We are a 22-person industrial equipment supplier based in Riyadh. Together with our legal counsel we went through the PDF of Saudi Arabia's new personal data protection law and the executive regulations issued by the authorities from cover to cover. The text is packed with legal obligations penalties and general frameworks, but on the operational side, it's completely unclear what we're supposed to do first thing tomorrow morning when we walk into the office.
Our annual turnover is around 6 million SAR and our database contains contact details of local clients passport or iqama copies for over 200 supplier representatives, and payroll records for our employees. The clauses in the regulations regarding records of processing activities, explicit consent forms, and cross-border data transfers are really intimidating.
What is the bare minimum documentation we must have ready on our desks before facing an audit, and at what concrete point should we begin our technical preparations?