Book an appointment with us, or search the directory to find the right lawyer for you directly through the app.
Find out more
Deal by Design
Welcome to this edition of Law Update, focusing on the evolving M&A landscape across the MENA region. With deal activity and value continuing to grow, the region is seeing increased investor interest alongside a changing regulatory environment.
This edition explores key legal and market developments affecting M&A transactions, including regulatory reforms, foreign investment, governance, due diligence and deal structuring across the region.
We have observed that SDAIA is increasingly requiring entities to register as data controllers on the National Data Governance Platform (NDGP). In practice, this may occur either through direct outreach by SDAIA or indirectly via the entity’s sector regulator, in some cases without a prior assessment of whether the entity is in fact required—under the PDPL and its Implementing Regulations—to register.
In light of this, our recommendations are as follows:
We have also seen cases where entities seeking to register as data controllers for the purpose of submitting a data breach notification encounter difficulties because they are not recognized as eligible to register. This has resulted in risks of delay in meeting the 72-hour breach notification deadline mandated by the PDPL and enforced by SDAIA.
To mitigate this risk, we have adopted the approach of submitting the initial breach notification directly by e-mail to the National Data Management Office (which administers the NDGP) within the 72-hour timeframe, while completing the formal registration process on the platform if and when registration is required. This ensures compliance with statutory deadlines. Please note, however, that if the notification is submitted after the 72-hour window, SDAIA requires a written justification for the delay.
Regarding the PDPL training, we would like to emphasize the importance of conducting internal training for employees who process or handle personal data within organizations. This is a key requirement under the PDPL and its Implementing Regulations.
Specifically, Article 36 of the Implementing Regulations mandates that entities conduct regular audits to ensure the protection of personal data. It also highlights the need for staff to be adequately trained to manage personal data responsibly, identify internal compliance gaps, and implement the necessary administrative and organizational measures to ensure data accuracy and integrity.
Additionally, Article 32 outlines the responsibilities of the data protection officer, which include participating in awareness initiatives, delivering training, and promoting knowledge transfer related to data protection, compliance, and the ethical handling of personal data.
Should you wish to learn more about the above points, please feel free to contact us at:
نشارك معكم أدناه ملخص ملاحظاتنا حول التوجيهات الحالية من الهيئة السعودية للبيانات والذكاء الاصطناعي (سدايا):
لاحظنا أن سدايا تطلب بشكل متزايد من الشركات (جهات التحكم) التسجيل كـ “جهات تحكم بالبيانات” في المنصة الوطنية لحوكمة البيانات (NDGP). وفي الواقع العملي، قد يتم الطلب إما مباشرة من سدايا أو عن طريق الجهة التنظيمية القطاعية، وأحيانًا يتم ذلك حتى بدون تقييم مسبق لمدى إلزامية التسجيل بموجب النظام واللوائح.
بناءً عليه نقترح التالي:
وجدنا في بعض الحالات أن بعض الشركات تواجه صعوبات عند محاولة التسجيل كـ جهات تحكم بالبيانات على المنصة، خصوصًا عند رغبتهم بتقديم إخطار بخرق بيانات. هذا قد يسبب تأخيرًا في استيفاء شرط الإخطار خلال 72 ساعة، وهو الشرط المحدد بالنظام وتطبقه سدايا بشكل صارم.
ولتفادي هذا الخطر، ننصح بالآتي: إرسال الإخطار الأولي عن الخرق مباشرة عبر البريد الإلكتروني للمكتب الوطني لإدارة البيانات خلال 72 ساعة. كما واستكمال التسجيل الرسمي على المنصة في حال تأكد أن التسجيل مطلوب. مع ملاحظة أنه إذا تم الإخطار بعد 72 ساعة، تطلب سدايا تبريرًا كتابيًا للتأخير.
نؤكد كذلك على أهمية تنفيذ برامج تدريبية داخلية للموظفين الذين يتعاملون مع البيانات الشخصية. التدريب يُعد مطلبًا أساسيًا وفق النظام ولوائحه.
وبالتحديد:
المادة (36) من اللائحة التنفيذية تنص على ضرورة إجراء تدقيقات دورية والتأكد من تدريب الموظفين بشكل كافٍ للتعامل مع البيانات الشخصية بمسؤولية، والتعرف على الثغرات الداخلية، وتطبيق الضوابط الإدارية والتنظيمية لحماية دقة وسلامة البيانات.
المادة (32) تحدد مهام مسؤول حماية البيانات، ومنها المشاركة في مبادرات التوعية، وتقديم التدريب، وتعزيز المعرفة المتعلقة بالامتثال والمعالجة الأخلاقية للبيانات.
للاستفسار أو لمزيد من التفاصيل يمكن التواصل مع:
To learn more about our services and get the latest legal insights from across the Middle East and North Africa region, click on the link below.