هل تملك منشأتك سياسة حماية بيانات معتمدة؟ إذا كانت إجابتك "لا" أو "لست متأكداً" — فأنت أمام مخاطرة حقيقية اليوم. Does your organization have an approved data protection policy? If your answer is "no" or "I'm not sure" — you're carrying real regulatory risk today.
منذ 14 سبتمبر 2024، انتهت فترة السماح لنظام حماية البيانات الشخصية (PDPL). وفي عام 2025 وحده، أصدرت هيئة البيانات والذكاء الاصطناعي (SDAIA) قرارات بالمخالفة ضد منشآت متعددة. الغرامات تبدأ من التحذير وتصل إلى 5 ملايين ريال، وفي حالات الإفصاح عن بيانات حساسة قد تصل العقوبة إلى السجن. Since September 14, 2024, the grace period for the Personal Data Protection Law (PDPL) has ended. SDAIA's enforcement committees have issued formal violation decisions against multiple organizations. Fines range from warnings up to SAR 5 million, and unlawful disclosure of sensitive data can lead to imprisonment.
من يقع تحت نطاق نظام PDPL؟Who Falls Under PDPL?
النظام يشمل كل منشأة — حكومية أو خاصة — تجمع أو تعالج أو تخزن بيانات شخصية لأفراد داخل المملكة: The law applies to every organization — public or private — that collects, processes, or stores personal data of individuals inside Saudi Arabia:
ما الذي يجب أن تتضمنه سياسة حماية البيانات؟What Must the Policy Include?
بحسب نظام PDPL واللوائح التنفيذية الصادرة عن سدايا، يجب أن تتضمن السياسة كحد أدنى: Under PDPL and SDAIA's Implementing Regulations, the policy must address at minimum:
- الغرض من الجمع — لماذا تجمع هذه البيانات تحديداًPurpose of collection — exactly why this data is collected
- أنواع البيانات المجموعة — اسم، هوية، صحة، ماليةTypes of data — name, ID, health, financial
- مدة الاحتفاظ والإتلاف — كم تحتفظ بها وكيف تُحذفRetention & destruction — how long kept and how deleted
- حقوق صاحب البيانات — الوصول، التصحيح، الحذف، الاعتراضData subject rights — access, correction, deletion, objection
- الأمن والحماية — إجراءات حماية البيانات من التسريبSecurity measures — protection from breach
- مشاركة ونقل البيانات — مع من، ولماذا، وضوابط النقل خارج المملكةSharing & transfers — with whom, why, and cross-border safeguards
الفرق بين سياسة الخصوصية وسياسة حماية البياناتPrivacy Policy vs. Data Protection Policy
سياسة الخصوصية (خارجية)Privacy Policy (External)
وثيقة تُنشر للعملاء تخبرهم كيف تتعامل مع بياناتهم. مطلوبة على موقعك وتطبيقك ونقاط جمع البيانات.A public document telling customers how you handle their data. Required on your website, app, and collection points.
سياسة الحماية (داخلية)Data Protection (Internal)
وثيقة داخلية تحكم كيف يتعامل موظفوك مع البيانات. مطلوبة للتدقيق الداخلي ولجان SDAIA.An internal document governing how staff handle data. Required for internal audit and SDAIA review.
الوثيقتان تكمّلان بعضهما — واحدة للعملاء وواحدة للموظفين.The two documents complement each other — one for customers, one for staff.
5 أخطاء شائعة تعرّضك للغرامة5 Common Mistakes That Expose You to Fines
1. نسخ سياسة من الإنترنت1. Copying a policy from the internet
النظام السعودي له متطلبات تختلف عن GDPR الأوروبي. النسخ المباشر لا يحقق الامتثال.Saudi PDPL differs from GDPR. Direct copying does not achieve compliance.
2. سياسة بالإنجليزية فقط2. English-only policy
إذا كانت خدماتك للسعوديين، يجب أن تكون السياسة بالعربية — وهو شرط شفافية في النظام.For Saudi-facing services, the policy must be in Arabic — a transparency requirement.
3. سياسة عامة لا تعكس نشاطك3. A generic policy
عيادة أسنان تجمع بيانات صحية حساسة تختلف عن محل يجمع رقم جوال. السياسة يجب أن تعكس بياناتك الفعلية.A dental clinic's sensitive health data differs from a store collecting phone numbers. The policy must reflect your actual data.
4. عدم تحديث السياسة4. Not updating the policy
إضافة خدمة أو نظام جديد يجمع بيانات يستوجب تحديث السياسة. الثبات في بيئة متغيرة = ثغرة.A new service or system collecting data requires an update. Static policy in a dynamic environment = a gap.
5. سياسة موجودة لكن مجهولة5. A policy no one knows
وجود السياسة في درج المدير لا يكفي. يجب نشرها وتدريب الموظفين وتوثيق ذلك.A policy in the drawer isn't enough. It must be published, staff trained, and documented.
ما تحتاجه العيادة الخاصة تحديداًWhat Private Clinics Specifically Need
لأنها تتعامل مع بيانات صحية حساسة تستوجب حماية مضاعفة، مع ضوابط إضافية من وزارة الصحة والمجلس الصحي السعودي.They process sensitive health data requiring heightened protection, with additional controls from the Ministry of Health and Saudi Health Council.
الحد الأدنى للعيادة:Minimum for a clinic:
- سياسة خصوصية المريض — منشورة في الاستقبال والموقعPatient privacy policy — at reception and on the website
- نموذج موافقة واضح — يُوقَّع قبل جمع البيانات الصحيةClear consent form — signed before collecting health data
- سياسة حماية داخلية — تحكم وصول الموظفين للملفات الطبيةInternal protection policy — governing staff access to records
- إجراء الاستجابة لطلبات المرضى — الاطلاع أو الحذفPatient request procedure — access or deletion
- إجراء الإخطار عن التسريب — ماذا تفعل عند تسرب البياناتBreach notification procedure — what to do on a leak
خطوات إعداد سياستكSteps to Prepare Your Policy
رسم خريطة البياناتMap your data
ما البيانات التي تجمعها، من أين، ومن يصل إليهاWhat you collect, from where, and who accesses it
تحديد الأساس القانونيEstablish a lawful basis
لكل عملية جمع مسوّغ قانوني واضحEvery collection needs a clear legal basis
صياغة السياساتDraft the policies
السياسة الخارجية والداخلية متوافقتين مع PDPLExternal and internal policies, PDPL-aligned
الاعتماد والنشرApprove & publish
اعتماد من الإدارة ونشر موثّقManagement approval and documented publication
التدريب والمراجعةTrain & review
تدريب الموظفين ومراجعة سنويةStaff training and annual review
الخلاصةIn Summary
سياسة حماية البيانات الشخصية ليست وثيقة قانونية جافة — هي أداة حوكمة حقيقية تحمي منشأتك من المسؤولية، وتبني ثقة عملائك، وتجعلك جاهزاً لأي تدقيق. الوقت الأنسب لإعدادها كان أمس، والوقت التالي الأنسب هو الآن. A Personal Data Protection Policy is not a dry legal formality — it's a real governance instrument that protects your organization from liability, builds customer trust, and keeps you audit-ready. The best time to prepare it was yesterday; the next best is now.
هل تحتاج سياسة حماية بيانات لمنشأتك؟Need a Data Protection Policy?
نعدّ لك سياسة متوافقة مع PDPL ومخصّصة لقطاعك — أو قِس جاهزيتك أولاً.We prepare a PDPL-compliant policy tailored to your sector — or measure your readiness first.