Skip to content
KaminClarity for your next step.

PDPL mapping and implementation status

A transparent engineering mapping to Saudi PDPL articles, showing working controls and remaining gaps.

Scope of this page

Updated 30 September 2026. This preliminary engineering mapping is not a compliance certificate or legal opinion. Browser-only processing does not complete organisational requirements. Review the mapping and implementing regulations with the responsible institution before adoption.

DPV terms from a W3C Community Group help describe practices. Their presence in the ontology registry does not mean complete DPV consent receipts are exported. The mapping below is a project interpretation, not an officially approved equivalence.

PDPL articlesDPVTopic and statusKamin implementationRemaining gap
4, 21dpv:DataSubjectRights, access and correction
Partial
Profile view, transcript review, local export/restore and browser deletion.Name a controller and a formal rights channel and response process.
5, 7dpv:ConsentConsent and withdrawal
Implemented locally
Separate transcript and interest permissions; optional processing does not start automatically.Assess lawful basis, capacity and institutional consent procedures.
10, 11dpv:PurposePurpose and minimisation
Implemented locally
Student-chosen inputs; snapshots share selected capabilities only; no social-account collection.Document necessity for each field in any new integration.
12, 13dpv:DataControllerNotice and identity
Partial
Privacy notice, browser-processing explanation, project supervisor and contact route.An institutional controller’s identity, address and approved notice are not yet designated.
14, 17dpv:ProcessingAccuracy and updates
Partial
Students review evidence before approval; outputs recompute after edits and withdrawal.No issuer verification; updating recipient copies needs a separate process.
18dpv:ProcessingRetention and destruction
Partial
Temporary session or opt-in local saving; withdrawal and deletion controls.Device deletion does not erase downloads or sent snapshots; an institutional retention schedule is needed.
19dpv:TechnicalOrganisationalMeasureSafeguards
Partial
AES-GCM backups/snapshots, CSP, local read-only queries and disabled analytics.Ordinary local storage is not an encrypted vault; independent review and organisational measures remain.
20, 22dpv:RiskIncidents and impact assessment
Institutional action required
Risk boundaries are documented; student profiles are not collected centrally.Complete impact assessment, incident response and responsibilities before expansion.
29dpv:ProcessingInternational transfers
Review required
Text and transcripts are not sent to external models; asset downloads use the hosting provider.Review provider IP/operational logs, snapshot delivery channels and any external integration.
31dpv:DataControllerProcessing records
Partial
Code documents purposes and boundaries. A student’s local activity log is not an institutional compliance register.Prepare a formal register covering roles, purposes, retention and recipients.

Limits to understand

Semantic recall processes the interest phrase locally without saving it. Model files are public, and its cache can be deleted from the same screen. A snapshot link includes its key; its holder can read and forward it. Encryption does not authenticate the sender, verify claims or prevent copying.

Hosting and asset delivery may process IP addresses and request metadata under provider policies. “No central account” describes the student profile; it does not mean the hosting provider has no operational data.

Privacy notice · User guide · Questions and rights

Review sources and evidence

Law — SDAIA National Data Governance Platform · DPV 2.0 Community Group Report

Withdrawal, export and encryption tests · Automated verification history