Conformance with the Personal Data Protection Law
This is the formal PDPL conformity statement for the Veltrixair Industries BU. It maps PDPL articles to what the BU actually does with data, documents the notices we give at the point of collection, sets out how we respond to a breach, and describes how the programme is governed. It's written for legal and compliance teams to review. If you want the plain-language version, that's the Privacy Notice. Together, the two documents cover what Saudi law requires us to disclose.
The Industries BU operates in conformance with the Saudi PDPL
The Veltrixair Industries Business Unit follows the Saudi Personal Data Protection Law, issued under Royal Decree No. M/19, along with its Implementing Regulations from the Saudi Data and Artificial Intelligence Authority (SDAIA) and any further SDAIA guidance. This document is the BU's formal compliance statement, issued by the VP — Data Protection function.
We only process personal data on a documented legal basis, keep it no longer than set out in Section 9, only send it outside the Kingdom under the legal conditions in Section 8, and honour the rights described in Section 7. If this document and the Privacy Notice ever seem to differ, the Privacy Notice is what applies to you — this document is our internal compliance reference.
We review this statement every year, and any time something meaningful changes. The version number at the top updates with every revision, and we keep a change log available on request.
Four articles. The structural anchors
Four parts of Saudi data protection law do most of the heavy lifting in this document: your rights, the legal bases we rely on, how we handle sensitive data, and our obligation to be transparent. Each is explained in the sections below.
Data Subject Rights
Eight rights granted to individuals — access, correction, erasure, restriction, object, portability, withdraw consent, be informed. 30-day response window.
Lawful Basis
Permitted bases for processing personal data — consent, contractual necessity, legal obligation, legitimate interests, vital interests, and prescribed purposes.
Sensitive Data
Special category data — health, biometric, ethnic origin, religious belief, political opinion, criminal record. Explicit consent required for processing.
Transparency Obligation
Requirement to inform data subjects at point of collection of identity, purpose, basis, recipients, retention, rights, complaint route. Layered notices below.
Data controller & DPO function
Veltrixair Industries, based in Riyadh, is the Data Controller for the Industries business — meaning we decide why and how personal data is processed, as described here and in the Privacy Notice.
Tarique Ahmad, who's also our Chairman and CFO, holds the role of Data Protection Officer. This function reports directly to the Chairman rather than through the commercial side of the business, which keeps it independent when handling rights requests, breach reviews, and refusals.
The DPO function is contactable at privacy@veltrixair.com for data subject rights requests, regulator correspondence, and any matter falling within Articles 4 and 14. Substantive correspondence is reviewed by the function personally; routine administrative correspondence may be delegated.
Regulatory framework stack
We operate under several overlapping Saudi regulations. PDPL is the main one — the others either build on it, reference it, or add related obligations on the same data.
- PDPL — Personal Data Protection Law · Royal Decree No. M/19. The primary instrument.
- PDPL Implementing Regulations · issued by SDAIA. Operational specifics on consent, retention, breach notification, cross-border transfers.
- SDAIA Guidance Notes · supplementary regulatory guidance issued from time to time on specific PDPL matters.
- ZATCA Fatoora Phase 2 · e-invoicing regulations, governing the financial data category.
- Saudi Labour Law · workforce records, end-of-service gratuity, and employment data retention obligations.
- HCIS site access protocols · access logs and permit-to-work records on petrochemical complex sites.
- NCA Essential Cybersecurity Controls (ECC) · adopted as the supplementary security control framework over personal data.
- ISO/IEC 27001 · adopted as a best-practice baseline for the information security management system supporting personal data processing.
Where two regulations overlap — for example PDPL's retention rules and ZATCA's mandatory record-keeping period — we follow whichever requires the longer retention, while still limiting who can access the data to only those who need it for its original purpose.
Lawful basis map
Saudi data protection law sets out the legal grounds for processing personal data. The table below matches each of our activities to its legal basis — nothing we do is undocumented.
Sensitive data handling
Saudi law sets extra requirements for sensitive personal data — things like health information, biometric data, ethnicity, religion, political views, union membership, or criminal record. We can only process this kind of data with explicit consent, or under another basis specifically allowed by the regulations.
