What employee data privacy means
Employee data privacy, also called employee data protection, is an organisation’s obligation to process the data it holds on its employees and its job candidates in line with the Personal Data Protection Law (نظام حماية البيانات الشخصية), or PDPL. The PDPL was issued by Royal Decree M/19 of 9/2/1443H and amended by Royal Decree M/148 of 5/9/1444H.
The PDPL is a separate instrument from the Saudi Labor Law (نظام العمل), and a different authority stands behind it. Its text leaves the competent authority to be designated by a resolution of the Council of Ministers. The body that publishes the PDPL and its Implementing Regulations, and operates the national platform that carries its procedures, is the Saudi Data and Artificial Intelligence Authority (الهيئة السعودية للبيانات والذكاء الاصطناعي), or SDAIA, not the Ministry of Human Resources and Social Development. A question about how an organisation handles the data of its staff therefore starts from the PDPL, not from the Labor Law.
Article 43 of the PDPL brings the law into force 720 days after the date of its publication in the Official Gazette. That provision fixes a period, not a calendar date. We have not confirmed the publication date against the Official Gazette issue itself, so no calendar date of entry into force is given for the PDPL, and the same applies to any grace period for the private sector. Dates for both circulate in secondary sources, and we have not relied on them.
Why employee files fall within employee data privacy
Article 2 of the PDPL applies the law to any processing of personal data relating to individuals that takes place in the Kingdom, by any means, including processing carried out from outside the Kingdom on the data of individuals who reside in it. The only carve out in Article 2 of the PDPL is an individual processing personal data for purposes that do not go beyond personal or family use. An organisation keeping records on its staff is not within that carve out.
Article 1 of the PDPL defines personal data broadly. In SDAIA’s English translation, it is any data, regardless of its source or form, “that may lead to identifying an individual specifically, or that may directly or indirectly make it possible to identify an individual”, and the definition names among its examples the name, the personal identification number, addresses and contact numbers. Article 1 of the PDPL also defines processing as any operation carried out on personal data, and the operations it lists include collecting, recording, saving, indexing, organising, storing, retrieving, using, disclosing, sharing and destroying.
Keeping an employee file is therefore processing within the meaning of the PDPL. So is running reports on that file for HR analysis, and so is circulating applicants’ files through an applicant tracking system during recruitment. Candidates are covered as individuals: the scope provision does not turn on employment, so the file of someone who applied and was never hired is personal data in the same way as the file of a current employee. The candidate side of the subject is examined alongside AI recruitment and cybervetting.
Within personal data, Article 1 of the PDPL defines a category of sensitive data, which includes data revealing religious or intellectual belief or ethnic origin, health data and biometric data. The PDPL attaches further duties to sensitive data. They go beyond the definition of employee data privacy and are not set out in it.
The organisation’s role in employee data privacy: controller or processor
Article 1 of the PDPL defines the controller (جهة التحكم) as the party that determines the purpose of processing personal data and the manner of that processing, whether it processes the data itself or through a processor. It defines the processor (جهة المعالجة) as the party that processes personal data for the benefit of the controller and on its behalf.
For its employee files, the employer is the controller, because the employer is the party that decides why the data is processed and how. A provider whose system processes that data for the employer is a processor. The distinction is not a matter of wording. The PDPL imposes its obligations on the controller by name, so an organisation that has not identified its role cannot tell which of those obligations apply to it.
What employee data privacy requires of the controller
Each of the duties below is set out in the text of the PDPL.
- Specifying the purpose of collection, and keeping processing within it. Article 10 of the PDPL provides that a controller may collect personal data only directly from the data subject, and may process that data only to achieve the purpose for which it was collected, subject to the situations the same article lists as exceptions. Article 11 of the PDPL requires the purpose of collection to be directly related to the controller’s purposes and not to conflict with any provision established in law.
- Collecting no more than the purpose needs. Article 11 of the PDPL requires the content of personal data to be appropriate and limited to the minimum necessary to achieve the purpose of its collection. Applied to a joining form, the question becomes whether each field serves a purpose the organisation can name.
