Saif Ali AlghamdiTransformation & Growth Advisor
تواصل
LibraryمكتبتيDigital & Technologyرقمي وتقنية
PRIVACY · OPERATIONAL FRAMEWORKالخصوصية · إطار تشغيلي

Personal Data Protection & Privacyحماية البيانات الشخصية والخصوصية

SectionالقسمDigital & Technologyرقمي وتقنية
Reading timeزمن القراءة9 min٩ دقيقة
ByإعدادSaif Alghamdiسيف الغامدي
One

Overview

Field: Personal data protection & privacy
Scope: Governing how an organization collects, uses, and protects personal data
Owner role: Data protection officer, with business and system owners
Review cadence: Continuous, with a formal privacy review each quarter
By: Saif Alghamdi

Data protection is the discipline of handling personal data responsibly: collecting only what is needed, using it only for what was intended, keeping it safe, and respecting the rights of the people it describes. It is where an organization's duty to individuals and its legal obligations meet the daily reality of how data actually flows through its systems.

The subject of the discipline is personal data, meaning any information relating to an identifiable person. That definition is broad on purpose, because the harm from mishandling data does not depend on how sensitive a single field looks, it depends on what can be learned and done when data is combined. A name alone seems harmless, but joined to a location, a purchase history, and a health detail it becomes a profile that can expose or discriminate.

This framework describes an operational privacy program organized around the principles common to modern data protection regimes, illustrated with the structure of Saudi Arabia's Personal Data Protection Law and its regulator, and written to be reusable wherever similar obligations apply. It aligns to the published law and guidance without reproducing their text.

Note: Privacy is not the enemy of using data, it is the condition that makes using data sustainable. An organization that handles personal data carelessly eventually loses the trust and the legal permission to use it at all.
الأول

نظرة عامة

المجال: حماية البيانات الشخصية والخصوصية
النطاق: حوكمة كيف تجمع المنشأة البيانات الشخصية وتستخدمها وتحميها
دور المالك: مسؤول حماية البيانات، مع ملّاك العمل والأنظمة
دورية المراجعة: مستمرة، مع مراجعة خصوصية رسمية كل ربع
إعداد: سيف الغامدي

حماية البيانات انضباط التعامل المسؤول مع البيانات الشخصية: جمع ما يلزم فقط، واستخدامه لما قُصِد فقط، وإبقاؤه آمنًا، واحترام حقوق من تصفهم. وهي حيث يلتقي التزام المنشأة تجاه الأفراد والتزاماتها القانونية بواقع كيف تتدفّق البيانات فعلًا عبر أنظمتها.

موضوع الانضباط هو البيانات الشخصية، أي أي معلومةٍ تتعلّق بشخصٍ يمكن تحديده. وذلك التعريف واسعٌ عمدًا، لأن الأذى من سوء التعامل لا يعتمد على كم يبدو حقلٌ مفرد حساسًا، بل على ما يمكن معرفته وفعله حين تُدمَج البيانات. فاسمٌ وحده يبدو غير ضار، لكنه مقرونًا بموقعٍ وسجل شراءٍ وتفصيلٍ صحّي يصير ملفًّا قد يفضح أو يميّز.

يصف هذا الإطار برنامج خصوصيةٍ تشغيلي منظَّمًا حول المبادئ المشتركة لأنظمة حماية البيانات الحديثة، موضَّحًا ببنية نظام حماية البيانات الشخصية في السعودية وجهته المنظِّمة، ومكتوبًا ليكون قابلًا لإعادة الاستخدام حيثما تنطبق التزاماتٌ مشابهة. ويتوافق مع القانون والإرشاد المنشورين دون نسخ نصّهما.

