Does Approov Comply with Saudi Arabia’s Personal Data Protection Law (PDPL)?
Does Approov collect or process personal data from mobile app users in Saudi Arabia?
Approov is designed to minimize the collection and processing of user data. Approov does not process personal data or personally identifiable information (PII), other than the IP address and Device ID required by the service, and both are anonymized.
Saudi Arabia’s Personal Data Protection Law (PDPL) establishes the framework for protecting personal data and regulating its processing. The PDPL applies to the processing of personal data relating to individuals in Saudi Arabia, including processing carried out by organizations located outside the Kingdom.
Under the PDPL, personal data includes information that can directly or indirectly identify an individual. This may include names, identification numbers, addresses, contact information, financial information, photographs, and other information of a personal nature.
SDAIA's guidance explains that data is not considered personal data under the PDPL when it is impossible to identify a particular individual from that data. The Implementing Regulation further defines anonymization as the removal of direct and indirect identifiers in a way that permanently makes it impossible to identify the individual. Properly anonymized data is no longer considered personal data and is outside the scope of the PDPL.
How does Approov Protect Mobile App Users' Data?
Approov follows a data-minimization approach and limits the information collected by the Approov Mobile Security platform to what is required to provide its security functionality.
The platform collects:
- IP address
- Device ID
Both are anonymized. Approov does not collect names, email addresses, telephone numbers, government identification numbers, payment information, or other information that directly identifies an individual through the Approov Mobile Security platform.
By minimizing the data collected and anonymizing the data it processes, Approov is designed to reduce the privacy risks associated with processing mobile application security data.
Is Anonymized Data Subject to the Saudi PDPL?
Under the PDPL Implementing Regulation, anonymization requires the removal of direct and indirect identifiers so that it is permanently impossible to identify the individual. The controller must take appropriate organizational, administrative, and technical measures to prevent re-identification and assess the effectiveness of the anonymization techniques used.
Once personal data has been properly anonymized, the anonymized data is no longer considered personal data under the PDPL.
This distinction is important: pseudonymized data remains personal data under the PDPL, whereas properly anonymized data does not.
What Rights does the Saudi PDPL Provide to Individuals?
The PDPL provides data subjects with rights concerning their personal data, subject to the conditions and procedures established by the Law and its Implementing Regulations.
These rights include, among others:
- The right to be informed about the legal basis and purpose for collecting their personal data.
- The right to access their personal data.
- The right to request their personal data in a readable and clear format.
- The right to request correction, completion, or updating of their personal data.
- The right to request destruction of their personal data in applicable circumstances.
- The right to withdraw consent where consent is the legal basis for processing.
The specific application of these rights depends on the circumstances and applicable provisions of the PDPL and its Implementing Regulations.
Because Approov is designed to anonymize the IP address and Device ID it processes, these data elements are not considered personal data once they have been properly and permanently anonymized in accordance with the PDPL requirements.
How does Approov Protect Data?
Approov Limited has extensively assessed its data collection and storage methodologies in proportion to the potential impact of a breach of this data on an individual.
The controls implemented by Approov are designed to provide protection appropriate to the assessed risk and to protect the confidentiality and security of the data throughout its lifecycle.
Approov's approach also incorporates data minimization and anonymization to reduce the amount of information that could potentially be used to identify an individual.
Does the Saudi PDPL Regulate Data Transferred Outside the Kingdom?
The Saudi data protection framework includes specific requirements governing the transfer or disclosure of personal data outside Saudi Arabia. The Regulation on Personal Data Transfer Outside the Kingdom establishes requirements and safeguards that apply when personal data is transferred or disclosed to an entity outside the Kingdom.
Where personal data is involved, organizations should therefore assess the applicable requirements for international transfers and any required safeguards.
Where data has been properly anonymized so that an individual can no longer be identified, it is no longer considered personal data under the PDPL.
Approov's Approach to Saudi Data Privacy
Approov takes a privacy-by-design and data-minimization approach to mobile application security. The platform is designed to:
- Minimize the information collected from mobile app users.
- Avoid collecting directly identifying information such as names, email addresses, or telephone numbers.
- Anonymize the IP address and Device ID processed by the platform.
- Apply technical and organizational controls appropriate to the assessed risk.
- Protect the confidentiality and security of data throughout its lifecycle.
Approov Limited has assessed its data collection, processing, and storage practices in relation to the potential impact of a data breach and has implemented controls designed to protect the data in accordance with the assessed risk.
Important: This article provides general information about how Approov's data practices relate to Saudi Arabia's Personal Data Protection Law. It is not legal advice and does not constitute a legal determination that a particular customer's use of Approov is compliant with the PDPL. Organizations should assess their own obligations under the PDPL and its Implementing Regulations based on their specific processing activities.