PDPL compliance

Article by article, not a badge.

Checked against the Implementing Regulations published by SDAIA.

Last updated 13 September 2026
National Data Governance Platform

1. What this page covers

The Kingdom’s personal data regime has two instruments: the Personal Data Protection Law, and the Implementing Regulations that sit under it. The competent authority is the Saudi Data and Artificial Intelligence Authority (SDAIA).

Every article cited on this page is from the Implementing Regulations, checked against SDAIA’s published text. The Law’s own article numbers are different, and are not cited here.

2. Controller and processor

The restaurant group is the controller. It decides which stations are recorded, who receives alerts, and how long records are kept. Proof Manager is the processor, acting on those instructions under a written processing agreement.

That split decides who answers a rights request. A request about branch footage goes to the group; we support them in answering it. Several obligations — the national register in Article 34, for instance — sit with the controller, not with us.

Article 17 governs our side of it. It requires the controller to choose a processor that gives sufficient guarantees, and to put the purpose, the categories of data, the term, and breach notification in writing. Our processing agreement is built around those four.

3. Article by article

Art. 3
General provisions
A request from a data subject is answered within 30 days.
The controller answers. We supply what they need to answer inside that window, on the timing agreed with them.
Art. 4
Right to be informed
The subject is told why data is processed and how to exercise their rights.
Branch notices are the controller’s to post. We supply the wording they need.
Art. 5
Right of access
The subject may access their personal data.
Branch records are visible to the controller in the portal, order by order.
Art. 6
Right to obtain the data
The subject may obtain their personal data.
Records are exportable from the portal. What an export contains is set with the controller.
Art. 7
Right to correction
Inaccurate data is corrected on request.
Correction is made by the controller’s administrator, or by us on their instruction.
Art. 8
Right to destruction
Data is destroyed when no longer needed for its purpose.
Retention is agreed per branch in the contract and expires automatically. Earlier deletion is made on the controller’s instruction.
Art. 11
Consent
Sets the conditions for valid consent.
Consent, where it applies, is obtained by the controller, not by us.
Art. 12
Withdrawal of consent
Consent may be withdrawn.
Withdrawal is handled by the controller. We act on their instruction.
Art. 16
Legitimate interest
A controller may process for a legitimate interest that does not affect the subject’s rights.
The basis we rely on for business contact data. Branch data is processed on the controller’s instructions instead.
Art. 17
Processor selection
The controller must choose a processor that gives sufficient guarantees. The agreement must set the purpose, the categories of data, the term, and the processor’s duty to notify the controller of a breach.
This is the article about us. Our processing agreement carries all four, so the controller can show it did what Article 17 asks.
Art. 19
Data minimisation
Only the minimum data needed for the purpose is collected.
Cameras are framed on process, not faces. An exception carries a POS, a door and a time, and nothing more.
Art. 20
Disclosure
Disclosure is limited to the minimum necessary.
Alerts go to the recipients the controller nominates, and nowhere else.
Art. 23
Information security
The controller applies information security measures.
Measures appropriate to the risk, access limited to named staff. The measures for a deployment are set in the agreement.
Art. 24
Breach notification
The competent authority is notified within 72 hours where a breach causes harm.
We notify the controller without undue delay so the 72-hour duty can be met.
Art. 32
Data protection officer
A data protection officer is appointed where the Regulations require it.
Privacy questions reach us at hello@proofmanager.co.
Art. 33
Records of processing
The controller keeps records of its processing activities.
A record of the processing carried out for each customer is kept.
Art. 34
National register of controllers
Controllers are entered in the national register.
This obligation sits with the restaurant group as controller, not with us.

4. Design choices that reduce the obligation

The cheapest way to comply is to hold less.

No biometric data is collected, so the stricter regime for sensitive data does not arise.
Cameras are framed on process — the station, the shelf, the drawer, the lane — not on faces.
An exception attaches to a POS, a door and a time. It never attaches to a named employee.
Retention is agreed with each customer, set per branch, and expires without anyone remembering to act.

5. What your legal team can ask us for

A data processing agreement, a short PDPL note, the processing register for your account, and a branch notice you can post at the station.

6. This is not legal advice

This page describes how the product is built and what we are prepared to commit to contractually. It is a summary, not a substitute for the Law or the Regulations, and your own counsel should confirm what applies to you as controller. The official texts are published by SDAIA.

QUESTIONS

Rights requests reach the controller first. Anything addressed to us goes to hello@proofmanager.co.

PDPL compliance

Article by article, not a badge.

Checked against the Implementing Regulations published by SDAIA.