- Informing the data subject. Article 13 of the PDPL requires the controller, when it collects personal data directly from the data subject, to inform them of the purpose of the collection and of which data is mandatory and which is optional. Article 12 of the PDPL requires the controller to adopt a privacy policy, made available before collection, that states the purpose of collection among its elements.
- Protecting what is collected. Article 19 of the PDPL requires the controller to take the organisational, administrative and technical measures needed to protect personal data, including when it is transferred, in accordance with the provisions and controls set by the Implementing Regulations. The article names those three kinds of measure and does not list particular ones.
- Destroying data once it is no longer needed. Article 18 of the PDPL requires the controller to destroy personal data once it is no longer necessary for the purpose for which it was collected, and Article 11 of the PDPL requires the controller, once the data is no longer needed for that purpose, to stop collecting it and to destroy what was collected without undue delay. Article 18 of the PDPL also permits keeping data after the purpose has ended once nothing in it can identify the data subject specifically, in accordance with controls set by the Implementing Regulations, and requires keeping it where there is a legal basis for retaining it for a specific period, or for a pending case. In the sources we reviewed, we found no number of years for which employee data is to be kept, and a retention period taken from another statute is not carried over into the definition of employee data privacy.
- Reporting a breach. Article 20 of the PDPL requires the controller to notify the competent authority of a personal data breach, and to notify the data subject where the breach may harm them.
- Confidentiality after the relationship ends. Article 41 of the PDPL provides that anyone who processes personal data must keep it confidential even after their occupational or contractual relationship has ended. An employee who handled HR records is therefore still bound by that duty after leaving.
- Accuracy before processing. Article 14 of the PDPL bars the controller from processing personal data without taking sufficient steps to verify that the data is accurate, complete, up to date and relevant to the purpose for which it was collected.
- The rights of the data subject. Article 4 of the PDPL gives the data subject the right to be informed, the right to access their personal data, the right to obtain a copy of it, and the right to request its correction and its destruction. Except in the cases the law provides for, Article 5 of the PDPL makes the processing of personal data, and any change to the purpose of that processing, subject to the data subject’s consent, which may be withdrawn at any time.
The PDPL also sets penalties for violating its provisions. Their amounts sit outside the definition of employee data privacy and are not restated in it.
Beyond these duties, SDAIA’s national platform carries statutory procedures, among them the national register for personal data protection, impact assessments on the processing of personal data, breach notification and complaints. The PDPL also contains provisions on transferring personal data outside the Kingdom and on appointing a person responsible for personal data protection. Those subjects are separate from the definition of employee data privacy, and the conditions under which each one reaches a particular employer are not set out in it.
The provisions relied on are those of the Personal Data Protection Law as published by the Saudi Data and Artificial Intelligence Authority: Article 1 (personal data, processing, sensitive data, the controller and the processor), Article 2 (scope and the personal or family use carve out), Article 4 (the rights of the data subject), Article 5 (consent and its withdrawal), Article 10 (direct collection and purpose limitation), Article 11 (purpose, the minimum necessary, and destruction once no longer necessary), Articles 12 and 13 (the privacy policy and informing the data subject), Article 14 (verifying accuracy before processing), Article 18 (destruction and retention), Article 19 (protective measures), Article 20 (breach notification), Article 41 (confidentiality after the relationship ends) and Article 43 (entry into force).
Good practice in employee data privacy, as distinct from duty
Keeping practice apart from duty is deliberate. Limiting access to the people whose role requires it, writing an internal policy on retention and destruction, and deciding who answers an employee who asks about their data are all administrative practices. They serve compliance, but the duties set out above do not prescribe them in that form. They belong in an employee handbook or a bring your own device policy, not in the list of duties. Presenting them as statutory text would attribute to the statute something that is not in it.
This is an explanation of the concept and of the statutory provisions cited, not legal advice.
A standalone Saudi HR system
One employee file holding the contract, the documents and their expiry dates, the attendance record, leave, salary and end-of-service entitlements. End-of-service, overtime and leave-balance calculations are built into the system.
A standalone system on its own subscription. The connection to Qoyod Accounting is now available.