing Personal Data without first taking sufficient steps to verify the data's accuracy, completeness, timeliness and relevance to the purpose for which it was collected, in accordance with the provisions of the Law.",
          "summary_ar": "تحظر على جهة التحكم معالجة البيانات الشخصية دون اتخاذ خطوات كافية للتحقق من دقتها واكتمالها وحداثتها وملاءمتها للغرض الذي جُمعت من أجله، وذلك وفقًا لأحكام النظام.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 15",
          "label": "Permitted Disclosure Cases",
          "label_ar": "حالات جواز الإفصاح",
          "summary": "Restricts Disclosure of Personal Data to six situations: the Data Subject's consent; data from a publicly available source; a Public Entity's request for public interest, security, legal or judicial purposes; protection of public health, safety or specific lives; non-identifying subsequent Processing; or the Controller's legitimate interests excluding Sensitive Data.",
          "summary_ar": "تقصر الإفصاح عن البيانات الشخصية على ست حالات: موافقة صاحب البيانات؛ أو جمعها من مصدر متاح للعموم؛ أو طلب جهة عامة لأغراض المصلحة العامة أو لأغراض أمنية أو لتنفيذ نظام آخر أو متطلبات قضائية؛ أو حماية الصحة العامة أو السلامة العامة أو حياة أفراد بعينهم؛ أو معالجة لاحقة بصورة لا تحدد الهوية؛ أو مصلحة مشروعة لجهة التحكم دون بيانات حساسة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 16",
          "label": "Prohibited Disclosures",
          "label_ar": "حالات حظر الإفصاح",
          "summary": "Prohibits Disclosure under several of Article 15's grounds where it would threaten security, harm the Kingdom's reputation, interests or foreign relations, impede crime detection or fair trial, compromise an individual's safety, violate another person's privacy, harm persons lacking legal capacity, breach professional obligations or judicial decisions, or expose confidential sources against the public interest.",
          "summary_ar": "تحظر الإفصاح في عدد من حالات المادة الخامسة عشرة إذا كان يمثل تهديدًا للأمن، أو يضر بسمعة المملكة أو مصالحها أو علاقاتها مع الدول الأخرى، أو يحول دون اكتشاف جريمة أو يمس حق متهم في محاكمة عادلة، أو يعرض سلامة فرد للخطر، أو ينتهك خصوصية شخص آخر، أو يتعارض مع مصلحة ناقص الأهلية أو فاقدها، أو يخل بالتزامات مهنية أو بقرار قضائي، أو يكشف مصدرًا سريًا للمعلومات بما يضر بالمصلحة العامة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 17",
          "label": "Notification of Data Corrections",
          "label_ar": "الإشعار بتصحيح البيانات",
          "summary": "Procedural article: when Personal Data is corrected, completed or updated, the Controller must notify all entities to which the data was transferred and make the amendment available to them. The Regulations set time frames, types of correction, and procedures to avoid Processing incorrect, inaccurate or outdated data.",
          "summary_ar": "مادة إجرائية: عند تصحيح البيانات الشخصية أو إكمالها أو تحديثها، يجب على جهة التحكم إشعار جميع الجهات التي نُقلت إليها البيانات بالتعديل وإتاحته لها. وتحدد اللوائح المدد الزمنية للتصحيح والتحديث وأنواع التصحيح والإجراءات اللازمة لتفادي آثار معالجة بيانات غير صحيحة أو غير دقيقة أو غير محدثة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 18",
          "label": "Data Destruction and Retention",
          "label_ar": "إتلاف البيانات والاحتفاظ بها",
          "summary": "Requires the Controller to Destroy Personal Data without undue delay once no longer necessary, while permitting retention in a form that cannot identify the Data Subject. Retention is mandatory where a legal basis prescribes a specific period or the data relates to a case before a judicial authority, with Destruction afterwards.",
          "summary_ar": "توجب على جهة التحكم إتلاف البيانات الشخصية دون تأخير متى انتفت الحاجة إليها، مع جواز الاحتفاظ بها بصورة لا تؤدي إلى تحديد هوية صاحبها وفق ضوابط اللوائح. ويجب الاحتفاظ بها بعد انتهاء الغرض إذا وُجد سند نظامي يقضي بذلك لمدة محددة أو كانت متصلة بقضية منظورة أمام جهة قضائية، على أن تُتلف بعد ذلك.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 19",
          "label": "Data Security Measures",
          "label_ar": "التدابير الأمنية لحماية البيانات",
          "summary": "Requires the Controller to implement all necessary organizational, administrative and technical measures to protect Personal Data, including during its Transfer, in accordance with the provisions and controls set out in the Regulations.",
          "summary_ar": "توجب على جهة التحكم اتخاذ جميع التدابير التنظيمية والإدارية والتقنية اللازمة لحماية البيانات الشخصية، بما في ذلك عند نقلها، وفقًا للأحكام والضوابط التي تحددها اللوائح.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 21",
          "label": "Responding to Data Subject Requests",
          "label_ar": "الاستجابة لطلبات أصحاب البيانات",
          "summary": "Procedural provision requiring the Controller to respond to Data Subjects' requests concerning their rights under the Law within the period and in the manner set out in the Regulations.",
          "summary_ar": "حكم إجرائي يلزم جهة التحكم بالاستجابة لطلبات صاحب البيانات الشخصية المتعلقة بحقوقه بموجب النظام خلال المدة وبالطريقة اللتين تحددهما اللوائح.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 23",
          "label": "Health Data Processing Controls",
          "label_ar": "ضوابط معالجة البيانات الصحية",
          "summary": "Mandates additional controls in the Regulations for Processing Health Data, protecting Data Subjects' privacy and rights. These include restricting access to Health Data, including medical files, to the minimum number of employees necessary to provide Health Services, and limiting Processing operations to what health services or insurance programs require.",
          "summary_ar": "تقضي بأن تتضمن اللوائح ضوابط وإجراءات إضافية لمعالجة البيانات الصحية بما يضمن خصوصية أصحابها ويحمي حقوقهم، ومنها قصر الاطلاع على البيانات الصحية، بما فيها الملفات الطبية، على أقل عدد ممكن من الموظفين والعاملين وبالقدر اللازم لتقديم الخدمات الصحية، وقصر عمليات المعالجة على القدر اللازم لتقديم الخدمات الصحية أو برامج التأمين الصحي.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 24",
          "label": "Credit Data Processing Controls",
          "label_ar": "ضوابط معالجة البيانات الائتمانية",
          "summary": "Requires the Regulations to set additional controls for Processing Credit Data consistent with this Law and the Credit Information Law, including verifying the Data Subject's explicit consent to Collection, purpose changes, Disclosure or Publishing, and notifying the Data Subject whenever a request to disclose their Credit Data is received.",
          "summary_ar": "توجب أن تتضمن اللوائح ضوابط وإجراءات إضافية لمعالجة البيانات الائتمانية بما يتفق مع هذا النظام ونظام المعلومات الائتمانية، ومنها التحقق من موافقة صاحب البيانات الصريحة على جمعها أو تغيير الغرض من جمعها أو الإفصاح عنها أو نشرها، وإشعاره عند ورود طلب من أي جهة للإفصاح عن بياناته الائتمانية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 25",
          "label": "Advertising and Awareness Communications",
          "label_ar": "المواد الدعائية والتوعوية",
          "summary": "Prohibits using a Data Subject's personal means of communication, including post and email, to send advertising or awareness-raising materials, except Public Entities' awareness materials, unless the recipient gave prior consent and the sender provides a clear mechanism to stop receiving them; the Regulations govern such materials and recipient consent.",
          "summary_ar": "تحظر استخدام وسائل الاتصال الشخصية لصاحب البيانات، بما فيها البريد العادي والإلكتروني، لإرسال مواد دعائية أو توعوية، باستثناء المواد التوعوية التي ترسلها الجهات العامة، ما لم تتوافر موافقة مسبقة من المستهدف ويوفر المرسل آلية واضحة تمكنه من طلب إيقاف إرسالها. وتحدد اللوائح الأحكام المتعلقة بهذه المواد وبموافقة المستقبِل.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 26",
          "label": "Processing for Marketing Purposes",
          "label_ar": "المعالجة للأغراض التسويقية",
          "summary": "Permits Processing Personal Data, other than Sensitive Data, for marketing purposes only where the data was collected directly from the Data Subject and their consent was given in accordance with the Law. The Regulations set out the applicable controls.",
          "summary_ar": "تجيز معالجة البيانات الشخصية، عدا البيانات الحساسة، للأغراض التسويقية بشرط أن تكون قد جُمعت من صاحبها مباشرة وأن يكون قد وافق على ذلك وفقًا لأحكام النظام، وتحدد اللوائح الضوابط اللازمة في هذا الشأن.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 27",
          "label": "Scientific, Research and Statistical Purposes",
          "label_ar": "الأغراض العلمية والبحثية والإحصائية",
          "summary": "Allows Collection or Processing of Personal Data without consent for scientific, research or statistical purposes where the data does not specifically identify the Data Subject, identity evidence is destroyed before Disclosure and the data is not Sensitive, or another law or a prior agreement so requires. The Regulations set the required controls.",
          "summary_ar": "تجيز جمع البيانات الشخصية أو معالجتها دون موافقة صاحبها للأغراض العلمية أو البحثية أو الإحصائية إذا كانت لا تدل على هويته تحديدًا، أو أُتلف ما يدل على هويته أثناء المعالجة وقبل الإفصاح عنها ولم تكن بيانات حساسة، أو كان ذلك مقتضى نظام آخر أو تنفيذًا لاتفاق سابق يكون طرفًا فيه. وتحدد اللوائح الضوابط اللازمة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 28",
          "label": "Copying Official Documents",
          "label_ar": "نسخ الوثائق الرسمية",
          "summary": "Prohibits copying official documents that identify Data Subjects, except where copying is required by law or a competent public authority requests such copies in accordance with the Regulations.",
          "summary_ar": "تحظر نسخ الوثائق الرسمية التي تدل على هوية أصحاب البيانات الشخصية، إلا إذا كان النسخ مطلوبًا بموجب نص نظامي أو بطلب من جهة عامة مختصة وفقًا لما تحدده اللوائح.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 29",
          "label": "Cross-Border Data Transfers",
          "label_ar": "نقل البيانات خارج المملكة",
          "summary": "Permits Transfer or Disclosure of Personal Data outside the Kingdom for agreements the Kingdom is party to, the Kingdom's interests, obligations the Data Subject is party to, or other purposes per the Regulations, subject to national security, an adequate protection level assessed by the Competent Authority, and data minimization, waived in extreme necessity involving life or health.",
          "summary_ar": "تجيز نقل البيانات الشخصية إلى خارج المملكة أو الإفصاح عنها لجهة خارجها تنفيذًا لاتفاقية تكون المملكة طرفًا فيها، أو خدمةً لمصالحها، أو تنفيذًا لالتزام يكون صاحب البيانات طرفًا فيه، أو لأغراض أخرى تحددها اللوائح؛ وذلك بشروط تتعلق بعدم المساس بالأمن الوطني، ووجود مستوى حماية مناسب تُقيّمه الجهة المختصة، والاقتصار على الحد الأدنى من البيانات، وتُستثنى من الشروط حالات الضرورة القصوى المتعلقة بالحياة أو الصحة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 30",
          "label": "Supervisory Role of Competent Authority",
          "label_ar": "إشراف الجهة المختصة",
          "summary": "Designates the Competent Authority, without prejudice to the Saudi Central Bank's powers, as overseer of the Law's implementation. The Regulations identify when Controllers must appoint personal data protection officers. Controllers must cooperate with the Authority, which may request documents, seek other parties' assistance, maintain a national register of Controllers, charge service fees, and delegate supervisory duties.",
          "summary_ar": "تُسند إلى الجهة المختصة، دون إخلال بصلاحيات البنك المركزي السعودي، مهمة الإشراف على تنفيذ النظام واللوائح. وتحدد اللوائح الحالات التي يجب فيها على جهة التحكم تعيين مسؤول (أو أكثر) لحماية البيانات الشخصية. وتلتزم جهة التحكم بالتعاون مع الجهة المختصة، التي لها طلب الوثائق والمعلومات، والاستعانة بالغير، وإنشاء سجل وطني لجهات التحكم، وتحصيل مقابل مالي عن خدماتها، وتفويض بعض مهماتها إلى جهات أخرى.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 32",
          "label": "Repealed Provision",
          "label_ar": "مادة ملغاة",
          "summary": "The text of this article states only that it has been repealed. It contains no operative provisions in the amended version of the Law, reflecting the removal of its former content while the article numbering of the Law is preserved.",
          "summary_ar": "يقتصر نص هذه المادة على بيان أنها مُلغاة، فلا تتضمن أي أحكام نافذة في النسخة المعدلة من النظام، بما يعكس إلغاء محتواها السابق مع المحافظة على تسلسل ترقيم مواد النظام.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 33",
          "label": "Licensing, Accreditation and Audits",
          "label_ar": "التراخيص والاعتماد والتدقيق",
          "summary": "Empowers the Competent Authority to set requirements for commercial, professional or non-profit personal data protection activities, license entities issuing accreditation certificates to Controllers and Processors, license entities auditing Processing activities, and establish tools and procedures for monitoring and enforcing compliance of Controllers and Processors outside the Kingdom processing residents' data.",
          "summary_ar": "تخوّل الجهة المختصة وضع متطلبات مزاولة الأنشطة التجارية أو المهنية أو غير الربحية المتعلقة بحماية البيانات الشخصية، ومنح تراخيص للجهات التي تصدر شهادات اعتماد لجهات التحكم وجهات المعالجة، ومنح تراخيص لجهات التدقيق والفحص على أنشطة معالجة البيانات، وتحديد الأدوات والآليات والإجراءات اللازمة لمراقبة التزام جهات التحكم والمعالجة خارج المملكة التي تعالج بيانات المقيمين فيها وإنفاذ أحكام النظام خارجها.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 34",
          "label": "Complaints to Competent Authority",
          "label_ar": "الشكاوى لدى الجهة المختصة",
          "summary": "Procedural article entitling Data Subjects to submit to the Competent Authority any complaint arising from the implementation of the Law and the Regulations, and directing the Regulations to set out the rules for processing such complaints.",
          "summary_ar": "مادة إجرائية تخوّل صاحب البيانات الشخصية التقدم إلى الجهة المختصة بأي شكوى تنشأ عن تطبيق النظام واللوائح، وتقضي بأن تحدد اللوائح قواعد معالجة تلك الشكاوى.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 35",
          "label": "Criminal Penalties for Sensitive Data",
          "label_ar": "عقوبة الإفصاح عن البيانات الحساسة",
          "summary": "Penal provision: disclosing or publishing Sensitive Data in violation of the Law, with intent to harm the Data Subject or gain personal benefit, is punishable by imprisonment up to two years and/or a fine up to three million riyals. The Public Prosecution prosecutes; the competent court adjudicates and may double fines for recidivism.",
          "summary_ar": "حكم جزائي: يعاقب من يفصح عن بيانات حساسة أو ينشرها بالمخالفة لأحكام النظام بقصد الإضرار بصاحب البيانات أو تحقيق منفعة شخصية بالسجن مدة لا تزيد على سنتين أو بغرامة لا تزيد على ثلاثة ملايين ريال أو بهما معًا. وتتولى النيابة العامة التحقيق والادعاء، وتختص المحكمة المختصة بالفصل ولها مضاعفة الغرامة في حال العود.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 36",
          "label": "Administrative Penalties",
          "label_ar": "العقوبات الإدارية",
          "summary": "For violations not covered by Article 35, provides a warning or fine up to five million riyals, doublable for repeat violations. A committee of at least three members formed by the Competent Authority's president examines violations and imposes penalties, subject to the president's approval; decisions are appealable before the competent court.",
          "summary_ar": "تقرر في غير الحالات المشمولة بالمادة الخامسة والثلاثين عقوبة الإنذار أو غرامة لا تزيد على خمسة ملايين ريال، مع جواز مضاعفتها عند تكرار المخالفة. وتتولى لجنة (أو أكثر) لا يقل أعضاؤها عن ثلاثة، تُشكل بقرار من رئيس الجهة المختصة، النظر في المخالفات وإيقاع العقوبات بعد اعتماد قراراتها من الرئيس، ويجوز الاعتراض عليها أمام المحكمة المختصة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 37",
          "label": "Inspection and Seizure Powers",
          "label_ar": "صلاحيات الضبط والتفتيش",
