Data protection is the discipline of handling personal data responsibly: collecting only what is needed, using it only for what was intended, keeping it safe, and respecting the rights of the people it describes. It is where an organization's duty to individuals and its legal obligations meet the daily reality of how data actually flows through its systems.
The subject of the discipline is personal data, meaning any information relating to an identifiable person. That definition is broad on purpose, because the harm from mishandling data does not depend on how sensitive a single field looks, it depends on what can be learned and done when data is combined. A name alone seems harmless, but joined to a location, a purchase history, and a health detail it becomes a profile that can expose or discriminate.
This framework describes an operational privacy program organized around the principles common to modern data protection regimes, illustrated with the structure of Saudi Arabia's Personal Data Protection Law and its regulator, and written to be reusable wherever similar obligations apply. It aligns to the published law and guidance without reproducing their text.
حماية البيانات انضباط التعامل المسؤول مع البيانات الشخصية: جمع ما يلزم فقط، واستخدامه لما قُصِد فقط، وإبقاؤه آمنًا، واحترام حقوق من تصفهم. وهي حيث يلتقي التزام المنشأة تجاه الأفراد والتزاماتها القانونية بواقع كيف تتدفّق البيانات فعلًا عبر أنظمتها.
موضوع الانضباط هو البيانات الشخصية، أي أي معلومةٍ تتعلّق بشخصٍ يمكن تحديده. وذلك التعريف واسعٌ عمدًا، لأن الأذى من سوء التعامل لا يعتمد على كم يبدو حقلٌ مفرد حساسًا، بل على ما يمكن معرفته وفعله حين تُدمَج البيانات. فاسمٌ وحده يبدو غير ضار، لكنه مقرونًا بموقعٍ وسجل شراءٍ وتفصيلٍ صحّي يصير ملفًّا قد يفضح أو يميّز.
يصف هذا الإطار برنامج خصوصيةٍ تشغيلي منظَّمًا حول المبادئ المشتركة لأنظمة حماية البيانات الحديثة، موضَّحًا ببنية نظام حماية البيانات الشخصية في السعودية وجهته المنظِّمة، ومكتوبًا ليكون قابلًا لإعادة الاستخدام حيثما تنطبق التزاماتٌ مشابهة. ويتوافق مع القانون والإرشاد المنشورين دون نسخ نصّهما.
Modern data protection rests on a small set of principles that together define responsible processing. They are not independent rules to be ticked off, they are a coherent standard, and a program that honors all of them handles data in a way individuals and regulators can trust.
Minimization deserves particular emphasis because it runs against a common instinct to collect everything that might one day be useful. That instinct is a liability: every extra field is a field to secure, to govern, and to answer for in a breach, and the cheapest way to protect data is to never collect it in the first place. A disciplined program asks of every data element not could this be useful, but is this necessary for the stated purpose.
تقوم حماية البيانات الحديثة على مجموعةٍ صغيرة من المبادئ تُعرّف معًا المعالجة المسؤولة. وهي ليست قواعد مستقلّة تُؤشَّر، بل معيارٌ متماسك، وبرنامجٌ يحترمها كلها يتعامل مع البيانات بطريقةٍ يثق بها الأفراد والجهات المنظِّمة.
ويستحق التقليل تأكيدًا خاصًا لأنه يخالف غريزةً شائعة بجمع كل ما قد يفيد يومًا. وتلك الغريزة عبء: فكل حقلٍ إضافي حقلٌ يُؤمَّن ويُحوكَم ويُساءَل عنه في اختراق، وأرخص طريقة لحماية البيانات ألّا تُجمَع أصلًا. والبرنامج المنضبط يسأل عن كل عنصر بيانات ليس «هل قد يفيد» بل «هل هو لازمٌ للغرض المُعلَن».
Every use of personal data needs a reason the law recognizes. Before processing anything, the organization has to be able to name the basis on which it is allowed, because processing without one is unlawful regardless of how careful the handling is.