ملاحظة: الخصوصية ليست عدوّة استخدام البيانات، بل الشرط الذي يجعل استخدامها مستدامًا. فمنشأةٌ تتعامل مع البيانات الشخصية باستهتار تفقد آخرًا الثقة والإذن القانوني باستخدامها أصلًا.
Two

Core Principles

Modern data protection rests on a small set of principles that together define responsible processing. They are not independent rules to be ticked off, they are a coherent standard, and a program that honors all of them handles data in a way individuals and regulators can trust.

  • Lawfulness and fairness: personal data is processed on a valid legal basis and in a way people would find reasonable, not through hidden or deceptive collection.
  • Purpose limitation: data is collected for a specific, stated purpose and not later used for something incompatible with it without a fresh basis.
  • Data minimization: only the data actually needed for the purpose is collected, because data you do not hold cannot be lost or misused.
  • Accuracy: data is kept correct and up to date, since decisions made on wrong data harm the person they describe.
  • Storage limitation: data is kept only as long as it is needed, then deleted, because indefinite retention is indefinite risk.
  • Security: data is protected against loss, unauthorized access, and misuse, through the controls covered in the security frameworks.
  • Accountability: the organization can demonstrate, with evidence, that it meets these principles, not merely claim it.

Minimization deserves particular emphasis because it runs against a common instinct to collect everything that might one day be useful. That instinct is a liability: every extra field is a field to secure, to govern, and to answer for in a breach, and the cheapest way to protect data is to never collect it in the first place. A disciplined program asks of every data element not could this be useful, but is this necessary for the stated purpose.

Note: Accountability turns the other principles from good intentions into an obligation. If you cannot show evidence that you minimize, limit, and secure data, then in the eyes of a regulator you do not.
الثاني

المبادئ الأساسية

تقوم حماية البيانات الحديثة على مجموعةٍ صغيرة من المبادئ تُعرّف معًا المعالجة المسؤولة. وهي ليست قواعد مستقلّة تُؤشَّر، بل معيارٌ متماسك، وبرنامجٌ يحترمها كلها يتعامل مع البيانات بطريقةٍ يثق بها الأفراد والجهات المنظِّمة.

  • المشروعية والإنصاف: تُعالَج البيانات الشخصية على أساسٍ قانوني صحيح وبطريقةٍ يراها الناس معقولة، لا بجمعٍ خفيّ أو خادع.
  • تحديد الغرض: تُجمَع البيانات لغرضٍ محدَّد مُعلَن ولا تُستخدَم لاحقًا لما يتعارض معه دون أساسٍ جديد.
  • تقليل البيانات: تُجمَع فقط البيانات اللازمة فعلًا للغرض، لأن بياناتٍ لا تحوزها لا يمكن فقدها أو إساءتها.
  • الدقة: تُبقى البيانات صحيحة ومحدَّثة، لأن قراراتٍ على بياناتٍ خاطئة تؤذي من تصفهم.
  • تحديد التخزين: تُحفَظ البيانات بقدر الحاجة فقط، ثم تُحذَف، لأن الاحتفاظ اللامحدود خطرٌ لامحدود.
  • الأمن: تُحمى البيانات من الفقد والوصول غير المصرَّح والإساءة، عبر الضوابط المغطّاة في أطر الأمن.
  • المساءلة: تستطيع المنشأة أن تُظهر بالدليل أنها تفي بهذه المبادئ، لا أن تدّعيه فحسب.

ويستحق التقليل تأكيدًا خاصًا لأنه يخالف غريزةً شائعة بجمع كل ما قد يفيد يومًا. وتلك الغريزة عبء: فكل حقلٍ إضافي حقلٌ يُؤمَّن ويُحوكَم ويُساءَل عنه في اختراق، وأرخص طريقة لحماية البيانات ألّا تُجمَع أصلًا. والبرنامج المنضبط يسأل عن كل عنصر بيانات ليس «هل قد يفيد» بل «هل هو لازمٌ للغرض المُعلَن».