          "summary": "Grants employees appointed by the Competent Authority's president powers to control and inspect violations of the Law and Regulations, under rules the president issues. Such employees may seek assistance from criminal investigation and other competent authorities, and the Competent Authority may seize the means or tools used in committing a violation.",
          "summary_ar": "تمنح الموظفين والعاملين المعينين بقرار من رئيس الجهة المختصة صلاحيات ضبط مخالفات أحكام النظام واللوائح والتفتيش عليها وفق القواعد التي يصدرها الرئيس، ولهم الاستعانة بجهات التحري الجنائي وغيرها من الجهات المختصة لأداء مهماتهم، وللجهة المختصة حجز الوسائل أو الأدوات المستخدمة في ارتكاب المخالفة حتى يُبت فيها.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 38",
          "label": "Confiscation and Judgment Publication",
          "label_ar": "المصادرة ونشر الأحكام",
          "summary": "Empowers the competent court to order confiscation of funds obtained from violations, without prejudice to bona fide third parties. The court or the violations committee may also order publication of a summary of the penalty decision at the violator's expense once final, according to the violation's type, seriousness and impact.",
          "summary_ar": "تجيز للمحكمة المختصة، دون إخلال بحقوق الغير حسن النية، الحكم بمصادرة الأموال المتحصلة من ارتكاب المخالفات المنصوص عليها في النظام. كما يجوز للمحكمة أو للجنة النظر في المخالفات تضمين الحكم أو القرار النص على نشر ملخصه على نفقة المخالف بعد صيرورته نهائيًا، بحسب نوع المخالفة وجسامتها وأثرها.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 39",
          "label": "Disciplining Public Entity Employees",
          "label_ar": "تأديب موظفي الجهات العامة",
          "summary": "Requires Public Entities, without prejudice to the penalties in Article 35 and Paragraph 1 of Article 36, to discipline any of their employees who violate the Law or the Regulations, in accordance with the disciplinary provisions and procedures prescribed by law.",
          "summary_ar": "توجب على الجهة العامة، دون إخلال بما ورد في المادة الخامسة والثلاثين والفقرة الأولى من المادة السادسة والثلاثين، تأديب أي من موظفيها يخالف أيًا من أحكام النظام واللوائح، وفقًا لأحكام وإجراءات التأديب المقررة نظامًا.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 40",
          "label": "Compensation for Damage",
          "label_ar": "التعويض عن الضرر",
          "summary": "Entitles any individual who suffers damage as a result of a violation of the Law or the Regulations to apply to the competent court for compensation proportionate to the material or moral damage sustained, without prejudice to the penalties prescribed by the Law.",
          "summary_ar": "تخوّل كل من لحقه ضرر ناتج عن مخالفة أي من الأحكام الواردة في النظام أو اللوائح اللجوء إلى المحكمة المختصة للمطالبة بتعويض يتناسب مع الضرر المادي أو المعنوي الذي أصابه، دون إخلال بالعقوبات المقررة في النظام.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 41",
          "label": "Ongoing Confidentiality Obligation",
          "label_ar": "الالتزام المستمر بالسرية",
          "summary": "Imposes a duty of confidentiality on any person who engages in the Processing of Personal Data, requiring them to protect the confidentiality of that data even after the end of their occupational or contractual relationship.",
          "summary_ar": "تفرض على كل من يشارك في معالجة البيانات الشخصية التزامًا بالمحافظة على سريتها، ويستمر هذا الالتزام حتى بعد انتهاء علاقته الوظيفية أو التعاقدية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 42",
          "label": "Issuance of Implementing Regulations",
          "label_ar": "إصدار اللوائح التنفيذية",
          "summary": "Directs the president of the Competent Authority to issue the Regulations within seven hundred twenty days of the Law's publication, after coordination with seven named bodies, including the communications and foreign affairs ministries, the cybersecurity and digital government authorities, the Saudi Health Council and the Saudi Central Bank, each within its jurisdiction.",
          "summary_ar": "توجب على رئيس الجهة المختصة إصدار اللوائح خلال مدة لا تتجاوز سبعمائة وعشرين يومًا من تاريخ نشر النظام، بعد التنسيق مع سبع جهات محددة، منها وزارة الاتصالات وتقنية المعلومات ووزارة الخارجية والهيئة الوطنية للأمن السيبراني وهيئة الحكومة الرقمية والمجلس الصحي السعودي والبنك المركزي السعودي، كل فيما يخصه.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 43",
          "label": "Entry Into Force",
          "label_ar": "بدء العمل بالنظام",
          "summary": "Final provision stating that the Law shall come into force after seven hundred and twenty days commencing on the date of its publication in the Official Gazette.",
          "summary_ar": "حكم ختامي ينص على أن يُعمل بالنظام بعد مضي سبعمائة وعشرين يومًا من تاريخ نشره في الجريدة الرسمية.",
          "parent": null,
          "official_anchor": null
        }
      ]
    },
    {
      "slug": "saudi-central-bank-law",
      "name": "Saudi Central Bank Law",
      "name_ar": "نظام البنك المركزي السعودي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Law",
      "tier": 1,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/saudi-central-bank-law",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "sdaia-organizational-arrangements",
      "name": "SDAIA Organizational Arrangements",
      "name_ar": "الترتيبات التنظيمية للهيئة السعودية للبيانات والذكاء الاصطناعي",
      "subtitle": "الترتيبات التنظيمية للهيئة السعودية للبيانات والذكاء الاصطناعي",
      "subtitle_ar": "الترتيبات التنظيمية للهيئة السعودية للبيانات والذكاء الاصطناعي",
      "summary": "SDAIA's constitutive charter — the **Organizational Arrangements** of the Saudi Data & AI Authority.\n\nIssued by **Council of Ministers Resolution No. 292** (27/4/1441 AH) and amended by **Resolution No. 195** (15/3/1444 AH), under **Royal Order A/471** (29/12/1440 AH) — the order that established SDAIA and created the NDMO and NCAI.\n\nIt constitutes the Authority and defines its powers, as distinct from the substantive laws SDAIA administers (e.g. the PDPL). In Saudi terms this is a Cabinet-level organizational instrument (tartībāt tanẓīmiyya) — **not** a niẓām (Law) or an implementing regulation.\n\n_English text is an unofficial translation; the Arabic text governs._",
      "summary_ar": "الوثيقة التأسيسية لـSDAIA — **الترتيبات التنظيمية** للهيئة السعودية للبيانات والذكاء الاصطناعي.\n\nصدرت بموجب **قرار مجلس الوزراء رقم 292** (27/4/1441هـ) وعُدّلت بموجب **القرار رقم 195** (15/3/1444هـ)، استنادًا إلى **الأمر الملكي رقم أ/471** (29/12/1440هـ) — وهو الأمر الذي أنشأ SDAIA واستحدث مكتب إدارة البيانات الوطني NDMO والمركز الوطني للذكاء الاصطناعي NCAI.\n\nوتؤسس هذه الوثيقة الهيئة وتحدد صلاحياتها، بوصفها متمايزة عن الأنظمة الموضوعية التي تتولى الهيئة إدارتها (مثل نظام حماية البيانات الشخصية). وهي بالمصطلح السعودي أداة تنظيمية على مستوى مجلس الوزراء (ترتيبات تنظيمية) — وليست نظامًا (قانونًا) ولا لائحة تنفيذية.\n\n_النص الإنجليزي ترجمة غير رسمية؛ والنص العربي هو المعتمَد._",
      "type": "Council of Ministers Resolution",
      "tier": 2,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/sdaia-organizational-arrangements",
      "date_note": "CoM Resolution No. 292 (27/4/1441 AH), amended by No. 195 (15/3/1444 AH); under Royal Order A/471 (29/12/1440 AH)",
      "date_note_ar": "قرار مجلس الوزراء رقم 292 (27/4/1441هـ)، المعدّل بالقرار رقم 195 (15/3/1444هـ)؛ بموجب الأمر الملكي أ/471 (29/12/1440هـ)",
      "provisions": []
    },
    {
      "slug": "cloud-regs",
      "name": "Cloud Computing Regulatory Framework",
      "name_ar": "الإطار التنظيمي للحوسبة السحابية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "CST framework for cloud computing; CSP Class A/B/C tiers.",
      "summary_ar": "إطار هيئة الاتصالات والفضاء والتقنية (CST) للحوسبة السحابية؛ تصنيف مزوّدي الخدمات السحابية إلى الفئات CSP من النوع A/B/C.",
      "type": "Regulation",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "telecom",
      "authority": "CST",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cloud-regs",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ndmo-standards",
      "name": "NDMO Data Management & Personal Data Protection Standards",
      "name_ar": "معايير إدارة البيانات وحماية البيانات الشخصية الصادرة عن NDMO",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "77 controls / 191 specifications; mandatory for government entities.",
      "summary_ar": "77 ضابطًا / 191 مواصفة؛ إلزامية للجهات الحكومية.",
      "type": "Standard",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/DataManagementPersonalDataProtectionStandards.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/ndmo-standards",
      "date_note": null,
      "date_note_ar": null,
      "provisions": [
        {
          "kind": "control",
          "code": "PDP.1",
          "label": "Plan",
          "label_ar": "الخطة",
          "summary": "Personal Data Protection domain, control PDP.1 — the PDP plan. NDMO DM & PDP Standards: 15 domains → 77 controls → 191 specifications; codes are PDP.x (control) / PDP.x.x (specification), e.g. PDP.1.1. (No 'CS'/'MQ' infix exists.)",
          "summary_ar": "نطاق حماية البيانات الشخصية، الضابط PDP.1 — خطة حماية البيانات. معايير NDMO: 15 مجالاً ← 77 ضابطاً ← 191 مواصفة؛ والرموز بصيغة PDP.x للضابط وPDP.x.x للمواصفة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "control",
          "code": "PDP.2",
          "label": "Training and Awareness",
          "label_ar": "التدريب والتوعية",
          "summary": "Personal Data Protection domain, control PDP.2 — training and awareness.",
          "summary_ar": "نطاق حماية البيانات الشخصية، الضابط PDP.2 — التدريب والتوعية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "control",
          "code": "PDP.3",
          "label": "Data Breach",
          "label_ar": "انتهاك البيانات",
          "summary": "Personal Data Protection domain, control PDP.3 — data-breach detection, logging and notification to the regulator.",
          "summary_ar": "نطاق حماية البيانات الشخصية، الضابط PDP.3 — اكتشاف انتهاكات البيانات وتسجيلها والإشعار بها للجهة المنظِّمة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "control",
          "code": "PDP.4",
          "label": "Data Lifecycle Management",
          "label_ar": "إدارة دورة حياة البيانات",
          "summary": "Personal Data Protection domain, control PDP.4 — data lifecycle management; its specifications include risk-assessment findings (PDP.4.3) and monitoring (PDP.4.4).",
          "summary_ar": "نطاق حماية البيانات الشخصية، الضابط PDP.4 — إدارة دورة حياة البيانات؛ وتشمل مواصفاته نتائج تقييم المخاطر (PDP.4.3) والمراقبة (PDP.4.4).",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "control",
          "code": "PDP.5",
          "label": "Artifacts",
          "label_ar": "المُخرجات",
          "summary": "Personal Data Protection domain, control PDP.5 — artifacts (records and registers).",
          "summary_ar": "نطاق حماية البيانات الشخصية، الضابط PDP.5 — المُخرجات (السجلات والقيود).",
          "parent": null,
          "official_anchor": null
        }
      ]
    },
    {
      "slug": "implementing-regulation",
      "name": "Implementing (Executive) Regulation",
      "name_ar": "اللائحة التنفيذية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Implementing Regulation (September 2023) gives the PDPL its operational detail across 38 articles. **Amendments are pending**: a third public consultation closed on 27 May 2025 and had not been enacted as of July 2026 — the provisions below reflect the Regulation as in force.\n\n**What it covers.** Data-subject requests must be answered within 30 days, extendable by a further 30 (Art. 3). Consent must be freely given, purpose-specific, documented and separate per purpose — and **explicit** for sensitive data, credit data and solely automated decision-making (Art. 11); withdrawal must be as easy as consenting (Art. 12). Legitimate-interest processing requires a documented prior assessment and excludes public entities and sensitive data (Art. 16). Processor relationships need contracts covering purpose, data categories, breach notification and subcontracting (Art. 17). Security follows the National Cybersecurity Authority's controls, or recognised best practice where those are not mandatory (Art. 23). Personal-data breaches must be notified to SDAIA **within 72 hours** where harm is possible, and to affected individuals without undue delay (Art. 24). Impact assessments are mandatory for sensitive data, dataset linking, constant monitoring, new technologies and automated decisions (Art. 25). Sector rules cover health data (Art. 26) and credit data (Art. 27); advertising and direct marketing are opt-in with easy, free opt-out (Arts. 28–29). Controllers must appoint a **data protection officer** in the cases of Art. 32, keep records of processing for the duration of processing plus five years (Art. 33), and register on the national register per SDAIA's rules (Art. 34). Complaints go to SDAIA within 90 days (Art. 37).\n\n## Frequently asked questions\n\n**When must a data breach be notified in Saudi Arabia?**\n\nArticle 24 requires the controller to notify SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the data subject, or conflict with their rights or interests. Affected data subjects must be notified without undue delay where the breach may cause them damage — there is no GDPR-style \"unlikely risk\" carve-out.\n\n**Who must appoint a data protection officer (DPO)?**\n\nArticle 32 requires a DPO where the controller is a public entity providing large-scale processing services, where core activities involve regular and systematic monitoring of data subjects, or where core activities consist of processing sensitive data. The DPO may be an employee or an external provider.\n\n**What triggers a data protection impact assessment?**\n\nArticle 25 lists the mandatory cases: processing sensitive data; collecting, comparing or linking two or more datasets; large-scale or repetitive processing of persons lacking capacity; operations requiring constant monitoring; newly adopted technologies; solely automated decision-making; and any product or service likely to cause serious privacy harm.\n\n**What is changing in the pending amendments?**\n\nThe May 2025 consultation proposed consolidating the DPO and controller-registration rules into the Regulation, simplifying the records-of-processing format, easing some direct-marketing provisions and removing the 90-day complaint window. None of this had been enacted as of July 2026 — the September 2023 text remains in force.",
