K.A.CARE :
King Abdullah City for Atomic and Renewable Energy
CEO :
King Abdullah City for Atomic and Renewable Energy's Chief Executive Officer.
Data Management Office (DMO) :
The entity responsible for the management and governance of data as well as the purpose and manner of personal data processing, whether the data is processed by that entity or by the processor.
Data Processor:
Any independent governmental or public entity, or any natural or legal person, which engages in the processing of personal data on behalf of a data controller .
Data :
A collection of facts in a raw or unorganized form such as numbers, characters, images, video, voice recordings, or symbols.
Personal Data :
Any element of data, regardless of source or form, which independently or when combined with other available information could lead to the identification of a person, including but not limited to, name, national identity, address, phone number, bank account number, credit card number, images or videos of the person and so on.
Data Subject :
Any natural person to whom the personal data relates to.
Personal Data Processing:
Processing of personal data by any means, whether manual or automated processing, including collection, transfer, recording, storage, sharing, destruction, analysis, extraction of their patterns, conclusion and interconnection.
Disclosure of Personal Data :
Enabling any person, other than the controller, to obtain, use or view any personal data by any mean and for any purpose.
Personal Data Destruction :
Any action taken on personal data that makes it unreadable and irretrievable, or impossible to identify the related data subject.
Implied Consent :
Consent of the Data Subjects that is not given explicitly but is understood from their actions, certain events, or circumstances e.g. consent to the terms and conditions.
Policy Terms
Obligations of K.A.CARE
King Abdullah City for Atomic and Renewable Energy (K.A.CARE) shall be committed to implement best practices- in accordance with the Personal Data Protection Law and its Implementing Regulations issued under Royal Decree Number (M/19) dated 9/2/1443 H (16/9/2021) and amended pursuant to Royal Decree Number (M/148) dated 5/9/1444 H (27/3/2023)- in order to protect the privacy of individuals using K.A.CARE's website and systems as well as beneficiaries of its services.
Main Principles of Personal Data Protection
Principle 1: Accountability :
K.A.CARE shall be responsible for identifying and documenting its privacy policies and procedures.
Principle 2: Transparency :
A notice of K.A.CARE's privacy policies and procedures shall be prepared, indicating the purposes for which personal data was processed in a specified, clear, and explicit way.
Principle 3: Choice and Consent :
All the possible options available to a data subject shall be determined and his implicit or explicit consent shall be obtained with regard to the collection, use or disclosure of personal data.
Principle 4: Limiting Data Collection :
The collection of any personal data shall be limited to minimum data that enables fulfillment of the purposes set out in the privacy notice.
Principle 5: Limiting Data Use, Retention and Disposal :
Personal data usage shall be restricted to the purposes set out in the privacy notice, which the data subject has implicitly or explicitly approved. Moreover, such data shall be retained as long as necessary to achieve their intended purposes or as required by the laws, regulations and policies in force in the Kingdom. Furthermore, data shall be destroyed in a safe manner that prevents breach, loss, theft, misuse or legally unauthorized access.
Principle 6: Access to Data :
The means by which a data subject can access his personal data to review, update and correct the same shall be determined and provided.
Principle 7: Limiting Data Disclosure :
Disclosure of personal data to external parties shall be restricted to the purposes which are specified in the privacy notice, and for which the data subject gave his implicit or explicit consent.
Principle 8: Data Security :
Personal data shall be protected from breach, destruction, loss, theft, misuse, modification, or unauthorized access, pursuant to the controls issued by the National Cybersecurity Authority and the relevant entities.
Principle 9: Data Quality :
Personal data shall be retained in an accurate and complete manner, and such retention shall be directly related to the purposes specified in the privacy notice.
Principle 10: Monitoring and Compliance :
Compliance with a data controller's privacy policies and procedures shall be monitored, and any privacy-related inquires, complaints, and disputes shall be addressed.
Rights of Individuals
• First: The right to be informed about the legal basis and the purpose of the collection of his personal data.
• Second: The right to access his personal data held by K.A.CARE.
• Third: The right to request obtaining his personal data held by K.A.CARE in a readable and clear format, in accordance with the controls and procedures specified by the Regulations.
• Fourth: The right to request correcting, completing, or updating his personal data held by K.A.CARE.
• Fifth: The right to request a destruction of his personal data held by K.A.CARE when such personal data is no longer needed, without prejudice to the legal basis of retaining his personal data.
Collection of Personal Data
The following personal data is collected through the main communication channels for K.A.CARE's external services which are K.A.CARE's website and email. In this case, the personal data is collected directly from the data subject or from his guardian if he fully or partially lacks legal capacity. The below table clarifies the collected personal data for each of K.ACARE's external services, which are:
Personal Data Storage
Personal data of individuals is securely stored within the geographical borders of the Kingdom, with necessary controls applied to protect personal data, maintain individuals' privacy, ensure data confidentiality, and safeguard access. This is in accordance with the policies, regulation, and procedures issued by the Saudi Data and AI Authority and the National Cybersecurity Authority. The means of storing personal data within K.A.CARE are as follows:
• Personal work devices of K.A.CARE's employees.
• K.A.CARE's databases located at K.A.CARE's headquarters.
• Approved cloud systems used at K.A.CARE.
Destruction of Personal Data
Personal data is securely destroyed after (7) years unless there is a legal basis to retain the data. K.A.CARE shall have the right to retain the personal data until the legal basis expires. K.A.CARE shall be committed to securely destroying personal data once the legal basis for retention expires. K.A.CARE's secure destruction mechanism ensures the following to the data subjects:
• Their identity cannot be reidentified.
• Their personal data cannot be misused.
• They are able to know the measures taken to securely destruct their personal data.
External Links
K.A.CARE's website and systems include links to other websites whose privacy and protection standards may differ from those adopted by K.A.CARE. K.A.CARE's portal is not responsible for any content on such websites or their privacy policies. Therefore, K.A.CARE advises users to review the privacy polices of those websites.
Exercising the Rights of Personal Data Subjects
Individuals may exercise their rights as specified in Section (3) via email (DPO@energy.gov.sa), or by contacting K.A.CARE's personal data protection officer whose contact details are listed in Section (13). Such requests are replied to within (20) working days, and this can be extended to another (20) working days after notifying the requester.
Complaints and Suggestions
Individuals may submit complaints and suggestions via email (DPO@energy.gov.sa), or by contacting K.A.CARE's personal data protection officer whose contact details are listed in Section (13). Such requests are replied to within (20) working days, and this can be extended to another (20) working days after notifying the requester.
Contact Details of K.A.CARE's Personal Data Protection Officer:
Name: Mr. Abdulrahman Al Ahamed
Mobile Number: 0552505761
Email: A.ahamed@energy.gov.sa
Privacy Policy Updates
K.A.CARE's portal shall be committed to inform personal data subjects upon making any minor or major changes to the privacy policy by obtaining users' consents.