What a data sharing agreement is
A data sharing agreement (اتفاقية مشاركة البيانات) is a written agreement between two parties that governs the movement of data from one of them to the other: which data, for what purpose, in what capacity the recipient handles it, and for how long. Inside an organisation it is an administrative instrument, but its subject matter is governed by a law other than the Saudi Labor Law (نظام العمل). That law is the Personal Data Protection Law (نظام حماية البيانات الشخصية), issued by Royal Decree M/19 of 9/2/1443H and amended by Royal Decree M/148 of 5/9/1444H.
Employee data falls within it. Article 1 of the Personal Data Protection Law defines personal data as any data, whatever its source or form, that identifies an individual specifically or makes it possible to identify them directly or indirectly, and it names the person’s name, identity number, addresses and contact numbers among its examples. A list of staff names with their salaries is therefore personal data before anyone shares it.
Why a data sharing agreement is a statutory matter, not only a contractual one
The reason is that sharing is itself processing. The definition of processing in Article 1 of the Personal Data Protection Law lists, among its forms, transfer, disclosure, and data sharing or interlinking. Once an employee’s data moves from one party to another, what has taken place is a processing operation subject to the law, whether the contract calls it sharing, provision or integration. The label chosen in the agreement does not change the category.
That has a direct consequence. Article 10 of the Personal Data Protection Law provides that personal data may be processed only to achieve the purpose for which it was collected, subject to the situations the same article lists, which include the data subject’s consent. Article 5 of the Personal Data Protection Law provides that, except in the cases the law sets out, neither processing nor a change in the purpose of processing may take place without the data subject’s consent, and that this consent may be withdrawn at any time. So the first question in any data sharing agreement is not “what are the clauses?” but “is the purpose for which the data is being passed on the purpose for which it was collected?”
Article 19 of the Personal Data Protection Law requires the controller to take the organisational, administrative and technical measures needed to protect personal data, and SDAIA’s English translation of the law adds the words “including during the Transfer of Personal Data”. The moment of transfer is therefore named in the text as a point of protection in its own right, not treated as a passing state between two secure places.
The penalties for violating the law are set in Articles 35 and 36 of the Personal Data Protection Law.
In a data sharing agreement, capacity comes before the clauses
The law defines two capacities, and each is fixed by what a party does, not by what the contract calls it:
- The controller (جهة التحكم). It is the party that determines the purpose and manner of processing, whether it carries out the processing itself or through a processor.
- The processor (جهة المعالجة). It is the party that processes the data for the benefit of the controller and on its behalf.
A third position deserves attention, because the law gives it a separate definition. Article 1 of the Personal Data Protection Law defines disclosure (الإفصاح) as enabling any person other than the controller or the processor to obtain, use or view the data. A transfer to a party that processes on the organisation’s behalf is therefore not on the same footing as a transfer to a third party acting for itself. An agreement that treats the two alike treats as one what the law describes in two different terms.
What makes a data sharing agreement workable
The points that follow are administrative arrangements, not a list of clauses the law requires. In the sources we reviewed, we found no text listing the clauses that an agreement between a controller and a processor must contain, so the list is not presented as a statutory requirement.
- One named purpose. It is stated as a specific purpose, not as “for the purposes of cooperation between the parties”. A purpose that is not defined cannot be measured against later.
- A dataset defined field by field. It is set out as a list of fields, not as a general description. “Employee data” is not a dataset; it is the name of a door through which anything can pass. An agreement that names the employee file rather than its fields has named everything in it.
- The capacity of each party. It is written down, together with who responds to the data subject if they exercise one of the rights the law gives them. Article 4 of the Personal Data Protection Law lists those rights, among them the right to be informed, to access the data, to obtain a copy of it, and to request its correction and its destruction.
- A duration, and what happens when it ends. It names destruction or return of the data at the end, and who confirms that this has happened. In the provisions we reviewed, the Personal Data Protection Law states no retention period as a number. Article 18 of the Personal Data Protection Law requires the controller to destroy personal data without undue delay once it is no longer necessary for the purpose for which it was collected. The same article allows the data to be kept after that point once everything that identifies the data subject has been removed in accordance with controls set by the law’s Implementing Regulations, and requires it to be kept where a legal basis calls for retention over a set period or where the data is closely connected to a case before a judicial body.
- What happens on a leak. It sets out who notifies whom, and when, while the statutory duty to notify stays where the law places it. Under Article 20 of the Personal Data Protection Law, that duty rests on the controller, which notifies the competent authority on learning of a breach and notifies the data subject where the breach may harm them.
- Confidentiality that outlasts the agreement. It continues after the agreement ends, which is consistent with Article 41 of the Personal Data Protection Law: anyone who carries out processing must keep the data confidential even after their employment or contractual relationship has ended.
Two subjects sit close to any data sharing agreement and are left out of that list on purpose: transferring personal data outside the Kingdom, and the additional duties that attach to sensitive data. The sources we reviewed for this term did not cover either, and neither is inferred by analogy from the provisions above. Sensitive data is defined in Article 1 of the Personal Data Protection Law, and the definition includes health data and biometric data that identifies a person; what the law requires for that category beyond the general rules has its own provisions in the law, and no rule on it is drawn from the definition of a data sharing agreement.
Where a data sharing agreement begins: collection
The obligations that come before any data sharing agreement begin when the data is collected. Article 10 of the Personal Data Protection Law requires the controller to collect personal data directly from the data subject, subject to the situations listed in the same article, and the purpose for which the data was collected is the one against which any later sharing is measured. An organisation that cannot say why it collected a field cannot show that passing the field on serves that purpose. The same question arises when an organisation gathers what candidates have published online, a practice described under cybervetting.
How a data sharing agreement differs from a non disclosure agreement
A data sharing agreement is not a non disclosure agreement, although the two can sit side by side. The first governs a deliberate transfer of specified data to a specified party for a specified purpose; the second prohibits disclosure. Having the second does not make the first unnecessary, because a prohibition on disclosure sets no purpose, limits no fields and assigns no capacity.
A trade secret is a different subject again. A data sharing agreement concerns personal data about individuals, and the law that governs its movement is the Personal Data Protection Law.
Questions to settle before a data sharing agreement is signed
Before signing, an organisation can put four questions to the draft. Does the purpose written in it match the purpose stated when the data was collected? Are the fields listed the ones that purpose needs, and no more? Does the recipient act on the organisation’s instructions, or decide for itself what to do with the data? And what happens to the data on the last day of the agreement, and who confirms it? A draft that cannot answer one of them can be returned before signature, rather than renegotiated after the data has already moved.
This is an explanation of the concept and of the statutory provisions cited, not legal advice.
A standalone Saudi HR system
One employee file holding the contract, the documents and their expiry dates, the attendance record, leave, salary and end-of-service entitlements. End-of-service, overtime and leave-balance calculations are built into the system.
A standalone system on its own subscription. The connection to Qoyod Accounting is now available.