ملاحظة: المساءلة تحوّل بقية المبادئ من نوايا حسنة إلى التزام. فإن لم تستطع إظهار دليلٍ على أنك تُقلّل وتُحدّد وتُؤمّن البيانات، فأنت في نظر الجهة المنظِّمة لا تفعل.
Three

Lawful Basis for Processing

Every use of personal data needs a reason the law recognizes. Before processing anything, the organization has to be able to name the basis on which it is allowed, because processing without one is unlawful regardless of how careful the handling is.

The most familiar basis is consent, where the person freely agrees to a specific use after being clearly told what it is. Consent has to be a genuine choice, informed and revocable, which means it cannot be buried in dense terms, bundled so that refusing a minor use blocks an essential service, or made so hard to withdraw that agreement is effectively permanent. Consent that a person could not realistically refuse or reverse is not consent, it is the appearance of it.

Consent is not the only basis, and often not the best one. Processing may also be justified where it is necessary to perform a contract the person is party to, to meet a legal obligation, or to serve a legitimate interest that does not override the person's rights. Choosing the right basis matters, because relying on consent for something a person cannot really decline is weaker than relying on the actual necessity, and using the honest basis is both more robust and more respectful.

Note: Decide and record the lawful basis for each processing activity before it starts. Reverse-engineering a justification after a complaint is both harder to defend and a sign that the basis was never really considered.
الثالث

الأساس القانوني للمعالجة

كل استخدام لبياناتٍ شخصية يحتاج سببًا يعترف به القانون. فقبل معالجة أي شيء، على المنشأة أن تستطيع تسمية الأساس الذي يُسمَح لها عليه، لأن المعالجة بلا أساسٍ غير مشروعة أيًّا كان حذر التعامل.

أشهر الأسس هو الموافقة، حيث يوافق الشخص بحريةٍ على استخدامٍ محدَّد بعد إخباره بوضوح بما هو. والموافقة يجب أن تكون خيارًا حقيقيًا، مطّلعًا وقابلًا للسحب، بمعنى ألّا تُدفَن في شروطٍ كثيفة، ولا تُحزَم بحيث يمنع رفضُ استخدامٍ ثانوي خدمةً أساسية، ولا يُصعَّب سحبها حتى تصير الموافقة دائمةً فعليًا. فموافقةٌ لا يستطيع الشخص واقعيًا رفضها أو عكسها ليست موافقة بل مظهرها.

والموافقة ليست الأساس الوحيد، وغالبًا ليست الأفضل. فقد تُبرَّر المعالجة أيضًا حيث تلزم لتنفيذ عقدٍ الشخص طرفٌ فيه، أو للوفاء بالتزامٍ قانوني، أو لخدمة مصلحةٍ مشروعة لا تتجاوز حقوق الشخص. واختيار الأساس الصحيح يهمّ، لأن الاتّكاء على الموافقة لأمرٍ لا يستطيع الشخص رفضه أضعف من الاتّكاء على اللزوم الفعلي، واستخدام الأساس الصادق أمتن وأكثر احترامًا.

ملاحظة: حدّد وسجّل الأساس القانوني لكل نشاط معالجةٍ قبل بدئه. فهندسة مبرّرٍ عكسيًا بعد شكوى أصعب دفاعًا ودليلٌ على أن الأساس لم يُنظَر فيه حقًّا.
Four

Rights of the Individual

Data protection gives individuals real, exercisable rights over their own data, and an organization has to be able to honor them within defined timelines. These rights are the mechanism through which a person keeps some control over information about themselves.

The rights are practical, not abstract. A person can ask what data an organization holds about them and why, correct it when it is wrong, ask for it to be deleted when there is no longer a valid reason to keep it, and withdraw a consent they previously gave. Where processing relies on consent, the right to withdraw it must be as easy to use as the consent was to give, otherwise the original consent was never truly free.