      "summary_ar": "توفر اللائحة التنفيذية (سبتمبر 2023) التفاصيل التشغيلية لنظام حماية البيانات الشخصية عبر (38) مادة. **وثمة تعديلات قيد الإقرار**: فقد أُغلقت مشاورة عامة ثالثة في 27 مايو 2025 دون أن تُقر التعديلات حتى يوليو 2026 — وتعكس الأحكام الواردة أدناه اللائحة بصيغتها النافذة.\n\n**ما تغطيه اللائحة.** يجب الاستجابة لطلبات أصحاب البيانات الشخصية خلال (30) يومًا مع إمكانية التمديد لمدة (30) يومًا إضافية (المادة (3)). ويجب أن تكون الموافقة صادرة عن إرادة حرة، ومحددة الغرض، وموثقة، ومنفصلة لكل غرض على حدة — وأن تكون **صريحة** عند معالجة البيانات الحساسة والبيانات الائتمانية واتخاذ القرارات المبنية بالكامل على المعالجة الآلية (المادة (11))؛ ويجب أن يكون الرجوع عن الموافقة بالسهولة ذاتها التي مُنحت بها (المادة (12)). وتتطلب المعالجة القائمة على المصلحة المشروعة تقييمًا مسبقًا موثقًا، وتُستبعد منها الجهات العامة والبيانات الحساسة (المادة (16)). وتستلزم العلاقة مع جهة المعالجة عقودًا تغطي الغرض وفئات البيانات والإشعار عن حوادث التسرب والتعاقد من الباطن (المادة (17)). ويخضع أمن البيانات لضوابط الهيئة الوطنية للأمن السيبراني، أو لأفضل الممارسات المعتبرة حيثما لا تكون تلك الضوابط إلزامية (المادة (23)). ويجب إشعار سدايا بحوادث تسرب البيانات الشخصية **خلال (72) ساعة** متى كان وقوع الضرر محتملًا، وإشعار الأفراد المتأثرين دون تأخير غير مبرر (المادة (24)). ويكون تقييم الأثر إلزاميًا في حالات البيانات الحساسة، وربط مجموعات البيانات، والمراقبة المستمرة، والتقنيات الحديثة، والقرارات المؤتمتة (المادة (25)). وتتناول الأحكام القطاعية البيانات الصحية (المادة (26)) والبيانات الائتمانية (المادة (27))؛ ويقوم الإعلان والتسويق المباشر على الموافقة المسبقة مع إتاحة إيقافهما بطريقة ميسّرة ودون مقابل (المادتان (28) و(29)). ويجب على جهة التحكم تعيين **مسؤول حماية البيانات** في الحالات المنصوص عليها في المادة (32)، والاحتفاظ بسجلات أنشطة المعالجة طوال مدة المعالجة مضافًا إليها خمس سنوات (المادة (33))، والتسجيل في السجل الوطني وفقًا للقواعد التي تضعها سدايا (المادة (34)). وتُقدَّم الشكاوى إلى سدايا خلال (90) يومًا (المادة (37)).\n\n## الأسئلة الشائعة\n\n**متى يجب الإشعار عن حادثة تسرب البيانات في المملكة العربية السعودية؟**\n\nتوجب المادة (24) على جهة التحكم إشعار سدايا خلال (72) ساعة من علمها بحادثة التسرب إذا كان من شأنها الإضرار بالبيانات الشخصية أو بصاحبها، أو التعارض مع حقوقه أو مصالحه. كما يجب إشعار أصحاب البيانات الشخصية المتأثرين دون تأخير غير مبرر إذا كان من شأن الحادثة إلحاق ضرر بهم — ولا يوجد استثناء من قبيل «الخطر المستبعد» على نمط اللائحة الأوروبية العامة لحماية البيانات (GDPR).\n\n**من الملزم بتعيين مسؤول حماية البيانات (DPO)؟**\n\nتوجب المادة (32) تعيين مسؤول حماية البيانات إذا كانت جهة التحكم جهة عامة تقدم خدمات تنطوي على معالجة واسعة النطاق، أو إذا كانت الأنشطة الأساسية لجهة التحكم تتضمن مراقبة منتظمة ومنهجية لأصحاب البيانات الشخصية، أو إذا كانت أنشطتها الأساسية تقوم على معالجة البيانات الحساسة. ويجوز أن يكون مسؤول حماية البيانات موظفًا لدى الجهة أو مقدم خدمة خارجيًا.\n\n**ما الحالات التي تستوجب إجراء تقييم الأثر لحماية البيانات الشخصية؟**\n\nتعدد المادة (25) الحالات الإلزامية، وهي: معالجة البيانات الحساسة؛ وجمع مجموعتين أو أكثر من مجموعات البيانات أو مقارنتها أو ربطها؛ والمعالجة الواسعة النطاق أو المتكررة لبيانات فاقدي الأهلية؛ والعمليات التي تتطلب مراقبة مستمرة؛ والتقنيات حديثة الاعتماد؛ واتخاذ القرارات المبنية بالكامل على المعالجة الآلية؛ وأي منتج أو خدمة يُرجَّح أن يُلحق ضررًا جسيمًا بالخصوصية.\n\n**ما الذي سيتغير في التعديلات قيد الإقرار؟**\n\nاقترحت مشاورة مايو 2025 دمج قواعد مسؤول حماية البيانات وقواعد تسجيل جهات التحكم في اللائحة، وتبسيط نموذج سجلات أنشطة المعالجة، وتخفيف بعض أحكام التسويق المباشر، وإلغاء مهلة تقديم الشكاوى المحددة بـ(90) يومًا. ولم يكن أي من ذلك قد أُقر حتى يوليو 2026 — ويظل نص سبتمبر 2023 هو النافذ.",
      "type": "Implementing Regulation",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "pdpl-law",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/ImplementingRegulationPersonalDataProtectionLaw.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/implementing-regulation",
      "date_note": "Amendments pending — consultation closed 27 May 2025; not enacted as of Jun 2026",
      "date_note_ar": "تعديلات قيد الإعداد — أُغلقت المشاورة في 27 مايو 2025؛ لم تُسَنّ حتى يونيو 2026",
      "provisions": [
        {
          "kind": "article",
          "code": "Art. 4",
          "label": "Right to be informed",
          "label_ar": "الحق في العلم",
          "summary": "The data subject's right to be informed — the transparency / privacy-notice obligation at or before collection (IR Arts. 3-8 set out the data-subject rights).",
          "summary_ar": "حق صاحب البيانات في العلم — التزام الشفافية وإشعار الخصوصية عند الجمع أو قبله (تنظّم المواد 3-8 من اللائحة حقوق صاحب البيانات).",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 1",
          "label": "Definitions",
          "label_ar": "التعريفات",
          "summary": "Adopts the definitions of Article 1 of the Personal Data Protection Law and defines additional terms used in the Regulation, including Direct Marketing, Personal Data Breach, Vital Interest, Actual Interest, Legitimate Interest, Pseudonymisation, Anonymization, and Explicit Consent.",
          "summary_ar": "تعتمد التعريفات الواردة في المادة الأولى من نظام حماية البيانات الشخصية، وتحدد معاني مصطلحات إضافية مستخدمة في اللائحة، منها التسويق المباشر، وتسرب البيانات الشخصية، والمصلحة الحيوية، والمصلحة الفعلية، والمصلحة المشروعة، والترميز، وإخفاء الهوية، والموافقة الصريحة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 24",
          "label": "Personal Data Breach Notification",
          "label_ar": "الإشعار بانتهاك البيانات الشخصية",
          "summary": "The Controller must notify SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the data subject; affected data subjects are notified without undue delay.",
          "summary_ar": "يجب على جهة التحكم إشعار سدايا خلال 72 ساعة من علمها بالانتهاك الذي قد يضر بالبيانات الشخصية أو بصاحبها، وإشعار أصحاب البيانات المتأثرين دون تأخير غير مبرر.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 2",
          "label": "Personal or Family Use",
          "label_ar": "الاستخدام الشخصي أو العائلي",
          "summary": "Excludes from the Law's scope an individual's Processing of Personal Data for purposes not exceeding personal or family use, defined as Processing within a family or limited social circle. Publishing data to the public, disclosure beyond that circle, or professional, commercial, or non-profit use is not covered.",
          "summary_ar": "تستثني من نطاق تطبيق النظام معالجة الفرد للبيانات الشخصية لأغراض لا تتجاوز الاستخدام الشخصي أو العائلي، وتعرّفه بأنه المعالجة داخل الإطار العائلي أو الاجتماعي المحدود، ولا يُعد منه نشر البيانات للعموم أو الإفصاح عنها خارج هذا النطاق أو استخدامها لأغراض مهنية أو تجارية أو غير ربحية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 25",
          "label": "Data Protection Impact Assessment",
          "label_ar": "تقييم الأثر على حماية البيانات",
          "summary": "Specifies the processing activities that require an impact assessment — including sensitive data, large-scale processing, vulnerable data subjects, new technologies and automated decision-making.",
          "summary_ar": "يحدد أنشطة المعالجة التي تستوجب إجراء تقييم للأثر — ومنها البيانات الحساسة والمعالجة واسعة النطاق وأصحاب البيانات الأكثر عرضة والتقنيات الحديثة واتخاذ القرارات الآلية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 3",
          "label": "General Provisions for Data Subject Rights",
          "label_ar": "الأحكام العامة لحقوق صاحب البيانات الشخصية",
          "summary": "Requires the Controller to act on data subject rights requests within 30 days, extendable by a further 30 days with notice, verify the requester's identity, and document all requests. Repetitive, manifestly unfounded, or disproportionate requests may be refused with reasons; legal guardians exercise rights for those lacking capacity.",
          "summary_ar": "توجب على جهة التحكم تنفيذ طلبات صاحب البيانات الشخصية المتعلقة بحقوقه خلال (30) يوماً، قابلة للتمديد (30) يوماً إضافية مع إشعاره، والتحقق من هوية مقدم الطلب، وتوثيق جميع الطلبات. ويجوز رفض الطلبات المتكررة أو غير المبررة أو التي تتطلب جهوداً غير متناسبة مع بيان السبب، ويمارس الولي الحقوق نيابةً عن فاقدي الأهلية كلياً أو جزئياً.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 32",
          "label": "Data Protection Officer",
          "label_ar": "مسؤول حماية البيانات",
          "summary": "Lists the processing that requires appointing a DPO (public bodies processing at scale, regular and systematic monitoring, core processing of sensitive data); the appointment is documented and notified to SDAIA.",
          "summary_ar": "يحدد حالات المعالجة التي تستوجب تعيين مسؤول لحماية البيانات (الجهات العامة، والمراقبة المنتظمة والممنهجة، ومعالجة البيانات الحساسة)، ويُوثَّق التعيين ويُبلَّغ به سدايا.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 33",
          "label": "Records of Processing Activities (RoPA)",
          "label_ar": "سجل أنشطة المعالجة",
          "summary": "The Controller maintains a written record of processing activities during processing and for five years afterwards, kept accurate and produced to SDAIA on request. (Being simplified under the pending IR amendments.)",
          "summary_ar": "تحتفظ جهة التحكم بسجل مكتوب لأنشطة المعالجة أثناء المعالجة ولمدة خمس سنوات بعدها، محدَّثاً ويُقدَّم لسدايا عند الطلب. (يجري تبسيطه ضمن تعديلات اللائحة المرتقبة.)",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 34",
          "label": "National Register of Controllers",
          "label_ar": "السجل الوطني لجهات التحكم",
          "summary": "Sets the requirements for registering controllers in the national register — distinct from the RoPA in Art. 33.",
          "summary_ar": "يحدد متطلبات تسجيل جهات التحكم في السجل الوطني — ويختلف عن سجل أنشطة المعالجة في المادة 33.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 5",
          "label": "Right of Access",
          "label_ar": "حق الاطلاع على البيانات الشخصية",
          "summary": "Grants the data subject the right to access their Personal Data held by the Controller, either on request or through a direct-access channel, provided access does not adversely affect others' rights such as intellectual property or trade secrets, and no Personal Data identifying another individual is disclosed.",
          "summary_ar": "تمنح صاحب البيانات الشخصية حق الاطلاع على بياناته الشخصية المتوفرة لدى جهة التحكم، سواء بناءً على طلب أو عبر قناة تتيح الاطلاع المباشر، على ألا يؤثر ذلك سلباً في حقوق الآخرين كحقوق الملكية الفكرية أو الأسرار التجارية، ومع ضمان عدم الإفصاح عن بيانات شخصية تحدد هوية فرد آخر.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 6",
          "label": "Right to Request Data Copy",
          "label_ar": "حق طلب الحصول على نسخة من البيانات",
          "summary": "Entitles the data subject to request a copy of their Personal Data in a readable and clear format, provided in a commonly used electronic format or, if feasible, a printed hard copy, without adversely affecting others' rights or disclosing Personal Data that identifies another individual.",
          "summary_ar": "تخوّل صاحب البيانات الشخصية طلب الحصول على نسخة من بياناته الشخصية بصيغة واضحة ومقروءة، تُقدَّم بصيغة إلكترونية شائعة الاستخدام أو نسخة ورقية مطبوعة متى كان ذلك ممكناً، دون المساس بحقوق الآخرين أو الإفصاح عن بيانات شخصية تحدد هوية فرد آخر.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 36",
          "label": "Auditing and Controlling",
          "label_ar": "التدقيق والرقابة",
          "summary": "Audits and checks of personal-data processing to ensure the entity properly protects personal data. (This — not Art. 24/25/33 — is the audit obligation.)",
          "summary_ar": "تدقيق ومراجعة معالجة البيانات الشخصية للتأكد من أن الجهة تحمي البيانات الشخصية على نحو سليم. (هذه — وليست المواد 24/25/33 — هي مادة التدقيق.)",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 7",
          "label": "Right to Request Correction",
          "label_ar": "حق طلب تصحيح البيانات الشخصية",
          "summary": "Allows the data subject to obtain restriction of Processing while the accuracy of contested Personal Data is verified. The Controller may request supporting documents, which must be destroyed once verification is complete, and must notify parties to whom the data was previously disclosed after correction, without undue delay.",
          "summary_ar": "تتيح لصاحب البيانات الشخصية تقييد المعالجة خلال فترة التحقق من دقة البيانات الشخصية المعترض عليها. ويجوز لجهة التحكم طلب مستندات مؤيدة على أن تُتلف فور اكتمال التحقق، وعليها إشعار الجهات التي سبق الإفصاح لها عن البيانات بعد تصحيحها دون تأخير غير مبرر.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 8",
          "label": "Right to Request Destruction",
          "label_ar": "حق طلب إتلاف البيانات الشخصية",
          "summary": "Obliges the Controller to destroy Personal Data upon the data subject's request, when no longer necessary for the collection purpose, on withdrawal of consent where consent is the sole legal basis, or if processed unlawfully. All copies including backups must be destroyed and recipients notified, subject to Article 18 of the Law.",
          "summary_ar": "تلزم جهة التحكم بإتلاف البيانات الشخصية بناءً على طلب صاحب البيانات الشخصية، أو عند انتفاء الحاجة إليها لتحقيق غرض جمعها، أو عند سحب الموافقة إذا كانت الأساس النظامي الوحيد للمعالجة، أو إذا عُولجت بطريقة غير مشروعة، مع إتلاف جميع النسخ بما فيها النسخ الاحتياطية وإشعار الجهات التي أُفصح لها عنها، دون إخلال بالمادة (18) من النظام.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 9",
          "label": "Anonymisation",
          "label_ar": "إخفاء الهوية",
          "summary": "Sets conditions for anonymising Personal Data: the Controller must ensure re-identification is impossible, assess the impact and re-identification risk, apply and update organisational, administrative, and technical measures in light of technological developments, and evaluate the effectiveness of the techniques used. Anonymised data is no longer considered Personal Data.",
          "summary_ar": "تحدد ضوابط إخفاء هوية البيانات الشخصية؛ إذ يجب على جهة التحكم ضمان استحالة إعادة تحديد هوية صاحب البيانات الشخصية، وتقييم الأثر واحتمالية إعادة تحديد الهوية، واتخاذ التدابير التنظيمية والإدارية والتقنية اللازمة وتحديثها وفق التطورات التقنية، وتقييم فعالية التقنيات المطبقة. ولا تُعد البيانات بعد إخفاء الهوية بيانات شخصية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 10",
          "label": "Means of Communication",
          "label_ar": "وسائل التواصل",
          "summary": "Requires the Controller to provide appropriate means for handling data subject rights requests. The data subject may choose among the options made available, including e-mail, text messages, the national address, electronic applications, or any other lawful communication means provided by the Controller for this purpose.",
          "summary_ar": "توجب على جهة التحكم توفير الوسائل المناسبة لمعالجة الطلبات المتعلقة بحقوق صاحب البيانات الشخصية، وله الاختيار من بين الخيارات المتاحة، ومنها البريد الإلكتروني، والرسائل النصية، والعنوان الوطني، والتطبيقات الإلكترونية، أو أي وسيلة تواصل نظامية أخرى توفرها جهة التحكم لهذا الغرض.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 11",
          "label": "Consent Conditions",
          "label_ar": "شروط الموافقة",
          "summary": "Sets conditions for valid consent: freely given without misleading methods, for clear and specific purposes explained in advance, given by a person with full legal capacity, documented verifiably, and obtained separately for each Processing purpose. Explicit consent is required for Sensitive Data, Credit Data, and solely automated decision-making.",
          "summary_ar": "تحدد شروط الموافقة الصحيحة: أن تصدر بحرية دون أساليب مضللة، ولأغراض واضحة ومحددة تُوضَّح مسبقاً، وأن تصدر ممن يتمتع بالأهلية النظامية الكاملة، وأن تُوثَّق بوسائل تتيح التحقق منها مستقبلاً، وأن تكون موافقة مستقلة لكل غرض من أغراض المعالجة. وتُشترط الموافقة الصريحة لمعالجة البيانات الحساسة والبيانات الائتمانية والقرارات المبنية كلياً على المعالجة الآلية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 12",
          "label": "Consent Withdrawal",
          "label_ar": "سحب الموافقة",
          "summary": "Confirms the data subject may withdraw consent at any time. Withdrawal must be as easy as giving consent, with procedures established in advance. The Controller must then cease Processing without undue delay and notify recipients to destroy the data; prior Processing and Processing on other legal bases remain unaffected.",
          "summary_ar": "تؤكد حق صاحب البيانات الشخصية في سحب موافقته في أي وقت، على أن يكون السحب بسهولة منحها أو أيسر، مع وضع إجراءات السحب مسبقاً. وعلى جهة التحكم التوقف عن المعالجة دون تأخير غير مبرر وإشعار من أُفصح لهم عن البيانات بطلب إتلافها، دون أن يؤثر السحب في مشروعية المعالجة السابقة أو المعالجة المستندة إلى أساس نظامي آخر.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 13",
          "label": "Legal Guardian",
          "label_ar": "الولي الشرعي",
          "summary": "Regulates how the legal guardian of a data subject lacking full or partial legal capacity exercises rights and consents to Processing in the subject's best interests. The Controller must verify guardianship validity, ensure the guardian's consent causes no harm, and let the data subject exercise rights upon reaching legal capacity.",
          "summary_ar": "تنظم قيام الولي الشرعي لصاحب البيانات الشخصية فاقد الأهلية كلياً أو جزئياً بممارسة حقوقه والموافقة على معالجة بياناته بما يحقق مصلحته الفضلى. وعلى جهة التحكم التحقق من صحة الولاية، وضمان ألا تُلحق موافقة الولي ضرراً بمصالح صاحب البيانات، وتمكينه من ممارسة حقوقه متى اكتسب الأهلية النظامية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 14",
          "label": "Processing for Actual Interest",
          "label_ar": "المعالجة لتحقيق المصلحة الفعلية",
          "summary": "When Processing Personal Data to serve the data subject's Actual Interest, the Controller must retain evidence demonstrating both that the actual interest exists and that it is not possible to contact or communicate with the data subject.",
