01

Define controller, processor and purpose

The Saudi Personal Data Protection Law distinguishes the Controller, which determines the purpose and manner of processing, from the Processor, which processes personal data on the Controller’s behalf. A personalised-print brief should state the parties’ roles, permitted purpose, approved output and instructions before data is transferred.

SDAIA’s guidance says controllers remain accountable for processing and must ensure the processors they engage comply with the PDPL. Legal and privacy owners should determine the applicable basis, notices, retention and contractual requirements; the production workflow should implement those decisions visibly.

02

Send only the fields production needs

Build the production dataset from the approved output backwards. If the pack needs a name, language, delivery address and tier, do not also send job title, personal email, internal notes or a full CRM export. Replace internal identifiers with a controlled production ID where possible.

Separate sensitive instructions from visible packing labels. The outside of a carton should help delivery without revealing the gift value, employee status, customer segment or confidential contents.

03

Agree the secure transfer and access route

Use the client-approved secure transfer method, encryption and authentication controls. Name the supplier personnel who can access the data and prevent local copies, uncontrolled forwarding and shared-account access. Keep artwork files separate from live recipient data until the production merge requires both.

The National Cybersecurity Authority’s Essential Cybersecurity Controls require third-party cybersecurity requirements to be defined, documented and approved. They also identify non-disclosure, incident communication, compliance obligations and secure removal of organisational data at the end of service as contract considerations.

04

Test with synthetic records before live data

Prove the merge, Arabic and English rendering, long names, line breaks, missing values, duplicate detection, address fields and pack logic using invented records. Live personal data should arrive only after the template and exception rules work.

For final proofing, expose the smallest useful sample to the fewest authorised reviewers. Mask or omit fields that are irrelevant to the approval decision.

05

Reconcile and close the data lifecycle

Reconcile input records, generated pieces, accepted output, rejects, reprints, packed items and dispatched items using the production ID. Secure rejects and setup sheets immediately; personalised waste should not enter ordinary recycling while readable.

At the agreed end of service, remove working files, exports and temporary copies according to the contract and retention instruction, then provide the required deletion or return evidence. Record exceptions such as undelivered packs or approved reserve stock instead of keeping data indefinitely for convenience.

  • Documented purpose and party roles
  • Minimum production dataset
  • Approved secure transfer method
  • Named access and incident contacts
  • Synthetic-data testing before live merge
  • Count reconciliation and secure waste handling
  • Contractual return, retention or deletion evidence