The Capital Market Authority (CMA) oversees regulation and development of Capital Market, by issuing rules and regulations for implementing Capital Market Law provisions, aiming to create a conducive investment environment, boost market confidence, reinforce disclosure and transparency of all listed companies, and protect investors and dealers from illegal activities in the market. To affirm its commitment to protecting Personal Data it collects under legally granted powers and maintaining its confidentiality, CMA has developed this Privacy Policy to clarify aspects related to the collection of such data, how it is stored and handled, and associated rights.
What Personal Data is Collected?
The Authority collects and processes the following personal data:
Data Category
|
Data Collected
|
Mandatory Level
|
|---|
|
Data Category
Main Personal Data
|
Data Collected
Includes name, nationality, ID number, date of birth, gender, marital status, social security number, type of disability (if any), civil status (deceased or alive).
|
Mandatory Level
Mandatory
|
|
Data Category
Contact Data
|
Data Collected
Includes email, mobile number, national address.
|
Mandatory Level
Mandatory
|
|
Data Category
Education Data
|
Education Data
Includes educational institution name, academic degree, specialization, and GPA.
|
Mandatory Level
Mandatory
|
|
Data Category
Employment Data
|
Employment Data
Includes professional certificates, previous employment entities, previous job positions, and social security employment establishment number.
|
Mandatory Level
Non-mandatory
|
|
Data Category
Financial Data
|
Financial Data
Includes data collected for financial compensation purposes such as IBAN number and bank name.
|
Mandatory Level
Mandatory
|
How is Personal Data Collected and What is the Purpose of Collection?
The Authority collects personal data directly or indirectly according to the service provided, and the methods of collecting personal data include the following:
Personal data collected directly:
- When applying for services provided on the Authority's electronic website.
- When communicating with the Authority either via phone, email, or the Authority's social media accounts.
Personal data collected indirectly:
- Cookie data, which is data automatically collected by the browser when visiting the Authority's electronic website.
- From entities under the Authority's supervision or other government entities for mandatory processing operations.
Personal data is collected and processed to achieve the following purposes:
- Compliance with regulations and bylaws that govern the Authority's work.
- Enabling the Authority to provide its services to the fullest extent.
- Processing complaints, inquiries, and requests received by the Authority.
- Achieving public interest or for security or judicial purposes.
In the event of not obtaining the data, the Authority will not be able to perform its assigned role in accordance with the regulations and bylaws governing its work.
Legal Basis for Collecting and Processing Personal Data
The Authority collects and processes personal data based on one of the following legal bases:
- Collecting and processing data pursuant to the Capital Market Law and its executive regulations or other regulations in force in the Kingdom of Saudi Arabia or in execution of a previous agreement where the personal data owner is a party.
- Collecting and processing data required for security purposes or to fulfill judicial or security requirements or to achieve public interest.
- Collecting and processing non-sensitive personal data to achieve legitimate interests of the Authority without prejudice to the personal data owner's rights or conflicting with their interests.
- Consent of the personal data owner to process their data for specific purposes.
How is Personal Data Disclosed?
Personal data is disclosed to:
- Government and non-government entities according to the cases mentioned in Article Fifteen of the Personal Data Protection Law.
- Entities under the Authority's supervision; for processing complaints and inquiries.
The Authority may transfer personal data outside the geographical boundaries of the Kingdom or disclose it to entities outside the Kingdom when needed, in accordance with what is stipulated in Article Twenty-Nine of the Personal Data Protection Law and its executive regulations.
How is Personal Data Stored?
The Authority retains personal data within the Kingdom of Saudi Arabia in a secure and reliable environment where necessary security measures are applied according to the requirements of the National Cybersecurity Authority. The Authority destroys data when the purpose of collection ends or in any of the cases mentioned in paragraph (1) of Article Eight of the Executive Regulations of the Personal Data Protection Law, and digital data is destroyed using secure destruction techniques and methods.
The Authority may retain personal data even after the purpose of collection ends, in accordance with what is mentioned in Article Eighteen of the Personal Data Protection Law.
