Back to Blog
Data Protection

Customer Data, Security, and Compliance at the Kingdom's Biggest Event

Origami TeamEditorial Team
6 min read
Customer Data, Security, and Compliance at the Kingdom's Biggest Event

Customer Data, Security, and Compliance at the Kingdom's Biggest Event

In part four we built smart customer service capable of handling millions of questions. Every one of those questions leaves a trace: a name, a mobile number, a booking, a payment, a language, a location. When the 2034 season ends you will not just have sold more — you will hold the most valuable database in your business's history, and simultaneously the most dangerous. This final part of the series covers the side many overlook while preparing for the opportunity: how to collect that data lawfully, protect it from breaches, and turn it into an asset that remains after the last fan has left.

Why your data responsibility rises in 2034

The difference between an ordinary day and tournament season is not the type of data but its volume, its sensitivity, and the attention it attracts. Three factors converge at once:

  • Volume: you may register more customers in a few weeks than you collected in years, and every record is a new legal obligation.
  • Sensitivity: hotel bookings mean IDs and passports, sales mean payment data, apps mean location. These are categories that leave no room for carelessness.
  • Targeting: major events attract attackers because pressure is high, teams are stretched, and new systems are untested. A breach at peak season costs double what it costs on a quiet day.

Add a dimension most business owners rarely face: the majority of these visitors come from outside the Kingdom, and their data may move between systems and providers in different countries. That alone turns data from a technical detail into a management decision that deserves your attention before the season, not after.

The Personal Data Protection Law in practice

Saudi Arabia has a clear Personal Data Protection Law, issued by Royal Decree M/19, amended in 2023, with implementing regulations in force, and full compliance required after the grace period ended on 14 September 2024. It is supervised by the Saudi Data and AI Authority (SDAIA). Beyond the legal language, what it means in practice for a business preparing for 2034 comes down to six obligations:

  • Specified purpose: collect data for a stated purpose, and do not repurpose it later without a lawful basis.
  • Data minimization: do not request a field you do not genuinely need. Every extra field is extra liability with no return.
  • Clear consent: marketing consent must be separate and explicit — no pre-ticked boxes and no condition buried inside the booking flow.
  • Data subject rights: customers can access, correct, and request deletion of their data, and you need a working process to honour that, not a promise on a privacy page.
  • Breach notification: when a leak occurs there is an obligation to notify as the regulator specifies — which assumes you have someone who detects the leak and knows what to do.
  • Cross-border transfer: moving data to a provider or server outside the Kingdom is governed by controls, so know where your data is hosted before you sign with any vendor.

Non-compliance is not a formality: the law provides penalties reaching a fine of up to five million riyals, which may be doubled for repeat violations, with harsher penalties for disclosing sensitive data with intent to harm. The good news is that compliance for a mid-sized business is not a massive project: a real privacy policy, a register of what you collect and where it is stored, a consent and deletion mechanism, and properly drafted contracts with your providers. A few weeks of work now is far cheaper than a crisis mid-season.

Cybersecurity at peak season

Compliance tells you what to do with data; cybersecurity stops others from taking it. And most breaches that hit mid-sized businesses do not come from sophisticated attacks but from neglected basics. Focus on what delivers the greatest impact:

  • Two-factor authentication on every admin account, dashboard, and payment system, and revoke access for anyone who no longer needs it.
  • Encryption in transit and at rest, and no storing card data yourself as long as your payment provider handles it.
  • Least privilege: a front-desk employee does not need to export the entire customer database, and broad access should be a documented exception.
  • Tested backups: a backup you have never restored is not a backup, it is an assumption. Test a restore before the season.
  • Patching and monitoring: known vulnerabilities in old systems are the first door in, and access logs nobody reads mean discovering the breach far too late.
  • Vendor risk: your systems connect to providers and middleware, and a breach at one of them is a breach of yours. Ask about their security commitments before you integrate.

