What data subject rights are
Data subject rights (حقوق صاحب البيانات الشخصية) are the rights that the Personal Data Protection Law, PDPL (نظام حماية البيانات الشخصية) gives an individual against the controller (جهة التحكم), the party that decides the purpose and manner of processing the individual’s personal data. Article 1 of the PDPL defines the data subject as “The individual to whom the Personal Data relate”, in the wording of SDAIA’s official English translation. An employee, a job applicant, a trainee and a former employee are individuals whose personal data an establishment may hold, and the establishment that keeps their files is the controller of that data.
Two regulations share the name Implementing Regulations. The PDPL Implementing Regulations (اللائحة التنفيذية لنظام حماية البيانات الشخصية) are the regulations issued under the PDPL, and the Implementing Regulations of the Labor Law are named in full each time. SDAIA’s official English translation covers the PDPL. English statements about the PDPL Implementing Regulations are our rendering of the Arabic text, and they are not an official translation.
Paragraph 1 of Article 2 of the PDPL applies the Law to any processing of personal data about individuals that takes place in the Kingdom, by any means. Paragraph 2 of Article 2 of the PDPL excludes only an individual’s processing for purposes that go no further than personal or family use, on this condition in the Arabic text: «ما دام أنه لم ينشرها أو يفصح عنها للغير». SDAIA’s official English translation renders the condition as “as long as the Data Subject did not publish or disclose it to others”.
Paragraph 3 of Article 2 of the PDPL Implementing Regulations names two things that are not personal or family use: the individual publishing the personal data to the public or disclosing it to a person outside the scope set in paragraph 2 of the same Article, and the individual using the data for professional, commercial or non-profit purposes.
The five rights in Article 4 of the PDPL
Article 4 of the PDPL gives the data subject five rights. In SDAIA’s official English translation, the Article gives them “pursuant to this Law and as set out in the Regulations”. In our wording, the five rights are:
- The right to be informed includes informing the individual of the legal basis for collecting the data and of the purpose of the collection.
- The right of access is the individual’s right to obtain access to the data that the controller holds, under the controls and procedures that the PDPL Implementing Regulations set and without prejudice to Article 9 of the PDPL.
- The right to request a copy is the individual’s right to ask for the data that the controller holds in a readable and clear format.
- The right to correction is the individual’s right to ask for the data to be corrected, completed or updated.
- The right to destruction is the individual’s right to ask for the destruction of data that is no longer needed, without prejudice to Article 18 of the PDPL.
Withdrawal of consent is not one of the five. Article 5 of the PDPL is the provision that allows a data subject to withdraw consent at any time, and it refers the controls to the PDPL Implementing Regulations. The duties that the PDPL places on an establishment as controller are described in employee data privacy.
How a right is exercised: Articles 3 and 10 of the PDPL Implementing Regulations
Under Article 3 of the PDPL Implementing Regulations, a controller that receives a request from a data subject about the data subject’s rights must do four things:
- Execute the request within a period not exceeding 30 days, without delay.
- Adopt the technical, administrative and organisational means needed to ensure a prompt response.
- Take appropriate steps to verify the identity of the person making the request before executing it.
- Document and keep every request submitted to it, including oral requests.
The controller may extend the period by no more than 30 additional days. It may do so if execution requires additional effort that is unexpected or out of the ordinary, or if it has received multiple requests from the same data subject. The condition is that it notifies the data subject in advance of the extension and its reasons. That gives a maximum period of 60 days in all (30 + 30).
Under paragraph 2 of Article 3 of the PDPL Implementing Regulations, a controller may decline to process a request that is repeated without justification, or whose execution requires effort out of the ordinary, provided that it gives its reasons and informs the data subject. Under paragraph 3 of the same Article, the legal guardian of a data subject who partly or wholly lacks legal capacity may exercise the rights on that person’s behalf.
Article 10 of the PDPL Implementing Regulations requires the controller to provide suitable means of responding to requests. The data subject may use one or more of these means, at the data subject’s choice and according to what the controller makes available: email, text messages, the national address, communication through electronic applications, and any other lawful means of communication set up for the purpose.
Here is an example with assumed figures. On day 0, an employee sends one message that asks for a copy of the employee’s file, for correction of the date of joining, and for destruction of an image of an old document. The message contains three separate requests, and the first period of 30 days ends on day 30. If the establishment finds that execution needs additional effort, it notifies the employee of the extension and its reasons before the 30 days pass, and the maximum becomes day 60. An extension announced after day 30 does not meet the condition of advance notice in paragraph 1 of Article 3 of the PDPL Implementing Regulations.
