PDPL Guide No. 26 – Appendix 1 – Non-exhaustive list of examples of bad data protection practices

Please see below a list of examples of bad data protection practices that violate the PDPL. The Competent Authority strongly encourages you to avoid such practices.

Please note that this list is not exhaustive and is for illustrative purposes only. Even if you avoid the practices from this list, it still means that you must comply with all the requirements of the PDPL.

Example 1 | Use of personal data without an established lawful basis

A retail electronic store collects from each customer, before completing the sale, their name, email and phone number. The customers are not provided with any explanations for such collection and are not requested to give any consent for the processing of their personal data.

After collection of the above personal data, the store:

1. places the collected personal data into a cloud storage system, hosted outside the Kingdom;

2. starts regularly sending marketing information to collected emails;

3. transfers the collected personal data to a data analytics agency.

The retail store has not identified any lawful bases for any of the above purposes of the use of personal data. The management of the store does not understand what lawful bases could be used in principle.

This is a bad practice. You must avoid it. You must always identify lawful bases for each purpose of processing of personal data, as such lawful bases are specified in Art. 5 and Art. 6 of the PDPL.

Example 2 | Collection of personal data without defined purpose

A pharmacy collects phone numbers of all its customers. When asked about the reasons for such collection, neither the cashier nor the manager of the pharmacy could explain why the pharmacy needs phone numbers. They provide an explanation such as “the pharmacy has always done so”. The pharmacy does not have any documents that show that purposes of such collection are formally defined.

This is a bad practice. You must avoid it. You must not collect personal data unless you have identified and documented purposes for such a collection.

Example 3 | Storage of personal data indefinitely

An HR department stores in its system the data about all the employees of the organization, including those who left the organization. The HR department also stores CV of all candidates that have ever applied to the organization. The personal data of all its candidates and employees is stored indefinitely and never deleted.

This is a bad practice. You must avoid it. You must destroy personal data when you no longer need it (subject to exception of Art. 18 of the PDPL).

Example 4 | Processing of personal data without a record of processing activities (RoPA)

A marketing company analyzes large volumes of personal data of various customers. The company has a number of departments with different roles.

The marketing company has not documented any of its processing activities. As a result, the management of the company does not know what types of personal data it processes, where the personal data is stored and to whom personal data is transferred.

This is a bad practice. You must avoid it. You must maintain a record of processing activities so that you understand what personal data you process.

Example 5 | Sharing of personal data without any lawful bases and without providing any privacy notice to individuals

A customer obtains a new phone number at a telecommunication company. On the same day, the company sells the database with the customer’s personal data to an advertising agency. The customer was not aware of the transfer of his personal data for advertising purposes.

To his surprise, the customer starts soon receiving advertising from retail stores, restaurants, and pharmacies which he never contacted or visited.

This is a bad practice. You must avoid it. You must not share personal data with any entity, unless you have a lawful basis to do so and unless you comply with other requirements of the PDPL regarding the disclosure of personal data. The individual whose personal data you share with others must be provided with a privacy notice so that he/she understands how and why you process his/her personal data.

Example 6 | Absence of data protection-related policies and training

A pharmacy does not have any data protection-related policies or procedures in place. Further, the pharmacy’s employees have not been provided training and awareness on good data protection practices. As a result, its employees do not understand how to process the personal data of its customers on a daily basis.

This is a bad practice. You must avoid it. You must have in place data protection policies and procedures that regulate how personal data is used within your organization. Once you develop such policies or procedures, it is important that they are enforced within your organization and that your employees are aware of their roles. You must regularly train your employees who handle personal data so that they do so in accordance with the PDPL and your internal policies.

Example No. 7 | Announcing patients’ personal data in the clinic

A clinic has a waiting area for its patients prior to receiving treatments. When the clinic’s doctor is ready to accept a patient, a nurse comes to the waiting area and calls out loud the patient and the reasons for the visit. All other patients in the waiting area could hear what was called out loud.

This is a bad practice. You must avoid it. The name of the patient (and the reason for the visit) is the patient’s personal data. You must ensure that the name of your client is not disclosed, other than based on the lawful bases, as specified in Art. 5, Art. 6 and subject to compliance with the additional requirements of Art. 15 PDPL.

Scroll to Top