Managing employee health insurance enrolment, claims processing, and medical benefit records.

Data Details
Data Subjects
EmployeesEmployee Dependants
Data Volume
500 - 2,000 records (including dependants)
Data Categories
National IDMedical HistoryInsurance Policy NumberClaims DataFamily Members Data
Processing Type
Sharing
Automated Decision-Making
No
Legal Basis
Legal Basis
Legal Obligation
Consent Mechanism
Mandatory (Legal Obligation) - employees informed via policy
Purpose
Providing and administering mandatory health insurance coverage as required by Saudi law.
Legal Basis Detail
Cooperative Health Insurance Law, Council of Health Insurance requirements.
Recipients & Transfers
Internal Recipients
HR Benefits TeamFinance
External Recipients
Bupa Arabia (Insurer) (SA)Council of Health Insurance (SA)
Retention & Security
Retention Period
Duration of employment + 5 years
Retention Justification
Security Measures
✓ Health Data Encryption✓ Need-to-Know Access✓ Confidentiality Agreements✓ Secure File Transfer
PDPL Compliance Assessment
Update →
D1 Data Subject Rights & Consent
78%
Partial

Most requirements for Data Subject Rights & Consent are addressed. Some gaps identified in documentation or process.

D2 Processing Principles & Lawful Basis
82%
Compliant

All requirements for Processing Principles & Lawful Basis are met. Documentation is complete and up to date.

D3 Data Protection & Security
88%
Compliant

All requirements for Data Protection & Security are met. Documentation is complete and up to date.

D4 Organizational Requirements & Governance
80%
Compliant

All requirements for Organizational Requirements & Governance are met. Documentation is complete and up to date.

D5 Cross-Border Data Transfer
95%
Compliant

All requirements for Cross-Border Data Transfer are met. Documentation is complete and up to date.

D6 Compliance & Accountability
75%
Partial

Most requirements for Compliance & Accountability are addressed. Some gaps identified in documentation or process.

Associated Risks
1
High Health data inadequately protected - sensitive category… Open
Edit Activity Add Risk