Rights of Personal Data Owner Regarding Data Processing
The personal data owner - under the Personal Data Protection Law - has specific rights that depend primarily on the purpose of collecting and processing personal data, which are:
- Right to Know: The personal data owner has the right to know the methods of collecting personal data, the legal basis for collecting it, the purpose of collecting and processing it, how it is processed, stored and destroyed, and to whom it will be disclosed. All details can be found through the privacy policy or by contacting the Authority through the contact information shown below.
- Right to Access Personal Data: The personal data owner has the right to request access to their personal data by contacting the personal data protection officer at the Authority, and they will be provided with it within thirty working days unless an extension is required.
- Right to Request Personal Data: The personal data owner has the right to request their personal data available at the Authority in a readable and clear format when technically possible, by contacting the personal data protection officer at the Authority, and they will be provided with it within thirty working days unless an extension is required.
- Right to Correct Personal Data: The personal data owner has the right to request correction of their personal data that they consider inaccurate, incorrect, or incomplete, by contacting the personal data protection officer at the Authority, and they will be notified of the correction via email within thirty working days unless an extension is required.
- Right to Destroy Personal Data: The personal data owner has the right to request destruction of their personal data in a manner that does not conflict with what is stated in the Personal Data Protection Law and its executive regulations, and they will be notified of its destruction via email within thirty working days unless an extension is required.
- Right to Withdraw Consent for Data Processing: The personal data owner has the right to withdraw their consent for processing their personal data - at any time - unless there are legal justifications that require otherwise.
Except as stipulated by law, the personal data owner will not be required to pay any fees for exercising these rights.
Use of Cookies
Cookies may be used in electronic exchange for the purpose of serving the user better.
A cookie is a data element that the electronic service may send to the browser and which may be stored on the user's computer. The purpose of cookies that are placed on the user's computer is to facilitate browsing websites only and serve no other functions.
Security Measures to Protect Information
The user must take all reasonable means to protect their personal information from loss or misuse, examples of which include:
Immediate communication with the Capital Market Authority when suspecting that someone has obtained their password, user code, or any other confidential information, through the Authority's email or contact center numbers:
- Using a secure network to access the internet and the Authority's website.
- Using a secure browser when using the internet while closing unused applications on the network.
- Ensuring that antivirus software is always updated.
How to Submit a Complaint or Objection?
In case of any concerns or our non-compliance with the Personal Data Protection Law, a complaint can be submitted to the personal data protection officer at the Data Management Office according to the contact information shown below:
Capital Market Authority - Data Management Office – Personal Data Protection Officer
Riyadh – Al-Mohammadiyyah District
Phone Number: 0114906065
Email: PDP@cma.org.sa
If you are not satisfied with our handling of the complaint, you can submit a complaint to the Saudi Data and Artificial Intelligence Authority according to the contact information below:
Saudi Data and Artificial Intelligence Authority
Kingdom of Saudi Arabia, Riyadh
Website: (sdaia.gov.sa)
National Data Governance Platform: (dgp.sdaia.gov.sa)
Safe Usage Policies
All information provided on this website is owned and updated by the Capital Market Authority. Best practices are implemented to ensure the quality and updating of information. However, there are no express or implied warranties regarding the accuracy, reliability, or availability of the information provided on this website, and therefore the Authority does not bear responsibility for any inaccurate, incomplete, or outdated information or any actions taken regarding the information provided. The Authority makes every possible effort to maintain the website's operation in a good and easy manner, and the Authority bears no responsibility and will not be subject to any accountability or claims for the website's unavailability due to technical problems beyond the Authority's control.
The user agrees not to use, encourage, promote, facilitate, or instruct others to use the services in the following ways:
- Engaging in, promoting, or encouraging activities that violate any law, regulation, government decision, royal decree, legal agreement, or published policies issued by the Authority.
- Accessing or investigating any service or system without authorization, including but not limited to violations, security vulnerability scans, or penetration testing.
- Disabling, interfering with, or circumventing any aspect of the service; or violating any security or authentication procedures used by the system or service.
- Any theft of resources including sensitive information.