Technical Accountability = Legal Accountability means regulators no longer separate “Tech” from “Legal.” Under the PDPL’s Executive Regulations, you must demonstrate compliance.
Therefore, the issue related to the breaches that occurred at ElAraby may require us to conduct an investigation to determine whether the entity has applied the technical and industrial standards set out in the guidelines.
Bear in mind that ElAraby operates, in some respects, as a Controller. This means data subjects may bring a direct claim against it before the courts under primary liability if they can prove the entity failed to implement the following technical safeguards:
1. Security by Design: Encryption, pseudonymization, and least-privilege access.
2. Records of Processing: ROPA and DPIAs for high-risk/sensitive data.
3. Breach Notification: Within 72 hours to the NDMO, and without undue delay to data subjects where there is a high risk.
4. Vendor Management: You remain liable for the acts and omissions of your sub-processors.
Conclusion: As a product/service provider, ElAraby cannot rely on “the tech failed” or “it was the cloud vendor’s fault.” The PDPL holds it legally accountable for technical safeguards, data quality, and compliance governance over personal data, and especially sensitive data.
ElAraby is in a critical position, and I believe future discussions and case law will provide further detail on this type of infringement.)




