PDPL mapping and implementation status
A transparent engineering mapping to Saudi PDPL articles, showing working controls and remaining gaps.
Scope of this page
Updated 30 September 2026. This preliminary engineering mapping is not a compliance certificate or legal opinion. Browser-only processing does not complete organisational requirements. Review the mapping and implementing regulations with the responsible institution before adoption.
DPV terms from a W3C Community Group help describe practices. Their presence in the ontology registry does not mean complete DPV consent receipts are exported. The mapping below is a project interpretation, not an officially approved equivalence.
| PDPL articles | DPV | Topic and status | Kamin implementation | Remaining gap |
|---|---|---|---|---|
| 4, 21 | dpv:DataSubject | Rights, access and correction Partial | Profile view, transcript review, local export/restore and browser deletion. | Name a controller and a formal rights channel and response process. |
| 5, 7 | dpv:Consent | Consent and withdrawal Implemented locally | Separate transcript and interest permissions; optional processing does not start automatically. | Assess lawful basis, capacity and institutional consent procedures. |
| 10, 11 | dpv:Purpose | Purpose and minimisation Implemented locally | Student-chosen inputs; snapshots share selected capabilities only; no social-account collection. | Document necessity for each field in any new integration. |
| 12, 13 | dpv:DataController | Notice and identity Partial | Privacy notice, browser-processing explanation, project supervisor and contact route. | An institutional controller’s identity, address and approved notice are not yet designated. |
| 14, 17 | dpv:Processing | Accuracy and updates Partial | Students review evidence before approval; outputs recompute after edits and withdrawal. | No issuer verification; updating recipient copies needs a separate process. |
| 18 | dpv:Processing | Retention and destruction Partial | Temporary session or opt-in local saving; withdrawal and deletion controls. | Device deletion does not erase downloads or sent snapshots; an institutional retention schedule is needed. |
| 19 | dpv:TechnicalOrganisationalMeasure | Safeguards Partial | AES-GCM backups/snapshots, CSP, local read-only queries and disabled analytics. | Ordinary local storage is not an encrypted vault; independent review and organisational measures remain. |
| 20, 22 | dpv:Risk | Incidents and impact assessment Institutional action required | Risk boundaries are documented; student profiles are not collected centrally. | Complete impact assessment, incident response and responsibilities before expansion. |
| 29 | dpv:Processing | International transfers Review required | Text and transcripts are not sent to external models; asset downloads use the hosting provider. | Review provider IP/operational logs, snapshot delivery channels and any external integration. |
| 31 | dpv:DataController | Processing records Partial | Code documents purposes and boundaries. A student’s local activity log is not an institutional compliance register. | Prepare a formal register covering roles, purposes, retention and recipients. |
Limits to understand
Semantic recall processes the interest phrase locally without saving it. Model files are public, and its cache can be deleted from the same screen. A snapshot link includes its key; its holder can read and forward it. Encryption does not authenticate the sender, verify claims or prevent copying.
Hosting and asset delivery may process IP addresses and request metadata under provider policies. “No central account” describes the student profile; it does not mean the hosting provider has no operational data.
Privacy notice · User guide · Questions and rightsReview sources and evidence
Law — SDAIA National Data Governance Platform · DPV 2.0 Community Group Report
Withdrawal, export and encryption tests · Automated verification history