Last updated 13 September 2026
National Data Governance Platform

1. What this page covers

The Kingdom’s personal data regime has two instruments: the Personal Data Protection Law, and the Implementing Regulations that sit under it. The competent authority is the Saudi Data and Artificial Intelligence Authority (SDAIA).

Every article cited on this page is from the Implementing Regulations, checked against SDAIA’s published text. The Law’s own article numbers are different, and are not cited here.

2. Controller and processor

The restaurant group is the controller. It decides which stations are recorded, who receives alerts, and how long records are kept. Proof Manager is the processor, acting on those instructions under a written processing agreement.

That split decides who answers a rights request. A request about branch footage goes to the group; we support them in answering it. Several obligations — the national register in Article 34, for instance — sit with the controller, not with us.

Article 17 governs our side of it. It requires the controller to choose a processor that gives sufficient guarantees, and to put the purpose, the categories of data, the term, and breach notification in writing. Our processing agreement is built around those four.

3. Article by article

Art. 3 · GENERAL PROVISIONS
A request from a data subject is answered within 30 days.
The controller answers. We supply what they need to answer inside that window, on the timing agreed with them.
Art. 4 · RIGHT TO BE INFORMED
The subject is told why data is processed and how to exercise their rights.
Branch notices are the controller’s to post. We supply the wording they need.
Art. 5 · RIGHT OF ACCESS
The subject may access their personal data.
Branch records are visible to the controller in the portal, order by order.
Art. 6 · RIGHT TO OBTAIN THE DATA
The subject may obtain their personal data.
Records are exportable from the portal. What an export contains is set with the controller.
Art. 7 · RIGHT TO CORRECTION
Inaccurate data is corrected on request.
Correction is made by the controller’s administrator, or by us on their instruction.
Art. 8 · RIGHT TO DESTRUCTION
Data is destroyed when no longer needed for its purpose.
Retention is agreed per branch in the contract and expires automatically. Earlier deletion is made on the controller’s instruction.
Art. 11 · CONSENT
Sets the conditions for valid consent.
Consent, where it applies, is obtained by the controller, not by us.
Art. 12 · WITHDRAWAL OF CONSENT
Consent may be withdrawn.
Withdrawal is handled by the controller. We act on their instruction.
Art. 16 · LEGITIMATE INTEREST
A controller may process for a legitimate interest that does not affect the subject’s rights.
The basis we rely on for business contact data. Branch data is processed on the controller’s instructions instead.
Art. 17 · PROCESSOR SELECTION
The controller must choose a processor that gives sufficient guarantees. The agreement must set the purpose, the categories of data, the term, and the processor’s duty to notify the controller of a breach.
This is the article about us. Our processing agreement carries all four, so the controller can show it did what Article 17 asks.
Art. 19 · DATA MINIMISATION
Only the minimum data needed for the purpose is collected.
Cameras are framed on process, not faces. An exception carries a POS, a door and a time, and nothing more.
Art. 20 · DISCLOSURE
Disclosure is limited to the minimum necessary.
Alerts go to the recipients the controller nominates, and nowhere else.
Art. 23 · INFORMATION SECURITY
The controller applies information security measures.
Measures appropriate to the risk, access limited to named staff. The measures for a deployment are set in the agreement.
Art. 24 · BREACH NOTIFICATION
The competent authority is notified within 72 hours where a breach causes harm.
We notify the controller without undue delay so the 72-hour duty can be met.
Art. 32 · DATA PROTECTION OFFICER
A data protection officer is appointed where the Regulations require it.
Privacy questions reach us at hello@proofmanager.co.
Art. 33 · RECORDS OF PROCESSING
The controller keeps records of its processing activities.
A record of the processing carried out for each customer is kept.
Art. 34 · NATIONAL REGISTER OF CONTROLLERS
Controllers are entered in the national register.
This obligation sits with the restaurant group as controller, not with us.

4. Design choices that reduce the obligation

The cheapest way to comply is to hold less.

No biometric data is collected, so the stricter regime for sensitive data does not arise.
Cameras are framed on process — the station, the shelf, the drawer, the lane — not on faces.
An exception attaches to a POS, a door and a time. It never attaches to a named employee.
Retention is agreed with each customer, set per branch, and expires without anyone remembering to act.

5. What your legal team can ask us for

A data processing agreement, a short PDPL note, the processing register for your account, and a branch notice you can post at the station.

6. This is not legal advice

This page describes how the product is built and what we are prepared to commit to contractually. It is a summary, not a substitute for the Law or the Regulations, and your own counsel should confirm what applies to you as controller. The official texts are published by SDAIA.

QUESTIONS

Rights requests reach the controller first. Anything addressed to us goes to hello@proofmanager.co.