Abstract
Many corporate organizations use personal information (e.g. customers, citizens, and employees data) to perform their business mandates. However, a very huge amount of the processed information is considered private and many countries have issued laws to regulate how private information is collected, stored, manipulated or disclosed [1][2][3]. We propose the adoption and usage of XACML as a framework to map and specify all privacy provisions found in government regulations in order to enhance compliance. We have chosen health sector regulations in Saudi Arabia as a case study to demonstrate the appropriateness of XACML to map all privacy provisions.