  • Right to be informed: to know that data is collected, for what purpose, and how it is used, in clear language up front.
  • Right of access: to see the personal data held about them and confirm how it is being processed.
  • Right to correction: to have inaccurate or incomplete data put right.
  • Right to deletion: to have data erased when the purpose is served or the basis is gone.
  • Right to withdraw consent: to revoke a previously given consent as easily as it was given.

Honoring these rights is an operational capability, not just a policy statement. It requires knowing where personal data actually lives, which is often scattered across many systems, so that a deletion request can be fulfilled everywhere rather than in the one obvious database while copies persist elsewhere. An organization that cannot find all copies of a person's data cannot honestly claim to have deleted it, which is why the data-mapping work of governance underpins the rights.

Note: Build a defined process for each right, with an owner and a timeline, before the first request arrives. Rights requests are not rare edge cases, they are a routine obligation, and handling them ad hoc is how deadlines and data get missed.
الرابع

حقوق الفرد

تمنح حماية البيانات الأفراد حقوقًا حقيقية قابلة للممارسة على بياناتهم، وعلى المنشأة أن تستطيع الوفاء بها خلال مُهَلٍ محدَّدة. وهذه الحقوق الآلية التي يُبقي بها الشخص شيئًا من السيطرة على المعلومات عنه.

الحقوق عملية لا مجرّدة. فيستطيع الشخص أن يسأل ما البيانات التي تحوزها المنشأة عنه ولماذا، ويصحّحها حين تكون خاطئة، ويطلب حذفها حين لا يبقى سببٌ صحيح لحفظها، ويسحب موافقةً منحها سابقًا. وحيث تعتمد المعالجة على الموافقة، يجب أن يكون حقّ سحبها سهل الاستخدام كسهولة منحها، وإلا لم تكن الموافقة الأصلية حرّةً حقًّا.

  • حقّ العلم: أن يعرف أن البيانات تُجمَع، ولأي غرض، وكيف تُستخدَم، بلغةٍ واضحة مقدَّمًا.
  • حقّ الوصول: أن يرى بياناته الشخصية المحفوظة ويؤكّد كيف تُعالَج.
  • حقّ التصحيح: أن تُصحَّح بياناته غير الدقيقة أو الناقصة.
  • حقّ الحذف: أن تُمحى بياناته حين يتحقّق الغرض أو يزول الأساس.
  • حقّ سحب الموافقة: أن يُلغي موافقةً سابقة بسهولة منحها.

والوفاء بهذه الحقوق قدرةٌ تشغيلية لا مجرد بيان سياسة. يتطلّب معرفة أين تعيش البيانات الشخصية فعلًا، وهي غالبًا مبعثرة عبر أنظمةٍ كثيرة، ليُنفَّذ طلب حذفٍ في كل مكان لا في قاعدة البيانات الظاهرة الواحدة بينما تبقى نسخٌ في غيرها. ومنشأةٌ لا تستطيع إيجاد كل نسخ بيانات شخصٍ لا تقدر أن تدّعي بصدقٍ أنها حذفتها، ولذا يسند عملُ رسم البيانات في الحوكمة هذه الحقوق.

ملاحظة: ابنِ عمليةً محدَّدة لكل حقّ، بمالكٍ ومُهلة، قبل وصول أول طلب. فطلبات الحقوق ليست حالاتٍ نادرة، بل التزامٌ روتيني، ومعالجتها ارتجالًا هي كيف تُفوَّت المُهَل وتضيع البيانات.
Five

Controller & Processor Obligations

Responsibility for personal data is assigned to defined roles. The controller decides why and how data is processed, the processor acts on the controller's behalf, and each carries obligations that make accountability concrete rather than diffuse.

The controller holds the primary duty: it chooses the purpose, sets the lawful basis, honors the rights, and answers to the regulator. A processor, such as a cloud provider or an outsourced service, processes data only on the controller's documented instructions and must protect it, and the relationship between them is set out in a contract so the obligations follow the data even as it moves to a third party. Handing data to a processor never hands away the controller's accountability for it.

