Personal Data Protection Policy
Abaq Al-Hayat — Last updated: July 24, 2026 — Effective as of the publication date
Table of Contents
- Introduction
- Core Data Protection Principles
- Governance and Responsibilities
- Privacy by Design and by Default
- Data Classification and Security Controls
- Data Protection Impact Assessment (DPIA)
- Third-Party and Service Provider Management
- Response to Data Breach Incidents
- Employee Training
- Managing Consent and Data Subject Rights
- Changes to This Policy
- Contact Us
1. Introduction
This policy establishes the internal framework through which Abaq Al-Hayat manages personal data protection across all of its activities and affiliated brands, in compliance with the Saudi Personal Data Protection Law and its implementing regulations.
2. Core Data Protection Principles
3. Governance and Responsibilities
Data protection policies are approved by senior management, and an internal individual or function is designated to oversee compliance with this policy across all departments and affiliated brands. Data protection contact details: info@abqalhayat.com.
4. Privacy by Design and by Default
When developing any new service, product, or web page (such as launching a new online store for one of our brands), we treat data protection as an integral part of the design from the outset rather than as an afterthought — including enabling the lowest level of data collection as the default setting.
5. Data Classification and Security Controls
We classify the data we process according to its level of sensitivity (general identification data, financial data, and sensitive data such as identity documents), and apply security controls appropriate to each classification, including access controls and encryption where feasible.
6. Data Protection Impact Assessment (DPIA)
Before launching any high-risk data processing activity (such as introducing a new system for tracking customer behavior or a platform that collects sensitive data), we conduct a Data Protection Impact Assessment to identify potential risks and mitigation measures before implementation.
7. Third-Party and Service Provider Management
We review the data protection practices of any external service provider we work with (such as hosting providers, payment gateways, and analytics tools), and contractually require them to meet data protection standards no lower than those to which we hold ourselves.
8. Response to Data Breach Incidents
Determine the scope of the incident as soon as it is discovered and take immediate steps to prevent further impact.
Identify the affected data, the individuals concerned, and the level of risk.
Notify the Saudi Data and Artificial Intelligence Authority and affected individuals within the legally required timeframes.
Analyze the causes of the incident and update controls to prevent recurrence.
9. Employee Training
All employees who handle personal data receive periodic training on the principles of this policy and their legal responsibilities regarding customer data.
10. Managing Consent and Data Subject Rights
We apply a standardized internal procedure for recording consent and tracking withdrawals, and for responding to data subject requests (information, access, correction, and destruction) within defined timeframes. For full details of your rights as a customer, please see our Privacy Policy.
11. Changes to This Policy
We may update this policy to reflect developments in our internal practices or in the law and its regulations. Any update will be published on this page together with the date of the latest revision.
12. Contact Us
For any questions regarding this policy, please contact us through:
- Email:
info@abqalhayat.com - Address: Riyadh - King Fahd Road South - Al Jafal Commercial Center - Third Floor - Office 21
