1. Introduction

Out of our keenness to safeguard your personal data and protect your privacy while you interact with us across all our official channels and branches, the General Authority for Awqaf—being a public authority with an independent legal personality pursuant to its Statute issued under Royal Decree No. M/11 dated 26/2/1437H—recognizes the importance of your understanding of this Privacy Policy and how we collect and process your personal data. This Policy has been formulated in accordance with the personal data protection laws and regulations in the Kingdom, with the aim of helping you understand the types of data we collect from you and how such data is handled by the Authority. Please read this Policy carefully to ensure full clarity on the Authority’s practices. By using the Authority’s website or any of its other official channels, you acknowledge and consent to this Privacy Policy.

1.1 Objectives of The Document

This Policy aims to define and document the Authority’s Privacy Policy. It clarifies the working relationship between the Data Office and the various departments of the Authority, and outlines the rights of the Authority’s customers regarding their personal data obtained or held by the Authority.

1.2 Document Scope

The Privacy Policy of the General Authority for Awqaf applies the provisions of the Personal Data Protection Law and its implementing regulations, which serve as the primary reference for the rules and provisions contained herein. This Policy becomes effective upon approval and issuance, is communicated internally to Authority personnel through internal communication channels, and is made available to the public through the Authority’s electronic portal.

1.3 Definitions and Terminology

Term

Description

Authority:

General Authority for Awqaf 

Office: 

Data Office

Data

A set of facts in their raw or unstructured form, such as numbers, letters, photographs, video recordings, audio recordings, or emojis. 

You

Refers to the user of the Authority’s website or any beneficiary interacting through any of the Authority’s official channels.

We / Us / Our

The first person pronoun refers to the governmental entity—the General Authority for Awqaf.

Website

The official website of the General Authority for Awqaf.

Other Official Channels

Applications, online platforms, social media accounts, paper-based processes across all Authority branches, or any official means through which the Authority handles personal data.

Personal Data

Names, ID numbers, addresses, contact details, bank account numbers, credit card numbers, health data, static or moving images of the user, and any other data of a personal or sensitive nature that identifies a specific individual.

Beneficiary / Data Subject

Any individual or entity whose personal data is collected and is subject to this Policy, whether interacting directly with the Authority or through a third party acting on their behalf.

Processing / Use of Data

Any operation performed on personal data, including collection, recording, storage, modification, retrieval, use, disclosure, transfer, or any other form of data handling.

Beneficial Owner

A natural person or entity that ultimately owns or controls, directly or indirectly, the waqf or benefits from it, or who enjoys the right to derive economic or regulatory advantages from it.

External Parties / Processors

Any party or third party with whom data is shared, including governmental, supervisory, or advisory bodies, or trusted partners providing specific services under legal and contractual safeguards ensuring data protection.

Data Sharing

The transfer or provision of personal data to external parties for a specified and authorized purpose, subject to adequate protective measures. This includes sharing data for regulatory, security, or service-enhancement purposes

Disclosure

Making personal data available to any person—other than the controller or processor, as applicable—for access, use, or review by any means and for any purpose.

Public Sources

Any publicly available data sources the Authority may use for data verification or processing, such as public websites, social media platforms, or open databases.

Regulatory Purposes

The reasons for which personal data is collected, including the Authority’s regulatory functions, information security protection, service improvement, compliance with laws and regulations, cooperation with competent authorities, or other lawful purposes.

2. Document Statement

  1. Purpose of Collecting Your Personal Data

The collection of personal data from users/beneficiaries through the Authority’s website or any other official channel is carried out for several regulatory purposes, including:

  1. Enabling the Authority to perform its regulatory functions relating to waqf activities within the Kingdom. 

    1. Implementing enhanced measures and controls to protect the security of information and technology and to prevent fraud or unauthorized access to our systems.

      1. Preparing any external reports to competent authorities or entities as part of the Authority’s regulatory mandate or service provision, while ensuring that your identity is anonymized in accordance with applicable laws to avoid affecting the rights and interests of the data subject.

      2. Regular and periodic updates of protection measures and controls that meet or exceed standard requirements.

      3. Detecting and identifying potential violations, misuse, or abuse when using the website or any of our official channels.

      4. Understanding beneficiary needs, verifying their eligibility for waqf-related products and services, and notifying them of any new services.

      5. Sending awareness and marketing materials, while giving the data subject the right to opt out by contacting the Authority using the communication methods outlined in this Policy.

      6. Handling complaints and inquiries related to the Authority’s services, transactions, and products.

      7. Where personal data is shared or disclosed to any external party, such sharing occurs strictly under contractual arrangements and solely for the purpose of improving the service provided to you, and is limited to the minimum necessary.

