Definitions
Term |
Definition |
Law |
The Personal Data Protection Law issued by Royal Decree No. (M/19) dated 09/02/1443H. |
Regulation |
The Executive Regulation of the Personal Data Protection Law. |
Authority |
The Transport General Authority. |
Office |
The Data Management and Governance Office at the Transport General Authority. |
Personal Data |
Any information, regardless of its source or form, that may lead to identifying an individual specifically or makes identification possible directly or indirectly, such as: name, personal ID number, addresses, contact numbers, license numbers, personal property records, bank account numbers, credit card numbers, fixed or moving images of the individual, and other personal data. |
Data Processing |
Any operation performed on personal data by any means, whether manual or automated, including collection, recording, preservation, indexing, arranging, formatting, storage, modification, updating, merging, retrieval, use, disclosure, transfer, publication, sharing, interconnection, blocking, erasure, and destruction. |
Controller |
The entity that determines the purpose and means of processing personal data, whether it directly processes the data or through a processor. |
Processor |
The entity that processes personal data on behalf of the controller. |
Public Entity |
Any ministry, department, public institution, authority, or independent entity in the Kingdom, or any of their affiliates. |
Competent Authority |
The Saudi Data and Artificial Intelligence Authority (SDAIA). |
Personal Data Subject |
The individual to whom the personal data pertains, or their representative or legal guardian. |
Personal Data Protection Officer |
Responsible for monitoring the implementation of the law and its regulations, supervising the procedures followed within the controller’s entity, and receiving requests related to personal data according to the law and its regulations. |
Explicit Consent |
Consent granted directly and explicitly by the personal data subject by any means indicating their acceptance of personal data processing, which cannot be interpreted otherwise, and must be provable. |
Destruction |
Any action performed on personal data that makes it impossible to access, retrieve, or identify the data subject again. |
Disclosure |
Enabling any person, other than the controller or processor as appropriate, to obtain, use, or access personal data by any means and for any purpose. |
Transfer |
Transferring personal data from one place to another for processing purposes. |
Publication |
Broadcasting any personal data through a readable, audible, or visual medium or making it available. |
Sensitive Data |
Any personal information related to an individual’s racial or ethnic origin, religious, intellectual, or political beliefs. This also includes security and criminal data, biometric identifiers, genetic data, health data, and data indicating that an individual is parentless or has unknown parentage. |
Genetic Data |
Any personal information related to the genetic or acquired characteristics of a natural person that uniquely identifies their physiological or health traits, derived from the analysis of a biological sample such as DNA analysis or any other analysis leading to the extraction of genetic data. |
Health Data |
Any personal information related to an individual’s health condition, whether physical, mental, or psychological, or related to specific health services. |
Credit Data |
Any personal information related to an individual’s application for or receipt of financing, whether for personal or family purposes, from an entity practicing financing, including any information related to their ability to obtain credit or fulfill it, or their credit history. |
Personal Data Breach |
Any incident leading to the disclosure, damage, or unauthorized access to personal data, whether intentional or unintentional, by any means, whether automated or manual. |
Vital Interest |
Any essential interest necessary for preserving the life of the personal data subject. |
Realized Interest |
Any moral or material interest of the personal data subject directly linked to the purpose of personal data processing, where processing is necessary to achieve that interest. |
Purpose of the Policy
Information about the Authority
- Al-Olaya Main Road - Al-Sahafa District, P.O. Box 11634, Riyadh 87078
- Unified Number:19929
- Email: 19929@tga.gov.sa
Personal Data to be Collected
- Account Data:Information requested when creating an account or profile on our platforms.
- Payment Data:Data collected for processing payment transactions.
- Cookies Data:Information collected through website logs, cookie technologies, or other technologies, including IP address, browser type and version, operating system, login details, browsing data, internet traffic monitoring, and other online identifiers.
- Identity Data:Name, date of birth, gender, ID/Iqama number, nationality, personal ID photos, and static personal images.
- Contact Data:Email address, phone number, and mobile number.
- Establishment Data:Establishment name, license numbers, commercial registration number, commercial registration images, license images, and permit details.
- Vehicle Data:Vehicle information, vehicle plate number, vehicle serial number, chassis number, and violations.
- Geographic Location Data:National address, short address, and geographic location on maps.
Cookies
Legal Basis for Collecting and Processing Your Personal Data
Purpose of Using and Processing Your Personal Data
- Issuance of licenses, operation cards, and driver cards for establishments in all activities overseen and regulated by the Authority.
