Personal Data Protection Policy
Abaq Al-Hayat — Last updated: July 24, 2026 — Effective as of the date of publication
Contents
- Introduction
- Core Data Protection Principles
- Governance and Responsibilities
- Privacy by Design and by Default
- Data Classification and Security Controls
- Data Protection Impact Assessment (DPIA)
- Third-Party and Service Provider Management
- Response to Data Breach Incidents
- Employee Training
- Consent Management and Data Subject Rights
- Changes to This Policy
- Contact Us
1. Introduction
This policy establishes the internal framework through which Abaq Al-Hayat manages personal data protection across all of its activities and affiliated brands, in accordance with the Saudi Personal Data Protection Law and its Implementing Regulations.
2. Core Data Protection Principles
3. Governance and Responsibilities
Data protection policies are approved by senior management, and an internal person or function is designated to oversee compliance with this policy across all departments and affiliated brands. Contact details for the data protection function: info@ur.abqalhayat.com.
4. Privacy by Design and by Default
When developing any new service, product, or web page (such as launching a new online store for one of our brands), we treat data protection as an integral part of the design from the outset, not as a later addition — including enabling the minimum necessary level of data collection by default.
5. Data Classification and Security Controls
We classify the data we process according to its level of sensitivity (general identifying data, financial data, and sensitive data such as identity documents), and we apply security controls appropriate to each classification, including access controls and encryption where feasible.
6. Data Protection Impact Assessment (DPIA)
Before launching any high-risk data processing activity (such as a new system for tracking customer behavior or a platform that collects sensitive data), we conduct a Data Protection Impact Assessment to identify potential risks and ways to mitigate them before implementation.
7. Third-Party and Service Provider Management
We review the data protection practices of any external service provider we work with (such as hosting providers, payment gateways, and analytics tools), and we contractually require them to meet data protection standards no less stringent than those we apply ourselves.
8. Response to Data Breach Incidents
Determine the scope of the incident as soon as it is discovered and take immediate action to prevent further impact.
Identify the affected data, the individuals concerned, and the level of risk.
Notify the Saudi Data and Artificial Intelligence Authority and affected individuals within the timeframes required by law.
Analyze the causes of the incident and update controls to prevent recurrence.
9. Employee Training
All employees who handle personal data receive periodic training on the principles of this policy and their legal responsibilities regarding customer data.
10. Consent Management and Data Subject Rights
We apply a standardized internal procedure for recording consents, tracking their withdrawal, and responding to data subject requests (notice, access, correction, and deletion) within defined timeframes. For full details of your rights as a customer, please see the Privacy Policy.
11. Changes to This Policy
We may update this policy to reflect changes in our internal practices or in the law and its regulations. Any update will be published on this page with the date of the latest revision.
12. Contact Us
For any questions regarding this policy, please contact us via:
- Email:
info@ur.abqalhayat.com - Address: Riyadh - King Fahd Road South - Al Jafal Commercial Center - 3rd Floor - Office 21