    2. Sources of Personal Data Collection

      • Directly from Data Subjects during their use of the Authority’s digital platforms, including direct correspondence with the Authority (such as via email), or through other direct interactions, including but not limited to: completing job application forms, applying for the Authority’s services, creating an account on the Authority’s digital platforms, benefiting from the Authority’s services, participating in surveys conducted by the Authority, submitting feedback, or contacting the Authority through any official means to submit complaints or inquiries. The collection of personal data is not limited to electronic interactions but also includes all paper-based transactions conducted by the Authority with beneficiaries and relevant stakeholders.

      • From a third party acting under a lawful mandate or legal authorization on behalf of the data subject.

      • From publicly available sources, where the Authority may lawfully rely on public sources, including but not limited to publicly accessible websites, social media platforms, and open-access applications (such as Google Maps),

      • Through technical points of integration with governmental entities.

      • Cookies and browser logs, where consent is provided. Cookies may store certain data based on the user’s most recent login to the website. Cookies are used to distinguish users from each other, enhance service quality, support data collection and classification, and improve the beneficiary experience. Cookie identifiers may retain user recognition information to facilitate subsequent access to the website in an efficient manner.

 

 

 

 

 

 

 

 

 

  1. Personal Data Collected

    1. Identity Data: Includes full name, username or similar unique identifier, date of birth, gender, official identification numbers (such as passport number or national ID number), and any other identifying information as may be needed by the Authority.

      1. Contact Data: Includes physical addresses, email addresses, and telephone numbers.

      2. Geospatial and Geographic Data: It refers, by way of example and not limitation, to jurisdictional information such as the data subject’s country and city of residence, latitude and longitude coordinates of waqf assets, and any related data as may be required by the Authority.

      3. Transaction Data: Includes direct banking transactions such as payments, purchases, IBAN numbers, and any other relevant transactional information where necessary.

      4. Credit Data: Any information required by the Authority to meet its regulatory obligations or in connection with the services it provides, where the Authority determines the lawful purpose for collecting such data. This may include, by way of example, bank documents containing credit-related information.

      5. Technical Data: Includes, without limitation, Internet Protocol (IP) addresses, login credentials, browser type and configuration, browser plug-in types and versions, information collected through cookies, operating systems and platforms, error and crash reports, system activity logs, request date, Uniform Resource Locators (URLs), and other technical data used to access the Authority’s website or other official channels.

      6. Health Data: Any information relating to an individual’s health that the Authority may require to carry out its functions based on a lawful justification, including, by way of example, health-related information concerning a waqf beholder.

    2. Rights of Personal Data Subjects

      1. Right to Be Informed: The data subject has the right to be informed of the methods of collecting their personal data, the lawful basis for its collection and processing, how it is processed, stored, retained, and destroyed, the parties with whom it may be shared, and the significance of collecting and processing such data. 

      2. Right of Access to Personal Data: The data subject has the right to access their personal data by submitting an access request, provided that the lawful basis for such access is one of the following: consent, the Authority’s legitimate interest, or the performance of an agreement to which the data subject is a party. This right shall be exercised without prejudice to the rights of others, including intellectual property rights and trade secrets.

      3. Right to Obtain a Copy of Personal Data: The data subject has the right to request a copy of their personal data, subject to a lawful base that may be: consent, the Authority’s legitimate interest, or the performance of an agreement to which the data subject is a party. Personal data shall be provided in a commonly used, readable, and clear electronic format. Where feasible, a hard copy may also be provided, on the condition that such disclosure does not adversely affect the rights of others, including intellectual property rights or confidential business information.

      4. Right to Rectification: The data subject has the right to request the correction of personal data that is incomplete, inaccurate, or incorrect by submitting a request via email. The Authority shall notify the data subject through the same means within a period not exceeding 30 days from the date of the request. The data subject may also request the restriction of processing for a specified period to allow verification of data accuracy, provided such restriction does not conflict with applicable laws or regulations.

      5. Right to Erasure: The data subject has the right to request the erasure of their personal data in legally prescribed circumstances, unless a statutory retention period or contractual obligation—accepted by the data subject—requires continued retention, provided that such retention does not adversely affect the data subject’s rights or interests. The Authority shall initiate erasure automatically in cases stipulated by applicable laws and regulations, including where it becomes aware that personal data is being processed in violation of the law.

      6. Right to Withdraw Consent The data subject has the right to withdraw their consent to data processing at any time by notifying the Authority through the designated communication channels. Upon withdrawal, the Authority shall take the necessary measures to cease processing and request the erasure of personal data previously disclosed to third parties.

