KSAPDPL.COM

Table of Contents

PDPL Implementing Regulation Article 1 – Definitions
PDPL Implementing Regulation Article 2 – Personal or Family Use
PDPL Implementing Regulation Article 3 – General Provisions of Data Subject Rights (DSR)
PDPL Implementing Regulation Article 4 – Right to be Informed
PDPL Implementing Regulation Article 5 – Right of Access to Personal Data
PDPL Implementing Regulation Article 6 – Right to Request Access to Personal Data
PDPL Implementing Regulation Article 7 – Right to Request Correction of Personal Data
PDPL Implementing Regulation Article 8 – Right to Request Destruction of Personal Data
PDPL Implementing Regulation Article 9 – Anonymisation
PDPL Implementing Regulation Article 10 – Means of Communication
PDPL Implementing Regulation Article 11 – Consent
PDPL Implementing Regulation Article 12 – Consent withdrawal
PDPL Implementing Regulation Article 13 – Legal Guardian
PDPL Implementing Regulation Article 14 – Processing to Serve the Actual Interest of Data Subject
PDPL Implementing Regulation Article 15 – Collecting Data from Third Parties
Load More

PDPL Implementing Regulation Article 27 – Processing Credit Data

Overview

PDPL Implementing Regulation Article 27 establishes the organizational, technical, and administrative safeguards required for protecting Credit Data from unauthorized use, misuse, access, or disclosure. The Article reinforces alignment with Saudi Central Bank (SAMA) requirements, mandates compliance with sector-specific credit information controls, and requires Controllers to obtain and notify Data Subjects regarding Credit Data disclosures.

The regulation also ensures consistency with the Credit Information Law and the PDPL’s consent standards, especially those referenced under Article 11.

SDAIA's Official Text

The text below reproduces official PDPL law, regulation, or guideline issued by the Saudi Data & AI Authority, verified against the original SDAIA source. No changes or reinterpretation applied.

Article 27: Processing Credit Data

Without prejudice to the provisions of the Credit Information Law, the Controller shall take organizational, technical, and administrative measures to protect Credit Data from any unauthorized use, misuse, access by unauthorized individuals, use for purposes other than for which it was collected, and Disclosure. The Controller shall adopt the following controls and procedures:

  1. Adopt and implement requirements and controls issued by the Saudi Central Bank and other relevant authorities, which define the roles and responsibilities of employees of establishments providing credit information services and of the parties that have contracts with such establishments to process Credit Data.

  2. Controller shall obtain the consent of the Data Subject and notify them of any request to disclose their Credit Data in accordance with the provisions of the Credit Information Law, while considering the provisions stated in subparagraph (d) of paragraph (1) of Article 11 of the Regulation.

Plain-Language Explanation

The explanation below is provided to help you understand the SDAIA’s legal text and does not replace or override the official PDPL law, regulation, or guideline.

Article 27(1)

Credit Sector Alignment (SAMA)

This provision requires Controllers to apply the requirements and controls issued by the Saudi Central Bank (SAMA) and other relevant authorities. These controls define the roles and responsibilities of employees and contracted parties involved in processing Credit Data for credit information services.

Article 27(2)

Consent and Notification Rules

This provision requires Controllers to obtain the Data Subject’s consent and notify them when their Credit Data is requested for disclosure. It must follow the Credit Information Law (CIL) while also considering the consent documentation requirement stated in Article 11(1)(d) of the Regulation.

Saudi Personal Data Protection Law Compliance Services (KSA PDPL)

KSA PDPL Compliance Implementation

Achieve PDPL Compliance in 4 weeks or less.

Data Protection Officer As A Service (DPOaaS)

Let us handle your daily PDPL Compliance Operations.

KSA PDPL Compliance Audit (External)

Audit your PDPL compliance obligations.

Scroll to Top