          "summary_ar": "عند معالجة البيانات الشخصية لتحقيق مصلحة فعلية لصاحب البيانات الشخصية، يجب على جهة التحكم الاحتفاظ بما يُثبت قيام تلك المصلحة وتعذُّر الاتصال أو التواصل مع صاحب البيانات الشخصية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 15",
          "label": "Collecting Data from Third Parties",
          "label_ar": "جمع البيانات من طرف ثالث",
          "summary": "Governs Processing of Personal Data collected from sources other than the data subject: Processing must be necessary, proportionate to the purpose, and must not affect the data subject's rights and interests. Collection from publicly available sources must be lawful, and the Regulation's anonymisation provisions apply where relevant.",
          "summary_ar": "تنظم معالجة البيانات الشخصية المجموعة من مصادر غير صاحب البيانات الشخصية مباشرةً؛ فيجب أن تكون المعالجة ضرورية ومتناسبة مع الغرض المحدد، وألا تؤثر في حقوق صاحب البيانات ومصالحه، مع التحقق من مشروعية الجمع من المصادر المتاحة للعموم، ومراعاة أحكام إخفاء الهوية الواردة في اللائحة عند الاقتضاء.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 16",
          "label": "Processing for Legitimate Interest",
          "label_ar": "المعالجة لتحقيق المصلحة المشروعة",
          "summary": "Permits Controllers other than Public Entities to process Personal Data for a Legitimate Interest, provided the purpose is lawful, interests are balanced against the data subject's rights, no Sensitive Data is involved, and Processing is within reasonable expectations. A documented prior assessment is required, with modification if harm is indicated.",
          "summary_ar": "تجيز لجهات التحكم - عدا الجهات العامة - معالجة البيانات الشخصية لتحقيق مصلحة مشروعة، بشرط ألا يخالف الغرض أنظمة المملكة، وتحقيق الموازنة بين مصلحة جهة التحكم وحقوق صاحب البيانات الشخصية ومصالحه، وألا تشمل المعالجة بيانات حساسة، وأن تكون ضمن التوقعات المعقولة لصاحب البيانات. ويلزم إجراء تقييم موثق قبل المعالجة، وتعديل المعالجة أو الاستناد إلى أساس آخر إذا تبين احتمال الضرر.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 17",
          "label": "Processor Selection",
          "label_ar": "اختيار جهة المعالجة",
          "summary": "Requires the Controller to select Processors offering sufficient guarantees and to conclude agreements covering purpose, data categories, duration, breach notification, and subcontractors. The Controller must issue instructions and periodically assess compliance; a Processor breaching instructions is treated as a Controller, and subcontracting requires guarantees and the Controller's prior acceptance.",
          "summary_ar": "توجب على جهة التحكم اختيار جهة معالجة تقدم ضمانات كافية لحماية البيانات الشخصية، وأن يتضمن الاتفاق بينهما الغرض من المعالجة وفئات البيانات ومدتها والالتزام بالإشعار عن حوادث تسرب البيانات وتحديد المتعاقدين من الباطن. وعلى جهة التحكم إصدار تعليمات واضحة وتقييم امتثال جهة المعالجة دورياً، وتُعد جهة المعالجة المخالفة للتعليمات أو الاتفاق جهة تحكم مسؤولة مباشرةً، ويشترط للتعاقد من الباطن ضمانات كافية وقبول مسبق من جهة التحكم.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 18",
          "label": "Processing Beyond Original Purpose",
          "label_ar": "المعالجة لغرض مغاير لغرض الجمع",
          "summary": "Applies when Personal Data is processed for a purpose other than the one for which it was collected: the Controller must clearly define the new purposes, record them in Processing activity records, document data-scoping procedures such as data maps, and limit Processing to the minimum data necessary.",
          "summary_ar": "تسري عند معالجة البيانات الشخصية لغرض غير الغرض الذي جُمعت من أجله؛ إذ يجب على جهة التحكم تحديد أغراض المعالجة بوضوح ودقة، وتدوينها في سجلات أنشطة معالجة البيانات الشخصية، وتوثيق إجراءات تحديد نطاق البيانات محل المعالجة بوسائل منها خرائط البيانات، وقصر الجمع والمعالجة على الحد الأدنى اللازم لتحقيق الغرض.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 19",
          "label": "Data Minimisation",
          "label_ar": "الحد الأدنى من البيانات",
          "summary": "Requires the Controller to collect only the minimum Personal Data necessary to achieve the Processing purpose, using appropriate means such as data maps to link each collected item to a purpose, to avoid collecting unnecessary data, and to retain only the minimal data needed for the purpose.",
          "summary_ar": "توجب على جهة التحكم الاقتصار على جمع الحد الأدنى من البيانات الشخصية اللازمة لتحقيق غرض المعالجة، باستخدام وسائل مناسبة منها خرائط البيانات التي تربط كل بيان مجموع بغرض المعالجة، وتجنب جمع بيانات غير ضرورية، والاحتفاظ بالحد الأدنى من البيانات اللازمة لتحقيق الغرض.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 20",
          "label": "Disclosure of Personal Data",
          "label_ar": "الإفصاح عن البيانات الشخصية",
          "summary": "Sets controls for disclosing Personal Data, including data from publicly available sources: disclosure must relate to a specific, clear purpose, protect privacy, and be limited to the minimum necessary. Disclosure requests from public authorities must be documented, third-party data safeguarded through balancing and pseudonymisation, and all disclosure operations recorded with dates, methods, and purposes.",
          "summary_ar": "تضع ضوابط الإفصاح عن البيانات الشخصية بما فيها البيانات المجموعة من مصادر متاحة للعموم؛ فيجب أن يرتبط الإفصاح بغرض محدد وواضح، مع العناية اللازمة بحماية خصوصية صاحب البيانات الشخصية، وقصره على الحد الأدنى اللازم. ويجب توثيق طلبات الإفصاح المقدمة من الجهات العامة، وحماية بيانات الغير بالموازنة بين الحقوق والترميز حيثما أمكن، وتدوين عمليات الإفصاح وتواريخها ووسائلها وأغراضها في سجلات أنشطة المعالجة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 21",
          "label": "Public Interest Processing Controls",
          "label_ar": "ضوابط المعالجة لأغراض المصلحة العامة",
          "summary": "Applies when a Public Entity collects Personal Data indirectly, processes it for a new purpose, or requests disclosure to achieve a public interest. The entity must ensure necessity for a clearly defined public interest within its mandate, limit potential damage, record the operations, and process only the minimum data.",
          "summary_ar": "تسري عندما تجمع جهة عامة بيانات شخصية من غير صاحبها مباشرةً، أو تعالجها لغرض مغاير لغرض جمعها، أو تطلب الإفصاح عنها لتحقيق مصلحة عامة؛ إذ يجب التحقق من ضرورة ذلك لتحقيق مصلحة عامة محددة بوضوح ترتبط باختصاص الجهة، واتخاذ تدابير مناسبة للحد من الضرر المحتمل، وتدوين تلك العمليات في سجلات أنشطة المعالجة، والاقتصار على الحد الأدنى من البيانات.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 22",
          "label": "Correction of Personal Data",
          "label_ar": "تصحيح البيانات الشخصية",
          "summary": "Details the Controller's correction duties: correcting inaccurate data, completing incomplete data, and updating outdated data. The Controller must verify accuracy, notify prior recipients and the data subject, document updates, suspend Processing where inaccurate data may cause harm, and maintain policies and periodic reviews of data accuracy.",
          "summary_ar": "تفصّل واجبات جهة التحكم في التصحيح، ويشمل تصحيح البيانات غير الصحيحة وإكمال الناقصة وتحديث القديمة. وعليها التحقق من دقة البيانات وسلامتها، وإشعار من سبق الإفصاح لهم عنها وإشعار صاحب البيانات الشخصية عند اكتمال التصحيح، وتوثيق التحديثات، وتعليق المعالجة إذا كان من شأن البيانات غير الدقيقة إلحاق ضرر بصاحبها، ووضع سياسات داخلية ومراجعة دورية لدقة البيانات وحداثتها.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 23",
          "label": "Information Security",
          "label_ar": "أمن المعلومات",
          "summary": "Requires the Controller to take organisational, administrative, and technical measures to secure Personal Data and protect privacy, including security measures limiting breach risks and adopting the controls, standards, and rules of the National Cybersecurity Authority, or recognised cybersecurity best practices where those rules are not mandatory for the Controller.",
          "summary_ar": "توجب على جهة التحكم اتخاذ التدابير التنظيمية والإدارية والتقنية اللازمة لضمان أمن البيانات الشخصية وخصوصية أصحابها، بما في ذلك تطبيق التدابير الأمنية والتقنية للحد من مخاطر تسرب البيانات، واعتماد الضوابط والمعايير والقواعد الصادرة عن الهيئة الوطنية للأمن السيبراني، أو أفضل الممارسات والمعايير المعتمدة في الأمن السيبراني إذا لم تكن جهة التحكم ملزمة بها.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 26",
          "label": "Processing Health Data",
          "label_ar": "معالجة البيانات الصحية",
          "summary": "Obliges the Controller to protect Health Data through organisational, technical, and administrative measures, adopting requirements of health and insurance regulators, embedding the Law in internal policies, segregating staff responsibilities with tiered access, documenting all Processing stages, binding Processors contractually, and limiting Processing to the minimum needed for healthcare or health insurance.",
          "summary_ar": "تلزم جهة التحكم بحماية البيانات الصحية عبر تدابير تنظيمية وتقنية وإدارية، تشمل اعتماد المتطلبات والضوابط الصادرة عن وزارة الصحة والمجلس الصحي السعودي والبنك المركزي السعودي ومجلس الضمان الصحي والجهات ذات العلاقة، وتضمين أحكام النظام ولوائحه في السياسات الداخلية، وتوزيع المهام والمسؤوليات بما يمنع تداخل الاختصاصات مع تفاوت مستويات الوصول، وتوثيق جميع مراحل المعالجة، وإلزام جهات المعالجة تعاقدياً، وقصر معالجة البيانات الصحية على الحد الأدنى اللازم لتقديم الخدمات الصحية أو برامج التأمين الصحي.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 27",
          "label": "Processing Credit Data",
          "label_ar": "معالجة البيانات الائتمانية",
          "summary": "Requires the Controller, without prejudice to the Credit Information Law, to protect Credit Data from unauthorised use, access, or disclosure by adopting requirements of the Saudi Central Bank and relevant authorities, and to obtain the data subject's consent and notify them of any request to disclose their Credit Data.",
          "summary_ar": "توجب على جهة التحكم - دون إخلال بنظام المعلومات الائتمانية - حماية البيانات الائتمانية من الاستخدام أو الوصول أو الإفصاح غير المصرح به، باعتماد المتطلبات والضوابط الصادرة عن البنك المركزي السعودي والجهات ذات العلاقة، والحصول على موافقة صاحب البيانات الشخصية وإشعاره عند أي طلب للإفصاح عن بياناته الائتمانية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 28",
          "label": "Advertising and Awareness Materials",
          "label_ar": "المواد الإعلانية أو التوعوية",
          "summary": "Regulates sending advertising or awareness materials: prior consent of the targeted recipient is required absent previous interaction, consent must be free, specific, and documented, the sender's identity must be clearly stated, and recipients must be able to halt such materials easily, immediately, and free of charge.",
          "summary_ar": "تنظم إرسال المواد الإعلانية أو التوعوية؛ إذ يجب الحصول على موافقة المستهدف مسبقاً عند عدم وجود تعامل سابق مع جهة التحكم، وأن تكون الموافقة حرة ومحددة وموثقة بما يتيح التحقق منها، مع الإفصاح بوضوح عن هوية المرسل، وتوفير آلية تمكّن المستهدف من إيقاف استقبال تلك المواد بسهولة وبشكل فوري ودون مقابل.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 29",
          "label": "Direct Marketing",
          "label_ar": "التسويق المباشر",
          "summary": "Requires the Controller, before Processing Personal Data for Direct Marketing, to obtain the data subject's consent and provide a mechanism to halt marketing material that is as simple as giving consent. The sender's identity must be clearly disclosed, and marketing must stop without undue delay upon consent withdrawal.",
          "summary_ar": "توجب على جهة التحكم قبل معالجة البيانات الشخصية لأغراض التسويق المباشر الحصول على موافقة صاحب البيانات الشخصية، وتوفير آلية لإيقاف استقبال المواد التسويقية لا تقل سهولةً عن إجراءات منح الموافقة، مع الإفصاح بوضوح عن هوية المرسل، والتوقف عن إرسال المواد التسويقية دون تأخير غير مبرر عند سحب الموافقة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 30",
          "label": "Scientific, Research or Statistical Purposes",
          "label_ar": "الأغراض العلمية أو البحثية أو الإحصائية",
          "summary": "Governs collecting or Processing Personal Data for scientific, research, or statistical purposes without the data subject's consent: purposes must be clearly specified in Processing records, only the minimum necessary data collected, data pseudonymised where the purposes can still be fulfilled, and any negative impact on the data subject's rights avoided.",
          "summary_ar": "تنظم جمع البيانات الشخصية أو معالجتها لأغراض علمية أو بحثية أو إحصائية دون موافقة صاحب البيانات الشخصية؛ إذ يجب تحديد تلك الأغراض بوضوح ودقة في سجلات أنشطة المعالجة، والاقتصار على الحد الأدنى اللازم من البيانات، وترميز البيانات محل المعالجة متى أمكن تحقيق الأغراض بذلك، واتخاذ التدابير اللازمة لضمان عدم تأثير المعالجة سلباً في حقوق صاحب البيانات ومصالحه.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 31",
          "label": "Photographing or Copying Official Documents",
          "label_ar": "تصوير الوثائق الرسمية أو نسخها",
          "summary": "Prohibits the Controller from photographing or copying official documents issued by Public Entities that identify data subjects, except at the request of a public competent authority or to fulfil a legal requirement. Such documents must be protected and destroyed once their purpose ends, unless retention is legally required.",
          "summary_ar": "تحظر على جهة التحكم تصوير الوثائق الرسمية الصادرة عن الجهات العامة التي تكشف هوية صاحب البيانات الشخصية أو نسخها، إلا بناءً على طلب من جهة عامة مختصة أو استيفاءً لمتطلب نظامي. ويجب توفير الحماية اللازمة لتلك الوثائق وإتلافها فور انتهاء الغرض من الحصول عليها ما لم يوجد متطلب نظامي يقضي بالاحتفاظ بها.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 35",
          "label": "Accreditation Bodies",
          "label_ar": "جهات الاعتماد",
          "summary": "Tasks the competent authority with issuing regulatory rules for licensing entities that grant accreditation certificates to Controllers and Processors under Article 33 of the Law, and with coordinating with the Digital Government Authority on licensing entities that provide such services on behalf of government entities.",
          "summary_ar": "تُسند إلى الجهة المختصة إصدار القواعد المنظمة للترخيص للجهات التي تصدر شهادات الاعتماد لجهات التحكم وجهات المعالجة وفقاً للمادة (33) من النظام، والتنسيق مع هيئة الحكومة الرقمية فيما يتعلق بالترخيص للجهات التي تقدم هذه الخدمات نيابةً عن الجهات الحكومية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 37",
          "label": "Submitting and Processing Complaints",
          "label_ar": "تقديم الشكاوى ومعالجتها",
          "summary": "Allows a data subject to file a complaint with the competent authority within 90 days of the incident or of becoming aware of it, with late complaints admissible for reasonable causes. The authority must register, examine, and act on complaints and inform the complainant of the outcome.",
          "summary_ar": "تجيز لصاحب البيانات الشخصية تقديم شكوى إلى الجهة المختصة خلال مدة لا تتجاوز (90) يوماً من تاريخ وقوع الحادثة أو العلم بها، مع جواز قبول الشكاوى المتأخرة لأسباب معقولة. وتتولى الجهة المختصة استقبال الشكاوى وقيدها في سجل مخصص ودراستها واتخاذ الإجراءات اللازمة بشأنها وإبلاغ مقدم الشكوى بالنتيجة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 38",
          "label": "Publication and Enforcement",
          "label_ar": "النشر والنفاذ",
          "summary": "Provides that the Regulation shall be published in the official gazette and on the competent authority's official website, and shall come into force from the date of the Law's enforcement.",
          "summary_ar": "تقضي بنشر اللائحة التنفيذية في الجريدة الرسمية وفي الموقع الإلكتروني الرسمي للجهة المختصة، وبأن يُعمل بها من تاريخ العمل بالنظام.",
          "parent": null,
          "official_anchor": null
        }
      ]
    },
    {
      "slug": "payment-services-provider-regulations",
      "name": "PAYMENT SERVICES PROVIDER REGULATIONS",
      "name_ar": "لائحة مقدمي خدمات المدفوعات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Regulation",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/payment-services-provider-regulations",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "freedom-of-information-policy",