More important than all of it: a written, rehearsed incident response plan. Who calls whom, how you isolate the affected system, what you tell your customers, and when you notify the regulator. The difference between an incident handled calmly and a crisis that dominates the conversation is usually that single page existing before it is needed. For businesses that want a clear reference framework, the Essential Cybersecurity Controls published by the National Cybersecurity Authority work well as a practical checklist.

From liability to asset

Talking about protection and compliance sounds defensive, but the offensive side is the real win. After the tournament ends visitors return home, and what remains is what you collected lawfully: a customer base with explicit consent, a purchase history that tells you what people actually wanted, and peak patterns that show you how to plan future seasons. That is the difference between a business that benefited from the season for a few weeks and one that built a base to serve it for years.

Start with three things: segment customers by behaviour rather than your impression of them, use the data to refine what you sell, when you open, and how much stock you prepare, and keep only what you need for a predefined period — reducing your liability while improving the quality of what you hold. We covered this in practical detail in fan data and PDPL compliance, a natural extension of what we discuss here.

The Origami view

At Origami we are a technology company that builds protection and compliance into the system rather than bolting them on at the last minute: forms that collect the minimum, marketing consent captured separately and logged, permissions scoped per role, encryption and tested backups, and logs that show who accessed what and when. We help you establish where your data is hosted and what your providers actually commit to, and build a dashboard that turns what you collected into operational decisions. As in every part of this series, the benefit does not start in 2034: a system that respects your customers' data today is a system ready for any scale tomorrow.

Conclusion

Data is what remains after the stadium lights go out. Those who collect it lawfully and protect it seriously leave the season with a commercial asset; those who cut corners may leave with a fine and a trust crisis that costs more than they earned. And with that we close Road to the 2034 World Cup: we began with why starting early matters, then the readiness of your website and app for the surge, then booking, payment, and operations systems, then smart customer service, and today protecting what you have gathered. The single thread across all five parts is that everything preparing you for the season serves your business from the first month — and the time remaining is shorter than it looks.

Sources

  • FIFA — announcement of Saudi Arabia hosting the 2034 World Cup (11 December 2024): https://www.fifa.com
  • Saudi Data and AI Authority (SDAIA) — Personal Data Protection Law and its implementing regulations: https://sdaia.gov.sa
  • National Cybersecurity Authority — Essential Cybersecurity Controls: https://nca.gov.sa
  • Saudi Vision 2030 — digital transformation and the tourism sector: https://www.vision2030.gov.sa
#Make the Most of Tech#World Cup 2034#Data Protection#Cybersecurity

Frequently Asked Questions

What do I legally need before collecting data from 2034 visitors?+

Collect for a stated purpose with the minimum number of fields, keep marketing consent separate from completing a booking, maintain a working process for customers to access, correct, and delete their data, and know where your data is stored and who can reach it. A real privacy policy and a register of what you collect are the starting point.

How large are the penalties for violating the Personal Data Protection Law?+

The law provides penalties reaching a fine of up to five million riyals, which may be doubled for repeat violations, with harsher penalties for disclosing sensitive data with intent to harm. Details and updates are published by SDAIA as the supervising authority.

Can I store customer data on servers outside the Kingdom?+

Transferring personal data outside the Kingdom is governed by controls rather than banned outright, but it requires a lawful basis and consideration of the protection level at the receiving party. In practice: know the hosting location of every system you use and ask your provider before signing, not after.

What are the fastest-impact cybersecurity steps before the season?+

Enable two-factor authentication on every admin account, revoke access for anyone who no longer needs it, turn on encryption in transit and at rest, actually test restoring a backup, patch legacy systems, and write a one-page incident response plan defining who calls whom when something happens.

Rate this article

Related Articles

Weekly newsletter

The latest articles that matter to business owners, once a week. Just your email.

Looking for a software solution for your business?

At Origami we build custom systems, websites, and stores tailored to how your business works. Get in touch and we'll show you how we can help.

One session. Twenty minutes. No commitments.