      7. It should be noted that some or all of the above rights may be subject to specific exemptions or limitations as prescribed under applicable laws and regulations. Each request shall be assessed on a case-by-case basis to ensure its compatibility with such statutory exemptions. This Policy defines the procedures through which data subjects may exercise their lawful rights.

 

 

 

  1. Retention and Destruction of Personal Data

    1. The Authority shall retain personal data only to the extent necessary and for lawful and regulatory purposes, including compliance with judicial orders and supervisory requirements. The Authority shall destroy personal data upon the request of the data subject, upon the expiry of the purpose for which the data was collected, or where it becomes aware that personal data is being processed unlawfully, it shall take the necessary measures.

      1. Personal data is stored electronically via databases or data repositories, or in paper documents protected by stringent methods. The means of destroying personal data is through paper shredding and ensuring its deletion from the designated databases and systems available to the Authority.

    2. Lawful Bases for Processing Personal Data

In accordance with applicable laws and regulations, the lawful bases relied upon by the Authority for processing personal data include:

  1. Explicit Consent: Subject to Article (11)(2) of the Executive Regulations of the Personal Data Protection Law, the data subject may withdraw consent at any time, except where exemptions apply under applicable laws and regulations. Requests may be submitted using the contact details specified in this Policy. Notwithstanding the above, the Authority may process personal data without consent in specific circumstances, in accordance with Article (6) of the Personal Data Protection Law.

    1. Public Interest: By development and improvement of shared governmental procedures, subject to the controls and limitations prescribed by applicable laws and regulations.

      1. Fulfilling the legitimate interests of the Authority or the owner of the personal data. The Personal Data Protection Law and its regulations specify their requirements.

      2. Implementing an agreement to which the personal data owner is a party, and if the personal data is publicly available or was collected from a publicly available source.

      3. Protecting the vital interests of the personal data owner or protecting them from any harm.

    2. Use of Personal Data

      1. Pursuant to applicable personal data protection laws and regulations, the Authority uses personal data across its official websites, communication channels, and service platforms, including all branches, for the purpose of: enhancing service delivery; performing public and regulatory functions within its statutory mandate. Personal data may be combined and/or analyzed to assess and deliver content and services relevant to the data subject. The Authority may retain personal data in dedicated records and use it to communicate with the data subject through lawful communication channels. Where appropriate, the Authority applies up-to-date organizational and technical anonymization measures to mitigate risks to personal data. The Authority affirms its commitment to the lawful, proportionate, and secure use of personal data.

      2. The Authority implements dedicated measures to ensure compliance with personal data protection laws and regulations, including adherence to the following core principles:

      • Lawful, fair, and transparent processing;

      • Limited to the specific purpose for which it was collected and to the minimum amount of data;

      • Continuous updating to ensure data accuracy and integrity;

      • Retention limited to necessity, with prompt destruction once the purpose ceases;

      • Secure storage; Enhanced confidentiality protections.

    3. Sharing of Personal Data

      1. The Authority seeks to adhere to the core data-sharing principles established by the competent authority, including: 

      • Promoting a culture of data sharing;

      • Lawful and legitimate purpose; 

      • Authorized access; 

      • Transparency and data security;

      • Ethical use of data; 

      • Shared accountability.

      1. Accordingly, the Authority ensures that personal data is not shared with any individual or entity outside the scope of its official functions, except in the following circumstances:

      • Where the data subject has authorized the sharing of personal data with licensed or competent public authorities for lawful processing purposes;

      • Where disclosure is required pursuant to applicable laws, in response to a judicial order, or for verification purposes in order to conduct lawful and legitimate activities, especially in cases of fraud or technical incidents;

      • The Authority may share personal data without obtaining the data subject’s consent, subject to specific safeguards, where such sharing serves the legitimate interests of the Authority, provided that it does not prejudice the rights or interests of the data subject, unless the data is classified as sensitive personal data. Where the Authority shares personal data with trusted external parties, it ensures that:

      • Only the minimum necessary data required to deliver the specified service or fulfill the stated purpose is disclosed;

      • Binding contractual arrangements are concluded with such third parties to ensure that personal data is not processed or used beyond the expressly defined purposes and scope;

      • We, in turn, ensure the protection of your personal data during the sharing process through stringent measures, and we verify that those with whom we share your personal data take the necessary procedures to maintain the privacy of your personal data.

      1. In pursuit of enhanced transparency and disclosure, the General Authority for Awqaf cooperates with regulatory bodies, including financial and judicial authorities, by making certain data available to such entities or, where appropriate, by publishing it for public access. Public disclosure may also be undertaken where the Authority determines that such publication contributes to raising public awareness of the importance of waqf and its social and economic role, in furtherance of the Authority’s objectives to develop, safeguard, and grow waqf assets.  