      "name": "Freedom of Information Policy",
      "name_ar": "سياسة حرية المعلومات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Government freedom-of-information policy.",
      "summary_ar": "السياسة الحكومية لحرية المعلومات.",
      "type": "Regulation",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/FreedomOfInformationPolicy.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/freedom-of-information-policy",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "transfer-regulation",
      "name": "Regulation on Personal Data Transfer Outside KSA",
      "name_ar": "لائحة نقل البيانات الشخصية خارج المملكة العربية السعودية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Regulation on Personal Data Transfer Outside the Kingdom operationalises PDPL Article 29. First issued in September 2023, it was reissued as **version 2.0 in September 2024**, and SDAIA published Standard Contractual Clauses and a transfer risk-assessment guideline to support it.\n\n**How transfers work.** A transfer or disclosure outside the Kingdom needs a permitted purpose — the Law's purposes (a Kingdom treaty obligation, the Kingdom's interests, an obligation the data subject is party to) extended by Article 2 to central processing operations, providing a service or benefit to the data subject, and scientific research. SDAIA is to publish and review — every four years or as needed — a list of countries and organisations providing an adequate level of protection (Art. 3); pending that list, transfers rely in practice on Article 4's exemptions, which require **appropriate safeguards**: SDAIA's Standard Contractual Clauses, Binding Common Rules for corporate groups, or an accreditation certificate. The Law and Regulation continue to apply to any onward transfer (Art. 5), exemptions lapse if safeguards fail (Art. 6), and a documented **risk assessment** is required before transfers under the exemptions and for continuous or large-scale transfers of sensitive data (Art. 7).\n\n## Frequently asked questions\n\n**Do we need SDAIA's approval for each transfer?**\n\nNo. There is no per-transfer approval requirement. The controller must have a permitted purpose (PDPL Art. 29; Transfer Regulation Art. 2), meet the conditions or fall within an Article 4 exemption backed by appropriate safeguards, and document a risk assessment where Article 7 requires one.\n\n**Is there a Saudi adequacy list?**\n\nArticle 3 directs the competent authority to publish a list of countries and international organisations with an adequate level of protection, reviewed every four years or as necessary. As of mid-2026 no list had been published, so transfers in practice proceed under the Article 4 exemptions with appropriate safeguards.\n\n**Which safeguards are recognised?**\n\nArticle 4 recognises three: Standard Contractual Clauses issued by SDAIA (published September 2024), Binding Common Rules for transfers within a corporate group, and accreditation certificates issued by licensed bodies. EU-style SCCs are not a recognised Saudi safeguard.\n\n**When is a transfer risk assessment mandatory?**\n\nArticle 7 requires one before transferring or disclosing personal data under the Article 4 exemptions, and whenever sensitive data is transferred on a continuous or wide-scale basis. The assessment covers the purpose and legal basis, the nature and scope of the transfer, the safeguards applied, data minimisation, the potential effects and their likelihood, and mitigation measures.",
      "summary_ar": "تضع لائحة نقل البيانات الشخصية إلى خارج المملكة المادة (29) من نظام حماية البيانات الشخصية موضع التطبيق العملي. وقد صدرت اللائحة أول مرة في سبتمبر 2023، ثم أُعيد إصدارها **بالإصدار 2.0 في سبتمبر 2024**، ونشرت سدايا البنود التعاقدية القياسية ودليلًا استرشاديًا لتقييم مخاطر النقل دعمًا لتطبيقها.\n\n**آلية النقل.** يتطلب نقل البيانات الشخصية إلى خارج المملكة أو الإفصاح عنها لجهة خارجها وجود غرض مسموح به — فالأغراض المقررة في النظام (تنفيذ التزام بموجب اتفاقية تكون المملكة طرفًا فيها، أو خدمة مصالح المملكة، أو تنفيذ التزام يكون صاحب البيانات الشخصية طرفًا فيه) وسّعتها المادة (2) لتشمل عمليات المعالجة المركزية، وتقديم خدمة أو منفعة لصاحب البيانات الشخصية، والبحث العلمي. وعلى سدايا أن تنشر وتراجع — كل أربع سنوات أو كلما دعت الحاجة — قائمة بالدول والمنظمات التي توفر مستوى مناسبًا من الحماية (المادة (3))؛ وإلى حين صدور تلك القائمة تستند عمليات النقل عمليًا إلى الاستثناءات الواردة في المادة (4)، التي تشترط **ضمانات مناسبة**: البنود التعاقدية القياسية الصادرة عن سدايا، أو القواعد المشتركة الملزمة لمجموعات الشركات، أو شهادة اعتماد. ويظل النظام واللائحة ساريين على أي نقل لاحق للبيانات (المادة (5))، وتسقط الاستثناءات متى اختلت الضمانات (المادة (6))، ويلزم إجراء **تقييم مخاطر** موثق قبل عمليات النقل المستندة إلى الاستثناءات، وكذلك في حالات النقل المستمر أو الواسع النطاق للبيانات الحساسة (المادة (7)).\n\n## الأسئلة الشائعة\n\n**هل نحتاج إلى موافقة سدايا على كل عملية نقل؟**\n\nلا. لا يوجد اشتراط للحصول على موافقة لكل عملية نقل على حدة. وإنما يجب على جهة التحكم أن يتوافر لديها غرض مسموح به (المادة (29) من نظام حماية البيانات الشخصية؛ والمادة (2) من لائحة نقل البيانات الشخصية إلى خارج المملكة)، وأن تستوفي الشروط المقررة أو تندرج ضمن أحد الاستثناءات الواردة في المادة (4) مدعومًا بضمانات مناسبة، وأن توثق تقييمًا للمخاطر متى أوجبته المادة (7).\n\n**هل توجد قائمة سعودية بالدول ذات مستوى الحماية المناسب؟**\n\nتوجب المادة (3) على الجهة المختصة نشر قائمة بالدول والمنظمات الدولية التي توفر مستوى مناسبًا من الحماية، على أن تُراجَع كل أربع سنوات أو عند الاقتضاء. وحتى منتصف عام 2026 لم تكن أي قائمة قد نُشرت؛ ولذلك تجري عمليات النقل عمليًا استنادًا إلى الاستثناءات الواردة في المادة (4) مع توافر الضمانات المناسبة.\n\n**ما الضمانات المعترف بها؟**\n\nتعترف المادة (4) بثلاث ضمانات: البنود التعاقدية القياسية الصادرة عن سدايا (نُشرت في سبتمبر 2024)، والقواعد المشتركة الملزمة لعمليات النقل داخل مجموعة الشركات الواحدة، وشهادات الاعتماد الصادرة عن الجهات المرخص لها. أما البنود التعاقدية القياسية على النمط الأوروبي فلا تُعد ضمانة معترفًا بها في المملكة.\n\n**متى يكون تقييم مخاطر النقل إلزاميًا؟**\n\nتوجب المادة (7) إجراء التقييم قبل نقل البيانات الشخصية أو الإفصاح عنها بموجب الاستثناءات الواردة في المادة (4)، وكذلك كلما جرى نقل بيانات حساسة بصورة مستمرة أو على نطاق واسع. ويغطي التقييم الغرض والأساس النظامي، وطبيعة عملية النقل ونطاقها، والضمانات المطبقة، والاقتصار على الحد الأدنى من البيانات، والآثار المحتملة ومدى احتمال وقوعها، وتدابير التخفيف منها.",
      "type": "Implementing Regulation",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "pdpl-law",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/RegulationonPersonalDataEN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/transfer-regulation",
      "date_note": "Updated 2024",
      "date_note_ar": "محدَّثة 2024",
      "provisions": [
        {
          "kind": "article",
          "code": "Art. 1",
          "label": "Definitions",
          "label_ar": "التعريفات",
          "summary": "Adopts the definitions of Article 1 of the Personal Data Protection Law and defines terms specific to this Regulation, including Appropriate Safeguards, Operational Processes, Standard Contractual Clauses, and Binding Common Rules applicable to transfers of personal data outside the Kingdom.",
          "summary_ar": "تعتمد التعريفات الواردة في المادة الأولى من نظام حماية البيانات الشخصية، وتحدد معاني مصطلحات خاصة بهذه اللائحة، منها الضمانات المناسبة، والعمليات التشغيلية، والبنود التعاقدية القياسية، والقواعد المشتركة الملزمة، فيما يتعلق بنقل البيانات الشخصية إلى خارج المملكة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 2",
          "label": "Other Purposes for Transfer",
          "label_ar": "أغراض أخرى لنقل البيانات",
          "summary": "Specifies additional purposes for transferring or disclosing personal data to a party outside the Kingdom under Article 29 of the Law, including performing central processing operations necessary for the controller's activities, providing a service or benefit to the data subject, and conducting scientific research and studies.",
          "summary_ar": "تحدد أغراضاً أخرى لنقل البيانات الشخصية أو الإفصاح عنها لجهة خارج المملكة وفقاً للمادة (29) من النظام، ومنها تنفيذ العمليات اللازمة للمعالجة المركزية بما يمكّن جهة التحكم من مزاولة نشاطها، وتقديم خدمة أو منفعة لصاحب البيانات الشخصية، وإجراء البحوث والدراسات العلمية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 3",
          "label": "Adequacy Assessment",
          "label_ar": "تقييم مستوى الحماية خارج المملكة",
          "summary": "Requires the competent authority to publish, and review every four years or as necessary, a list of countries and international organisations providing an adequate level of personal data protection, based on criteria including legislation, supervisory bodies, and cooperation. The authority may amend the list or suspend transfers; the standards also apply to cities, special economic zones, and global trade centres.",
          "summary_ar": "توجب على الجهة المختصة نشر قائمة بالدول والمنظمات الدولية التي توفر مستوى مناسباً لحماية البيانات الشخصية ومراجعتها كل أربع سنوات أو عند الحاجة، وفق معايير منها وجود تنظيمات لحماية البيانات، وجهة إشرافية معنية بإنفاذها، واستعدادها للتعاون مع الجهة المختصة. ويجوز للجهة المختصة تعديل القائمة أو تعليق النقل، وتسري المعايير أيضاً على المدن والمناطق الاقتصادية الخاصة والمراكز التجارية العالمية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 4",
          "label": "Exemptions and Appropriate Safeguards",
          "label_ar": "حالات الإعفاء والضمانات المناسبة",
          "summary": "Exempts controllers, in defined cases, from the adequacy and data-minimisation conditions of Article 29 of the Law, provided appropriate safeguards apply: standard contractual clauses, binding common rules, or accreditation certificates. Cases cover public-body agreements, limited transfers, multinational central operations, services to data subjects, and scientific research; the competent authority may review the safeguards every two years or as necessary.",
          "summary_ar": "تعفي جهة التحكم في حالات محددة من شرطي توفر المستوى المناسب من الحماية والحد الأدنى من البيانات المنصوص عليهما في المادة (29) من النظام أو من أحدهما، شريطة تطبيق ضمانات مناسبة تشمل البنود التعاقدية القياسية أو القواعد المشتركة الملزمة أو شهادات الاعتماد. وتشمل الحالات الاتفاقيات بين الجهات العامة، والنقل غير المتكرر المحدود، والعمليات المركزية لمجموعات الكيانات متعددة الجنسيات، وتقديم خدمة أو منفعة لصاحب البيانات الشخصية، والبحث العلمي، مع مراجعة الجهة المختصة لكفاية الضمانات كل سنتين أو عند الحاجة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 5",
          "label": "Subsequent Transfers of Personal Data",
          "label_ar": "النقل اللاحق للبيانات الشخصية",
          "summary": "Provides that the Law and its Regulations continue to apply to any subsequent transfer of personal data that has already been transferred or disclosed to a party outside the Kingdom, without prejudice to Articles 8 and 15 of the Law and Article 17 of the Implementing Regulation.",
          "summary_ar": "تقضي باستمرار سريان النظام ولوائحه على عمليات النقل اللاحق للبيانات الشخصية التي سبق نقلها أو الإفصاح عنها لجهة خارج المملكة، وذلك دون إخلال بأحكام المادتين (8) و(15) من النظام والمادة (17) من اللائحة التنفيذية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 6",
          "label": "Revocation of Exemption",
          "label_ar": "إلغاء الإعفاء",
          "summary": "Terminates exemptions granted under Article 4 of the Regulation where the controller fails to implement the appropriate safeguards or the competent authority finds those safeguards inadequate in a specific case. The controller must then halt the transfer or disclosure and notify the entities that received the personal data.",
          "summary_ar": "تقضي بعدم سريان أي من الإعفاءات الممنوحة وفقاً للمادة (4) من اللائحة إذا أخفقت جهة التحكم في تطبيق الضمانات المناسبة، أو إذا قررت الجهة المختصة عدم كفاية تلك الضمانات في حالة معينة. وعلى جهة التحكم عندئذٍ إيقاف النقل أو الإفصاح وإشعار الجهات التي نُقلت إليها البيانات الشخصية أو أُفصح لها عنها.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 7",
          "label": "Risk Assessment for Transfers",
          "label_ar": "تقييم مخاطر النقل",
          "summary": "Requires the controller to conduct a risk assessment before transferring or disclosing personal data outside the Kingdom under Article 4 exemptions, or when transferring sensitive data continuously or widely. The assessment covers purpose, legal basis, nature and scope, safeguards, data minimisation, potential effects and their likelihood, and mitigation measures.",
          "summary_ar": "توجب على جهة التحكم إجراء تقييم للمخاطر قبل نقل البيانات الشخصية أو الإفصاح عنها لجهة خارج المملكة في حالات الإعفاء وفقاً للمادة (4) من اللائحة، وعند نقل البيانات الحساسة بصفة مستمرة أو واسعة النطاق. ويشمل التقييم الغرض والأساس النظامي، ووصف طبيعة النقل ونطاقه الجغرافي، والضمانات المناسبة ومدى كفايتها، وتدابير الاقتصار على الحد الأدنى من البيانات، والآثار المادية والمعنوية المحتملة واحتمالية وقوعها، والتدابير اللازمة لمنع المخاطر أو الحد من آثارها.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 8",
          "label": "Guides and Guidelines",
          "label_ar": "الأدلة والإرشادات",
          "summary": "Directs the competent authority to issue guides and guidelines related to the provisions of this Regulation on the transfer of personal data outside the Kingdom.",
          "summary_ar": "تقضي بأن تصدر الجهة المختصة الأدلة والإرشادات المتعلقة بالأحكام الواردة في هذه اللائحة الخاصة بنقل البيانات الشخصية إلى خارج المملكة.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "article",
          "code": "Art. 9",
          "label": "Entry into Force",
          "label_ar": "النفاذ",
          "summary": "The Regulation enters into force on the date of its publication in the Official Gazette.",
          "summary_ar": "يُعمل باللائحة من تاريخ نشرها في الجريدة الرسمية.",
          "parent": null,
          "official_anchor": null
        }
      ]
    },
    {
      "slug": "data-classification-policy",
      "name": "Data Classification Policy",
      "name_ar": "سياسة تصنيف البيانات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NDMO national data-classification policy (Top Secret / Secret / Confidential / Public).",
      "summary_ar": "سياسة التصنيف الوطنية للبيانات الصادرة عن مكتب إدارة البيانات الوطني NDMO (سري للغاية / سري / مقيّد / عام).",
      "type": "Standard",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/DataClassificationPolicy.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/data-classification-policy",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "open-data-policy",
      "name": "Open Data Policy",
      "name_ar": "سياسة البيانات المفتوحة",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NDMO open-data policy for government entities.",
      "summary_ar": "سياسة البيانات المفتوحة الصادرة عن مكتب إدارة البيانات الوطني NDMO للجهات الحكومية.",
      "type": "Regulation",
      "tier": 3,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/OpenDataPolicy.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/open-data-policy",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "nca-cybersecurity-toolkits",
      "name": "NCA Cybersecurity Toolkits",
      "name_ar": "أدوات الأمن السيبراني الصادرة عن NCA",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/nca-cybersecurity-toolkits",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ai-adoption-framework",
      "name": "AI Adoption Framework",
      "name_ar": "إطار تبنّي الذكاء الاصطناعي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Framework for AI adoption.",
      "summary_ar": "إطار لتبنّي الذكاء الاصطناعي.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/AIAdoptionFramework.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/ai-adoption-framework",
      "date_note": "2024",
      "date_note_ar": "2024",
      "provisions": []
    },
    {
      "slug": "dpo-appointment-rules",
      "name": "Rules for Appointing a DPO",
