An official government website of the Kingdom of Saudi Arabia
How to verify
Official Saudi government websites end with gov.sa

All official educational websites in Saudi Arabia end with sch.sa or edu.sa

Government websites use HTTPS protocol for encryption and security.

Secure websites in Saudi Arabia use HTTPS protocol for encryption.

Privacy Policy

1. Introduction

1.1 Introduction

This Privacy Policy represents the Authority's commitment to maintaining the privacy and confidentiality of users' personal data. This policy has been developed to clarify how personal data is collected, processed, and protected in accordance with relevant regulations and guidelines.

1.2 Objective

This policy aims to:

  • • Ensure the protection of users' personal data.
  • • Define the regulatory basis for collecting and processing data.
  • • Enhance transparency regarding methods of data collection and processing.
  • • Provide means for users to exercise their rights relating to their personal data.

1.3 Scope

This policy applies to all personal data collected and processed by the Higher Commission for Industrial Security, and includes:

  • • User data provided through registration or interaction with the comprehensive platform.
  • • Any data automatically collected during use of the platform, such as cookies and IP addresses.
  • • This policy applies to all users who interact with the comprehensive platform.

1.4 Definitions

Term Description
Authority Higher Commission for Industrial Security
Data Management Office The Data Management Office at the Higher Commission for Industrial Security
Data A collection of facts in their raw or unstructured form, such as numbers, letters, still images, video, audio recordings, or symbols
Personal Data Protection Officer The employee responsible for monitoring policies, plans, and activities related to personal data protection to ensure the Authority handles personal data in accordance with controls and specifications, and to ensure the highest levels of protection for personal data through the application of relevant policies and procedures.
Personal Data Any statement that would lead to identifying you specifically, or makes it possible to identify you directly or indirectly, including: name, national ID number, addresses, contact numbers, license numbers, records, personal property, still or moving images of an individual, and other data of a personal nature.

2. Policy Terms

2.1 About the Authority

The Higher Commission for Industrial Security was established by Cabinet Decision No. (707) dated 27/12/1443 AH. The Authority provides high-quality services through a professional and experienced team committed to fulfilling its duties in a manner that satisfies beneficiaries. In its commitment to users' data and information, the Authority undertakes to maintain the confidentiality and privacy of this data and to use it to achieve the desired level of service for the user in accordance with the terms and conditions in force in Saudi Arabia. Use of the comprehensive platform constitutes the user's agreement to the user privacy policy.

2.2 Consent to the Secure Usage and Privacy Policy Notice

The Higher Commission for Industrial Security ("Authority") places the privacy and confidentiality of the personal data of users of the comprehensive platform ("Platform") dedicated to providing services at the top of its priorities, in accordance with the controls stipulated in the Personal Data Protection System issued by Royal Decree No. (M/19) dated 9/2/1443 AH and its implementing regulations.

Personal data is not collected by the Authority without the knowledge of the data owner and their choice to provide such data. When the data owner registers or uses the comprehensive platform, this constitutes their implicit consent to the terms of the Secure Usage and Privacy Policy.

When using the "Comprehensive Platform," the Authority collects various types of personal data. This data collected through registration on the comprehensive platform or use of the services provided on it is used for research, studies, publishing reports, dashboards, and the like. The Authority commits to not disclosing or sharing any personal data that can identify the data owner, in accordance with applicable regulations and instructions, except with their consent.

2.3 Privacy Policy Updates

  • • The Authority's platform management reserves the right to add or change any provisions of the Privacy Policy, and will notify the data owner accordingly. The platform management has the right to terminate the data owner's account if they do not accept any change in the Privacy Policy, provided this does not conflict with applicable regulations and laws.
  • • Arabic is the official language for the application of terms and conditions. In the event of a discrepancy in the interpretation of any text in another language, the Arabic text shall prevail.

2.4 Contact Information

2.5 Personal Data Protection Officer

2.6 Data to be Collected and Purpose of Collection

First: Personal Data to be Collected

When using the comprehensive platform, various types of personal data are collected, including but not limited to:

  • - Full name, national ID, gender, nationality, date of birth, mobile number, email address, residential address.
  • - Account information: login data, passwords (encrypted), and account settings.
  • - Technical information: IP address, device type, operating system, browser, and internet connection information.
  • - Usage information: browsing patterns, interactions with the platform, and preferences.

