Article (15)
Obligations of the Licensee
The Licensee shall satisfy the following requirements:
1. Details and documents submitted by the Licensee to the TDRA must be up-to-date
and accurate throughout the License period.
2. Acting in a fair and impartial way in respect of all its activities, transactions and service
offer and marketing, without causing monopoly or an impact on the sector
competitiveness or Subscribers, including the Licensee’s obligation not to publish
incorrect or inaccurate information or preclude the mechanisms of executing the
Decree-Law, the present Resolution, resolutions issued by the TDRA in pursuance of
the Decree-Law and the present Resolution and the requirements of the Competent
Authorities.
3. Assuming the liability for damage deliberately or negligently afflicting any Person due
to the Licensee’s failure to fulfil the obligations prescribed under the Decree-Law and
this Resolution and the resolutions issued by the TDRA in implementation of both of
which and the requirements of the Competent Authorities.
4. Informing Subscribers of Trust Services or Qualified Trust Services provided by the
Licensee of any restrictions on the use of such services before such services are
provided to Subscribers, and that the Licensee will not assume any liability for damage
caused by using such services should such restrictions be bypassed.
5. Adopting adequate policies relied on the assessment of risks threatening the services
provided by the Licensee, along with taking adequate necessary technical and
organizational measures for the management of legal, administrative, security and
operational risks and other direct and indirect risks, without being prejudicial to
security and reliability levels and to the extent of being adequate to the degree of
severity. In particular, due diligence and necessary measures shall be taken for:
a. Procedures of registration and verification of Subscribers and activation of
services to them;
-- 10 of 30 --
Cabinet Resolution on the Executive Regulations of Federal Decree-Law on Electronic Transactions and Trust Services 11
b. Procedural and sanction controls;
c. Management and implementation of services;
d. Preventing and minimizing the impact of security incidents and informing the
Competent Authorities, as the case may be, Subscribers and qualified entities
of the negative impacts of any of such incidents if occurred; and
e. Ensuring the protection of cybersecurity of information systems of the
Licensee, as per the approved cybersecurity policies.
6. Taking all necessary technical and organizational measures to comply with the federal
laws and regulations governing the protection of data or personal data, so as to ensure
the protection and preservation of the Subscriber's personal data and prevent any
accessibility to and disclosure of such data without obtaining the Subscriber’s consent
and within the limits necessary to provide the service to the same.
7. Promptly notifying the TDRA and the Subscribers in the following cases:
a. Exposure of the Licensee’s information systems to any risk affecting the
integrity and safety of the services provided;
b. Exposure of information or documents of the Subscribers to unauthorized
disclosure; or
c. Hacking the security of retained personal or non-personal information or data
or lacking the validity and integrity thereof, in a manner affecting the services
provided.
8. Informing the Subscribers and the Relying Parties in a clear and accessible way before
starting to provide Trust Services or Qualified Trust Services of all terms and
conditions related to the use of such services, including any restrictions on such use,
obligations and responsibilities to be assumed by the Subscribers and the Relying
Parties when using such services, as well as seeking the consent of the Subscribers and
the Relying Parties before starting to provide the services to them.
9. Notifying the party relying on Trust Services or Qualified Trust Services of levels of
security and trust of the used Digital Identity as part of the service provision.
-- 11 of 30 --
Cabinet Resolution on the Executive Regulations of Federal Decree-Law on Electronic Transactions and Trust Services 12
10. Ensuring the compliance with the requirements, standards and controls of the security
and trust level technology defined in the Electronic Identification System approved by
the TDRA.
11. Preparing a constantly-updated Termination Plan to ensure a continuous service,
pursuant to the Decree-Law, the present Resolution and the resolutions issued by the
TDRA in pursuance to the Decree-Law and the present Resolution, and the
requirements of the Competent Authorities. The Termination Plan shall show the
following:
a. Means for notifying the Subscribers upon the termination or discontinuation
of services;
b. Mechanism for ensuring the safety and reliability of the Subscribers’ records;
c. Methods for the Subscribers affected by the termination or discontinuation of
services to access to their records; and
d. Methods to ensure unaffected transactions and records made and created by
the Subscribers throughout the period of providing Trust Services by the
Licensee.
12. Recording and maintaining information related to data issued and received by the
Licensee, particularly data used to provide proofs for any legal proceedings or to
ensure the continuity of service for a period not less than (15) fifteen years from the
date of creating the master register, other than identification proofs used to issue the
authentication certificate, which shall be recorded and maintained for a period not
less than (10) ten years from the certificate expiry date, along with giving access to
such information.
13. Developing adequate mechanisms to receive and handle complaints, as per the
requirements identified by the TDRA.
14. Drawing up the service policy document and the practice statement, as per the
standards and controls issued by the TDRA.
-- 12 of 30 --
Cabinet Resolution on the Executive Regulations of Federal Decree-Law on Electronic Transactions and Trust Services 13
15. Fulfilling the standards and requirements issued by the TDRA when identifying
service procedures, as listed in the service policy document and the practice statement
document.
16. Publishing the service policy and the practice statement, as amended, to the public in
Arabic and English, in an electronic format accessible 24/7.
17. Publishing the service policy disclosure document provided, which briefly shows key
points of the policy of providing the service to the Subscribers and the Relying Parties.