  • Records of processing: a documented inventory of what data is held, why, where, and on what basis, which is the foundation everything else relies on.
  • A responsible person: a designated data protection officer or equivalent, accountable for the program and reachable by regulators and individuals.
  • Processor contracts: written terms binding any processor to protect the data and act only on instruction, with the right to verify.
  • Registration and cooperation: meeting any obligation to register with or respond to the regulator, in Saudi Arabia the Data and AI Authority.

The record of processing is the quiet backbone of the whole program. It is unglamorous, but without an accurate map of what data the organization holds and why, none of the other obligations can be met reliably: rights cannot be honored across unknown systems, breaches cannot be scoped, and minimization cannot be checked. Building and maintaining that record is the first practical step of a real privacy program.

Note: The controller remains accountable even when a processor causes the harm. Choose processors carefully, bind them contractually, and verify them, because their failure will be attributed to you.
الخامس

التزامات المتحكّم والمعالِج

تُسنَد مسؤولية البيانات الشخصية لأدوارٍ محدَّدة. المتحكّم يقرّر لماذا وكيف تُعالَج البيانات، والمعالِج يتصرّف نيابةً عنه، وكلٌّ يحمل التزاماتٍ تجعل المساءلة ملموسة لا مشتّتة.

المتحكّم يحمل الالتزام الأول: يختار الغرض، ويضع الأساس القانوني، ويفي بالحقوق، ويُجيب الجهة المنظِّمة. والمعالِج، كمزوّد سحابةٍ أو خدمةٍ مُسنَدة، يعالج البيانات فقط بتعليمات المتحكّم الموثَّقة وعليه حمايتها، والعلاقة بينهما تُبيَّن في عقدٍ لتتبع الالتزاماتُ البياناتِ ولو انتقلت لطرفٍ ثالث. وتسليم البيانات لمعالِجٍ لا يُسلّم أبدًا مساءلة المتحكّم عنها.

  • سجلات المعالجة: جردٌ موثَّق لما يُحفَظ من بيانات، ولماذا، وأين، وعلى أي أساس، وهو الأساس الذي يعتمد عليه كل ما عداه.
  • شخصٌ مسؤول: مسؤول حماية بياناتٍ مُعيَّن أو ما يعادله، مساءَل عن البرنامج وقابل للوصول من الجهات والأفراد.
  • عقود المعالِجين: شروطٌ مكتوبة تُلزِم أي معالِجٍ بحماية البيانات والتصرّف بالتعليمات فقط، مع حقّ التحقّق.
  • التسجيل والتعاون: الوفاء بأي التزامٍ بالتسجيل لدى الجهة المنظِّمة أو الاستجابة لها، وفي السعودية هيئة البيانات والذكاء الاصطناعي.

سجل المعالجة هو العمود الفقري الهادئ للبرنامج كله. غير برّاقٍ، لكن بلا خريطةٍ دقيقة لما تحوزه المنشأة من بياناتٍ ولماذا، لا يُوفى بأيٍّ من الالتزامات الأخرى بموثوقية: فالحقوق لا تُلبّى عبر أنظمةٍ مجهولة، والاختراقات لا يُحدَّد نطاقها، والتقليل لا يُفحَص. وبناء ذلك السجل وصونه أول خطوةٍ عملية لبرنامج خصوصيةٍ حقيقي.

ملاحظة: يبقى المتحكّم مساءَلًا حتى حين يُسبّب المعالِج الأذى. اختر المعالِجين بعناية، وألزِمهم تعاقديًا، وتحقّق منهم، لأن فشلهم سيُنسَب إليك.
Six

Cross-Border Data Transfer

Data does not respect borders, but data protection law does. When personal data moves out of the country whose law protects it, that protection can be lost, so transfers are governed to make sure the data does not shed its safeguards by crossing a line on a map.

