Update Your Address? Fine. But Who Actually Delivers the Card?
Riyad Bank posted a simple reminder today: “Update your national address.”
On the surface, it sounds reasonable. Almost harmless. A bank asking its customers to keep their information current — what could be wrong with that?
But behind that small request lies a deeper question the bank never asks itself in public: Who is responsible for the data once it is updated?
Because an address is not just a line in a database. It is part of a much larger system of identity, trust, and security.

And when that system ends with a courier standing outside your door holding a credit card, the quality of the last mile matters as much as the quality of the first form.
The Real Issue Is Not the Update
Let’s be clear: updating your address is not the problem.
The problem is what happens after the update.
If the bank uses private courier companies like Aramex to deliver sensitive cards, then the customer’s address — the same one the bank is asking them to update — is being handed to a third party.
And here the logical question arises:
Why is Saudi Post (SPL) not the primary delivery channel?
This is not a matter of preference. It is a matter of architecture.
The national address is already linked to an official government system. Saudi Post already delivers official government documents using that same system. It has documented delivery mechanisms, national coverage, and a direct relationship with the state’s identity infrastructure.
So when a bank asks you to update your national address, but then delivers your card through a private courier, a quiet contradiction appears:
You are being asked to trust a government-grade identity system, while your most sensitive financial object is being transported through a different chain entirely.
Data Sensitivity Is Not a Bureaucratic Detail
A national address is not a preference. It is not a delivery note.
It is part of a person’s identity. It sits beside the national ID, the phone number, the digital records. It is data that deserves high protection.
And when it is connected to a credit card — an instrument that can be used across borders, linked to accounts, and targeted by fraud — the stakes become serious.
The security of the card is not only about encryption. It is also about who physically handles it, who calls the recipient, and how the delivery attempt is recorded.
Trust Is Built in the Last Mile
A bank can update its apps. It can refresh its branding. It can publish gentle reminders asking customers to update their data.
But trust is not built in the header of a mobile application.
Trust is built in the final step: when a card reaches the right hands, through the right channel, with the right records.
If the bank asks you to update your address, but cannot explain why a private courier is still the one holding your card, then the message is incomplete.
The question is not whether the customer should update their data.
The question is whether the bank is ready to handle that data with the same seriousness it demands from the customer.
HD.39 / Digital Forensics Record