We have been operating in the commercial kitchen equipment and technical service sector out of Riyadh for three years. Our system contains roughly 12,000 customer records across Saudi Arabia, including company names, commercial registration numbers, mobile numbers, locations, and billing histories. To date, this data has been stored in cloud spreadsheets and a basic order management app; candidly, we never collected explicit data processing consent, gathering it merely as part of doing business.
The recent increase in regulatory enforcement and corporate audits under the Saudi Personal Data Protection Law has us worried. Operationally, we don't know how to categorize this three-year backlog of data and bring it onto solid legal ground. We have hundreds of companies on file whose contracts ended long ago, yet their records still sit in our spreadsheets.
What concrete steps should we take to bring this three-year historical customer data into compliance with Saudi data protection regulations before an official audit hits? How should we destroy expired data, and how do we properly document consent?