The most familiar basis is consent, where the person freely agrees to a specific use after being clearly told what it is. Consent has to be a genuine choice, informed and revocable, which means it cannot be buried in dense terms, bundled so that refusing a minor use blocks an essential service, or made so hard to withdraw that agreement is effectively permanent. Consent that a person could not realistically refuse or reverse is not consent, it is the appearance of it.
Consent is not the only basis, and often not the best one. Processing may also be justified where it is necessary to perform a contract the person is party to, to meet a legal obligation, or to serve a legitimate interest that does not override the person's rights. Choosing the right basis matters, because relying on consent for something a person cannot really decline is weaker than relying on the actual necessity, and using the honest basis is both more robust and more respectful.
كل استخدام لبياناتٍ شخصية يحتاج سببًا يعترف به القانون. فقبل معالجة أي شيء، على المنشأة أن تستطيع تسمية الأساس الذي يُسمَح لها عليه، لأن المعالجة بلا أساسٍ غير مشروعة أيًّا كان حذر التعامل.
أشهر الأسس هو الموافقة، حيث يوافق الشخص بحريةٍ على استخدامٍ محدَّد بعد إخباره بوضوح بما هو. والموافقة يجب أن تكون خيارًا حقيقيًا، مطّلعًا وقابلًا للسحب، بمعنى ألّا تُدفَن في شروطٍ كثيفة، ولا تُحزَم بحيث يمنع رفضُ استخدامٍ ثانوي خدمةً أساسية، ولا يُصعَّب سحبها حتى تصير الموافقة دائمةً فعليًا. فموافقةٌ لا يستطيع الشخص واقعيًا رفضها أو عكسها ليست موافقة بل مظهرها.
والموافقة ليست الأساس الوحيد، وغالبًا ليست الأفضل. فقد تُبرَّر المعالجة أيضًا حيث تلزم لتنفيذ عقدٍ الشخص طرفٌ فيه، أو للوفاء بالتزامٍ قانوني، أو لخدمة مصلحةٍ مشروعة لا تتجاوز حقوق الشخص. واختيار الأساس الصحيح يهمّ، لأن الاتّكاء على الموافقة لأمرٍ لا يستطيع الشخص رفضه أضعف من الاتّكاء على اللزوم الفعلي، واستخدام الأساس الصادق أمتن وأكثر احترامًا.
Data protection gives individuals real, exercisable rights over their own data, and an organization has to be able to honor them within defined timelines. These rights are the mechanism through which a person keeps some control over information about themselves.
The rights are practical, not abstract. A person can ask what data an organization holds about them and why, correct it when it is wrong, ask for it to be deleted when there is no longer a valid reason to keep it, and withdraw a consent they previously gave. Where processing relies on consent, the right to withdraw it must be as easy to use as the consent was to give, otherwise the original consent was never truly free.
Honoring these rights is an operational capability, not just a policy statement. It requires knowing where personal data actually lives, which is often scattered across many systems, so that a deletion request can be fulfilled everywhere rather than in the one obvious database while copies persist elsewhere. An organization that cannot find all copies of a person's data cannot honestly claim to have deleted it, which is why the data-mapping work of governance underpins the rights.
تمنح حماية البيانات الأفراد حقوقًا حقيقية قابلة للممارسة على بياناتهم، وعلى المنشأة أن تستطيع الوفاء بها خلال مُهَلٍ محدَّدة. وهذه الحقوق الآلية التي يُبقي بها الشخص شيئًا من السيطرة على المعلومات عنه.
الحقوق عملية لا مجرّدة. فيستطيع الشخص أن يسأل ما البيانات التي تحوزها المنشأة عنه ولماذا، ويصحّحها حين تكون خاطئة، ويطلب حذفها حين لا يبقى سببٌ صحيح لحفظها، ويسحب موافقةً منحها سابقًا. وحيث تعتمد المعالجة على الموافقة، يجب أن يكون حقّ سحبها سهل الاستخدام كسهولة منحها، وإلا لم تكن الموافقة الأصلية حرّةً حقًّا.