The core concern is simple: if data about a person is protected at home but sent to a place with weaker rules or none, the protection is hollow. Regimes address this by allowing transfers only under conditions that preserve protection, such as the destination having an adequate level of protection, or the transfer being covered by binding safeguards, or specific narrow exceptions. The practical duty is to know where your data goes, including where your processors and their sub-processors are located, because a transfer often happens invisibly through a supplier rather than by a deliberate export.

  • Know the flows: map where personal data physically goes, including through cloud services and sub-processors.
  • Check the condition: confirm each cross-border transfer meets a permitted basis before it happens.
  • Bind the safeguards: where required, put contractual or other protections in place so the data stays protected abroad.
Note: The most common cross-border transfer is not a dramatic export, it is routine use of a cloud service hosted elsewhere. Map your suppliers' locations, because that is where the obligation quietly bites.
السادس

نقل البيانات عبر الحدود

البيانات لا تحترم الحدود، لكن قانون حماية البيانات يحترمها. فحين تخرج بياناتٌ شخصية من بلد قانونه يحميها، قد تُفقَد تلك الحماية، لذا يُحوكَم النقل ليضمن ألّا تخلع البيانات وقاياتها بعبور خطٍّ على خريطة.

الهاجس الجوهري بسيط: إن كانت بيانات شخصٍ محمية في الوطن لكن أُرسِلت لمكانٍ بقواعد أضعف أو بلا قواعد، فالحماية جوفاء. وتعالج الأنظمة هذا بالسماح بالنقل فقط بشروطٍ تحفظ الحماية، كأن يكون للوجهة مستوى حمايةٍ كافٍ، أو يكون النقل مغطّىً بوقاياتٍ مُلزِمة، أو باستثناءاتٍ ضيّقة محدَّدة. والالتزام العملي معرفة أين تذهب بياناتك، بما فيه أين يقع معالِجوك ومعالِجوهم الفرعيون، لأن النقل يقع غالبًا خفيةً عبر مورّدٍ لا بتصديرٍ متعمَّد.

  • اعرف التدفّقات: ارسم أين تذهب البيانات الشخصية فعليًا، بما فيه عبر الخدمات السحابية والمعالِجين الفرعيين.
  • تحقّق من الشرط: أكّد أن كل نقلٍ عبر الحدود يفي بأساسٍ مسموح قبل وقوعه.
  • ألزِم الوقايات: حيث يلزم، ضع حمايةً تعاقدية أو غيرها لتبقى البيانات محمية في الخارج.
ملاحظة: أشيع نقلٍ عبر الحدود ليس تصديرًا دراميًا، بل استخدامًا روتينيًا لخدمةٍ سحابية مُستضافة في مكانٍ آخر. ارسم مواقع مورّديك، فهناك يعضّ الالتزام بهدوء.
Seven

Breach Response & Impact Assessment

Two forward-looking duties complete the program: responding correctly when data is exposed, and assessing risk before a high-risk use begins. One handles the failure, the other tries to prevent it.

A personal data breach is any event that exposes, loses, or allows unauthorized access to personal data, and regimes typically require the organization to notify the regulator, and sometimes the affected individuals, within a defined time once a qualifying breach is known. That deadline is the reason breach response cannot be improvised: the clock starts when the breach is discovered, so the organization needs a ready process to assess the breach, decide whether it is notifiable, and notify in time, all under pressure. This is the incident response loop from security operations, pointed specifically at personal data.

Privacy by design and impact assessment

The preventive counterpart is to build privacy in from the start rather than bolting it on. Privacy by design means considering data protection as a system is being designed, choosing to minimize and protect data by default. Where a new use of data is likely to be high-risk to people, a data protection impact assessment examines that risk before the processing begins, identifies how to reduce it, and records the decision. Doing this early is far cheaper than discovering a privacy problem after a system is live and people's data is already exposed.

