Privacy Policy
Data Controller & Activity
The British International School of Al Khobar (BISAK/the School) looks after the personal data of pupils and their parents or guardians. We do this responsibly and in line with the Personal Data Protection Law (PDPL) of Saudi Arabia. We are the Data Controller for the information that we collect and use.
BISAK is an independent, not-for-profit school that provides international education from early years through to pre-university. Our focus is on helping pupils achieve academically while also supporting their personal growth and wellbeing.
As part of this, we run lessons, extracurricular activities, pastoral care, exams, and wider school events. We work closely with families, staff, and trusted partners to make sure our pupils receive the best possible support and opportunities.
Contact Details
School can be contacted at:
- Phone: (+966) 13 831 7300 Ext: 100
- Website: www.bisak.org
- Full Saudi Postal Address: EAAA3909, As Sadafah, 34215
If you would like more information about how your personal data is used, or if you wish to exercise any of your data protection rights, you may contact our Data Protection Officer:
- Email: DPO@bisak.org
- Telephone: 013 831 7300
The DPO is here to help with questions about how school collects, uses, and protects personal data.
Personal Data to Be Collected
School collects different types of personal data to provide education, support pupil wellbeing, and meet our legal and safeguarding responsibilities. Families are informed about this either before or at the time the data is collected. Some data is mandatory for us to deliver our services, while other information may be optional and collected with consent.
We group this information into two broad categories:
General Personal Data
This includes information we need to run the school and keep in touch with families:
- Contact details (names, Saudi national postal addresses, phone numbers, email addresses)
- Identification documents (passport copies, national IDs, residency permits)
- Academic records (enrolment forms, assessments, grades, progress reports)
- Attendance information
- Behaviour and pastoral records
- Financial and payment information (fee records, billing, bank transfers)
- Account details for accessing school systems and portals
- Images and videos from classes, school events, or extracurricular activities (with consent)
- CCTV footage on school premises for security
Sensitive Personal Data
This includes information that requires extra protection under the Saudi PDPL:
- Health and medical records (allergies, medication, vaccination, special educational needs)
- Information collected for safeguarding and child protection purposes
- Religion, nationality, or other details required for legal or regulatory reasons
- Biometric data if used (for example, ID cards or access systems)
- Any other information that may reveal sensitive details about a pupil or family
Other Data
In addition, school may collect:
- Information from third parties (such as previous schools or regulatory bodies)
- Technical data from the use of our website or online platforms (cookies, login activity, or location data where relevant)
How We Collect and Use Personal Data
School collects personal data in two main ways:
Data collected directly from families and pupils
This is information you provide to us, for example when you fill out application forms, update pupil records, or communicate with the school. This can include paper forms, verbal communication, online enrolment portals, emails, meetings, or telephone calls. This data is open to change based on circumstances within the school.
Data collected indirectly
This is information gathered through our systems and services. Examples include:
- Technical data such as cookies and website analytics when you use our website or online platforms
- Security systems such as CCTV
- Information provided by third parties such as previous schools or regulators where needed
Purpose and legal basis for collection
We only collect and use personal data where it is relevant to our role as a school and where we have a clear legal basis under the Saudi Personal Data Protection Law (PDPL). These include:
- Fulfilling our contract with parents – for example, using pupil and parent details to deliver education, issue reports, manage enrolment, and communicate about school life.
- Protecting health, safety, and welfare – for example, recording medical information to provide appropriate care, safeguarding pupils, or sharing concerns with relevant authorities.
- The school’s legitimate interests – for example responding to enquiries, managing timetables and activities, keeping archives, or engaging debt collection services where fees remain unpaid.
- Consent (in limited cases) – for example, when we ask permission to use photographs or videos for promotional material, publications, or social media. You may withdraw consent at any time.
- Meeting legal obligations – for example, compliance with Ministry of Education requirements, statutory reporting, health and safety duties, or external CCTV required under Saudi law.
Images, videos, and consent
We rely on consent for optional uses of pupil photographs or videos, such as promotional material, school publications, or social media. Parents can choose whether to give this consent for their children, and if consent is not given, we will take steps to avoid the pupil’s inclusion in these materials (for example, adjusting seating or excluding them from filming areas).
