Skip contents to text

  • TopicTelecom By Law
  • EditionIssued under the Council of Ministers Resolution No. (592), dated 01/11/1443 AH
  • Published13 June 2021
  • SectorsCommunicationsTechnology

Disclaimer: In the event of any discrepancy between the Arabic and the English versions, the Arabic version shall prevail in determining of this Law.

Issuance of the Act

Royal Decree (M/106)

Telecommunication and Information Technology Act — 1443 AH

In the Name of Allah, the Most Gracious, the Most Merciful

Royal Decree (M/106), Dated 02/11/1443 AH

By the Grace of Allah

We, Salman bin Abdulaziz Al Saud, King of Saudi Arabia

Based on Article (Seventy) of Basic Law of Governance, enacted by virtue of Royal Decree (A/90), dated 28/08/1412 AH;

Article (Twenty) of Law of the Council of Ministers, enacted by virtue of Royal Decree (A/13), dated 03/03/1414 AH;

Article (Eighteen) of Law of the Shura Council, enacted by virtue of Royal Decree (A/91), dated 27/08/1412 AH; and after reviewing Shura Council Resolution No. (85/16), dated 16/05/1443 AH; and

Council of Ministers Resolution No. (592), dated 01/11/1443 AH,

We have decided the following:

First: Approving the Telecommunications and Information Technology Act, in the enclosed form.

Second: Provisions of the Act, referred to in Clause “First” herein, shall not invalidate licenses issued prior to enforcement thereof. Further, any entity providing telecommunication or information technology services, since Act enforcement date, must correct its situation in accordance with its provisions within twelve months as from its enforcement date.

Third: Enforcement of the Act, referred to in Clause “First” herein, and its Bylaws shall not prejudice competencies and duties of the National Cybersecurity Authority.

Fourth: Communications and Information Technology Commission shall follow up on service providers’ exercise of due diligence to ensure protection of cybersecurity and critical infrastructure, in accordance with NCA controls and guidelines. In this context, NCA has the right to:

  1. 1

    Require service providers to conclude mutual agreements to realize the aforementioned objectives, in accordance with National Cybersecurity Authority controls and guidelines.

  2. 2

    Follow up and verify adequacy of cybersecurity level of service providers, in accordance with National Cybersecurity Authority controls and guidelines.

  3. 3

    Charge service providers cost of such follow-up process if found negligent.

  4. 4

    Impose penalties stipulated in Article (Twenty-seventh) of the Act, referred to in Clause “First” herein, on service providers breaching this Clause.

National Cybersecurity Authority Board of Directors may decide to revoke this Clause after coordinating with Communications and Information Technology Commission.

Fifth: His Highness the Deputy Prime Minister, ministers and heads of independent concerned agencies, each within its competence, must enforce this Royal Decree.

Salman bin Abdulaziz Al Saud

Council of Ministers Resolution No. (592)

In the Name of Allah, the Most Gracious, the Most Merciful

Council of Ministers Resolution No. (592), dated 01/11/1443 AH

The Council of Ministers,

Having reviewed the Case received from the Royal Court No. (32021), dated 22/05/1443 AH, which includes the Telegram of H.H the Minister of Communications and Information Technology No. (01/40/5118), dated 18/09/1440 AH, regarding the Draft Telecommunication and Information Technology Act;

Having reviewed the Draft Act referred to above; and Telecommunications Act, enacted by virtue of Royal Decree (M/12), dated 12/03/1422 AH;

Notes No. (1157), dated 11/07/1442 AH, No. (1955), dated 11/11/1442 AH, No. (2273). dated 18/12/1442 AH, No. (359), dated 12/02/1443 AH, No. (2192), dated 24/09/1443 AH, prepared by the Bureau of Experts at the Council of Ministers;

Having reviewed recommendation issued by the Council of Economic and Development Affairs No. (12-46/43/d), dated 11/10/1443 AH;

Having considered the Shura Council Resolution No. (85/16), dated 16/05/1443 AH; and

Recommendation of the General Committee of the Council of Ministers No. (9465), dated 29/10/1443 AH,

Decided the Following:

First: Approving the Telecommunications and Information Technology Act, in the enclosed form.

Second: Provisions of the Act, referred to in Clause “First” herein, shall not invalidate licenses issued prior to enforcement thereof. Further, any entity providing telecommunication or information technology services, since the Act enforcement date, must correct its situation in accordance with its provisions within twelve months from its enforcement date.

Third: Enforcement of the Act, referred to in Clause “First” herein, and its Bylaws shall not prejudice competencies and duties of the National Cybersecurity Authority.

Fourth: Communications and Information Technology Commission shall follow up on service providers’ exercise of due diligence to ensure the protection of cybersecurity and critical infrastructure, in accordance with NCA controls and guidelines. In this context, National Cybersecurity Authority has the right to:

  1. 1

    Require service providers to conclude mutual agreements to realize the aforementioned objectives, in accordance with National Cybersecurity Authority controls and guidelines.

  2. 2

    Follow up and verify adequacy of cybersecurity level of service providers, in accordance with NCA controls and guidelines.

  3. 3

    Charge service providers cost of such follow-up process if found negligent.

  4. 4

    Impose penalties stipulated in Article (Twenty-seventh) of the Act, referred to in Clause “First” herein, on service providers breaching this Clause.

The National Cybersecurity Authority Board of Directors may decide to revoke this Clause after coordinating with Communications and Information Technology Commission.

A Draft Royal Decree has been produced to that effect, in the enclosed form.

Fifth: Fees, referred to in Articles (Fourth) and (Thirty-ninth) of the Act, referred to in Clause “First” herein, shall be determined in agreement with Ministry of Finance and Non-Oil Revenue Development Center, until issuance of (Regulations for the Practice of Public Bodies, Institutions and the Like Imposing Fees against their Services and Works) and application thereof.

Sixth: Amount deducted from fees stipulated in Paragraph (2) of Article (Fourth) of the Act, referred to in Clause “First” herein, shall be deposited in a current account of the Ministry of Finance in the Saudi Central Bank for the benefit of Ministry of Communications and Information Technology.

Seventh: Amount deducted from fees in favor of Ministry of Communications and Information Technology, as stipulated in Paragraph (2) of Article (Fourth) of the Act, referred to in Clause “First” herein, shall be within its budgetary provisions.

Eighth: Ministry of Communications and Information Technology shall carry out disbursement from the account stipulated in Clause “Sixth” herein or from other bank accounts established for such purpose.

Ninth: Ministry of Communications and Information Technology and Ministry of Finance shall establish a mechanism to govern the disbursement of deducted amount, as stipulated in Paragraph (2) of Article (Fourth) of the Act, referred to in Clause “First” herein.

Prime Minister

Chapter One: General Provisions

Chapter Two: Licenses

Chapter Three: Frequency Spectrum

Chapter Four: Interconnection or Access Submitted

Chapter Five: Use of Real Estate

Chapter Six: Competition

Chapter Seven: Maintaining User's Information and Confidential Documents

Chapter Eight: Surveillance and Inspection

Chapter Nine: Violations and Sanctions

Chapter Ten: Closing Provisions

Source: “Telecommunication and Information Technology Act” — issued under Council of Ministers Resolution No. (592), dated 01/11/1443 AH, and approved by Royal Decree No. (M/106), dated 02/11/1443 AH. The text is reproduced from the original file (PDF) with no change to its content.

Download PDF PDF - 0.83 MB