Second: Purpose of Collecting Personal Data

  • - Data is collected to provide the necessary services to the user and to follow up on any inquiries, suggestions, or complaints submitted by the user.
  • - Data is used to complete the registration process and improve the beneficiary's experience.
  • - Data is used for the purposes specified in this policy or the regulatory purposes stipulated in the Personal Data Protection System.
  • - Data is used for analysis and issuing reports that serve the necessary operational requirements.

2.7 Methods of Collecting Personal Data

  • - Data provided by the data owner to the platform through registration.
  • - Data collected indirectly through cookies collected when visiting the platform.
  • - The platform automatically records the IP address of your internet connection when you visit the website.

2.8 Processing of Personal Data

Personal data is collected and processed based on the consent of the data owner, who may withdraw their consent to the collection and processing of their personal data at any time, unless there is another regulatory basis. To do so, the Data Management Office at the Higher Commission for Industrial Security may be contacted.

Via Email: DMO@hcis.gov.sa

2.9 Privacy

The comprehensive platform provides beneficiaries with access to its electronic services and commits to facilitating access to these services using the highest safety standards recommended by relevant authorities. The Authority also commits to preserving and protecting the privacy of beneficiaries' personal data, and the Higher Commission for Industrial Security undertakes not to use this data for unlawful purposes.

2.10 Sharing of Personal Data

The Authority commits to not sharing any personal data. However, the Authority may disclose personal data collected directly or indirectly to regulatory and legislative authorities for the purpose of achieving public interest, for security purposes, for executing another regulation, or for meeting judicial requirements, provided this does not conflict with applicable regulations and instructions.

2.11 Storage of Personal Data

Personal data is stored through secure solutions at the Authority or third parties authorized by the Authority, protected by the best technologies in accordance with the National Cybersecurity Authority's policies, controls, and international standards to ensure no unauthorized access and to limit cybersecurity risks. Data will then be securely destroyed within three years from the date of storage in a manner that prevents access or retrieval, in accordance with the Authority's policies.

2.12 Rights of Personal Data Owners

  • • Right to Know: The personal data owner has the right to know the ways we collect their data, the regulatory basis for collection and processing, how it is processed, stored, and destroyed, and with whom it will be shared. You can review all details through the Privacy Policy or by contacting us via the information provided in Section 4.
  • • Right to Access Personal Data: The personal data owner has the right to request a copy of their personal data via the email address provided in Section 4, and it will be provided at no cost within five working days by email.
  • • Right to Correct Personal Data: The personal data owner may request the correction of their personal data that they deem inaccurate, incorrect, or incomplete via the email address provided in Section 4. It will be reviewed and updated within five working days, and the data owner will be notified by email.
  • • Right to Destroy Personal Data: The personal data owner may request the destruction of their personal data under certain circumstances, unless there is a regulatory text specifying a retention period or contractual requirements.
  • • Right to Withdraw Consent to Data Processing: The personal data owner may withdraw their consent to the processing of their personal data at any time, unless there are legitimate purposes requiring otherwise.
  • • Right to Object: The data owner has the right to object to the collection, processing, storage, sharing, or disclosure of their personal data without their explicit consent, or if the processing is for direct marketing purposes.
  • • Right to Restrict Processing: The data owner has the right to request that the processing of their personal data be restricted to one or more purposes.

2.13 External Links

The comprehensive platform may include links to other websites on the internet. The Authority is therefore not responsible for the content of those sites, and the risks of browsing those sites through any link available on the website are the responsibility of the data owner. The data owner may review the privacy policies and content of those sites accessed through any link within those sites.

2.14 Exercising Data Owner Rights

The personal data owner has the right to request access to, correction of, or destruction of their data by contacting via the following email: DMO@hcis.gov.sa

2.15 Termination of Use

The Authority may, at its absolute discretion, terminate, restrict, or suspend the user's right to access and use the platform without notice and for any reason, including violation of the terms and conditions of use or any other conduct that we may consider, at our own discretion, unlawful or harmful to others. In the event of termination, you will no longer be authorized to access this platform.

2.16 Complaints and Inquiries

If you have any complaints or inquiries related to the Privacy Policy or the handling of personal data, please contact the platform management via email at: DMO@hcis.gov.sa

2.17 Applicable System

This policy is subject to applicable regulations, laws, and instructions. In the event of a conflict between any of the provisions of this policy and any applicable regulations, laws, or instructions, the applicable regulations, laws, and instructions — along with any decisions and instructions issued in this regard — shall prevail.

3. References and Related Systems