Regulatory Compliance: What Your Company Must Comply With
This article sets out the areas requiring attention, without procedural detail that ages quickly.
1. Sector licensing: the highest priority
Certain activities may not be conducted without a licence from a competent supervisory authority — financial, insurance, health, and education activities foremost among them. Financial activities in particular fall under the supervision of the central bank or the capital market authority depending on the nature of the activity.
A rule without exception: determine licensing requirements before building the product, not after. A company that builds a financial product and then discovers it requires a licence may face a complete redesign or a forced partnership with a licensed entity.
Some regulators operate sandbox environments permitting innovative models to be tested within a limited scope and defined period — a route worth exploring early for anyone working in financial technology.
2. Personal data protection
If you collect data about individuals — and most digital products do — you are subject to the obligations of the Personal Data Protection Law. The general principles to build the product around:
- Specified purpose: don't collect data without a clear, declared purpose.
- Minimisation: collect only what is necessary.
- A lawful basis for processing, including the data subject's consent where required.
- Transparency: a clear, comprehensible privacy policy, not a copied page.
- Data subject rights: access, correction, and deletion in accordance with the applicable controls.
- Security: technical and organisational measures to protect the data.
- Cross-border transfers: subject to specific controls that merit review before choosing a hosting provider.
- Breach notification in accordance with statutory requirements.
Practical advice: building these principles into the product from the design stage is far cheaper than retrofitting them later.
3. E-commerce and platforms
Online stores and digital platforms are subject to obligations concerning disclosure of merchant identity and contact details, clarity of prices and terms, return and exchange policies, protection of consumer data, and controls on advertising and marketing content.
Also review advertising and digital marketing controls, particularly those concerning disclosure of paid content.
4. Labour obligations
- Compliant, documented employment contracts and a valid establishment file.
- Social insurance contributions paid on time.
- Compliance with the Saudisation requirements applicable to your activity.
- Wage protection requirements and rules on working hours, leave, and end-of-service.
These are among the first items examined in an acquisition, and accumulated violations translate directly into a reduction in deal price.
5. Zakat and tax obligations
- Registration with the Zakat, Tax and Customs Authority.
- VAT once the statutory threshold is reached, and compliance with e-invoicing requirements.
- Filings submitted on time, supported by regular books.
- Attention to withholding on payments to non-residents where applicable.
6. Anti-money laundering and know-your-customer
Stricter obligations apply to financial and analogous activities: verifying customer identity, monitoring transactions, and reporting suspicious activity. If your model involves transferring, holding, or intermediating funds, this area is neither optional nor deferrable.
7. A light compliance system
You don't need a compliance department at early stage — you need four elements:
- An obligations register: every statutory obligation, the authority, the renewal or filing date, and the person responsible.
- A calendar of reminders set sufficiently ahead of deadlines.
- A named compliance owner, even if that's one of the founders.
- A semi-annual review of the register with legal counsel.
Common mistakes
- Conducting a licensed activity before licensing.
- A copied privacy policy that doesn't reflect what the product actually does.
- Collecting more data than necessary "because it might be useful later."
- Choosing hosting without reviewing cross-border transfer controls.
- Deferring labour and tax obligations until they accumulate.
- Assuming small size exempts you from compliance.
Checklist
- Regulator identified and licensing requirements determined
- Privacy policy reflecting actual processing
- Data protection principles built into the product design
- Cross-border data transfer controls reviewed
- E-commerce obligations where applicable
- Employment contracts, insurance, and Saudisation requirements
- Tax registrations, e-invoicing, and filings
- AML obligations where applicable
- Obligations register, named owner, and periodic review
FAQ
When should I start worrying about compliance?
Before launching the product, not after. Some requirements change the product design itself.
Do I need permanent legal counsel?
Not necessarily. Periodic review with counsel specialised in your sector is usually sufficient at early stage.
Which area is most often neglected?
Personal data protection, because its consequences don't appear until an incident occurs or an investment review begins.
Atheer helps companies identify their regulatory requirements and build a compliance system proportionate to their size.
Talk to us
