• Definitions​
  • Data:

    A set of facts in their raw form or in an unstructured format, such as numbers, letters, static images, videos, audio recordings, or emojis.

    Personal Data:

    Any data—regardless of its source or format—that can specifically identify an individual or make them identifiable, directly or indirectly, when combined with other data. This includes, but is not limited to, names, personal identification numbers, addresses, contact numbers, bank account numbers, credit card details, static or dynamic user images, and other personally identifiable information.

    Sensitive Data:

    Data whose loss, misuse, unauthorized access, or modification could cause significant harm or have a negative impact on national interests, government activities, or the privacy of individuals and the protection of their rights.

    Verification:

    Verifying the identity of any user, process, or device as a fundamental requirement to allow access to technical resources.

    Personal Data Sub-processing:

    The natural person to whom the personal data relate or his representative or legal guardian.

    Personal data subject:

    Maintaining authorized access restrictions to data or disclosure of it.

    Control unit:

    Any administrative unit within the university that processes personal data.

    Personal data leak:

    The disclosure, acquisition, or unauthorized access to personal data, whether intentional or unintentional, without proper authorization or legal basis.

    Implicit consent:

    Consent that is not explicitly given by the data subject but is inferred through their actions, circumstances, or the context of the situation, such as signing contracts or agreeing to terms and conditions.

  • Objective
  • The purpose of the Personal Data Protection Policy is to maintain the confidentiality of personal information to ensure the protection of individuals' rights, regulating the procedures of collecting, processing, sharing, and safeguarding digital sovereignty related to personal data. It complies with national data governance policies and the fundamental legislation protecting individuals' rights and privacy concerning their personal data, which is subject to the Personal Data Protection Law. This policy aims to adhere to the requirements for data management and governance, as well as related legislative and regulatory requirements. It is a legislative requirement in specification DG.1.2 of the National Data Management and Governance Standards and Personal Data Protection (version 1.5) issued by the National Data Management Office.

  • Scope
  • The provisions of this policy apply to all control units that process personal data, either wholly or partially, as well as external entities that process personal data related to the university's staff, whether through the internet or any other means. This policy does not apply to the collection of personal data from individuals without their direct knowledge, or to processing for purposes other than the original purpose for which the data was collected, or disclosing it without consent, or transferring it outside the Kingdom in the following cases:

  • 1- If the collection or processing of personal data is required to meet regulatory requirements according to the laws, regulations, and policies in effect in the Kingdom, or to fulfill judicial requirements, or to comply with obligations under an agreement in which the Kingdom is a party.
  • 2. If the collection or processing of personal data is necessary to protect public health or safety or to protect the vital interests of individuals. ​

  • Key Principles for Personal Data Protection
  • Principle 1: Responsibility

    The university's privacy policies and procedures should be defined and documented by the Data Management Office, approved by the university president (or their delegate), and published to all relevant parties involved in their implementation.

    Principle 2: Transparency

    A notice of the University's privacy policies and procedures shall be prepared specifying the purposes for which the personal data have been processed in a specific, clear and explicit manner.

    Principle 3: Selection and consent

    All possible options for the data subject are identified and their consent (implied or explicit) is obtained in relation to the collection, use or disclosure of their data.

    Principle 4: Data Minimization

    The collection of personal data should be limited to the minimum necessary to achieve the purposes specified in the privacy notice.

    Principle 5: Data Use, Retention, and Disposal Limitation

    The processing of personal data should be restricted to the purposes specified in the privacy notice, for which the data subject has provided implicit or explicit consent. The data should be retained only as long as necessary to fulfill the specified purposes or as required by applicable laws, regulations, and policies in the Kingdom. When no longer needed, the data should be securely destroyed to prevent leakage, loss, theft, misuse, or unauthorized access.

    Principle 6: Access to Data

    The means by which the data subject can access their personal data for review, updating, and correction should be identified and provided.

    Principle 7: Limit Data Disclosure

    The disclosure of personal data to external parties should be restricted to the purposes specified in the privacy notice, for which the data subject has provided implicit or explicit consent.

    Principle 8: Data Security

    Personal data should be protected from leakage, damage, loss, theft, misuse, alteration, or unauthorized access, in accordance with the guidelines issued by the National Cybersecurity Authority and relevant authorities.

    Principle 9: Data Quality

    Personal data is kept accurate, complete, and directly related to the purposes specified in the Privacy Notice.

    Principle 10: Monitoring and Compliance

    Monitor compliance with privacy policies and procedures, and address privacy-related inquiries, complaints, and disputes.

​​​

​​​​​​