Executive Regulation of the Personal Data Protection Law
Executive Regulation of the Personal Data Protection Law — Article 39
Chapter Eight · Cross-border Transfers
The Controller must assess the foreign recipient's protection and transfer risks, including: nature, volume and sensitivity of data; purpose, scope and recipients; Processing duration and whether restricted, one-off, repeated or regular; transfer stages, transit states and final destination; and effects and risks for the Data Subject.
Interpretation and application must be checked against the official Arabic text and the current version.