We don't normally process sensitive personal data. Our everyday work — quotes, engagement records, site photos, financial records, workforce admin — doesn't need it. Where an exception comes up, it's handled the way described below.
- HSE incident health information · Where a workplace incident or near-miss requires processing of health-related information, the data is collected on the explicit basis of vital interests under PDPL Article 5, retained under elevated controls (encrypted, role-restricted access), and is the subject of a documented incident-specific processing record.
- CCHI medical insurance administration · Workforce health insurance administration is handled by the CCHI-licensed insurer as a separate Controller under their own Article 6 basis. Veltrixair Industries acts only as a transmission point for enrolment data.
- Biometric site access · Where a client site (Aramco, SABIC, HCIS-regulated complex) operates biometric access, the client is the Controller for that processing. Veltrixair Industries’ role is limited to facilitating its workforce's enrolment under the client's framework.
We never process the other categories of sensitive data — ethnicity, religion, political views, union membership, or criminal record — under any circumstance.
Transparency obligation
Saudi law requires us to be upfront at the moment we collect your data — who we are, why we're collecting it, our legal basis, who might see it, how long we'll keep it, your rights, and how to complain if needed.
We do this in layers: the full legal detail sits here, the plain-language version is the Privacy Notice, and short notices appear right at the point of collection — on forms, in confirmation emails, and spoken aloud during site visits where photos are taken.
These three layers work together — this document and the Privacy Notice are always accessible from the footer, the shorter notices appear right when you're submitting something, and confirmations are sent after. Each layer links to the others, and each one gives you enough information on its own.
Layered notice — point of collection
The cards below show, in short form, exactly what you're told when you submit each of our main forms. Each one gives you everything you need without reading the full Privacy Notice — though the link to it is always there.
Request a quote
Request a site visit
Career application
Newsletter subscription
When we capture data on site — photos of equipment condition, occasional videos of faults — the lead engineer tells you verbally at the start of the visit, and it's confirmed in writing afterward. If anyone appears in the shot by accident, we blur them out before using it externally.
Data subject rights workflow
Saudi law gives you eight rights over your personal data. The Privacy Notice explains them in plain terms. This section documents how we actually process a request internally — so these rights are real, not just words on a page.
- T+5 working days · Acknowledgement. Receipt of the request is acknowledged with a reference number routed to the requesting data subject. Initial routing to the DPO function is automatic.
- T+12 days · Identity verification. Where the request relates to specific personal data, the requester's identity is verified through proportionate means (existing relationship reference, ID document, secondary contact channel).
- T+30 days · Substantive response. Per Article 4, substantive response is delivered within thirty days of verified receipt. Complex requests may invoke a documented extension under the Implementing Regulations, with notification to the requester.
- Refusal grounds. Where a request is refused — for example, retention obligations under Saudi Labour Law preventing erasure — the refusal is documented with reference to the lawful basis. The DPO function reviews refusals before issue.
- External escalation. Every response includes the route to escalate to SDAIA as the Competent Authority, where the requester is dissatisfied with the BU's response.
Send requests to privacy@veltrixair.com. Standard requests are free; only clearly unreasonable or excessive requests might carry a fee, as allowed under the regulations.
Cross-border transfers
Saudi law governs how we can send personal data outside the Kingdom. Our default is to keep data inside Saudi Arabia — Saudi-based cloud infrastructure, Saudi-based servers, and Saudi-based processing wherever possible.
When data does need to leave — for example, routing technical support through a European vendor, or overflow cloud capacity — that transfer is documented in an assessment maintained by our Data Protection Officer.
- Lawful basis. Each transfer is mapped to a permitted basis under Article 29 — adequacy where SDAIA-recognised, contractual necessity for engagement-critical transfers, or explicit consent for non-essential transfers.
- Recipient assessment. Recipient jurisdiction's data protection regime is assessed. Where adequacy is not established, additional contractual safeguards are imposed via DPA.
- Technical safeguards. Transit encryption (TLS), at-rest encryption (AES-256), access controls (role-based), audit logging (centralised). Personal data in transit is never sent unencrypted.
