•  
  •  
 

Abstract

Saudi Arabia's Personal Data Protection Law (PDPL) and its Implementing Regulation impose binding duties on controllers, including public universities that process extensive personal and sensitive information. This study examines King Faisal University's (KFU) published privacy policy to determine the extent to which it reflects the mandatory provisions of the PDPL and the regulatory orientations issued by the Saudi Data and Artificial Intelligence Authority (SDAIA). The study adopts a doctrinal legal method combined with qualitative content analysis and a gap assessment. It evaluates the policy's treatment of collection purposes, legal bases, data-subject rights, complaint channels, governance responsibilities, impact assessment, breach notification, response periods, processing records, and transfers outside the Kingdom. The findings indicate that the policy provides a meaningful foundation for transparency by identifying data categories, processing purposes, legal bases, and principal rights, while several procedural and accountability matters are less fully articulated in the published document. The study identifies targeted measures to strengthen the policy's regulatory clarity within the Saudi personal data protection framework.

Share

COinS