Document summary
This page explains data ownership, processing records, impact assessments, rights, retention, transfers, incidents, and access oversight.
Ownership and accountability
Each data domain has an operational owner, technical custodian, and privacy reviewer. The owner defines purpose, quality, retention, and access and does not transfer accountability to the storage provider.
Processing register
The register records activity, data and person categories, purpose, basis, source, recipients, location, transfer, retention, controls, and owner. It is reviewed when product, form, or integration changes.
Privacy by design
New collection does not start before minimization, privacy defaults, data flow, rights, and deletion are defined. High-risk activity requires an impact assessment and approval before launch.
Rights and retention
Requests have deadlines, verification, system maps, actions, and evidence. The retention schedule connects to legal holds and auditable disposal runs, and staff do not directly delete sensitive records.
Transfers and providers
Each provider links to a contract, assessment, processing locations, subprocessors, transfer safeguard, and exit plan. Technical connection is blocked while critical requirements are incomplete.
Incidents
A security event starts a separate privacy assessment covering categories, volume, impact, likelihood of harm, awareness time, and notification decision. Reporting or non-reporting decisions record basis and deadline.
Official references
References used to prepare this content
Links point to official legal or guidance sources. Applicability depends on the organization, product, and contract.
- Personal Data Protection LawSDAIA, National Data Governance Platformopens in a new tab
- PDPL Implementing RegulationsSDAIA, National Data Governance Platformopens in a new tab
- Personal data breach notification serviceSDAIA, National Data Governance Platformopens in a new tab
- Regulation on Personal Data Transfer Outside the KingdomSDAIA, National Data Governance Platformopens in a new tab
Versions
Change log
- Version 1.0.0
Published the first operational version with clear scope, responsibilities, rights, and escalation routes.