For school events and performances, parents and guests should be aware that filming or photography may take place as part of normal school activity. While we can manage consent for pupils, it is not practical to obtain or track consent from all parents and guests who attend. In these situations, BISAK relies on its legitimate interests under the PDPL. It may not be possible to prevent incidental appearances of parents or guests in wide-angle shots or group recordings.
If parents or guests do not wish to be filmed or photographed, they should inform the school in advance or speak to a member of staff on the day of the event. Wherever reasonably possible, staff will guide them to designated seating areas or ensure that steps are taken to minimise their inclusion in recordings or photographs.
Footage and images captured during school events are used for the purposes of documenting school life, celebrating pupil achievements, and promoting the school within our community and, where appropriate, in external publications, on our website, and across official school social media channels. All use will be in line with BISAK’s data protection responsibilities under the PDPL.
Keeping collection to the minimum
In all cases, BISAK limits personal data to the minimum necessary for the stated purpose. We collect information in fair and transparent ways and do our best to keep it relevant, accurate, and appropriate. We also rely on parents and guardians to let us know promptly if their personal details, or any information we hold about them, change so that our records remain up to date.
Personal Data Processing
Personal data is only processed for purposes that are directly linked to education, pupil welfare, and the safe running of the school. Processing means any activity we carry out with information, such as collecting it, storing it, using it, sharing it when necessary, and eventually deleting it.
All processing is done lawfully under the Saudi PDPL, using the appropriate legal basis, and is always limited to the minimum data needed for the task.
Data Sharing and Use of Processors
School may share personal data with third parties only where necessary to fulfil educational or legal requirements, or where we have another lawful basis under the PDPL. Examples include:
- Educational authorities (such as the Ministry of Education, Noor and MADARES platforms).
- A pupil’s previous school for academic or safeguarding information.
- A pupil’s new school, college, or university when leaving school.
- Government bodies where required by law or regulation such as ZAKAT.
- Appropriate authorities in line with our Safeguarding and Child Protection Policy.
In addition, school uses carefully chosen service providers (processors) to deliver services on our behalf, such as IT systems, cloud storage, learning platforms, payment services, and professional advisers. These providers act only on the school’s instructions and are bound by contracts that require them to protect personal data in line with the PDPL.
Where personal data is transferred outside the Kingdom of Saudi Arabia, including through cloud-based services, school ensure compliance with PDPL requirements and applies appropriate safeguards.
Data Storage, Retention and Destruction
Personal data is stored securely, either on school systems or with approved service providers. Some of these providers may be based outside Saudi Arabia, and we ensure that any such transfers meet PDPL requirements.
We keep personal data only for as long as it is needed to provide education and support services, to comply with the law, or to resolve disputes. For example, CCTV footage is stored for 30 days before being overwritten. Once data is no longer required, we securely delete or destroy it so it cannot be accessed or recovered.
Security Measures
School applies appropriate technical, organisational, and administrative measures to protect personal data from unauthorised access, use, or disclosure. This includes access controls, encryption, secure storage, monitoring, and other safeguards suited to the type and sensitivity of the information.
Your Rights
Parents and pupils have rights under the PDPL regarding the personal data we hold. These include the right to:
- Be informed about how personal data is collected, used, and shared.
- Request data from school about themselves or their child.
- Request correction or updating of inaccurate or incomplete data.
- Request deletion of personal data, where permitted by the PDPL and not prevented by legal or safeguarding requirements.
- Withdraw consent for optional uses, such as photographs or videos for promotional purposes, at any time.
- Submit a complaint if they believe their data protection rights are not respected.
Some rights may be subject to exemptions, for example where fulfilling a request would affect the rights of others or conflict with safeguarding or legal duties. Requests will be handled promptly, and parents may be asked to confirm identity before we proceed.
Pupils will also be informed in an age-appropriate way about how their data is used, particularly where it concerns their health, wellbeing, or behaviour.
Complaints and Objections
If you have concerns about how your personal data is handled, or if you believe we have not enabled you to exercise your rights, you can raise a complaint with the school by contacting the Data Protection Officer.
If you are not satisfied with the school’s response, you may also raise a complaint with the Competent Authority, the Saudi Data & AI Authority (SDAIA), via the National Data Governance Platform at dgp.sdaia.gov.sa.
Updates
This Privacy Policy will be reviewed and updated when needed.