    4. Security Measures for the Protection of Privacy of Personal Data

      1. The Authority is committed to maintaining the privacy of your personal data by using preventive security procedures to safeguard your privacy. We commend your awareness in protecting your login information, and therefore we emphasize the security of the information of beneficiaries of our website or our other official channels and means. Consequently, you will receive a verification code to your phone number to verify your identity. When sharing the same device with another person, please log out after each use to ensure the security of your data. You may also be able to access other websites through our site. When you do so, you are subject to the privacy and personal data collection policies of those other sites, and you must read the privacy policies of those sites to ensure your agreement before using them. Furthermore, the Authority affirms its adherence to regulatory steps for protecting your data regarding data cybersecurity, and accordingly, we follow the rules and guidelines of the National Cybersecurity Authority. All databases and online file systems are also password-protected and restricted only to authorized Authority personnel. The Authority also records access to personal data by creating personal data access logs and records this in the Personal Data Protection Register.

      2. Access to personal data is strictly limited to authorized employees, and all access activities are logged through formal access records maintained within the personal data protection register.

      3. When storing personal data electronically, the Authority applies cryptographic encryption measures, where appropriate, to ensure data security. To ensure protection of personal data, the Authority may also use pseudonymization techniques, particularly when processing special categories of personal data. Additionally, the Authority may anonymize personal data where identification of the individual is no longer required and where the original purpose for retention has expired, provided that the data remains valuable for the Authority’s operational purposes.

      4. When engaging data processors, the Authority verifies that such entities provide adequate safeguards for the protection of personal data and comply with applicable laws and regulations within the Kingdom. The Authority continuously monitors processor compliance throughout the entire data processing lifecycle and conducts periodic reviews.

 

  1. Personal Data Breach Incidents

    1. The Authority is committed to notifying the competent authority of any personal data breach within a period not exceeding seventy-two (72) hours from the time it becomes aware of the incident, unless justified reasons for delay exist. The Authority shall also notify the affected data subject of the breach, including a description of the potential risks, the measures taken to prevent or mitigate those risks, and any recommendations or guidance that may assist the data subject in taking appropriate protective actions.

 

  1. Cross-Border Transfer of Personal Data

    1. The General Authority for Awqaf shall protect personal data when transferring it outside the Kingdom for any lawful purpose, such as fulfilling an obligation under an agreement to which the Kingdom is a party, serving the interests of the Kingdom, fulfilling an obligation to which the personal data subject is a party, or implementing other lawful purposes, provided that such transfer does not result in prejudice to national security or the vital interests of the Kingdom, that an adequate level of protection of personal data is ensured outside the Kingdom, and that the transfer or disclosure is limited to the minimum amount of personal data necessary to meet the need. The conditions for transferring or disclosing data shall not apply in cases of extreme necessity related to the life of the data subject or the protection of their vital interests and matters related thereto.

      1. In the absence of an adequacy decision (i.e., where there is an inadequate level of protection of personal data outside the Kingdom) or an international agreement, data shall be transferred in accordance with safeguards specified by the applicable laws and regulations, including:

      • Binding Common Rules: provided that they include the matters stipulated in the Regulation on Transferring Personal Data Outside the Geographical Borders of the Kingdom of Saudi Arabia. 

      • Standard Contractual Clauses, where they ensure an adequate level of protection of personal data.

      • Certifications of compliance with the laws and regulations in the Kingdom, issued by an entity accredited by the competent authority.

      • Binding Codes of Conduct 

      1. In the absence of any of the aforementioned mechanisms, the Authority shall, when necessary, transfer personal data outside the Kingdom in accordance with the applicable laws and regulations and the decisions and recommendations approved by the competent authority.

      2. In cases of cross-border data transfers, the Authority shall apply the provisions of the Regulation on Transferring Personal Data Outside the Geographical Borders of the Kingdom of Saudi Arabia, given the multiplicity and diversity of cases, which cannot all be listed in this Policy. Accordingly, attention is drawn to the necessity of reviewing the said Regulation to understand the mechanism for its application and to clarify the Authority’s obligations and the data subject’s rights with respect to cross-border transfers.

    2. Updates to the Privacy Policy

      1. We reserve the right to update the Privacy Policy and its contents from time to time without prior notice, except in the case of material changes, in which case you will be notified. Accordingly, you are obliged to review the latest updates to this Policy, and by using this website or any of our other official channels, you agree to this Policy.

    3. Inquiries and Complaints

      1. If you have any inquiry, complaint, or request regarding the exercise of any of your rights related to the processing of your personal data, or regarding the contents of the Privacy Policy in general, you may contact us via email at:

Privacy@awqaf.gov.sa