Privacy Policy

The Personal Data Protection Law (PDPL), in its amended form, is the first of its kind to be enacted in the Kingdom of Saudi Arabia. The Law was issued by Royal Decree on 17 September 2021 and regulates how organizations collect, process, and store personal data relating to individuals residing in the Kingdom of Saudi Arabia.

SHL Finance Company is committed to protecting the privacy of personal data of its customers, website visitors, and all individuals whose personal data is collected or processed by the Company.

This Privacy Notice explains how SHL Finance Company collects, uses, shares, stores, and protects personal data when using the Company’s website or benefiting from its services, in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia, its Implementing Regulations, and the instructions and controls issued by the Saudi Central Bank (SAMA).

This Notice applies to all personal data processed by SHL Finance Company, whether collected directly from data subjects or through electronic channels, systems, or any other means related to the provision of the Company’s services and operational activities.

Contact details

 

 

Department/Specialized TeamSHL finance company-DPO
The Address

RCWA8246,

Building #:8246, Al Wizarat,

Postal Code :12622

Riyadh Saudi Arabia
 

Contact NumberT +966 11 8747900 Ext. 7956
EmailDPO@shlfinance.com

About SHL Finance Company


SHL Finance Company is a licensed finance company operating in the Kingdom of Saudi Arabia and is subject to the supervision of the Saudi Central Bank (SAMA).

The Company provides financing and credit services in accordance with the applicable laws and regulations and serves individuals and legal entities within the Kingdom of Saudi Arabia.

In the course of providing its services, SHL Finance Company collects and processes personal data for purposes that include, without limitation, reviewing financing applications, conducting credit assessments, delivering services to customers, complying with regulatory requirements, managing customer relationships, and carrying out internal operational activities.

 

Categories of Personal Data Collected

 

SHL Finance Company collects and processes various categories of personal data depending on the nature of the relationship with the data subject and the type of service provided. Such data may include, without limitation, the following:

  • Account Data: such as username, password, and login credentials.

  • Identification Data: such as full name, national identification number, date of birth, nationality, and copies of official documents.

  • Contact Data: such as phone number, email address, and residential address.

  • Employment and Financial Data: such as employer name, job title, income information, bank account details, and payment information.

  • Credit Data: including credit reports, credit history, credit scores, and related information obtained from credit bureaus and authorized entities, as a core part of the Company’s services related to financing application assessment, creditworthiness evaluation, risk management, and compliance with regulatory requirements.

  • Technical Data: such as Internet Protocol (IP) address, website usage data, device information, and cookies.

  •  Communication and Correspondence Data: such as call recordings, correspondence, and inquiries through customer service channels.

  • Status Data: such as marital status, where applicable.

  • Any other personal data provided directly by the data subject or collected in a lawful Manner.

  • Sensitive Personal Data In limited cases, and where required in accordance with applicable laws and regulations, SHL Finance Company may process certain categories of sensitive personal data, such as health data or biometric data, solely for specific and lawful purposes. In such cases, additional safeguards and protection measures are applied in accordance with the requirements of the Personal Data Protection Law (PDPL).

 

How Personal Data Is Collected?

 

SHL Finance Company collects personal data through both direct and indirect methods, including the following:

  • Direct Methods:
    • Registration and use of the Company’s website, applications, or digital services.
    • Communication through customer service or sales channels.
    • Completion of electronic or paper-based forms.
    • Surveys, where applicable.

  • Indirect Methods:
    • Personal data obtained from official or regulatory authorities for verification or update purposes.
    • Cookies and similar tracking technologies.

 

Purposes of Personal Data Processing

 

SHL Finance Company processes personal data for legitimate and specific purposes, including:

• Reviewing and processing financing applications.
• Conducting credit assessments and determining creditworthiness.
• Providing financing services and managing contractual relationships.
• Complying with applicable legal, regulatory, and supervisory requirements.
• Managing customer communications, inquiries, and complaints.
• Improving services and enhancing customer experience.
• Preventing fraud and managing risks and information security.
• Carrying out internal operational, administrative, and audit activities.

