-
Definition
Data:
A set of facts in their original form or in an unstructured format, such as numbers, letters, static images, videos, audio recordings, or emojis.
Requester:
Any government entity, private sector organization, or individual submitting a request for data sharing.
Source Entity:
The government entity responsible—within its regulatory jurisdiction—for setting technical standards for specific data fields or datasets, verifying data accuracy, and maintaining records.
Authorized Entity:
An entity delegated to share data by the source entity, following the procedures outlined in this policy and ensuring data accuracy.
Recipient Entity:
Any government entity that receives a data-sharing request, whether as the source entity or the authorized entity.
Data Sharing Stakeholders:
Any party involved in the data-sharing process, including the requester and the recipient entity.
Data sharing agreement:
A standard agreement signed between two parties—when government data is shared with a private entity or an individual—outlining the roles and responsibilities of stakeholders according to this policy.
Data Sharing Guidelines Template
A standard framework specifying the necessary controls for handling data, defining roles and responsibilities when stakeholders are government entities.
Authority:
The Saudi Data and Artificial Intelligence Authority (SDAIA).
Office:
The National Data Management Office (NDMO).
Entity Office:
The data management office within a government entity.
Government Integration Channel:
A secure platform for data sharing among government entities to enhance interoperability and enable service automation.
Data Marketplace:
A platform for automating data-sharing processes among government entities under this policy, allowing entities to subscribe to available APIs or request new services. The Data Marketplace is part of the National Data Bank.
Metadata:
Detailed information describing datasets and their usage characteristics, whether they relate to business, technical, or operational data.
-
Objective
The purpose of the Data Sharing Policy is to enhance data sharing to achieve integration between government entities and to acquire data from its sources. This policy aligns with the policies issued by the National Data Management Office—the legislative arm of the Saudi Data and Artificial Intelligence Authority (SDAIA). It aims to comply with data management and governance requirements, as well as related legislative and regulatory requirements. This is a legislative requirement in specification DG.1.2 of the National Data Management and Governance Regulations and Personal Data Protection Standards (version 1.5), issued by the National Data Management Office.
-
Scope
The provisions of this policy apply to all data produced by the university and intended for sharing with other government entities, private entities, or individuals, regardless of the data's source, format, or nature. This includes paper records, emails, data stored on electronic media, audio or video tapes, maps, photographs, manuscripts, handwritten documents, or any other form of recorded data. This policy does not apply when the requesting entity is a government body, and the request is for security purposes or to fulfill judicial requirements.
-
Key Principles of Data Sharing
Principle 1: Promoting a Culture of Participation
The university should share the key data it generates to achieve integration between itself and government entities. It should adopt the "once-only principle" to obtain data from its correct sources, reduce redundancy, avoid conflicts, and minimize multiple sources. If data is requested from a non-primary source, the university must obtain approval from the primary entity (the data source) before sharing it with the requesting party.
Principle 2: Legitimacy of Purpose
Data should be shared for legitimate purposes based on a regulatory foundation or a justified practical need aimed at achieving a public interest without causing harm to national interests, government activities, individual privacy, or environmental safety. This excludes data and entities exempted by royal orders.
Principle 3: Authorized Access
All parties involved in data sharing should have the authorization to view, obtain, and use the data (which may require a security clearance based on the nature and sensitivity of the data). Additionally, they should possess the knowledge, skills, and appropriately trained personnel to handle the shared data.
Principle 4: Transparency
All parties involved in data sharing must provide all necessary information for data exchange, including the requested data, the purpose of its collection, means of transmission, methods of storage, protection measures, and the process for data disposal.
Principle 5: Shared Responsibility
All parties involved in data sharing are jointly responsible for decisions regarding data sharing and processing in accordance with the specified purposes. They must ensure the application of security controls as outlined in the data-sharing agreement and comply with relevant laws, regulations, and policies.
Principle 6: Data Security
All parties involved in data sharing must implement appropriate security controls to protect the data and share it in a secure and trustworthy environment. This must align with relevant laws, regulations, and the standards set by the National Cybersecurity Authority.
Principle 7: Ethical Use
All parties involved in data sharing must follow ethical practices during the data-sharing process to ensure it is used fairly, transparently, and with integrity and respect. This includes adhering not only to information security policies but also to regulatory and legislative requirements.
-
Steps for the Data Sharing Process
The basic steps of the data sharing process have been determined by the National Data Management Office to help the entities unify the participation practices and ensure the fulfillment of all the necessary controls and requirements – which may not exceed 3 months and are outlined as follows:
First Step:
The requesting party—whether governmental, private, or individual—submits a data-sharing request to the university’s Data Management Office. If the request comes from a government entity, it must be submitted via the government’s Data Management Office.
Second Step:
The university’s Data Management Office forwards the request to the relevant business data representative, who will direct the request to a specialized business data professional for evaluation and processing.
Third Step:
The business data specialist checks the level of classification of the required data: A. If the classification level is not specified, the university’s Data Management Office must classify the data according to the Data Classification Policy B. If the classification level is "Public", the business data specialist can share the requested data without further evaluation, in accordance with the data-sharing principles. C. If the classification level is "Restricted", "Confidential", or "Highly Confidential", the business data specialist must evaluate the request according to the data-sharing principles.
Fourth Step:
The business data specialist in the university’s Data Management Office proceeds with the data sharing process only if all data-sharing principles are fully met.
Fifth Step:
If any data-sharing principle is not met, the business data specialist cannot proceed with sharing the data. The request should be returned to the requester with comments and the opportunity to address the non-compliant principles.
Sixth Step:
Once all principles are met, the business data specialist obtains approval from the business data representative to complete the data-sharing process.
Seventh Step:
The business data specialist determines the appropriate controls to ensure compliance with the data-sharing principles and the specific goals of each. An agreement must be reached between the business data specialist, the requester, and any other parties involved in the data sharing process to implement these controls.
Eighth Step:
After agreeing on the data-sharing controls, the business data specialist details them in a formal agreement. All parties involved in the data-sharing process must sign this data-sharing agreement.
Ninth Step:
Once the data-sharing agreement is signed, the university’s Data Management Office can share the requested data with the requesting entity.