Electronic Transactions and Trust Services Law

Article 35 — Article (35) Obligations of Licensees

Chapter Three

The Licensees shall have the following obligations: 1. Notifying TDRA, the Competent Authorities and the concerned person of any violation or breach of the security and integrity of the data, immediately upon becoming aware of such violation or within the period specified by the decisions issued by TDRA. 2. Indicating to the Relying Party the levels of security and trust of the Digital Identity issued under the Electronic Identification System. 3. Ensuring compliance with the technical and security specifications, standards and procedures for the level of security required in the Electronic Identification System as approved by TDRA. 4. Submitting a biennial report issued by the compliance assessment body to TDRA regarding compliance with the terms of the License issued thereto and the decisions issued thereby. 5. Protecting personal data and implementing controls and procedures in accordance with the requirements of the competent authorities and the legislation in force. 6. Taking all necessary measures to manage any risks that may arise to ensure the security and safety of electronic Trust Services and Qualified Trust Services in a way that prevents the occurrence of any security incidents or breaches or minimizes their effects if they occur. 7. Preparing a service termination plan in accordance with the requirements specified by the Executive Regulations of this Decree Law. 8. Any other obligations specified by the Executive Regulations of this Decree Law or other legislation in force in the State.

WAWhatsAppTGTelegram