Compliance Overview

XiKey is built from the ground up to comply with Saudi data and privacy regulations

Personal Data Protection Law

Full compliance with Royal Decree No. M/19 and its Implementing Regulations

Compliant

AI Ethics Principles

Adhering to SDAIA's 7 AI Ethics Principles

Adhered

National Data Governance

Aligned with the National Data Governance Interim Regulations

Aligned

Built-in PDPL Compliance Features

Built-in features to help you automatically comply with the Personal Data Protection Law

πŸ”

Role-Based Access Control

Multi-level permission system ensures each user accesses only authorized data, with complete logging of all access attempts.

πŸ“‹

Complete Audit Trail

Automatic logging of all operations: creation, modification, deletion, and viewing of data with timestamps and user identity.

πŸ”’

Data Encryption

Encryption of sensitive data at rest and in transit using encryption standards approved by the National Cybersecurity Authority (NCA).

🏠

On-Premise Storage

All business data is stored exclusively on your local servers within the Kingdom. No cross-border data transfers.

⏱️

Retention Period Management

Configurable data retention policies for each data type, with automatic deletion when the retention period expires.

πŸ“Š

Compliance Reports

Ready-made reports to demonstrate compliance to SDAIA and regulatory authorities, including processing records and impact assessments.

πŸ””

Breach Notification

Built-in mechanism for detecting unauthorized access attempts and sending immediate notifications to administrators.

πŸ‘€

Data Subject Rights

Built-in tools to facilitate responding to data subject requests: access, rectification, deletion, and processing restriction.

Our Commitment to AI Ethics Principles

We adhere to SDAIA's 7 AI Ethics Principles across all our operations

1
Fairness & Non-Discrimination

Our system treats all users fairly without discrimination based on gender, race, or nationality.

2
Privacy & Security

Personal data protection is embedded in the core system design with advanced encryption and granular permissions.

3
Humanity

Technology serving humanity - our system empowers teams to perform their tasks more efficiently.

4
Social & Environmental Benefit

E-invoicing reduces paper consumption, and automation reduces waste and loss.

5
Reliability & Safety

Extensively tested and reviewed system with automatic backups and recovery mechanisms.

6
Transparency & Explainability

Complete audit trail documenting every operation, providing full transparency in data processing.

7
Accountability & Responsibility

Designated Data Protection Officer with clear channels for reporting and complaints.

Data Governance

Comprehensive data governance framework aligned with national regulations

πŸ›οΈ

Data Stays in the Kingdom

All business data stored locally on customer servers. No transfer outside Kingdom borders.

πŸ“

Processing Records

Comprehensive record of all data processing operations with export capability for regulatory authorities.

βš–οΈ

Impact Assessment

Tools for conducting Data Protection Impact Assessments (DPIA) as required by the Implementing Regulations.

Regulatory Framework

Personal Data Protection Law (PDPL)

Royal Decree No. M/19, dated 9/2/1443H - The fundamental framework for personal data protection in Saudi Arabia.

Learn more at sdaia.gov.sa β†’

PDPL Implementing Regulations

Detailed rules for implementing the PDPL, including consent procedures and data processing.

Learn more at sdaia.gov.sa β†’

Cross-Border Data Transfer Regulation

Conditions and controls for transferring personal data outside the borders of Saudi Arabia (Article 29).

Learn more at sdaia.gov.sa β†’

AI Ethics Principles

Seven fundamental principles guiding the responsible use and development of AI technologies.

Learn more at sdaia.gov.sa β†’

AI Adoption Framework

Comprehensive methodology for adopting AI technologies in organizations while ensuring compliance and ethics.

Learn more at sdaia.gov.sa β†’

Have Compliance Questions?

Our team is ready to help you understand how XiKey can meet your organization's compliance requirements.

Contact Us Privacy Policy

Data Protection Officer: [email protected]