The right to be informed: Article 4 of the PDPL Implementing Regulations
Under Article 4 of the PDPL Implementing Regulations, a controller that collects data directly from the data subject takes the measures needed, before or at the time of collection, to inform the data subject of these items:
- The controller’s legal name and contact details, and any details of the communication channels that it has set up for the protection of personal data.
- The contact details of the personal data protection officer, if there is one.
- The legal basis and the purpose of collecting and processing the data, stated in a specific, clear and explicit way.
- The period for which the data is kept, or the criteria for calculating the period if it cannot be fixed in advance.
- The data subject’s rights under Article 4 of the PDPL and the mechanism for exercising any of them.
- How to withdraw the consent given for processing any of the data.
- Whether collecting or processing any of the data is mandatory or optional.
The duty to inform does not apply if the data subject already has the information, or if providing it conflicts with a law in force in the Kingdom (paragraph 2 of Article 4 of the PDPL Implementing Regulations). Where the data was not collected directly from the data subject, the controller must inform the data subject of the same items, without undue delay and within 30 days of receiving the data. It must add the categories of data that it processes and the source from which it obtained them (paragraph 3 of Article 4 of the PDPL Implementing Regulations).
Paragraph 4 of Article 4 of the PDPL Implementing Regulations sets five exceptions to the duty in paragraph 3:
- The data subject already has the information.
- Informing the data subject is impossible, or requires unreasonable effort.
- The controller obtained the data in implementation of a law.
- The controller is a public entity and collected the data for security purposes, to meet judicial requirements or for a public interest.
- The data is subject to professional secrecy rules established by law.
If a controller wants to process data further for a purpose other than the one for which it collected the data, paragraph 6 of Article 4 of the PDPL Implementing Regulations requires it to give the data subject the necessary information before the processing.
Applied to hiring, the application form that an applicant completes is direct collection, so the applicant is informed of these items before or at the time of collection. Data that an establishment obtains from a third party is collection from someone other than the data subject. Examples are a recruitment office, or a previous employer that the establishment contacts about the applicant. The 30-day period then applies, unless one of the five exceptions applies. This is an application of the text to hiring facts. The tools in which applicant files are kept are described in applicant tracking system and candidate database.
Access and copy: Articles 5 and 6 of the PDPL Implementing Regulations and Article 9 of the PDPL
Paragraph 1 of Article 9 of the PDPL allows the controller to set time frames for exercising the right of access, as the PDPL Implementing Regulations provide. It also allows the controller to limit the right where that is necessary to protect the data subject or others from harm, under the provisions that the PDPL Implementing Regulations set. A second case applies to a public entity, where the restriction is required for security purposes, by another law or to meet judicial requirements.
Paragraph 2 of Article 9 of the PDPL requires the controller to prevent the data subject from accessing the data in the first six situations of Article 16 of the PDPL, which are the situations in which the disclosure would:
- endanger security, harm the reputation of the Kingdom or conflict with its interests;
- affect the Kingdom’s relations with another state;
- prevent the detection of a crime, affect the rights of an accused to a fair trial or affect the integrity of criminal procedures in progress;
- endanger the safety of one or more individuals;
- violate the privacy of an individual other than the data subject, as the PDPL Implementing Regulations set out;
- conflict with the interest of a person who partly or wholly lacks legal capacity.
Article 5 of the PDPL Implementing Regulations adds that the right of access must not adversely affect the rights of others, such as intellectual property rights or trade secrets. The controller may give access on request, or through a means that it provides so that the data subject can obtain the data automatically without making a request. The controller must make sure that the access does not disclose personal data that identifies another individual.
Article 6 of the PDPL Implementing Regulations covers the copy. It repeats only two of the limits in Article 5 of the PDPL Implementing Regulations: that the copy must not adversely affect the rights of others, and that the controller must make sure the copy does not disclose data that identifies another individual. Article 6 of the same Regulations adds that the data is provided in a widely used electronic format, and that the data subject may ask for a printed copy where that is possible.
In practice, an employee file may hold material that relates to someone else, such as a complaint submitted by a colleague or a minute that names another worker. When a copy is delivered, the documents are reviewed and whatever identifies the other individual is withheld. This applies paragraph 2 of Article 5 and paragraph 3 of Article 6 of the PDPL Implementing Regulations to HR facts.
Correction: Articles 7 and 22 of the PDPL Implementing Regulations and Article 17 of the PDPL
Under Article 7 of the PDPL Implementing Regulations, a data subject whose data that the controller holds is not accurate may ask for processing to be restricted for a period in which the controller can verify the accuracy. That right to restriction does not apply if providing the data would conflict with the provisions of the PDPL and the PDPL Implementing Regulations. The controller may ask for documents that support a request for correction where that is necessary, and it must destroy those documents once the verification is complete. After a correction, the controller informs without delay the parties to which it had previously disclosed the data.