- India operations bilateral. Veltrixair Industries operations in India support the Industries BU's back-office functions. Transfers India-bound are governed by both PDPL Art 29 and the India Digital Personal Data Protection Act 2023, with the bilateral DPA framework documented and reviewed annually.
If data needs to move again after it's already left the Kingdom — from one foreign country to another — that requires separate approval. It's not allowed by default.
Retention schedule
Saudi law says we can only keep personal data as long as we actually need it. Our full retention schedule is in the Privacy Notice. This section explains the process behind it.
- Quarterly retention review. The DPO function reviews the retention schedule quarterly. Records past their retention period are flagged for the responsible function (HR for workforce, Finance for ZATCA, BU Operations for engagement records) for action.
- Documented destruction. Records reaching end-of-retention are destroyed via documented destruction workflows. Destruction certificates are retained for audit trail purposes; the certificates themselves are not personal data.
- Anonymisation alternative. Where data has continued analytical value but no continuing personal-data purpose, irreversible anonymisation is preferred over deletion. Anonymised aggregates are retained outside the personal-data control regime.
- Statutory minimums prevail. Where Saudi statutory law mandates a minimum retention period (Saudi Labour Law for workforce, ZATCA for invoicing, SASO for inspection certificates), the statutory minimum prevails over the BU's operational preference for shorter retention.
Breach response framework
Saudi regulations require us to notify the data protection authority within 72 hours of discovering a breach likely to cause harm. Our internal process is built to catch breaches early, contain them fast, assess them properly, and notify on time.
Detection & internal notification
Detection by any source — internal monitoring, employee report, vendor notification, regulator inquiry. CISO and DPO function notified within one hour.
Initial classification
Preliminary assessment of severity, scope, and the lawful processing affected. Triage decision: contained incident vs reportable breach.
Containment actions
Containment measures applied — credential rotation, system isolation, access revocation, log preservation. Preliminary incident report logged.
Severity assessment finalised
Severity assessment finalised; data subjects affected identified and counted; notification threshold under the IR evaluated; communications plan drafted.
SDAIA notification
Where the breach meets the notification threshold, SDAIA is notified within the 72-hour window per the Implementing Regulations. Notification is comprehensive — nature, scope, mitigation, contact.
Affected data subject notification
Where individual notification is required, affected data subjects are notified directly with a description of the breach, the data affected, the remedial actions taken, and their rights.
Post-incident review
Within 14 days of full resolution, the DPO function leads a documented post-incident review — root cause, control gaps, remediation actions, lessons learned, and updates to this notice if material.
Programme governance
A privacy programme that only exists on paper doesn't actually meet the requirements. Ours runs on six real, ongoing practices, each with a schedule, an owner, and a clear output.
Privacy Impact Assessments
Annual review of existing processing activities. PIA on every new processing activity before go-live. Outputs are version-controlled documents in the BU's governance library.
Internal audit cadence
Quarterly internal audit of the BU's PDPL conformity, conducted by the Privacy Advisory practice acting as second-line. Findings are tracked to closure.
Workforce training
Mandatory PDPL training on hire; annual refresh thereafter. Completion is tracked at individual level. Engineers handling site imagery receive additional contextual training.
Vendor DPAs
Every processor handling personal data on the BU's behalf is bound by a Data Processing Agreement. DPAs are reviewed annually; new vendors are onboarded only with DPA in place.
DPO independence
The DPO function reports directly to the Chairman, outside the commercial chain. Refusals of data subject rights requests are reviewed by the function before issue. Independence preserved structurally.
Continuous improvement
Material findings from audits or incidents trigger review of this notice and the Privacy Notice. Material updates are communicated; minor corrections are tracked in the change log.
Document control & updates
This document is version-controlled. Material changes — to processing activities, to the regulatory framework, to the lawful basis map, to the breach response framework — trigger a new version. The version reference at the top of this document is incremented; a change log is maintained internally and made available on legitimate request.
Document control register
If the Arabic and English versions ever differ, the English version is the one that applies — that's our standard operating language for governance documents. If you spot a translation issue, let our Data Protection team know.