Bottom line: a real privacy program is operational, not paper: it knows where personal data is, processes it on a clear basis, honors rights on a timeline, governs where data goes, and is ready to respond when something goes wrong.
السابع

الاستجابة للاختراق وتقييم الأثر

التزامان استشرافيان يكملان البرنامج: الاستجابة الصحيحة حين تنكشف البيانات، وتقييم الخطر قبل بدء استخدامٍ عالي الخطر. أحدهما يعالج الفشل، والآخر يحاول منعه.

اختراق البيانات الشخصية أي حدثٍ يكشف بياناتٍ شخصية أو يفقدها أو يتيح وصولًا غير مصرَّح إليها، وتُلزِم الأنظمة عادةً المنشأة بإبلاغ الجهة المنظِّمة، وأحيانًا الأفراد المتأثّرين، خلال وقتٍ محدَّد بمجرد العلم باختراقٍ مستوفٍ. وتلك المُهلة سبب أن الاستجابة لا تُرتجَل: فالساعة تبدأ عند اكتشاف الاختراق، فتحتاج المنشأة عمليةً جاهزة لتقييمه، وقرار هل يستوجب الإبلاغ، والإبلاغ في الوقت، كله تحت الضغط. وهذه حلقة الاستجابة للحوادث من عمليات الأمن، مُوجَّهة تحديدًا للبيانات الشخصية.

الخصوصية بالتصميم وتقييم الأثر

والنظير الوقائي هو بناء الخصوصية من البداية لا تركيبها لاحقًا. الخصوصية بالتصميم تعني مراعاة حماية البيانات أثناء تصميم النظام، واختيار تقليل البيانات وحمايتها افتراضيًا. وحيث يُرجَّح أن يكون استخدامٌ جديد عالي الخطر على الناس، يفحص تقييم أثر حماية البيانات ذلك الخطر قبل بدء المعالجة، ويحدّد كيف يُخفَّض، ويسجّل القرار. وفعل هذا مبكرًا أرخص بكثير من اكتشاف مشكلة خصوصيةٍ بعد تشغيل النظام وبيانات الناس مكشوفة أصلًا.

الخلاصة: برنامج الخصوصية الحقيقي تشغيليٌ لا ورقي: يعرف أين البيانات الشخصية، ويعالجها على أساسٍ واضح، ويفي بالحقوق في مُهلة، ويحوكم أين تذهب البيانات، ومستعدٌ للاستجابة حين يسوء شيء.
Eight

Key Takeaways & References

A privacy program keeps an organization's use of personal data lawful, trusted, and sustainable, by honoring principles, rights, and obligations as daily operations.

  • Handle personal data by the core principles, with minimization and accountability at the center.
  • Name and record a lawful basis for every processing activity before it starts.
  • Build operational processes to honor individual rights within their timelines.
  • Keep records of processing, bind processors, and govern where data crosses borders.
  • Be ready to respond to breaches on the clock, and assess privacy risk before high-risk uses begin.

References

الثامن

الخلاصات والمراجع

برنامج الخصوصية يُبقي استخدام المنشأة للبيانات الشخصية مشروعًا وموثوقًا ومستدامًا، بالوفاء بالمبادئ والحقوق والالتزامات كعملياتٍ يومية.

  • تعامل مع البيانات الشخصية بالمبادئ الأساسية، بالتقليل والمساءلة في المركز.
  • سمِّ وسجّل أساسًا قانونيًا لكل نشاط معالجةٍ قبل بدئه.
  • ابنِ عملياتٍ تشغيلية للوفاء بحقوق الأفراد خلال مُهَلها.
  • احتفظ بسجلات المعالجة، وألزِم المعالِجين، وحوكِم أين تعبر البيانات الحدود.
  • كن مستعدًّا للاستجابة للاختراقات على الساعة، وقيّم خطر الخصوصية قبل الاستخدامات عالية الخطر.

المراجع