Doing Business In..._2026

SAUDI ARABIA Law and Practice Contributed by: Dana Halwani and Leanne Farsi, Derayah LLPC

8.2 Geographical Scope The PDPR applies to any processing of the personal data of individuals, carried out in the Kingdom by any means whatsoever, including the processing of per - sonal data relating to individuals resident in the King - dom, by any means whatsoever, by any entity residing outside the Kingdom. Article 2 (b) of the 2018 E-Commerce Regulation details the provisions and sanctions in place to safe - guard the protection of consumer data, and also applies to traders outside Saudi Arabia who provide products or services inside the country by offering them in a manner that enables the consumer to obtain them. 8.3 Role and Authority of the Data Protection Agency Although each government authority supervising an activity is responsible for enforcing its specific data protection rules, the National Data Management Office is the national data regulator of Saudi Arabia, and creates laws, regulations and policies to facilitate the protection of data. The Saudi Authority for Data and Artificial Intelligence is the authority which supervises the implementation of the PDPR. One of the key aspects of Saudi Vision 2030, a gov - ernment programme launched with the goal of diver - sifying Saudi Arabia’s economy and culture, is the ref - ormation of the country’s legal and judicial framework. To this end, there have been increased efforts to leg - islate upon previously uncodified areas of the law, in order to create a more predictable legal environment, and encourage foreign investment. In 2022, the draft of the Commercial Transactions Law was uploaded to Istitlaa, the Saudi public consultation platform for feedback on legislation. The consultation period for this draft has since ended. The official pub - lication of the Commercial Transactions Law is highly anticipated, as it regulates a wide array of commercial 9. Looking Forward 9.1 Upcoming Legal Reforms

maintaining transparency with data owners regarding how their personal information is processed. Controlling entities, which is to say public bodies, natural persons or private bodies corporate that determine why and how personal data is processed (whether they themselves are processing it or whether this is done through a processing entity), may only (with certain exceptions) collect personal data directly from the owner of the data in question, and process such data solely for the purpose for which the data was collected. Privacy policies need to be adopted by controlling entities and made available to the own - ers of data. These privacy policies must inform data owners of: • the reason for their data’s collection; • the contents of the personal data that must be col - lected; • the method of data collection, storage and pro - cessing; • the means of deleting the data; and • the rights of the data owner in connection there - with, as well as the manner in which such rights may be exercised. A number of industries are also currently governed by regulations that set out measures to protect data col - lected in those fields. Examples include the following. • The Health Profession Practice Regulation (Royal Decree No M/59 of 4 Dhul Qada 1426 Hejra cor - responding to 6 December 2005), which provides that a medical practitioner must not disclose any confidential information obtained during the course of their work. The regulation lists a few exceptions to this rule, such as a court order requiring disclo - sure. • Article 5 of the E-Commerce Regulation (Royal Decree No M/126 of 7 Dhul Qada 1440 Hejra cor - responding to 9 July 2019), which provides that online merchants may not retain consumer data beyond the period required for an electronic com - merce transaction, and that online merchants must adopt the necessary safeguards to protect con - sumer data while it is retained. The same regula - tion prohibits online retailers from the unauthorised disclosure and usage of consumer data.

928 CHAMBERS.COM

Powered by