- Issuance of permits, operation cards, and driver cards for individuals in all activities overseen and regulated by the Authority.
- Monitoring the operation, service quality, and safety in these critical activities.
- Processing personal data related to violations and objections, including but not limited to: recording violations, analyzing them, receiving objections to violations, and handling them.
- Enabling beneficiaries to carry out operations and procedures related to the sector across more than 23 activities in integration with relevant government entities.
- Enabling carriers and freight brokers to issue goods transport documents and truck load statements on land roads and verify shipment information and status.
- Enabling carriers to book truck entry appointments to cities during restricted times, contributing to mitigating the negative impacts of the current situation.
- Regulating vehicle rental operations and issuing unified rental contracts to safeguard the rights of all relevant parties.
- Sending, transmitting, and receiving government correspondence within and outside the Authority with other entities and exchanging documents and letters.
- Receiving beneficiary reports, handling, and analyzing them.
- Sending periodic email and SMS messages—to process requests, provide updates and information about your request, and share general news and updates about the Authority and related products.
- Conducting various studies on all activities under its supervision and regulation to implement and achieve sector strategies, focusing on beneficiaries, improving transport services' competitiveness, and analyzing the market to identify opportunities and risks to enhance and improve the safe mobility of passengers and goods. Additionally, this includes developing executive regulations, ensuring compliance, employing technology in monitoring and control activities, ensuring fair competition among service providers, and protecting user interests, as the services provided by the Authority and its licensees are essential for supporting economic and social development in the Kingdom.
- Receiving, processing, and sorting job applications submitted by applicants for vacant positions listed on the Authority's website.
- Using the Transport General Authority's website for your Internet Protocol (IP) address helps diagnose issues occurring on its servers and assists in generating statistics necessary to measure site usage (number of visitors, computer language, and browser type used). No external party outside the technical team is allowed to access your IP address.
- Enhancing user experience by improving and developing the General Transport Authority's website to meet users' needs and services.
- Improving beneficiary services by responding more effectively to customer service requests and support needs.
- Using "Google Analytics" reports for website analysis, which obtains information from IP addresses, displaying data such as country, city, device, pages visited, and session time per page. These reports are used internally for analysis and website development purposes only.
- The Authority may process your personal data for purposes not listed in this policy as stipulated in Paragraph 3 of Article 10 of the Personal Data Protection Law.
Rights of the Personal Data Subject
- Right to be informed: This includes being informed about the legal basis for collecting your personal data and the purpose of its collection.
- Right to access your personal data: You have the right to access your personal data available with us according to the controls and procedures specified by the regulations.
- Right to request your personal data: You may request your personal data available with us in a readable and clear format, according to the controls and procedures specified by the regulations.
- Right to request the correction, completion, or updating of your personal data: You may request that any incomplete or inaccurate data be corrected.
- Right to request the deletion of your personal data: You may request the deletion of your personal data that is no longer needed, without prejudice to what is stipulated in Article 18 of the Law.
According to Clause (b) of Paragraph 1 and Paragraph 2 of Article 9 of the Law, your right to access your personal data as mentioned in Paragraph 2 above may be restricted. This may result in denying your ability to access your personal data.
Protection of Your Personal Data
-
We confirm that appropriate technical and organizational security measures are implemented to protect your personal data in accordance with the Personal Data Protection Law. These measures include, but are not limited to:
- Vulnerability scanning and penetration testing.
- Encryption of data during transmission and storage.
- Regular application of updates and security patches.
- Reviewing security settings and system hardening configurations.
- Applying security standards based on best practices for website and application development.
- Data is collected within a secure technical infrastructure that adheres to the Authority’s approved cybersecurity policies and standards, which are aligned with regulations and guidelines issued by the National Cybersecurity Authority.
- Security procedures are established based on the Authority’s approved cybersecurity policies and standards, in line with regulations issued by the National Cybersecurity Authority, to prevent accidental loss of personal data, unauthorized access, misuse, alteration, or disclosure.
- The Authority implements necessary procedures for managing data sharing, ensuring that personal data will not be publicly available or shared with any third party without prior consent, unless required by relevant laws and regulations.
- The Authority applies necessary access control measures, ensuring that only authorized individuals providing services for the Transport General Authority’s website and relevant government entities contributing to service development and user journey facilitation can access personal data.