Law note · Saudi Arabia
Personal Data Protection Law, sensitive data and biometric processing
What it requires
- An app that derives a faceprint, voiceprint, or other identity-linked biometric identifier from an individual in Saudi Arabia, for any purpose the purpose-based Sensitive Data definition would reach, must obtain the Data Subject's explicit consent before processing it, and must destroy it once the processing purpose is fulfilled or consent is withdrawn.
When LexLint raises it
processes_biometricsprocesses_voicetrains_modelscrawls_web
- Excludes recording-derived identifiers
- No
What we found
Art. 1(11) folds "biometric... Data for the purpose of identifying the person" directly into the Sensitive Data definition, with no standalone "Biometric Data" term and no worked-example list, unlike the UAE, Oman, and ADGM statutes. Implementing Regulations Art. 11(2)(a) requires explicit consent whenever processing involves Sensitive Data, reaching identifying biometric data by the Art. 1(11) definition. No modality-specific (voice or face) language was found.
Implementing Regulations Art. 8 requires the Controller to destroy Personal Data on enumerated grounds (purpose fulfilled, consent withdrawn), notifying every party the data was disclosed to and destroying all system copies; this is the general destruction duty applying to biometric data as Sensitive Data, with no biometric-specific retention ceiling found.