      "name_ar": "قواعد تعيين مسؤول حماية البيانات (DPO)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Rules on when and how to appoint a Data Protection Officer. May be folded into the amended Implementing Regulation.",
      "summary_ar": "قواعد بشأن متى وكيف يُعيَّن مسؤول حماية البيانات (DPO). وقد تُدمَج ضمن اللائحة التنفيذية المعدّلة.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/RulesforAppointingPersonalDataProtectionOfficer.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/dpo-appointment-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ndi",
      "name": "National Data Index (NDI)",
      "name_ar": "المؤشر الوطني للبيانات (NDI)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The **National Data Index (NDI)** is SDAIA's dynamic, results-oriented monitoring and evaluation index that assesses government entities across three lenses:\n\n- **DM Maturity** — how well an entity applies best practices across **14 data-management domains** (people, technology, processes), with improvement recommendations.\n- **DM & PDP Standards Compliance** — adoption and implementation of the NDMO Data Management and Personal Data Protection Standards.\n- **Operational Excellence (OE)** — progress in leveraging the National Data Platforms across **6 DM domains**.\n\nAssessments are measured and audited periodically via the NDI platform. The NDI supports Vision 2030 by strengthening data governance, data quality, lifecycle management, compliance reporting and a data-driven culture across the Kingdom.",
      "summary_ar": "**المؤشر الوطني للبيانات (NDI)** هو مؤشر الرصد والتقييم الديناميكي والموجَّه نحو النتائج التابع لـSDAIA، والذي يقيّم الجهات الحكومية عبر ثلاثة محاور:\n\n- **نضج إدارة البيانات** — مدى تطبيق الجهة للممارسات المثلى عبر **14 مجالًا من مجالات إدارة البيانات** (الأشخاص والتقنية والعمليات)، مع توصيات للتحسين.\n- **الامتثال لمعايير إدارة البيانات وحماية البيانات الشخصية** — تبنّي وتطبيق معايير إدارة البيانات وحماية البيانات الشخصية الصادرة عن مكتب إدارة البيانات الوطني NDMO.\n- **التميّز التشغيلي (OE)** — التقدّم في الاستفادة من المنصات الوطنية للبيانات عبر **6 من مجالات إدارة البيانات**.\n\nتُقاس عمليات التقييم وتُدقَّق دوريًا عبر منصة المؤشر الوطني للبيانات NDI. ويدعم المؤشر رؤية 2030 من خلال تعزيز حوكمة البيانات وجودة البيانات وإدارة دورة حياتها وإعداد تقارير الامتثال وترسيخ ثقافة قائمة على البيانات في جميع أنحاء المملكة.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/ndi",
      "date_note": null,
      "date_note_ar": null,
      "provisions": [
        {
          "kind": "section",
          "code": "Compliance",
          "label": "Compliance",
          "label_ar": "الالتزام",
          "summary": "Adherence to the NDMO Data Management & PDP specifications, assessed in phases. The NDI scores entities against the NDMO specifications — it does not define its own specification codes.",
          "summary_ar": "مدى الالتزام بمواصفات إدارة البيانات وحماية البيانات الشخصية الصادرة عن NDMO، ويُقيَّم على مراحل. يقيس المؤشر الجهات وفق مواصفات NDMO ولا يضع رموز مواصفات خاصة به.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "section",
          "code": "Maturity",
          "label": "Data Management Maturity (0–5)",
          "label_ar": "النضج (0–5)",
          "summary": "Maturity of data-management practice across the domains on a 0–5 scale (Absence of Capabilities → Pioneer), assessed via a questionnaire on the National Data Governance Platform.",
          "summary_ar": "نضج ممارسات إدارة البيانات عبر المجالات على مقياس 0–5 (غياب القدرات ← الريادة)، عبر استبيان على منصة حوكمة البيانات الوطنية.",
          "parent": null,
          "official_anchor": null
        },
        {
          "kind": "section",
          "code": "Operational Excellence",
          "label": "Operational Excellence",
          "label_ar": "التميّز التشغيلي",
          "summary": "Efficiency and effectiveness of data operations, drawn from national data platforms.",
          "summary_ar": "كفاءة وفعالية عمليات البيانات، مستمدة من منصات البيانات الوطنية.",
          "parent": null,
          "official_anchor": null
        }
      ]
    },
    {
      "slug": "ecc",
      "name": "Essential Cybersecurity Controls (ECC-2:2024)",
      "name_ar": "الضوابط الأساسية للأمن السيبراني (ECC-2:2024)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The NCA's baseline cybersecurity controls — 108 controls across 4 domains.",
      "summary_ar": "الضوابط الأساسية للأمن السيبراني الصادرة عن NCA — 108 ضابطًا موزّعة على 4 مجالات.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": "https://nca.gov.sa/en/regulatory-documents/controls-list/ecc/",
      "wadira_url": "https://www.wadiraksa.com/instrument/ecc",
      "date_note": "ECC-2:2024",
      "date_note_ar": "ECC-2:2024",
      "provisions": []
    },
    {
      "slug": "hie-policies",
      "name": "Health Information Exchange (HIE) Policies",
      "name_ar": "سياسات تبادل المعلومات الصحية (HIE)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "MOH policies for health information exchange.",
      "summary_ar": "سياسات وزارة الصحة (MOH) لتبادل المعلومات الصحية.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "health",
      "authority": "MOH",
      "parent": null,
      "in_library": true,
      "official_url": "https://nhic.gov.sa/standards/Policies/IS0303-Saudi-Health-Information-Exchange-Policies-v1.0.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/hie-policies",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "crf",
      "name": "Cybersecurity Regulatory Framework (CRF)",
      "name_ar": "الإطار التنظيمي للأمن السيبراني (CRF)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "CST cybersecurity regulatory framework for the ICT sector.",
      "summary_ar": "الإطار التنظيمي للأمن السيبراني الصادر عن هيئة الاتصالات والفضاء والتقنية (CST) لقطاع تقنية المعلومات والاتصالات.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "telecom",
      "authority": "CST",
      "parent": null,
      "in_library": true,
      "official_url": "https://www.cst.gov.sa/en/regulations-and-licenses/regulations/Document-413",
      "wadira_url": "https://www.wadiraksa.com/instrument/crf",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "national-register-controllers",
      "name": "Rules Governing the National Register of Controllers",
      "name_ar": "قواعد تنظيم السجل الوطني للمتحكمين",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Rules for the national register of data controllers.",
      "summary_ar": "قواعد السجل الوطني لجهات التحكم في البيانات.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/TheRulesGoverningTheNationalRegisterOfControllersWithinTheKingdomPublicEN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/national-register-controllers",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "sccs",
      "name": "Standard Contractual Clauses (SCCs)",
      "name_ar": "الشروط التعاقدية النموذجية (SCCs)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "SDAIA-issued standard contractual clauses for cross-border transfers.",
      "summary_ar": "بنود تعاقدية معيارية صادرة عن SDAIA لعمليات نقل البيانات عبر الحدود.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "transfer-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/StandardContractualClausesForPersonalDataTransferEN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/sccs",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "sama-outsourcing-rules",
      "name": "SAMA Rules on Outsourcing (Circular 2389)",
      "name_ar": "قواعد SAMA بشأن الإسناد إلى أطراف خارجية (التعميم 2389)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "SAMA rules governing outsourcing by regulated entities.",
      "summary_ar": "قواعد البنك المركزي السعودي (SAMA) المنظِّمة للإسناد (التعهيد) من قِبل الجهات الخاضعة للإشراف.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": "https://rulebook.sama.gov.sa/en/rules-outsourcing",
      "wadira_url": "https://www.wadiraksa.com/instrument/sama-outsourcing-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "health-data-rules",
      "name": "MOH Data Governance Policy",
      "name_ar": "سياسة حوكمة البيانات بوزارة الصحة (MOH)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "MOH rules for managing health data; health data is PDPL-sensitive.",
      "summary_ar": "قواعد وزارة الصحة (MOH) لإدارة البيانات الصحية؛ وتُعدّ البيانات الصحية بيانات حساسة بموجب نظام حماية البيانات الشخصية (PDPL).",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "health",
      "authority": "MOH",
      "parent": null,
      "in_library": true,
      "official_url": "https://www.moh.gov.sa/Ministry/OpenData/Documents/Data-Governance-Policy.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/health-data-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ndi-operational-excellence-oe",
      "name": "NDI — Operational Excellence (OE)",
      "name_ar": "المؤشر الوطني للبيانات (NDI) — التميز التشغيلي (OE)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/ndi-operational-excellence-oe",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cst-licensing",
      "name": "CST Licensing",
      "name_ar": "التراخيص الصادرة عن CST",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "CST telecom / ICT and cloud licensing.",
      "summary_ar": "تراخيص هيئة الاتصالات والفضاء والتقنية (CST) للاتصالات وتقنية المعلومات والخدمات السحابية.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "telecom",
      "authority": "CST",
      "parent": null,
      "in_library": false,
      "official_url": "https://www.cst.gov.sa/en/regulations-and-licenses",
      "wadira_url": "https://www.wadiraksa.com/instrument/cst-licensing",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ccc",
      "name": "Cloud Cybersecurity Controls (CCC-2:2024)",
      "name_ar": "ضوابط الأمن السيبراني للحوسبة السحابية (CCC-2:2024)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NCA controls for cloud service providers and their tenants.",
      "summary_ar": "ضوابط صادرة عن NCA لمزوّدي الخدمات السحابية ومستفيديها.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/ccc",
      "date_note": "CCC-2:2024",
      "date_note_ar": "CCC-2:2024",
      "provisions": []
    },
    {
      "slug": "regulations-documents-2",
      "name": "NCA Regulatory Documents (index)",
      "name_ar": "الوثائق التنظيمية للهيئة الوطنية للأمن السيبراني (NCA) (الفهرس)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/regulations-documents-2",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "secondary-use-rules",
      "name": "Rules for Secondary Use of Data",
      "name_ar": "قواعد الاستخدام الثانوي للبيانات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "General rules governing the secondary use of data.",
      "summary_ar": "القواعد العامة المنظِّمة للاستخدام الثانوي للبيانات.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/GeneralRulesForSecondaryUseOfData_EN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/secondary-use-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cscc",
      "name": "Critical Systems Cybersecurity Controls",
      "name_ar": "ضوابط الأمن السيبراني للأنظمة الحساسة",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NCA controls for organisations operating critical national systems.",
      "summary_ar": "ضوابط صادرة عن NCA للجهات التي تشغّل أنظمة وطنية حسّاسة.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cscc",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ndi-operational-excellence-faqs",
      "name": "NDI — Operational Excellence FAQs",
      "name_ar": "المؤشر الوطني للبيانات (NDI) — الأسئلة الشائعة حول التميز التشغيلي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/ndi-operational-excellence-faqs",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "financial-consumer-protection-principles-and-rules",
      "name": "Financial Consumer Protection Principles and Rules",
      "name_ar": "مبادئ وقواعد حماية المستهلك المالي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/financial-consumer-protection-principles-and-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "bcrs",
      "name": "Binding Common Rules (BCRs)",
      "name_ar": "القواعد الملزِمة المشتركة (BCRs)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Binding common rules as an intra-group transfer mechanism.",
      "summary_ar": "قواعد مُلزِمة مشتركة بوصفها آلية لنقل البيانات داخل المجموعة الواحدة.",
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "transfer-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/CommonRulesBCRForPersonalDataTransferEN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/bcrs",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "accreditation-certificate-rules",
      "name": "Rules Governing Issuance of Accreditation Certificates",
      "name_ar": "قواعد تنظيم إصدار شهادات الاعتماد",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Rules governing issuance and accreditation of certificates for controllers and processors.",
      "summary_ar": "قواعد إصدار شهادات الاعتماد لجهات التحكم وجهات المعالجة.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/RulesGoverningIssuanceAccreditationCertificatesControllersProcessers.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/accreditation-certificate-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cyber-resilience-fundamental-requirements-crfr",
      "name": "Cyber Resilience Fundamental Requirements (CRFR)",
      "name_ar": "المتطلبات الأساسية للمرونة السيبرانية (CRFR)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cyber-resilience-fundamental-requirements-crfr",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "otcc",
      "name": "Operational Technology Cybersecurity Controls",
      "name_ar": "ضوابط الأمن السيبراني للتقنية التشغيلية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NCA controls for OT / ICS environments.",
      "summary_ar": "ضوابط صادرة عن NCA لبيئات التقنية التشغيلية (OT) وأنظمة التحكم الصناعي (ICS).",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/otcc",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "controller-auditing-rules",
      "name": "Rules for Auditing & Inspecting Controllers and Processors",
      "name_ar": "قواعد تدقيق المتحكمين والمعالجين وتفتيشهم",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Rules for auditing and inspecting controllers/processors and their processing activities.",
      "summary_ar": "قواعد تدقيق وتفتيش جهات التحكم/جهات المعالجة وأنشطة المعالجة لديها.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/CertificatesControllersProcessorsAuditingInspectionPersonalDataProcessingActivities.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/controller-auditing-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "dcc",
      "name": "Data Cybersecurity Controls",
      "name_ar": "ضوابط الأمن السيبراني للبيانات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NCA controls for protecting data through its lifecycle.",
      "summary_ar": "ضوابط صادرة عن NCA لحماية البيانات عبر دورة حياتها.",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/dcc",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "committee-working-rules",
      "name": "Committee Working Rules",
      "name_ar": "قواعد عمل اللجنة",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Working rules of the relevant data-protection committee.",
      "summary_ar": "قواعد عمل لجنة حماية البيانات المختصة.",
      "type": "Rule",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/CommitteeWorkingRules.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/committee-working-rules",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "national-occupational-standard-framework-for-data-ai",
      "name": "National Occupational Standard Framework for Data & AI",
      "name_ar": "الإطار الوطني للمعايير المهنية للبيانات والذكاء الاصطناعي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Standard",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/File0002.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/national-occupational-standard-framework-for-data-ai",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "sama-4725",
      "name": "SAMA 4725",
      "name_ar": "SAMA 4725",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/sama-4725",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ncs",