 

Legal Basis for Personal Data Processing

 

SHL Finance Company relies on one or more of the following legal bases when processing personal data:

• Compliance with legal or regulatory obligations.
• Performance of a contract or taking steps prior to entering into a contract.
• Legitimate interests, provided that such interests do not conflict with the rights of the data subject.
• Consent, where required under applicable laws and regulations.

 

Disclosure and Sharing of Personal Data

 

SHL Finance Company may disclose personal data only when necessary, to the extent required, and for legitimate and specific purposes, depending on the nature of the recipient, as follows:

Service Providers and Data Processors:
Personal data may be disclosed to service providers and data processors for processing on behalf of the Company in order to enable service delivery, operate technical systems, and support operational activities, in accordance with the Company’s instructions and pursuant to contractual agreements that ensure their obligation to protect the data and refrain from using it for any other purposes.

Regulatory or Government Authorities:
Personal data may be disclosed to comply with legal, regulatory, and supervisory requirements, including competent supervisory authorities such as the Saudi Central Bank (SAMA).

Credit Bureaus and Authorized Entities:
Personal data may be disclosed for the purposes of conducting credit assessments, verifying creditworthiness, and managing risks, in accordance with applicable laws and regulations.

Professional Parties (such as auditors and legal advisors):
Personal data may be disclosed, where necessary, for legal, audit, or regulatory purposes, and within a limited scope consistent with the required purpose.

Personal data shall not be disclosed to any party except to the extent necessary to achieve the specified purpose and in accordance with appropriate contractual, regulatory, and technical frameworks that ensure data confidentiality, protection, and compliance with the Personal Data Protection Law and its related regulations and instructions.

 

Consent and Withdrawal Mechanism

 

Where required, SHL Finance Company obtains the data subject’s consent prior to processing personal data.

Withdrawal of Consent
The data subject has the right to withdraw their consent to the processing of their personal data, in whole or in part, at any time, through one of the following channels:

• Submitting a request through the Data Subject Rights Request Form available on SHL Finance Company’s website.
• Contacting the Data Protection Officer (DPO) via the email address provided in this Privacy Notice.
• Using the unsubscribe mechanism included in marketing communications, where the processing is for marketing purposes.

Upon receipt of a consent withdrawal request, the Company will cease processing personal data for the purpose for which consent was withdrawn without undue delay, without affecting the lawfulness of any processing carried out prior to the withdrawal or any processing based on another lawful basis.

Withdrawal of Consent for Marketing Purposes
Where the processing of personal data for marketing purposes is based on the data subject’s consent, the data subject may withdraw such consent at any time, and the Company will cease sending any future marketing materials or communications upon implementation of the request

 

Data Subject Rights

 

The data subject enjoys the following rights:

Right to be Informed: This includes informing the data subject of the lawful or legitimate basis for collecting their personal data, the purpose of such collection, and confirming that the data will not be subsequently processed in a manner inconsistent with the purpose for which it was collected, except in the cases stipulated under Article (10) of the Personal Data Protection Law.

Right of Access: This includes the right to access personal data, review it, and obtain a copy in a clear and readable format consistent with the contents of the records, free of charge, in accordance with the provisions of the Implementing Regulations, without prejudice to any fees stipulated under the Credit Information Law, and without prejudice to the provisions of Article (9) of the Personal Data Protection Law.

Right to Rectification or Update: The right to request the correction, completion, or updating of personal data held by the Company.

Right to Erasure: The right to request the deletion or destruction of personal data held by the Company when it is no longer necessary, in accordance with Article (18) of the Personal Data Protection Law. It should be noted that some or all of these rights may be subject to certain exceptions or exemptions as determined by the Law and will be assessed on a case-by-case basis, as appropriate.