والوفاء بهذه الحقوق قدرةٌ تشغيلية لا مجرد بيان سياسة. يتطلّب معرفة أين تعيش البيانات الشخصية فعلًا، وهي غالبًا مبعثرة عبر أنظمةٍ كثيرة، ليُنفَّذ طلب حذفٍ في كل مكان لا في قاعدة البيانات الظاهرة الواحدة بينما تبقى نسخٌ في غيرها. ومنشأةٌ لا تستطيع إيجاد كل نسخ بيانات شخصٍ لا تقدر أن تدّعي بصدقٍ أنها حذفتها، ولذا يسند عملُ رسم البيانات في الحوكمة هذه الحقوق.
Responsibility for personal data is assigned to defined roles. The controller decides why and how data is processed, the processor acts on the controller's behalf, and each carries obligations that make accountability concrete rather than diffuse.
The controller holds the primary duty: it chooses the purpose, sets the lawful basis, honors the rights, and answers to the regulator. A processor, such as a cloud provider or an outsourced service, processes data only on the controller's documented instructions and must protect it, and the relationship between them is set out in a contract so the obligations follow the data even as it moves to a third party. Handing data to a processor never hands away the controller's accountability for it.
The record of processing is the quiet backbone of the whole program. It is unglamorous, but without an accurate map of what data the organization holds and why, none of the other obligations can be met reliably: rights cannot be honored across unknown systems, breaches cannot be scoped, and minimization cannot be checked. Building and maintaining that record is the first practical step of a real privacy program.
تُسنَد مسؤولية البيانات الشخصية لأدوارٍ محدَّدة. المتحكّم يقرّر لماذا وكيف تُعالَج البيانات، والمعالِج يتصرّف نيابةً عنه، وكلٌّ يحمل التزاماتٍ تجعل المساءلة ملموسة لا مشتّتة.
المتحكّم يحمل الالتزام الأول: يختار الغرض، ويضع الأساس القانوني، ويفي بالحقوق، ويُجيب الجهة المنظِّمة. والمعالِج، كمزوّد سحابةٍ أو خدمةٍ مُسنَدة، يعالج البيانات فقط بتعليمات المتحكّم الموثَّقة وعليه حمايتها، والعلاقة بينهما تُبيَّن في عقدٍ لتتبع الالتزاماتُ البياناتِ ولو انتقلت لطرفٍ ثالث. وتسليم البيانات لمعالِجٍ لا يُسلّم أبدًا مساءلة المتحكّم عنها.
سجل المعالجة هو العمود الفقري الهادئ للبرنامج كله. غير برّاقٍ، لكن بلا خريطةٍ دقيقة لما تحوزه المنشأة من بياناتٍ ولماذا، لا يُوفى بأيٍّ من الالتزامات الأخرى بموثوقية: فالحقوق لا تُلبّى عبر أنظمةٍ مجهولة، والاختراقات لا يُحدَّد نطاقها، والتقليل لا يُفحَص. وبناء ذلك السجل وصونه أول خطوةٍ عملية لبرنامج خصوصيةٍ حقيقي.
Data does not respect borders, but data protection law does. When personal data moves out of the country whose law protects it, that protection can be lost, so transfers are governed to make sure the data does not shed its safeguards by crossing a line on a map.
The core concern is simple: if data about a person is protected at home but sent to a place with weaker rules or none, the protection is hollow. Regimes address this by allowing transfers only under conditions that preserve protection, such as the destination having an adequate level of protection, or the transfer being covered by binding safeguards, or specific narrow exceptions. The practical duty is to know where your data goes, including where your processors and their sub-processors are located, because a transfer often happens invisibly through a supplier rather than by a deliberate export.
البيانات لا تحترم الحدود، لكن قانون حماية البيانات يحترمها. فحين تخرج بياناتٌ شخصية من بلد قانونه يحميها، قد تُفقَد تلك الحماية، لذا يُحوكَم النقل ليضمن ألّا تخلع البيانات وقاياتها بعبور خطٍّ على خريطة.