      "name": "National Cryptographic Standards",
      "name_ar": "المعايير الوطنية للتشفير",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NCA cryptographic standards.",
      "summary_ar": "المعايير التشفيرية الصادرة عن NCA.",
      "type": "Standard",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/ncs",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ncnicc",
      "name": "Non-Critical National Infrastructure Cybersecurity Controls (NCNICC-1:2025)",
      "name_ar": "ضوابط الأمن السيبراني للبنى التحتية الوطنية غير الحساسة (NCNICC-1:2025)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "The Non-Critical National Infrastructure Cybersecurity Controls (NCNICC-1:2025) are the National Cybersecurity Authority's cybersecurity baseline for private-sector entities that are not classified as Critical National Infrastructure. They extend the NCA's ECC-derived control model to these entities across governance, defence and third-party/cloud domains. The controls are split into Category A (65 controls, for larger entities) and Category B (26 controls, for smaller entities).",
      "summary_ar": "ضوابط الأمن السيبراني للبنى التحتية الوطنية غير الحساسة (NCNICC-1:2025) هي الحد الأدنى من متطلبات الأمن السيبراني الذي تفرضه الهيئة الوطنية للأمن السيبراني على منشآت القطاع الخاص التي لا تُصنَّف ضمن البنى التحتية الوطنية الحساسة. وتوسّع هذه الضوابط نموذج الضوابط المشتق من الضوابط الأساسية للأمن السيبراني (ECC) ليشمل هذه المنشآت عبر مجالات الحوكمة والدفاع والأطراف الثالثة والحوسبة السحابية. وتنقسم إلى الفئة (أ) (65 ضابطًا للمنشآت الأكبر) والفئة (ب) (26 ضابطًا للمنشآت الأصغر).",
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": "https://nca.gov.sa/en/regulatory-documents/",
      "wadira_url": "https://www.wadiraksa.com/instrument/ncnicc",
      "date_note": "Issued by the NCA (NCNICC-1:2025), published January 2026",
      "date_note_ar": "صادرة عن الهيئة الوطنية للأمن السيبراني (NCNICC-1:2025)، نُشرت في يناير 2026",
      "provisions": []
    },
    {
      "slug": "sama-cyber-security-framework-csf",
      "name": "SAMA Cyber Security Framework (CSF)",
      "name_ar": "إطار الأمن السيبراني الصادر عن SAMA (CSF)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/sama-cyber-security-framework-csf",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "data-monetization-policy",
      "name": "Data Monetisation Policy",
      "name_ar": "سياسة تحقيق العائد من البيانات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "NDMO policy on monetising government data.",
      "summary_ar": "سياسة مكتب إدارة البيانات الوطني NDMO بشأن تحقيق العائد المالي من البيانات الحكومية.",
      "type": "Guideline",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/DataMonetizationPolicy.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/data-monetization-policy",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "saudi-academic-framework-for-ai-qualifications",
      "name": "Saudi Academic Framework for AI Qualifications",
      "name_ar": "الإطار الأكاديمي السعودي لمؤهلات الذكاء الاصطناعي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/File0003.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/saudi-academic-framework-for-ai-qualifications",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "guide-to-cloud-cybersecurity-controls-ccc-implementation",
      "name": "Guide to Cloud Cybersecurity Controls (CCC) Implementation",
      "name_ar": "دليل تطبيق ضوابط الأمن السيبراني للحوسبة السحابية (CCC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Framework",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-cloud-cybersecurity-controls-ccc-implementation",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cybersecurity-organizational-structure-template",
      "name": "Cybersecurity Organizational Structure Template",
      "name_ar": "نموذج الهيكل التنظيمي للأمن السيبراني",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cybersecurity-organizational-structure-template",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "regulatory-framework-for-licensing-managed-security-oper",
      "name": "Regulatory Framework for Licensing Managed Security Operations Centre Services (RFMSOC-1:2024)",
      "name_ar": "الإطار التنظيمي لترخيص خدمات مراكز العمليات الأمنية المُدارة (RFMSOC-1:2024)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/regulatory-framework-for-licensing-managed-security-oper",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "saudi-cybersecurity-higher-education-framework-scyber-ed",
      "name": "Saudi Cybersecurity Higher Education Framework (SCyber-Edu-1:2020)",
      "name_ar": "الإطار السعودي للتعليم العالي في الأمن السيبراني (SCyber-Edu-1:2020)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/saudi-cybersecurity-higher-education-framework-scyber-ed",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "guide-to-critical-systems-cybersecurity-controls-cscc-im",
      "name": "Guide to Critical Systems Cybersecurity Controls (CSCC) Implementation",
      "name_ar": "دليل تطبيق ضوابط الأمن السيبراني للأنظمة الحساسة (CSCC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Framework",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-critical-systems-cybersecurity-controls-cscc-im",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "guide-to-data-cybersecurity-controls-dcc-implementation",
      "name": "Guide to Data Cybersecurity Controls (DCC) Implementation",
      "name_ar": "دليل تطبيق ضوابط الأمن السيبراني للبيانات (DCC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Framework",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-data-cybersecurity-controls-dcc-implementation",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "operational-technology-cybersecurity-controls-methodolog",
      "name": "Operational Technology Cybersecurity Controls — Methodology & Mapping Annex",
      "name_ar": "ضوابط الأمن السيبراني للتقنية التشغيلية — ملحق المنهجية والمواءمة",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Framework",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/operational-technology-cybersecurity-controls-methodolog",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "national-policy-for-managed-security-operations-centres-",
      "name": "National Policy for Managed Security Operations Centres (NPMSOC-1:2024)",
      "name_ar": "السياسة الوطنية لمراكز العمليات الأمنية المُدارة (NPMSOC-1:2024)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/national-policy-for-managed-security-operations-centres-",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "organizations-social-media-accounts-cybersecurity-contro",
      "name": "Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC-1:2021)",
      "name_ar": "ضوابط الأمن السيبراني لحسابات الجهات على وسائل التواصل الاجتماعي (OSMACC-1:2021)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/organizations-social-media-accounts-cybersecurity-contro",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "alignment-guide-for-the-saudi-cybersecurity-higher-educa",
      "name": "Alignment Guide for the Saudi Cybersecurity Higher Education Framework (SCyber-Edu)",
      "name_ar": "دليل المواءمة للإطار السعودي للتعليم العالي في الأمن السيبراني (SCyber-Edu)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/alignment-guide-for-the-saudi-cybersecurity-higher-educa",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "saudi-cybersecurity-workforce-framework-scywf-1-2020",
      "name": "Saudi Cybersecurity Workforce Framework (SCyWF-1:2020)",
      "name_ar": "الإطار السعودي لكوادر الأمن السيبراني (SCyWF-1:2020)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Instrument",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/saudi-cybersecurity-workforce-framework-scywf-1-2020",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "telework-cybersecurity-controls-tcc",
      "name": "Telework Cybersecurity Controls (TCC)",
      "name_ar": "ضوابط الأمن السيبراني للعمل عن بُعد (TCC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Framework",
      "tier": 4,
      "legal_status": "Binding",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/telework-cybersecurity-controls-tcc",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "privacy-policy-guideline",
      "name": "Privacy Policy (Notice) Guideline",
      "name_ar": "دليل سياسة الخصوصية (الإشعار)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on drafting privacy notices.",
      "summary_ar": "إرشادات بشأن صياغة إشعارات الخصوصية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/PrivacyPolicyGuideline.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/privacy-policy-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cst-guide-for-cloud-computing-service-providers",
      "name": "CST Guide for Cloud Computing Service Providers",
      "name_ar": "دليل CST لمقدمي خدمات الحوسبة السحابية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "telecom",
      "authority": "CST",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cst-guide-for-cloud-computing-service-providers",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cma-cyber-guidelines",
      "name": "CMA Cybersecurity Guidelines",
      "name_ar": "إرشادات الأمن السيبراني الصادرة عن CMA",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Non-binding but examined at licensing; cloud must be in KSA.",
      "summary_ar": "غير ملزمة لكنها تُفحَص عند الترخيص؛ ويجب أن تكون الخدمات السحابية داخل المملكة العربية السعودية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "financial",
      "authority": "CMA",
      "parent": null,
      "in_library": true,
      "official_url": "https://cma.gov.sa/en/RulesRegulations/Guides/Documents/Cyber_Security_en.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/cma-cyber-guidelines",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cybersecurity-guidelines-for-internet-of-things-cgiot-1-",
      "name": "Cybersecurity Guidelines for Internet of Things (CGIoT-1:2024)",
      "name_ar": "إرشادات الأمن السيبراني لإنترنت الأشياء (CGIoT-1:2024)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cybersecurity-guidelines-for-internet-of-things-cgiot-1-",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ai-ethics-principles",
      "name": "AI Ethics Principles",
      "name_ar": "مبادئ أخلاقيات الذكاء الاصطناعي",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "SDAIA's AI Ethics Principles (2023).",
      "summary_ar": "مبادئ أخلاقيات الذكاء الاصطناعي الصادرة عن SDAIA (2023).",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/ai-principles.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/ai-ethics-principles",
      "date_note": "2023",
      "date_note_ar": "2023",
      "provisions": []
    },
    {
      "slug": "data-sharing-guideline",
      "name": "Data Sharing Guideline",
      "name_ar": "دليل مشاركة البيانات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on data-sharing arrangements.",
      "summary_ar": "إرشادات بشأن ترتيبات مشاركة البيانات.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "data-management-and-governance",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/DataSharingPolicyEN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/data-sharing-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "genai-guidelines-gov",
      "name": "Generative AI Guidelines — Government & Public",
      "name_ar": "إرشادات الذكاء الاصطناعي التوليدي — الجهات الحكومية والعموم",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on generative AI for government and the public.",
      "summary_ar": "إرشادات بشأن الذكاء الاصطناعي التوليدي للجهات الحكومية والجمهور.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/GenAIGuidelinesForGovernmentENCompressed.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/genai-guidelines-gov",
      "date_note": "2024",
      "date_note_ar": "2024",
      "provisions": []
    },
    {
      "slug": "guide-to-organizations-social-media-accounts-cybersecuri",
      "name": "Guide to Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC) Implementation",
      "name_ar": "دليل تطبيق ضوابط الأمن السيبراني لحسابات الجهات على وسائل التواصل الاجتماعي (OSMACC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-organizations-social-media-accounts-cybersecuri",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "destruction-anonymisation-guideline",
      "name": "Destruction / Anonymisation / Pseudonymisation Guideline",
      "name_ar": "دليل الإتلاف / إخفاء الهوية / الترميز المستعار",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on destruction, anonymisation and pseudonymisation of personal data.",
      "summary_ar": "إرشادات بشأن إتلاف البيانات الشخصية وإخفاء هويتها وإضفاء الطابع المستعار عليها.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/PersonalDataDestructionAnonymizationAndEncryptionGuideline.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/destruction-anonymisation-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "payment-services-provider-regulatory-guidelines",
      "name": "Payment Services Provider Regulatory Guidelines",
      "name_ar": "الإرشادات التنظيمية لمقدمي خدمات المدفوعات",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "financial",
      "authority": "SAMA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/payment-services-provider-regulatory-guidelines",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "registration-guide-in-the-qualifying-category",
      "name": "Registration Guide in the Qualifying Category",
      "name_ar": "دليل التسجيل في فئة التأهيل",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "telecom",
      "authority": "CST",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/registration-guide-in-the-qualifying-category",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "deepfakes-guidelines",
      "name": "Deepfakes Guidelines",
      "name_ar": "إرشادات التزييف العميق",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on deepfakes.",
      "summary_ar": "إرشادات بشأن التزييف العميق.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/File0001.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/deepfakes-guidelines",
      "date_note": "2024",
      "date_note_ar": "2024",
      "provisions": []
    },
    {
      "slug": "data-disclosure-guideline",
      "name": "Personal Data Disclosure Guideline",
      "name_ar": "دليل الإفصاح عن البيانات الشخصية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on lawful disclosure of personal data.",
      "summary_ar": "إرشادات بشأن الإفصاح المشروع عن البيانات الشخصية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/PersonalDataDisclosureCasesGuideline.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/data-disclosure-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "guide-to-telework-cybersecurity-controls-tcc-implementat",
      "name": "Guide to Telework Cybersecurity Controls (TCC) Implementation",
      "name_ar": "دليل تطبيق ضوابط الأمن السيبراني للعمل عن بُعد (TCC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-telework-cybersecurity-controls-tcc-implementat",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "cybersecurity-guidelines-for-e-commerce-service-provider",
      "name": "Cybersecurity Guidelines for E-commerce Service Providers (CGESP-1:2019)",
      "name_ar": "إرشادات الأمن السيبراني لمقدمي خدمات التجارة الإلكترونية (CGESP-1:2019)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cybersecurity-guidelines-for-e-commerce-service-provider",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "ropa-guideline",
      "name": "Records of Processing (RoPA) Guideline",
      "name_ar": "دليل سجلّات أنشطة المعالجة (RoPA)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on maintaining records of processing activities. The RoPA form may be repealed under the amendments.",
      "summary_ar": "إرشادات بشأن الاحتفاظ بسجلات أنشطة المعالجة. وقد يُلغى نموذج سجل أنشطة المعالجة (RoPA) بموجب التعديلات.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/PersonalDataProcessingActivitiesRecordsGuideline.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/ropa-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "generative-ai-public",
      "name": "Generative AI Guidelines — Public",
