KSAPDPL.COM

Table of Contents

The Rules Governing the National Register of Controllers Within the Kingdom – Introduction
The Rules Governing the National Register of Controllers Within the Kingdom Article 1 – Definitions
The Rules Governing the National Register of Controllers Within the Kingdom Article 2 – Scope and Objective
The Rules Governing the National Register of Controllers Within the Kingdom Article 3 – Controller Delegate Appointment
The Rules Governing the National Register of Controllers Within the Kingdom Article 4 – Registration Procedures
The Rules Governing the National Register of Controllers Within the Kingdom Article 5 – Profile Data
The Rules Governing the National Register of Controllers Within the Kingdom Article 6 – Circumstances for Appointing a Personal Data Protection Officer (DPO)
The Rules Governing the National Register of Controllers Within the Kingdom Article 7 – Information of the Personal Data Protection Officer (DPO)
The Rules Governing the National Register of Controllers Within the Kingdom Article 8 – Obligations
The Rules Governing the National Register of Controllers Within the Kingdom Article 9 – Representative Replacement
The Rules Governing the National Register of Controllers Within the Kingdom Article 10 – Registration Certificate Issuance
The Rules Governing the National Register of Controllers Within the Kingdom Article 11 – Making Registration Certificate Available to the Public
The Rules Governing the National Register of Controllers Within the Kingdom Article 12 – Services Provided on the Platform
The Rules Governing the National Register of Controllers Within the Kingdom Article 13 – Review and Amendment
The Rules Governing the National Register of Controllers Within the Kingdom Article 14 – Enforcement

The Rules Governing the National Register of Controllers Within the Kingdom Article 5 – Profile Data

Overview

The Rules Governing the National Register of Controllers Within the Kingdom Article 5 defines the mandatory profile data that must be provided on the National Data Governance Platform.

It distinguishes between the information required from Controller representatives and individuals, and it establishes accountability for ensuring that accurate and complete identification and contact details are maintained for regulatory monitoring and communication purposes.

SDAIA's Official Text

The text below reproduces official PDPL law, regulation, or guideline issued by the Saudi Data & AI Authority, verified against the original SDAIA source. No changes or reinterpretation applied.

Article 5: Profile Data

  1. The Controller representative shall be responsible for completing all required fields on the Platform, including:

    1. Controller Entity Data: Entity logo, official email and contact number, and headquarters.

    2. Representative Data: Official email and contacts number.

  2. Individuals must complete all required fields on the Platform, including official email and contact number.

Plain-Language Explanation

The explanation below is provided to help you understand the SDAIA’s legal text and does not replace or override the official PDPL law, regulation, or guideline.

Article 5(1)

Responsibility for Profile Completion

This Article assigns clear responsibility for completing and maintaining profile information on the National Data Governance Platform. For Controllers, this obligation rests with the appointed representative, while individuals bear direct responsibility for their own profile data.

Article 5(1)(a)

Controller Entity Information Requirements

The representative must provide core identification and contact information for the Controller entity. This includes the entity’s logo, official communication channels, and headquarters details. These elements enable the Competent Authority to identify Controllers accurately and facilitate official correspondence and regulatory follow up.

Article 5(1)(b)

Representative Contact Information

In addition to Controller entity data, the representative’s official email address and contact number must be provided. This ensures that the Competent Authority has a clear and reliable point of contact for matters related to registration, compliance monitoring, and regulatory communications.

Article 5(2)

Profile Data Obligations for Individuals

Individuals subject to registration requirements must complete their own profile information on the Platform. At a minimum, this includes an official email address and contact number, ensuring traceability and accountability for individuals processing personal data beyond personal or family use.

Saudi Personal Data Protection Law Compliance Services (KSA PDPL)

KSA PDPL Compliance Implementation

Achieve PDPL Compliance in 4 weeks or less.

Data Protection Officer As A Service (DPOaaS)

Let us handle your daily PDPL Compliance Operations.

KSA PDPL Compliance Audit (External)

Audit your PDPL compliance obligations.

Scroll to Top