Privacy Policy

This policy aims to meet the requirements of the National Data Management Office, enhance the protection of data for users of Najran University systems and their privacy, and establish methods for handling, storing, and destroying data through:

  • Protecting the privacy of personal data and sensitive data, and not sharing it with other parties without user consent within the system.
  • Guarantee of individual rights in dealing with personal data at Najran University.
  • Enhancing transparency and solidifying governance through the distribution of roles and responsibilities.   
  • Support integrity and combat corruption.
  • This is based on the following documents: Data Management and Governance Controls Document, and Personal Data Protection (Version 1.5 - January 2021), and the National Data Governance Policies (Version 2 dated May 26 / 2021 AD) issued by the National Data Office.

    Scope of Work

    This policy applies to all entities of Najran University and its branches to ensure the protection of personal data processed partially or wholly by them. It also applies to external parties that process the data of individuals residing in Saudi Arabia via the internet or any other means.

    However, the following cases are excluded from the scope of this policy: collecting personal data without the knowledge of its owner, processing it for purposes other than those for which it was collected, disclosing it without consent, or transferring it outside the Kingdom, subject to the following conditions:
    • If the controlling party is a governmental entity, personal data may be collected or processed if it is necessary to meet regulatory requirements in accordance with the systems, regulations, and policies approved in the Kingdom of Saudi Arabia, or to comply with judicial requirements, or to fulfill obligations arising from an agreement in which the Kingdom of Saudi Arabia is a party.
  • To protect public health and safety, or to ensure the vital interests of individuals.
    • Key Principles for Protecting Personal Data

    The First Principle: Responsibility

    Najran University is committed to establishing data privacy requirements and policies, documenting them, reviewing them annually, and approving them by the University President or his designee. It also works to disseminate them to all relevant parties to ensure their effective implementation.

    Principle Two: Transparency

    A notice is being prepared to clarify the privacy policies and procedures regarding personal data at Najran University, specifying the purposes for which personal data is processed in a clear, precise, and explicit manner.

    Principle Three: Choice and Consent

    All possible options must be provided to the data subject, and their consent obtained, whether explicit or implicit, regarding the collection, use, or disclosure of their data.

    Principle Four: Data Minimization

    Personal data collection is limited to the minimum necessary to achieve the purposes specified in the privacy notice.

    Principle Five: Limiting and Retaining the Use of Data and Disposal thereof

    Processing of personal data is restricted to the specific purposes outlined in the privacy notice agreed upon by the data subject, either explicitly or implicitly. Data will be retained as long as necessary to achieve those specified purposes or as required by applicable laws, regulations, and policies within the Kingdom of Saudi Arabia, and will be disposed of securely through destruction methods that prevent leakage, loss, theft, or unauthorized access.

    Principle Six: Access to Data

    That appropriate measures be provided to enable the data subject to access their data for review, update, and correction.

    Principle Seven: Limiting Data Disclosure

    The disclosure of personal data to third parties within Saudi Arabia or outside it is subject to the purposes specified in the privacy notice that the data subject has consented to, either expressly or implicitly.

    The Eighth Principle: Data Security

    Najran University provides full protection of personal data from leakage, damage, loss, theft, misuse, or unauthorized access, in accordance with the directives of the National Cybersecurity Authority and relevant authorities.

    The Ninth Principle: Data Quality

    Personal data is stored accurately and completely, and relates directly to the purposes specified in the privacy notice.

    The Tenth Principle: Monitoring and Compliance

    Monitoring compliance with the privacy policies and procedures of Najran University, addressing inquiries, complaints, and disputes related to them.

    Data Subject Rights

    • First: The right regarding data and includes that awareness of its systematic or actual need for collecting its personal data, the purpose of which, and that it is not processed later in a manner inconsistent with the purpose for which it was collected and for which he provided his implicit or explicit consent.
    Secondly: The right to withdraw his/her consent to the processing of his/her personal data – at any time – unless there are legitimate grounds requiring the reversal thereof.Thirdly: The right to access his personal data at Najran University; in order to view it, request its correction, or update it.