الهاجس الجوهري بسيط: إن كانت بيانات شخصٍ محمية في الوطن لكن أُرسِلت لمكانٍ بقواعد أضعف أو بلا قواعد، فالحماية جوفاء. وتعالج الأنظمة هذا بالسماح بالنقل فقط بشروطٍ تحفظ الحماية، كأن يكون للوجهة مستوى حمايةٍ كافٍ، أو يكون النقل مغطّىً بوقاياتٍ مُلزِمة، أو باستثناءاتٍ ضيّقة محدَّدة. والالتزام العملي معرفة أين تذهب بياناتك، بما فيه أين يقع معالِجوك ومعالِجوهم الفرعيون، لأن النقل يقع غالبًا خفيةً عبر مورّدٍ لا بتصديرٍ متعمَّد.
Two forward-looking duties complete the program: responding correctly when data is exposed, and assessing risk before a high-risk use begins. One handles the failure, the other tries to prevent it.
A personal data breach is any event that exposes, loses, or allows unauthorized access to personal data, and regimes typically require the organization to notify the regulator, and sometimes the affected individuals, within a defined time once a qualifying breach is known. That deadline is the reason breach response cannot be improvised: the clock starts when the breach is discovered, so the organization needs a ready process to assess the breach, decide whether it is notifiable, and notify in time, all under pressure. This is the incident response loop from security operations, pointed specifically at personal data.
The preventive counterpart is to build privacy in from the start rather than bolting it on. Privacy by design means considering data protection as a system is being designed, choosing to minimize and protect data by default. Where a new use of data is likely to be high-risk to people, a data protection impact assessment examines that risk before the processing begins, identifies how to reduce it, and records the decision. Doing this early is far cheaper than discovering a privacy problem after a system is live and people's data is already exposed.
التزامان استشرافيان يكملان البرنامج: الاستجابة الصحيحة حين تنكشف البيانات، وتقييم الخطر قبل بدء استخدامٍ عالي الخطر. أحدهما يعالج الفشل، والآخر يحاول منعه.
اختراق البيانات الشخصية أي حدثٍ يكشف بياناتٍ شخصية أو يفقدها أو يتيح وصولًا غير مصرَّح إليها، وتُلزِم الأنظمة عادةً المنشأة بإبلاغ الجهة المنظِّمة، وأحيانًا الأفراد المتأثّرين، خلال وقتٍ محدَّد بمجرد العلم باختراقٍ مستوفٍ. وتلك المُهلة سبب أن الاستجابة لا تُرتجَل: فالساعة تبدأ عند اكتشاف الاختراق، فتحتاج المنشأة عمليةً جاهزة لتقييمه، وقرار هل يستوجب الإبلاغ، والإبلاغ في الوقت، كله تحت الضغط. وهذه حلقة الاستجابة للحوادث من عمليات الأمن، مُوجَّهة تحديدًا للبيانات الشخصية.
والنظير الوقائي هو بناء الخصوصية من البداية لا تركيبها لاحقًا. الخصوصية بالتصميم تعني مراعاة حماية البيانات أثناء تصميم النظام، واختيار تقليل البيانات وحمايتها افتراضيًا. وحيث يُرجَّح أن يكون استخدامٌ جديد عالي الخطر على الناس، يفحص تقييم أثر حماية البيانات ذلك الخطر قبل بدء المعالجة، ويحدّد كيف يُخفَّض، ويسجّل القرار. وفعل هذا مبكرًا أرخص بكثير من اكتشاف مشكلة خصوصيةٍ بعد تشغيل النظام وبيانات الناس مكشوفة أصلًا.
A privacy program keeps an organization's use of personal data lawful, trusted, and sustainable, by honoring principles, rights, and obligations as daily operations.
برنامج الخصوصية يُبقي استخدام المنشأة للبيانات الشخصية مشروعًا وموثوقًا ومستدامًا، بالوفاء بالمبادئ والحقوق والالتزامات كعملياتٍ يومية.