Personal Data Protection Law (PDPL), 2021
The Personal Data Protection Law is Saudi Arabia’s first comprehensive data privacy law, issued pursuant to Royal Decree No. M/19 dated 09/02/1443 AH (16 September 2021), as amended by Royal Decree No. M/148 dated 5/9/1444H (27 March 2023). The law came into effect on 14 September 2023 with a one-year grace period for compliance ending […]
National Cybersecurity Authority (NCA) Essential Cybersecurity Controls (ECC), 2024
The Essential Cybersecurity Controls (ECC – 2: 2024) issued by the National Cybersecurity Authority establish mandatory cybersecurity requirements for organizations in Saudi Arabia. These controls cover various aspects of information security including access management, data protection, incident response, and security monitoring. Organizations must implement these controls to protect personal and sensitive data from cybersecurity threats. […]
Regulations on Personal Data Transfer Outside the Kingdom, 2023 (Updated 2024)
The Data Transfer Regulations, initially issued on 7 September 2023 and replaced by a new version on 1 September 2024, govern the transfer of personal data outside Saudi Arabia’s borders. These regulations establish requirements for cross-border data transfers including adequacy assessments, appropriate safeguards, and specific contractual requirements. Organizations must ensure transferred data receives protection comparable […]
Implementing Regulations of the PDPL, 2023
The Implementing Regulations were issued on 7 September 2023 and provide detailed guidance on various PDPL requirements. They include provisions for privacy policies, data breach notifications within 72 hours, Data Protection Impact Assessments for high-risk processing, and specific requirements for continuous and large-scale processing of personal data. The regulations also address data controller obligations for disclosure […]
Health Data Management Policy (under Ayushman Bharat Digital Mission)
ABDM participants must comply with the Health Data Management Policy. Healthcare laws include the Clinical Establishments Act, National Medical Commission Act provisions requiring physician confidentiality, and the proposed Digital Information Security in Healthcare Act (DISHA). Download PDF
Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016
The Aadhaar Act became law in March 2016 and regulates India’s biometric identification system. The Act includes provisions for authentication, offline verification, and informed consent. It governs the collection, storage, and use of biometric and demographic data for over 1 billion Indians. Download PDF
IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
These rules, known as SPDI Rules, are issued under the IT Act and define sensitive personal information to include passwords, financial information, physical/mental health conditions, sexual orientation, medical records, and biometric information. They establish requirements for collection, storage, and transfer of sensitive personal data by body corporates. Download PDF