The Saudi personal data protection regime, establishing controller obligations, data subject rights and transfer conditions.
Organisations processing the personal data of individuals in the Kingdom of Saudi Arabia, including those established outside the Kingdom where they process such data.
As with the other regional privacy regimes, discovery precedes control. Transfer conditions deserve early attention because they can constrain architecture, and architecture is expensive to revisit once a programme is underway.
Supervisory compliance, defensible to the competent authority.
SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.
Control mappings for this framework are not yet published in the library. It is carried in full for assessment and preparation, and cross-framework reuse will follow as the mapping matures. We would rather state that plainly than imply reuse that does not exist.