Paragraph 1 of Article 17 of the PDPL provides the same: if data is corrected, completed or updated, the controller notifies the amendment to every other entity to which the data has been transferred and makes the amendment available to it.
Article 22 of the PDPL Implementing Regulations sets out three types of correction: correcting wrong data, completing incomplete data, and updating earlier data. When it corrects, the controller must:
- ensure the accuracy and integrity of the data, by checking supporting documents where necessary;
- inform without delay the parties to which the data was disclosed;
- inform the data subject when the correction is finished;
- document every update it makes.
If the data is inaccurate or incomplete, and that would cause harm to its subject, processing must stop until the data is updated or corrected (paragraph 3 of Article 22 of the PDPL Implementing Regulations). When the controller learns that the data is inaccurate or out of date, it must correct, complete or update it without delay, by the means available to it (paragraph 4 of Article 22 of the PDPL Implementing Regulations).
An example is the date of joining in a worker’s file. If the date is wrong because of an entry error, the length of service on which the end of service award under Article 84 of the Saudi Labor Law (نظام العمل) rests may be affected. The worker’s request to correct it is the worker’s right, and once the establishment learns of the error, correcting it is the establishment’s duty under paragraph 4 of Article 22 of the PDPL Implementing Regulations.
Destruction: Article 8 of the PDPL Implementing Regulations and Articles 4 and 18 of the PDPL
Article 1 of the PDPL defines destruction as any action taken on personal data that “makes it unreadable and irretrievable, or impossible to identify the related Data Subject”, in the wording of SDAIA’s official English translation. The right to destruction in paragraph 5 of Article 4 of the PDPL is without prejudice to Article 18 of the PDPL. Under paragraph 1 of Article 8 of the PDPL Implementing Regulations, the controller must destroy the data in any of four situations:
- The data subject asks for it.
- The data is no longer necessary for the purpose for which it was collected.
- The data subject has withdrawn consent to the collection, and consent was the only legal basis for the processing.
- The controller learns that the data is being processed in a way that contravenes the PDPL.
On destruction, the controller takes appropriate steps to inform the parties to which it disclosed the data, and the persons to whom it was disclosed by any means, and to ask them to destroy it. It also destroys every copy in its storage systems, including backups, while observing the relevant legal requirements (paragraph 2 of Article 8 of the PDPL Implementing Regulations). None of this prejudices Article 18 of the PDPL or the legal requirements that the relevant competent bodies set (paragraph 3 of Article 8 of the PDPL Implementing Regulations).
Paragraph 1 of Article 18 of the PDPL requires the controller to destroy the data without undue delay once the purpose of collection has ended. The controller may keep the data if everything that could lead to identifying the data subject specifically has been removed, under the controls in the PDPL Implementing Regulations. Paragraph 2 of Article 18 of the PDPL requires the controller to keep the data after the purpose has ended in two cases:
- A legal basis requires the data to be kept for a specified period. The data is destroyed when that period ends or when the purpose ends, whichever is longer.
- The data is closely connected to a case before a judicial authority, and keeping it is required for that purpose. The data is destroyed once the judicial procedures are complete.
Destruction requests and the employer’s duty to keep the employment file
Article 17 of the Saudi Labor Law requires the employer to keep at the workplace the records, statements and files whose nature and contents the Implementing Regulations of the Labor Law (اللائحة التنفيذية لنظام العمل) specify. Article 5 of the Implementing Regulations of the Labor Law specifies seven records. One of them is an employment file (ملف عمل) for each worker, which contains the worker’s data, address, a copy of the employment contract, and any certificates or documents that the worker gives to the employer. A worker’s request for destruction and the employer’s duty to keep the worker’s file apply to the same documents.
The place of that Article among the others is described in implementing regulations of the labor law.
In Article 5 of the Implementing Regulations of the Labor Law, we found no period for keeping these files. In Articles 3 to 10 and Article 22 of the PDPL Implementing Regulations, we found no fees for exercising the rights. We also found no periods of the kind that paragraph 1 of Article 9 of the PDPL allows to be set for the right of access. So we do not state what is required in a particular case. That question needs a specialist who has the facts of the case.
Do data subject rights belong only to employees?
No. The data subject under the PDPL is any individual whose personal data a controller processes, and the PDPL applies to any processing of individuals’ data that takes place in the Kingdom. An applicant who was not accepted, a trainee and a worker whose service has ended hold the same five rights against the establishment, for as long as the establishment keeps their data.
This is an explanation of the concept and of the statutory provisions cited, not legal advice.
A standalone Saudi HR system
One employee file holding the contract, the documents and their expiry dates, the attendance record, leave, salary and end-of-service entitlements. End-of-service, overtime and leave-balance calculations are built into the system.
A standalone system on its own subscription. The connection to Qoyod Accounting is now available.
