What counts as personal data?
Under Article 1 of the law, personal data is any data, whatever its source or form, that leads to identifying a specific individual or makes it possible to identify them directly or indirectly. The text gives examples such as the name, ID number, addresses, contact numbers, bank account numbers and images of the person. In practice, most of an employee file is personal data.
The same article defines a narrower category, sensitive data, which carries stricter rules:
“Any personal data relating to the individual's racial or ethnic origin, or religious, intellectual or political belief. Also security and criminal data, biometric data that identifies the person, genetic data, health data, and data indicating that the individual's parents, or one of them, are unknown.”
PDPL, Article 1, definition of “sensitive data” as amended by Royal Decree (M/148), as published by the Bureau of Experts at the Council of Ministers. Unofficial translation; the Arabic text is the reference.
In an employee file, sick-leave medical reports and work-injury reports fall under health data, and a criminal record certificate, where one is requested, falls under security and criminal data. This is a general application of the definition, not an official classification of each document.
Who does it apply to?
The law applies to any processing of personal data about individuals carried out in the Kingdom by any means, including processing by a party outside the Kingdom of personal data about individuals residing in the Kingdom. The only exception is an individual processing data for purposes that do not go beyond personal or family use, as long as the data is not published or disclosed to others (Article 2). The text does not link its application to the size of the establishment. The establishment that decides the purpose and manner of processing its employees' data is the “controller”; an HR or payroll system provider that processes the data on its behalf is the “processor” (Article 1).
When is the employee's consent needed?
The starting point in Article 5 is that personal data may not be processed, and the purpose of processing may not be changed, without the data subject's consent, and consent can be withdrawn at any time. Article 6, however, does not require consent in several cases, including:
- Where the processing is required by another law, or carries out a prior agreement to which the data subject is a party.
- Where the processing is necessary for the controller's legitimate interests, provided it does not prejudice the data subject's rights or conflict with their interests, and the data is not sensitive.
Article 10 limits processing to the purpose for which the data was collected, except in listed cases, and Article 7 bars making consent a condition for a service unrelated to the processing. The Implementing Regulation requires a separate consent for each processing purpose.
A general reading: processing contract, payroll and GOSI data usually rests on the employment contract and the laws that require it. Using an employee's data for another purpose, such as posting their photo on the establishment's marketing accounts, is a different purpose to be weighed against Articles 5 and 10.
What must the establishment do when collecting and keeping data?
- A privacy policy: adopted by the establishment and available to data subjects when their data is collected, stating the purpose, the data collected, how it is collected, stored, processed and destroyed, the rights and how to exercise them (Article 12).
- A notice at collection: the legal basis, the purpose, whether the data is mandatory or optional, who is collecting it, who it will be disclosed to, whether it will be transferred or processed outside the Kingdom, the effects of not completing the collection, and the rights (Article 13).
- The minimum needed: the data must be appropriate and limited to the minimum the purpose needs, and data no longer needed must stop being collected and be destroyed without delay (Article 11).
- Copies of ID documents: official documents that identify the data subject may not be photographed or copied except to carry out a law, or when a competent public body asks for it as the regulations specify (Article 28).
- Processors: the establishment chooses a provider that offers the guarantees needed to apply the law, checks its compliance, and remains responsible itself (Article 8).
- Security: organisational, administrative and technical measures that protect the data, including when it is transferred (Article 19).
- Processing records: the establishment keeps records of its processing activities with a minimum content, including the purpose, the categories of data subjects, who receives the data, transfers outside the Kingdom and the expected retention period (Article 31).
- Transfers outside the Kingdom: if the HR system is hosted abroad, Article 29 and its regulations set the purposes and conditions for the transfer.
How long can data be kept?
Article 18 requires personal data to be destroyed without delay once the purpose of collecting it has ended, though it may be kept afterwards if everything that identifies the person is removed. The data must be kept even after the purpose ends in two cases: where a legal basis requires it to be kept for a set period, in which case it is destroyed at the end of that period or of the purpose, whichever is later; or where it is closely connected to a case pending before a judicial body. The PDPL does not set a specific retention period for employee files; the period follows the other laws that require records to be kept.
The employee's rights over their data
Article 4 gives the data subject, as the regulations specify: the right to know the legal basis and purpose of collecting their data, the right of access, the right to request a copy in a readable and clear format, the right to request correction, completion or updating, and the right to request destruction of data that is no longer needed. The controller must respond to these requests within a period and through a channel set by the regulations (Article 21).
If data leaks
The controller notifies the competent authority when it becomes aware of a leak, damage or unlawful access to personal data, and notifies the data subject where this may harm their data or conflict with their rights or interests (Article 20). The Implementing Regulation (Article 24) sets the notice to the competent authority at 72 hours from becoming aware of the incident, where the incident may harm the data or the data subjects, or conflict with their rights or interests. Under the Council of Ministers decision issued with the law, the competent authority is the Saudi Data and AI Authority (SDAIA) for two years, during which moving this role to the National Data Management Office is to be considered, so check the competent authority at the time of notice.
Penalties
- Article 36: a warning or a fine of up to SAR 5 million for any private natural or legal person that breaches the law or its regulations, which may be doubled for a repeat, up to twice the ceiling.
- Article 35: imprisonment of up to two years and a fine of up to SAR 3 million, or either, for disclosing or publishing sensitive data in breach of the law with intent to harm the data subject or for personal gain.
- Article 38: the court may order confiscation of money gained from the violation, and a summary of the judgment or decision may be published at the violator's expense.
The rules governing the National Register of Controllers require registration by a controller that processes sensitive data. Because employee files often hold health data, check whether this applies to your establishment in the official sources below.