Introduction of the "legitimate interest" legal basis for processing
Previously, unless the data subject's consent was obtained, processing could only be carried out in certain limited scenarios, being:
- 1. where processing achieves a definite interest for the data subject and it is impossible or difficult for the data subject to be contacted;
- 2. where processing is required by law;
- 3. implementation of an earlier agreement to which the data subject is a party; or
- 4. if the controller is a public entity and such processing is required for security purposes or to meet judicial requirements.
The PDPL now provides that processing can also be undertaken without the data subject's consent if it is necessary to achieve the legitimate interests of the data controller, "provided that this does not prejudice the rights of the data subject, nor conflict with their interests".
This new legal basis for processing without consent appears to reflect the commonly relied upon "legitimate interest" legal basis under the EU GDPR. The PDPL states that the Regulations will contain further controls in respect of the use of this new legal basis.
Critically, the legitimate interest legal basis is not available when the data being processed is sensitive personal data (for example health data). Accordingly, obtaining the consent of the data subject is still likely to remain critical in order to legitimise personal data processing in certain contexts.
Fortunately, the definition of sensitive personal data for the purposes of the PDPL has also been revised to exclude specific reference to data relating to non-governmental associations as well as location data and credit data. This will allow businesses to rely on the legitimate interest legal basis in a broader array of circumstances than was originally permitted.
The same concept of "legitimate interest" has also been introduced as an additional ground permitting the disclosure of personal data. This together with some other important limitations has introduced some much-needed flexibility to the PDPL's previously broad disclosure restrictions.
Further allowances for international data transfers
Previously the PDPL stated that by default personal data should remain within the Kingdom and should only be transferred outside of the Kingdom where it was necessary to protect the vital interests of the data subject, prevent or deal with a public health issue, or to protect the interests of the Kingdom.
While it was envisaged that further exceptions to the default rule would be introduced in the Regulations, the amended PDPL removes this assumption and instead introduces grounds to legitimise cross-border transfers of personal data in a manner like established foreign data protection laws, such as the EU GDPR. The export of personal data from the Kingdom will now be permitted where it is made pursuant to a contract to which the data subject is a party. This amendment reflects one of the various grounds that is set out in the data transfer principles contained in the National Data Management Office's (NDMO) National Data Regulations. The Regulations may provide for additional purposes for which international data transfers are permitted. However, it remains to be seen whether any of the further grounds set out in the National Data Regulations will be adopted in the PDPL.
Helpfully, the amended PDPL no longer envisages that all international data transfers must be approved by SDAIA. We will need to wait for the Regulations to be published to see what, if any, additional formalities will apply in this regard.
Data Protection Officer
Previously, the PDPL envisaged that all data controllers would be obliged to appoint one or more persons to be responsible for ensuring compliance with the PDPL. This appeared to suggest that each organisation would require a Data Protection Officer (DPO) to be appointed.
The amended PDPL takes a more nuanced approach, providing that in certain circumstances specified in the Regulations, a DPO will be required to be appointed. This aligns more closely with the position under the GPDR, where, unless the organisation's core activities require large scale, regular and systematic monitoring of data subjects or large-scale processing of sensitive personal data, a DPO is not strictly required by law (although many businesses processing large amounts of personal data may opt to appoint one anyway).
In addition, the amended PDPL now acknowledges that the DPO will have certain statutory responsibilities. These will be detailed in the Regulations.
Data breach notification requirements
Previously, the PDPL required that controllers notify SDAIA of data breaches as soon as they became aware of the breach. The amended PDPL now provides that notification should be made to SDAIA when a breach occurs, in accordance with the requirements of the Regulations. There is accordingly some scope for the Regulations to introduce a materiality threshold for notifying SDAIA, as is common in other leading data protection laws like the EU GDPR.
The amended PDPL also introduces a welcome threshold test, which must be met in order to trigger an obligation to notify data subjects affected by a data breach; namely where the breach would cause serious harm to the data subject's data or where it prejudices their rights or interests. Further detail on this data subject notification requirement will be specified in the Regulations.
A Potential Revision of the Implementation Framework
The amended PDPL has consolidated several of the existing provisions, which envision how the PDPL will be implemented. In particular, it removes the express reference to an online portal which all controllers are required to register on. Instead, SDAIA may, if it deems it necessary to monitor compliance with the PDPL, implement a national register that controllers may be required to register on and through which services can be provided to assist with the protection of personal data.
A reference to these more generic concepts may have been introduced due to the fact SDAIA has changed its plans for the law's implementing framework and it no longer wishes to be tied to any mode of operation, or it could simply be due to the fact that it intends to set out a more comprehensive description of this aspect of the regime in due course, either in the Regulations or in the associated policies. Only time will tell.
Removal of some criminal sanctions
The PDPL no longer imposes criminal sanctions for unauthorised transfers of personal data overseas. Previously, this breach of the law would have given rise to imprisonment for a period not exceeding one year and/or a fine not exceeding one million Riyals.