      "name_ar": "إرشادات الذكاء الاصطناعي التوليدي — العموم",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on generative AI for the public.",
      "summary_ar": "إرشادات بشأن الذكاء الاصطناعي التوليدي للجمهور.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "ai",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Files/GenerativeAIPublicEN.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/generative-ai-public",
      "date_note": "2024",
      "date_note_ar": "2024",
      "provisions": []
    },
    {
      "slug": "breach-incidents-guide",
      "name": "Personal Data Breach Incidents Procedural Guide",
      "name_ar": "الدليل الإجرائي لحوادث انتهاك البيانات الشخصية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Procedural guide for handling personal data breach incidents.",
      "summary_ar": "دليل إجرائي للتعامل مع حوادث انتهاك البيانات الشخصية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/PersonalDataBreachIncidents.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/breach-incidents-guide",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "alignment-guide-for-the-saudi-cybersecurity-workforce-fr",
      "name": "Alignment Guide for the Saudi Cybersecurity Workforce Framework (SCyWF)",
      "name_ar": "دليل المواءمة للإطار السعودي لكوادر الأمن السيبراني (SCyWF)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/alignment-guide-for-the-saudi-cybersecurity-workforce-fr",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "transfer-nonadequate-guideline",
      "name": "Transfer to Non-Adequate Country Guideline",
      "name_ar": "دليل النقل إلى دولة غير ذات مستوى حماية ملائم",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on transfers to countries without an adequacy decision.",
      "summary_ar": "إرشادات بشأن نقل البيانات إلى الدول التي لا يتوفر بشأنها قرار بكفاية مستوى الحماية.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "transfer-regulation",
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/RisksTransferringDataOutsideKingdomEn.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/transfer-nonadequate-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "guide-to-operational-technology-cybersecurity-controls-o",
      "name": "Guide to Operational Technology Cybersecurity Controls (OTCC) Implementation",
      "name_ar": "دليل تطبيق ضوابط الأمن السيبراني للتقنية التشغيلية (OTCC)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-operational-technology-cybersecurity-controls-o",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "self-assessment-guideline",
      "name": "Self-Assessment Guideline (incl. DPO-need tool)",
      "name_ar": "دليل التقييم الذاتي (متضمنًا أداة تحديد الحاجة إلى مسؤول حماية البيانات)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Self-assessment guidance, including a tool to determine whether a DPO is required.",
      "summary_ar": "إرشادات للتقييم الذاتي، تتضمن أداة لتحديد ما إذا كان تعيين مسؤول حماية البيانات (DPO) مطلوبًا.",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "implementing-regulation",
      "in_library": false,
      "official_url": "https://dgp.sdaia.gov.sa/wps/portal/pdp/services/servicesdetails/TooltoDeterminingDataProtectionOfficer",
      "wadira_url": "https://www.wadiraksa.com/instrument/self-assessment-guideline",
      "date_note": "Tool at dgp.sdaia.gov.sa",
      "date_note_ar": "الأداة متاحة على dgp.sdaia.gov.sa",
      "provisions": []
    },
    {
      "slug": "cybersecurity-guidelines-for-e-commerce-consumers-cgec-1",
      "name": "Cybersecurity Guidelines for E-commerce Consumers (CGEC-1:2019)",
      "name_ar": "إرشادات الأمن السيبراني لمستهلكي التجارة الإلكترونية (CGEC-1:2019)",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "cyber",
      "authority": "NCA",
      "parent": null,
      "in_library": true,
      "official_url": null,
      "wadira_url": "https://www.wadiraksa.com/instrument/cybersecurity-guidelines-for-e-commerce-consumers-cgec-1",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "minimum-pd-guideline",
      "name": "Minimum Personal Data Guideline",
      "name_ar": "دليل الحد الأدنى من البيانات الشخصية",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": "Guidance on collecting the minimum personal data necessary (data minimisation).",
      "summary_ar": "إرشادات بشأن جمع الحد الأدنى اللازم من البيانات الشخصية (تقليل البيانات).",
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": null,
      "in_library": true,
      "official_url": "https://sdaia.gov.sa/Documents/MinmumPDGuideline.pdf",
      "wadira_url": "https://www.wadiraksa.com/instrument/minimum-pd-guideline",
      "date_note": null,
      "date_note_ar": null,
      "provisions": []
    },
    {
      "slug": "guide-to-the-pdpl-for-controllers-and-processors",
      "name": "Guide to the PDPL for Controllers and Processors",
      "name_ar": "دليل نظام حماية البيانات الشخصية (PDPL) للمتحكمين والمعالجين",
      "subtitle": null,
      "subtitle_ar": null,
      "summary": null,
      "summary_ar": null,
      "type": "Guideline",
      "tier": 5,
      "legal_status": "Guidance",
      "framework": "pdpl",
      "authority": "SDAIA / NDMO",
      "parent": "pdpl-law",
      "in_library": true,
      "official_url": "https://dgp.sdaia.gov.sa/wps/wcm/connect/f579bc32-fda8-47bd-bc6f-66b8cb77985c/ENG-Guide+to+the+saudi+PDP+law+for+controllersprocessors.pdf?MOD=AJPERES",
      "wadira_url": "https://www.wadiraksa.com/instrument/guide-to-the-pdpl-for-controllers-and-processors",
      "date_note": "December 2023",
      "date_note_ar": "ديسمبر 2023",
      "provisions": []
    }
  ],
  "updates": [
    {
      "date": "2026-07-07",
      "type": "consultation",
      "title": "SDAIA consults on standards guides for the PDPL certification and audit market",
      "title_ar": null,
      "summary": "SDAIA opened a consultation (closing 6 August 2026, as reported) on three draft standards guides implementing the March-gazetted licensing rules: standards for issuing accreditation certificates to controllers and processors, for licensing personal-data audit and inspection activities, and for licensing certificate-issuance activities. They set the operating bar for the new PDPL certification and audit market, and matter to controllers seeking certificates as transfer safeguards.",
      "summary_ar": null,
      "instrument": "pdpl-law"
    },
    {
      "date": "2026-07-05",
      "type": "consultation",
      "title": "NCA consults on AI Cybersecurity Guidelines",
      "title_ar": null,
      "summary": "The National Cybersecurity Authority opened a consultation (5 July – 5 August 2026) on draft AI Cybersecurity Guidelines — its first AI-specific instrument — setting cybersecurity governance, defence, resilience and third-party requirements for organisations deploying or planning to adopt AI in the Kingdom, explicitly covering generative and agentic AI.",
      "summary_ar": null,
      "instrument": null
    },
    {
      "date": "2026-06-29",
      "type": "other",
      "title": "SDAIA committees issue further PDPL fines and warnings",
      "title_ar": null,
      "summary": "SDAIA's violation-review committees announced a further package of decisions — fines and warnings against several entities — for direct marketing without explicit consent and failing to maintain measures enabling timely responses to data-subject requests; press reports also cited 72-hour breach-notification failures and failures to appoint required DPOs. No entity names or amounts were disclosed.",
      "summary_ar": null,
      "instrument": "pdpl-law"
    },
    {
      "date": "2026-06-24",
      "type": "consultation",
      "title": "NCA consults on cybersecurity violations and penalties schedule",
      "title_ar": null,
      "summary": "The National Cybersecurity Authority opened a public consultation (24 June – 24 July 2026) on a draft classification of violations of NCA-mandated cybersecurity requirements and a corresponding penalties schedule, exercising enforcement powers under its amended statute (Royal Decree M/117). It would create the first formal penalty taxonomy behind the ECC, NCNICC and sector controls, affecting all entities subject to them.",
      "summary_ar": null,
      "instrument": null
    },
    {
      "date": "2026-06-19",
      "type": "new",
      "title": "SDAIA issues Data Revenue Generation Policy",
      "title_ar": null,
      "summary": "SDAIA published the Data Revenue Generation Policy (dated 27 April 2026, announced 19 June 2026), setting principles for government entities — and private entities holding government-sourced data — to develop revenue-generating data products and services. Products built on personal data must preserve privacy under the PDPL; open data remains free; government-to-government sharing cannot be charged. A national registry for data-product revenue generation now appears on SDAIA's National Data Governance Platform.",
      "summary_ar": null,
      "instrument": null
    },
    {
      "date": "2026-06-08",
      "type": "consultation",
      "title": "NCA consults on national incident-reporting framework (NFCISIR-1:2026)",
      "title_ar": null,
      "summary": "The National Cybersecurity Authority consulted on the draft National Framework for Cybersecurity Information Sharing and Incident Response; the consultation closed 10 July 2026. As drafted, public and private entities would report actual or suspected incidents via the national Haseen portal, follow tiered response timeframes (2/12/48/72 hours) across five severity levels, retain incident records for 15 years, and share threat intelligence under TLP. The final framework is pending.",
      "summary_ar": null,
      "instrument": null
    },
    {
      "date": "2026-04-03",
      "type": "consultation",
      "title": "SDAIA consults on draft Responsible AI Policy",
      "title_ar": null,
      "summary": "SDAIA opened a one-month public consultation (3 April – 3 May 2026) on a draft Responsible AI Policy applying to government, private and non-profit entities and individuals developing, deploying or publishing AI in the Kingdom. It moves beyond the 2023 AI Ethics Principles toward operational governance: risk-based classification, obligations for higher-risk systems, watermarking and content tracking of AI outputs, bias mitigation and performance monitoring. The final policy had not been issued as of mid-July 2026.",
      "summary_ar": null,
      "instrument": null
    },
    {
      "date": "2026-03-06",
      "type": "new",
      "title": "PDPL audit and certification licensing rules gazetted",
      "title_ar": null,
      "summary": "Two SDAIA instruments (Decisions 5135/2 and 5316, dated 16 December 2025; gazetted in Umm Al-Qura on 6 March 2026) create the PDPL compliance-services market: licences for accreditation-certificate issuers (SAR 10m capital, at least 10 qualified assessors, 3-year term) and for personal-data audit and inspection providers, plus rules for issuing controllers and processors 2-year accreditation certificates. Certificates also serve as a cross-border transfer safeguard under the Transfer Regulation.",
      "summary_ar": null,
      "instrument": "pdpl-law"
    },
    {
      "date": "2026-01-15",
      "type": "other",
      "title": "SDAIA reports 48 PDPL enforcement decisions",
      "title_ar": "سدايا تُعلن عن 48 قراراً بإنفاذ نظام حماية البيانات",
      "summary": "SDAIA's specialised committees confirmed 48 personal-data-protection violations in the first substantive enforcement wave — mostly processing without a legal basis, unauthorised disclosure, and marketing without consent. Decisions were reported in aggregate; no entities were named.",
      "summary_ar": "أكدت لجان سدايا المختصة 48 مخالفة لنظام حماية البيانات الشخصية في أول موجة إنفاذ جوهرية — معظمها معالجة دون أساس نظامي، وإفصاح غير مصرّح، وتسويق دون موافقة. ونُشرت القرارات بشكل إجمالي دون تسمية الجهات.",
      "instrument": "pdpl-law"
    },
    {
      "date": "2025-12-30",
      "type": "other",
      "title": "National Data Index — third measurement cycle launched",
      "title_ar": "المؤشر الوطني للبيانات — إطلاق الدورة الثالثة للقياس",
      "summary": "SDAIA launched the third NDI cycle, expanding measurement to 214 government entities (about +110%). The index scores data-management maturity, compliance and operational excellence via the National Data Governance Platform.",
      "summary_ar": "أطلقت سدايا الدورة الثالثة للمؤشر الوطني للبيانات، موسِّعةً القياس إلى 214 جهة حكومية (بزيادة نحو 110%). ويقيس المؤشر نضج إدارة البيانات والالتزام والتميّز التشغيلي عبر منصة حوكمة البيانات الوطنية.",
      "instrument": "ndi"
    },
    {
      "date": "2025-12-28",
      "type": "new",
      "title": "NCA issues cybersecurity controls for non-CNI private sector (NCNICC-1:2025)",
      "title_ar": null,
      "summary": "The National Cybersecurity Authority extended mandatory ECC-derived cybersecurity controls to all private-sector entities that are not critical-infrastructure operators — its largest scope expansion since the ECC. Category A entities (over 250 staff or SAR 200m revenue) face 65 controls across three domains; Category B (SMEs) face 26 controls. Compliance is continuous under Article 10(3) of the NCA statute, with no stated grace period.",
      "summary_ar": null,
      "instrument": "ncnicc"
    },
    {
      "date": "2025-12-02",
      "type": "new",
      "title": "SDAIA issues General Rules for Secondary Use of Data",
      "title_ar": null,
      "summary": "Approved by SDAIA Board Decision 22-1 (11/6/1447H) and publicised in January 2026, the General Rules govern reusing data — including personal data — beyond its original collection purpose, for research, development and public-interest uses. They cover government-to-government, government-to-private and private-to-government requests under six principles; any reuse of personal data must comply with the PDPL.",
      "summary_ar": null,
      "instrument": null
    },
    {
      "date": "2025-05-27",
      "type": "consultation",
      "title": "Third public consultation on Implementing Regulation amendments",
      "title_ar": "الاستطلاع العام الثالث لتعديلات اللائحة التنفيذية",
      "summary": "SDAIA's third public consultation (27 Apr – 27 May 2025) proposed to simplify the Implementing Regulation: folding the DPO-appointment and controller-registration rules into it, simplifying the RoPA requirement, and adding a plain-language privacy-notice clause. Not yet enacted as of mid-2026.",
      "summary_ar": "اقترح الاستطلاع العام الثالث لسدايا (27 أبريل – 27 مايو 2025) تبسيط اللائحة التنفيذية: بدمج قواعد تعيين مسؤول حماية البيانات وتسجيل جهات التحكم فيها، وتبسيط متطلب سجل المعالجة، وإضافة بند لإشعار الخصوصية بلغة واضحة. ولم تُعتمد بعدُ حتى منتصف 2026.",
      "instrument": "implementing-regulation"
    },
    {
      "date": "2025-04-23",
      "type": "consultation",
      "title": "Consultation on rules for data-protection service providers",
      "title_ar": "استطلاع حول قواعد مزوّدي خدمات حماية البيانات",
      "summary": "A parallel SDAIA consultation (closed May 2025) proposed to license firms providing PDPL consultancy, compliance technology and training — a separate instrument from the Implementing Regulation amendments.",
      "summary_ar": "اقترح استطلاع موازٍ لسدايا (أُغلق في مايو 2025) ترخيص الشركات التي تقدّم الاستشارات وتقنيات الامتثال والتدريب في مجال حماية البيانات — وهو أداة منفصلة عن تعديلات اللائحة التنفيذية.",
      "instrument": null
    },
    {
      "date": "2025-02-25",
      "type": "guidance",
      "title": "Guideline on cross-border transfer risk assessment",
      "title_ar": "دليل تقييم مخاطر النقل عبر الحدود",
      "summary": "SDAIA published a non-binding, four-phase methodology for assessing the risks of transferring personal data outside the Kingdom, with a companion risk-assessment tool on the National Data Governance Platform.",
      "summary_ar": "أصدرت سدايا منهجية غير ملزمة من أربع مراحل لتقييم مخاطر نقل البيانات الشخصية خارج المملكة، مع أداة مصاحبة لتقييم المخاطر على منصة حوكمة البيانات الوطنية.",
      "instrument": "transfer-regulation"
    }
  ]
}