-
Business risk services
The relationship between a company and its auditor has changed. Organisations must understand and manage risk and seek an appropriate balance between risk and opportunities.
-
Marketing and Client Service
We offer strategy, client service, digital and insight solutions to businesses that are shaping the future across the Middle East.
-
Forensic services
At Grant Thornton, we have a wealth of knowledge in forensic services and can support you with issues such as dispute resolution, fraud and insurance claims.
-
Transaction Advisory
Globalisation and company growth ambitions are driving an increase in transactions activity worldwide. We work with entrepreneurial businesses in the mid-market to help them assess the true commercial potential of their planned acquisition and understand how the purchase might serve their longer-term strategic goals.
-
Growth services
We have designed and developed growth services to support your business at each phase of its growth. So whether you are an SME that has just set up or a large business wishing to expand, at Grant Thornton we will help you unlock your potential for growth.
-
IFRS
At Grant Thornton, our IFRS advisers can help you navigate the complexity of financial reporting.
-
Audit quality monitoring
Having a robust process of quality control is one of the most effective ways to guarantee we deliver high-quality services to our clients.
-
Global audit technology
We apply our global audit methodology through an integrated set of software tools known as the Voyager suite.
The Saudi Data & Artificial Intelligence Authority (SDAIA) will supervise the implementation of the new legislation for the first two years, following which a transfer of supervision to the National Data Management Office (NDMO) will be considered.
According to SDAIA’s announcement, the PDPL is intended to ensure the privacy of personal data, regulate data sharing and prevent the abuse of personal data in line with the goals of the Kingdom’s Vision 2030 to develop a digital infrastructure and support innovation to grow a digital economy.
What are the penalties for non-compliance?
The disclosure or publication of sensitive data contrary to the PDPL may result in penalties of imprisonment for up to two years or a fine of up to SAR 3,000,000 (US$ 800,000). Violation of the data transfer provisions could result in imprisonment for up to one year and a fine of up to SAR 1,000,000 (US$ 266,600). In respect of all other provisions of the PDPL, the penalties are limited to a warning notice or a fine of up to SAR 5,000,000 (US$ 1,333,000).
Any of the fines could also be increased up to double the stated maximums for repeat offences and the court may order confiscation of funds gained as a result of breaching the law and/or require publication of the judgment in a newspaper or other media at the offender’s expense. Parties affected by the offences may be able to claim compensation.
The need to be prepared:
The PDPL is stated to take effect 180 days after its publication in the Official Gazette, which means that it will be effective from 23 March 2022. The executive regulations supplementing the Law should also be issued within this period.
All businesses operating in Saudi Arabia or processing the data of Saudi residents will now need to start assessing their activities and making changes to align with the PDPL. Controllers will be required to hold training for staff on the terms and principles of the PDPL and will need time to ensure that a culture of data protection is suitably embedded into the organisation.
How we can help.
The team at Grant Thornton have supported several businesses to comply with the regulations, our specialist team apply the data protection framework which includes identification of gap analysis through to ensuring you have a future ready process embedded to protect both your firm and its reputation.
Download the detailed report [ 1692 kb ]which has been co-authored by Clyde & Co.
To discuss how we can support your firm further, contact Ahmad Al Zoubi