Right to Withdraw Consent.
Right to Object, in cases permitted by applicable laws and regulations.
Right to Submit a Complaint.
Right to Claim Compensation: Without prejudice to the imposition of penalties stipulated under the Law, any person who has suffered harm as a result of a violation of the provisions of the Personal Data Protection Law or its Implementing Regulations has the right to bring a claim before the competent court to seek compensation for material or moral damages in proportion to the extent of the harm suffered.

 

Exercising Data Subject Rights and Submitting Complaints

 

The data subject has the right to submit a complaint or object to the processing of their personal data in cases permitted by law, including situations where the data subject is unable to exercise their rights within the specified timeframe or wishes to object to the processing of their personal data, through one of the following channels:

• Submitting a request through the complaints or objections form available on SHL Finance Company’s website.
• Contacting the Data Protection Officer (DPO) via the email address provided in this Privacy Notice.

Complaints and Objections Handling Procedures

Upon receipt of a complaint or objection, the Company shall review and verify the request in coordination with the relevant departments and take the appropriate action in accordance with the provisions of the Personal Data Protection Law and its Implementing Regulations.

Timeframe for Handling Complaints and Objections

SHL Finance Company is committed to processing complaints and objections and responding thereto within a period not exceeding 30 business days from the date of receipt. Where this is not feasible, the data subject will be notified of the reason for the delay and the expected timeframe for response.

 

Automated Processing

 

Certain Company services may involve the use of automated means to analyze personal data for operational or regulatory purposes. Such processing is carried out in accordance with applicable laws and regulations and without prejudice to the rights of data subjects.

 

Personal Data Protection Measures

 

SHL Finance Company is committed to protecting personal data by implementing appropriate technical and organizational measures, which may include, without limitation:

• Restricting and controlling access to systems and networks.
• Raising awareness and providing training to employees on personal data protection.
• Applying appropriate technical security measures, such as encryption.
• Providing a secure physical environment for paper-based personal data records.
• Securely deleting or destroying personal data upon the fulfillment of the purpose for which it was collected, in accordance with Article (18) of the Personal Data Protection Law.

 

Cross-Border Transfer of Personal Data

 

In accordance with applicable laws and regulations, personal data is stored and processed securely within the geographical boundaries of the Kingdom of Saudi Arabia, in order to preserve the Kingdom’s digital data sovereignty.

Personal data shall not be transferred outside the Kingdom of Saudi Arabia except in exceptional cases permitted under the Personal Data Protection Law and its Implementing Regulations, in compliance with the provisions of Article (29) of the Personal Data Protection Law, and after fulfilling all applicable legal requirements.

 

Data Retention and Disposal

 

SHL Finance Company retains personal data for the period necessary to achieve the purposes for which it was collected or as required under applicable laws and regulations. Upon completion of such purposes, personal data is securely deleted, destroyed, or anonymized, as appropriate.

Cookies

Cookies are subject to a separate Cookies Policy, which can be accessed through the designated link available on the Company’s website. Click here 

 

Competent Authority (Saudi Central Bank – SAMA)

 

In the event that a data subject is not satisfied with the handling of their request or complaint, they have the right to escalate the matter to the Saudi Central Bank (SAMA) through its official channels, including:

Free Number: 800 125 6666
Saudi Central Bank (SAMA) website: https://www.sama.gov.sa

 

Changes to the Privacy Notice

 

This Privacy Notice was last updated in February 2026. We reserve the right to make changes to this Privacy Notice at any time and for any reason. Any changes or amendments shall become effective immediately upon publication of the updated Privacy Notice on the website, and you waive the right to receive a specific notice for each such change or amendment.

Do You Have a Question or Complaint Regarding the Privacy Notice?

For any inquiries, requests, or complaints related to the protection of personal data, you may contact the Data Management Office at SHL Finance Company through the contact form available on the SHL’s website.

 

Privacy Policy Form