      Obligations of Najran University

    • Najran University is committed to preparing and implementing policies and procedures related to the protection of personal data, and the primary responsible party – or whoever delegates them – is responsible for approving and adopting them.
    The University is committed to establishing a unit for data governance affiliated with the Data Management Office and entrusted with the responsibility of developing, documenting, and monitoring the implementation of policies and procedures adopted by the Supreme Administration of the entity. The unit’s tasks and responsibilities will include setting appropriate standards to determine levels of sensitivity of personal data.The University undertakes to assess the risks and potential impacts of activities involving the processing of personal data, and to present the results of the assessment to the University President – or whoever delegates to him – in order to determine the level of acceptance of risk and approve it.The University is committed to reviewing and updating service level agreements and operational contracts in accordance with the privacy policies and procedures adopted by the Supreme Administration of the Entity.
  • Conducting preparation and documentation of the necessary procedures for managing and addressing privacy violations, identifying the tasks and responsibilities related to the specialized work team, and the cases in which notification is made to the regulatory authority and the Office according to the administrative sequence based on measuring the severity of the impact.
  • The University is implementing awareness programs for its personnel to enhance the culture of privacy and raise awareness levels in accordance with the privacy policies and procedures adopted by the Supreme Administration of the entity.The data subject will be notified – through an appropriate and timely manner – of the purpose, legal basis, actual needs, means, methods, and procedures used for collecting, processing, and sharing personal data, as well as the security measures to ensure protection of privacy in accordance with the systems, regulations, and policies implemented throughout the Kingdom.The data owner will be notified about other sources used if additional data is collected in a non-direct manner (from other agencies).
  • The data subject is notified of the privacy notice and consent is obtained for the processing of their personal data based on the nature of the data and methods of collection.
  • It shall be taken approval of the data owner on processing personal data after specifying the type of approval (explicit or implicit) based on the nature of the data and methods of collection.
  • that the purpose of data collection is consistent with the systems, regulations and policies in effect throughout the Kingdom and directly related to the entity’s activity.
  • That the content of the statements be limited to the minimum necessary data to achieve the purpose of its collection.
  • that data collection be restricted to content previously defined (detailed in Rule 12) and conducted fairly (directly, clearly, safely, and without deceptive or misleading methods).
  • that use of the data be limited to the purpose for which it was collected.
  • The University is responsible for drafting and documenting policies and procedures for recordkeeping in accordance with specified purposes, regulations, and related legislation.
  • The University stores and processes personal data within the geographical boundaries of the Kingdom of Saudi Arabia to ensure the preservation of its digital national sovereignty for this data, and it is not permitted to process it outside the Kingdom of Saudi Arabia unless the University obtains a written approval from the regulatory authority after coordination with the Office.
  • that the University undertakes to prepare and document a policy and procedures for disposing of data, including destroying data in a safe manner that prevents its loss, misuse, or unauthorized access – encompassing operational, archived, and backup data – and doing so in accordance with what is issued by the National Cyber Security Authority.
  • that the University incorporates the provisions of its policies regarding the retention and disposal of personal data within contracts when assigning these tasks to other processing entities.
  • that the University determines and provides the means by which a holder of personal data can access his data and review and update it.
  • that the University shall verify the identity of individuals before granting them access to their personal data in accordance with the standards adopted by the National Cybersecurity Authority and relevant authorities.
  • Sharing personal data with other parties is prohibited except in accordance with the specific purposes as determined after obtaining the consent of the data owner and in compliance with the relevant regulations, laws, and policies. Other parties shall be provided with privacy policies and procedures followed and included in contracts and agreements.
  • that the University feels owners of data and takes approval from them in case of sharing data with other parties for use other than specified purposes.
  • that the University takes approval from the Office – after coordinating with the regulatory authority – before sharing personal data with other parties outside the Kingdom.
  • that the University undertakes to prepare, document, and implement the necessary procedures to ensure the accuracy, completeness, currency, and relevance of personal data collected for its intended purpose.
  • It is necessary to use the approved administrative controls and technical procedures as defined in the policies of the entity for information security to ensure the protection of personal data, including, but not limited to:
    • Granting access rights to data according to the duties and responsibilities of employees, in a way that prevents interference in jurisdictions and avoids fragmentation of responsibilities.
  • Applying administrative procedures and technical regulations that document the stages of data processing and provide the ability to identify the user responsible for each stage of these stages (usage logs).
  • Signing of personnel who carry out data processing operations under contract to maintain the data and prevent its disclosure except in accordance with policies, procedures, regulations, and legislation.
  • Selection of personnel who undertake data processing operations characterized by integrity, responsibility, and in accordance with the nature and sensitivity of the data and the access policy adopted by the entity.
  • Utilize appropriate security measures – such as encryption, and isolating the development and testing environment from the operational environment – to protect personal data and safeguard it in a manner consistent with its nature, sensitivity, and the media used for its transmission and storage, in accordance with what is issued by the National Cyber Security Authority and relevant authorities.
  • that Najran University is responsible for monitoring compliance with privacy policies and procedures periodically, and that they are displayed to the Head of the Entity – or whoever delegates this responsibility to him – as well as determining and documenting corrective measures that will be taken in the event of non-compliance and notifying the regulatory authority and the Office according to the organizational sequence.
    • General Provisions

    • First: The regulatory authorities are responsible for aligning the provisions of this policy with their relevant regulations and disseminating them to all entities under or related to them, in a manner that achieves integration and ensures the achievement of the intended objective of preparing this policy.
    Secondly: Regulatory bodies monitor compliance with this policy periodically.Thirdly: The University must comply with this policy and document compliance according to the mechanisms and procedures specified by the regulatory authorities.Fourth: The University must immediately and without delay notify the regulatory authorities, no more than 72 hours after any incident of data breach is discovered, in accordance with the mechanisms and procedures determined by the authorities.Fifth: The University, when contracting with treatment agencies, shall periodically verify that these agencies comply with this policy in accordance with the mechanisms and procedures specified by regulatory bodies, including any subsequent contracts entered into by these agencies.Sixth: The Data Office performs the roles and responsibilities of regulatory agencies on the office of non-regulatory agencies.Seventh: Regulatory authorities may establish additional rules to process specific types of personal data in accordance with the nature and sensitivity of such data after coordinating with the Office.eighth: Regulatory bodies, after coordinating with the Office – prepare the mechanisms and procedures that regulate the complaint processing process according to a specific timeframe and in accordance with the University’s organizational sequence.
  • Ninth: The University Data Office establishes the necessary standards to help the University determine whether appointing a data protection officer is a mandatory or optional requirement.