- Job title
- Technical service technician
- Sector
- Furniture manufacturing
- Organization type
- family business
- Joined
- May 2024
- Message
- 255
We are a 35-person company based in Dammam, providing technical maintenance and engineering personnel to oil and petrochemical facilities. Along with rotational contractors on-site, our database contains hundreds of national IDs, passports, visas, and biometric certification records. Following the enactment of the Saudi Arabia Personal Data Protection Law (PDPL), we downloaded the legal text and the executive regulations PDF from the official portal.
We set up an internal working group and converted every article in the regulations into an Excel checklist. We updated our NDAs, gathered consent forms from field workers, added a privacy notice to our website, and formalized our data destruction policy with board approval.
On paper, we seem to have ticked every box, but would this documentation alone be considered sufficient during a potential audit? Are there additional mandatory obligations on the technical side (data encryption, access logs) or regarding registration with the regulatory authority (SDAIA)?