ARTICLE
30 April 2025

SDAIA's New Draft Controls Shaping The Future Of Data Protection

AT
Al Tamimi & Company

Contributor

With 17 offices across 10 countries, we are a full-service commercial firm combining knowledge, experience and expertise to ensure our clients have access to the best legal solutions that are commercially sound and cost effective.

Our clients are at the heart of everything we do. Founded in 1989, we are the leading corporate law firm in the UAE and throughout the Middle East & North Africa with more than 450 legal professionals in 17 offices across 10 countries. We’re determined to use our knowledge, experience and intellectual rigour to find innovative solutions to overcome complex business challenges. We actively encourage diversity and inclusion, enabling us to attract and retain the best talent, to ensure our clients succeed.

#SDAIA has released a draft of the Controls Governing Commercial, Professional, and Non-Profit Activities Related to Personal Data Protection on the Istitilaa portal for public feedback.
Saudi Arabia Privacy

#SDAIA has released a draft of the Controls Governing Commercial, Professional, and Non-Profit Activities Related to Personal Data Protection on the Istitilaa portal for public feedback.

This document offers organizations involved in commercial, professional, or non-profit activities that handle personal data, clear guidelines, procedures, and requirements to ensure they comply with the Personal Data Protection Law and its Implementing Regulations. It serves as a comprehensive guide to help these organizations establish effective data protection measures, fostering growth and encouraging broader participation. Additionally, it supports compliance efforts, promotes best practices, and contributes to the development of the Kingdom's data sector.

Specifically, the Controls cover the following:

1. Definitions and Scope

  • Key terms such as Activities Related to Personal Data Protection, Controls, Competent Authority (SDAIA), Supervising Entity, Licensee, Permit Holder, and National Data Governance Platform are defined. The controls apply to entities involved in personal data protection activities, including consultancy services, technical solutions, vocational training, and events related to personal data protection.

2. General Requirements

  • Entities must register on the National Data Governance Platform and comply with the Personal Data Protection Law and its Implementing Regulations.
  • They must disclose any prior complaints or violations and ensure no ongoing investigations exist.

3. Specific Requirements for Activities

  • Consultancy Services: Must comply with the law and maintain documentation of measures and practices for data protection.
  • Technical and Vocational Training: Providers must have relevant qualifications, submit supporting documentation, and get approval from the Competent Authority.
  • Technical Services: Providers must ensure compliance with the law, possess necessary technical tools, and conduct self-assessments.
  • Conferences, Workshops, and Seminars: Speakers must be qualified, content must comply with the law, and events must be approved by the Competent Authority.

4. Suspension and Review

  • The Competent Authority can suspend activities if there are ongoing proceedings or violations.
  • Activities must be recorded in a National Register.
  • The controls will be periodically reviewed and updated as necessary.

5. Entry into Force

  • The controls will become effective upon publication in the Official Gazette.

Start Date: 23 April 2025

End Date: 20 May 2025

David Yates, Partner and Head of Digital & Data, and Christine El Khoury, Senior Counsel, Digital & Data, are available to provide further insights and guidance on this subject.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More