3.2 Registration requirements 3.2.1 No Person may engage in the exercise of direct or effective control over Datacenters or other critical Cloud System infrastructure hosted in the Kingdom and used, in whole or in part, for the provision of Cloud Services before making a valid and complete registration with the Commission. 3.2.2 The information to be provided for the above registration, the form to be used, and the applicable procedure and time limits shall be determined by decision of the Commission. 3.3 Information security Customer Content Classification 3.3.1 Customer Content can be subject to different levels of information security, depending on the required level of preservation of the Customer Content’s confidentiality, integrity and availability, as defined in the table below and subject to the provisions of Articles ‎3.3.4 to ‎3.3.6, below: Classification of Customer Content by level of required information security Categories of Customer Content Level 1 Non-sensitive Customer Content of individuals or private sector companies, not subject to any sector-specific restrictions on the outsourcing of data. Customer Content qualifying for Level 2 or Level 3 treatment, for which the Cloud Customer elects Level 1 treatment. Sensitive Customer Content of individuals, not subject to any sector-specific restrictions on the outsourcing of data. Level 2 Sensitive Customer Content of private sector companies or organizations, not subject to any sector-specific restrictions on the outsourcing of data. Non-sensitive Customer Content from public authorities. Customer Content qualifying for Level 1 or Level 3 treatment, for which the Cloud Customer elects Level 2 treatment. Level 3 Any Customer Content from private sector-regulated industries subject to a level categorization by virtue of sector-specific rules or a decision by a regulatory authority Sensitive Customer Content from public authorities. Customer Content qualifying for Level 1 or Level 2 treatment, for which the Cloud Customer elects Level 3 treatment Cloud Computing Regulatory Framework Page 5 of 15

Select target paragraph3