KSAPDPL.COM

Table of Contents

PDPL Implementing Regulation Article 1 – Definitions
PDPL Implementing Regulation Article 2 – Personal or Family Use
PDPL Implementing Regulation Article 3 – General Provisions of Data Subject Rights (DSR)
PDPL Implementing Regulation Article 4 – Right to be Informed
PDPL Implementing Regulation Article 5 – Right of Access to Personal Data
PDPL Implementing Regulation Article 6 – Right to Request Access to Personal Data
PDPL Implementing Regulation Article 7 – Right to Request Correction of Personal Data
PDPL Implementing Regulation Article 8 – Right to Request Destruction of Personal Data
PDPL Implementing Regulation Article 9 – Anonymisation
PDPL Implementing Regulation Article 10 – Means of Communication
PDPL Implementing Regulation Article 11 – Consent
PDPL Implementing Regulation Article 12 – Consent withdrawal
PDPL Implementing Regulation Article 13 – Legal Guardian
PDPL Implementing Regulation Article 14 – Processing to Serve the Actual Interest of Data Subject
PDPL Implementing Regulation Article 15 – Collecting Data from Third Parties
Load More

PDPL Implementing Regulation Article 15 – Collecting Data from Third Parties

Overview

PDPL Implementing Regulation Article 15 explains the conditions that apply when a Controller processes Personal Data collected from sources other than the Data Subject.

It sets criteria for necessity, proportionality, and protection of the Data Subject’s Rights (DSR). It also clarifies the requirements for relying on publicly available data and references the anonymisation obligations that apply when processing under Article 10.

SDAIA's Official Text

The text below reproduces official PDPL law, regulation, or guideline issued by the Saudi Data & AI Authority, verified against the original SDAIA source. No changes or reinterpretation applied.

Article 15: Collecting Data from Third Parties

  1. Except for what is stated in Paragraph (3) of Article (10) of the Law, when Processing Personal Data collected from sources other than the Data Subject directly, the Controller shall consider the following:

    1. Processing shall be necessary and proportionate to the specified purpose.

    2. Processing shall not affect the rights and interests of the Data Subject.

  2. When Processing Personal Data in accordance with paragraph (2) of Article (10) of the Law, the Controller shall ensure that such data Collection from a publicly available source is lawful.

  3. When Processing Personal Data in accordance with paragraph (6) of Article (10) of the Law, the Controller shall consider the provisions of Article (9) of this Regulation regarding Anonymisation.

Plain-Language Explanation

The explanation below is provided to help you understand the SDAIA’s legal text and does not replace or override the official PDPL law, regulation, or guideline.

Article 15(1)

Conditions For Third Party Data

This provision establishes the conditions that apply when a Controller processes Personal Data collected from sources other than the Data Subject. It requires the Controller to ensure that the processing is necessary and proportionate to the intended purpose.

It also requires the Controller to make sure that processing does not negatively affect the rights or interests of the Data Subject.

Article 15(1)(a)

Necessity And Proportionality

This provision requires the Controller to confirm that processing Personal Data obtained from a third party is both necessary and proportionate to the specified purpose. It ensures that the scope and extent of processing align with what is required to achieve that purpose.

Article 15(1)(b)

Protection Of Data Subject Rights (DSR)

This provision requires the Controller to ensure that processing Personal Data sourced from third parties does not harm the rights and interests of the Data Subject. It maintains the requirement that safeguards remain in place even when data is not collected directly from the individual.

Article 15(2)

Lawful Public Source Collection

This provision requires the Controller to verify that collecting Personal Data from a publicly available source is lawful when processing under paragraph (2) of Article 10 of the Law. It ensures that the source and method of collection comply with the legal requirements associated with publicly available data.

Article 15(3)

Anonymisation Requirements Apply

This provision requires the Controller to consider the anonymisation obligations set out in Article 9 of the Regulation when processing under paragraph (6) of Article 10 of the Law. It ensures that the applicable anonymisation requirements are applied consistently during such processing.

Saudi Personal Data Protection Law Compliance Services (KSA PDPL)

KSA PDPL Compliance Implementation

Achieve PDPL Compliance in 4 weeks or less.

Data Protection Officer As A Service (DPOaaS)

Let us handle your daily PDPL Compliance Operations.

KSA PDPL Compliance Audit (External)

Audit your PDPL compliance obligations.

Scroll to Top