What the PDPL is
The Personal Data Protection Law (PDPL) is the law governing how personal data is collected, processed, disclosed, retained and transferred in the Kingdom. It was issued by Royal Decree No. (M/19) dated 9/2/1443H and amended by Royal Decree No. (M/148) dated 5/9/1444H.
Key dates
- The law came into force on 14 September 2023.
- Royal Decree M/19 gave organisations a one-year grace period to comply, which ended on 14 September 2024; the competent authority could extend it case by case.
- Since the grace period ended, organisations in scope are evaluated periodically through the National Data Governance Platform.
The competent authority
The Saudi Data and AI Authority (SDAIA) is the competent authority. It supervises the application of the law, issues its regulations and rules, and receives breach notifications and complaints.
The legal instruments
- The law itself.
- The Implementing Regulation.
- The Regulation on Personal Data Transfer outside the Kingdom.
- SDAIA rules and guidance, including the rules for appointing a personal data protection officer, the rules for the national register of controllers, and standard contractual clauses for transfers.
All are available on SDAIA's data protection page. SDAIA's supervision is without prejudice to the powers of the Saudi Central Bank, and the grace period never relieved organisations of other personal data rules in sectors such as finance and healthcare.
Who it applies to
Article 2 applies the law to any processing of personal data relating to individuals that takes place in the Kingdom by any means. That includes processing of personal data of individuals residing in the Kingdom by any party outside the Kingdom, and the data of a deceased person where it would identify them or a member of their family. The article sets no minimum size, so if you process personal data of customers, employees, job applicants or website visitors in the Kingdom, the law applies to you.
The exclusion is processing by an individual for purposes that do not go beyond personal or family use, as long as the data is not published or disclosed to others.
Controllers and processors
Most obligations fall on the controller: the public entity, natural person or private legal person that decides the purposes and manner of processing. A processor acts on the controller's behalf under an agreement that, among other things, commits it to notify the controller of a personal data breach without undue delay.
Registration on the national platform
SDAIA's rules for the national register of controllers require the following to register on the National Data Governance Platform:
- Public entities.
- Controllers whose main activity is based on processing personal data.
- Controllers that process sensitive data.
- Individuals who process personal data for purposes beyond personal or family use.
Key obligations
The main obligations every controller carries under the law and its Implementing Regulation:
- Legal basis and consent: consent may be given in any appropriate form, but it must be freely given, documented and separate for each purpose. Explicit consent is required for sensitive data, credit data and decisions based solely on automated processing.
- Notice: tell individuals the legal basis and purpose, who you are, who may receive their data, whether it will leave the Kingdom, and their rights.
- Data subject rights: act on requests for access, correction and destruction within 30 days, extendable by up to 30 more days in defined cases with advance notice of the reasons.
- Records of processing activities: a written, up-to-date record kept throughout processing and for five years after it ends, available to SDAIA on request.
- Impact assessment: required for sensitive data, linking datasets from different sources, large-scale and repetitive processing of data of people lacking legal capacity, constant monitoring, new technologies, automated decisions, and products likely to seriously harm privacy.
- Information security: apply NCA controls if you are obliged to, otherwise recognised cybersecurity standards and best practice.
Data protection officer
A DPO must be appointed where the controller is a public entity providing services that involve processing personal data on a large scale, or where its core activities are based on processing that by its nature requires regular and systematic monitoring of individuals, or on processing sensitive data. The DPO may be an executive, an employee or an external contractor.
Personal data breach notification
A personal data breach is any incident that leads to the disclosure, destruction or unauthorised access to personal data, whether intentional or accidental, and by any automated or manual means.
Notifying SDAIA
Under Article 24 of the Implementing Regulation, the controller must notify SDAIA within 72 hours of becoming aware of an incident if it could harm the personal data or the individuals concerned, or conflict with their rights or interests. The notification includes:
- A description of the breach: its time, date and circumstances, and when the controller became aware of it.
- The data categories, the actual or approximate number of individuals affected and the type of data.
- The risks and their actual or potential impact, the measures taken to limit them and the measures planned to prevent a recurrence.
- Whether the affected individuals have been notified.
- Contact details for the controller or its data protection officer.
If some information cannot be provided within 72 hours, provide it as soon as possible with the reasons for the delay. Keep a copy of every report and document the corrective measures and evidence.
Notifying individuals
Notify affected individuals without undue delay where the breach may damage their data or conflict with their rights or interests, in simple, clear language that describes the breach, the risks, the measures taken and recommendations to help them protect themselves.
These duties sit alongside any reporting required by the NCA or other regulations. And you can only meet a 72-hour deadline for an incident you have detected.
Transfers outside the Kingdom
Article 29 allows personal data to be transferred or disclosed outside the Kingdom for defined purposes: performing an obligation under an agreement to which the Kingdom is a party, serving the Kingdom's interests, performing an obligation to which the individual is a party, or other purposes set in the regulations. The Transfer Regulation adds central processing operations, providing a service or benefit to the individual, and scientific research.
Conditions
- The transfer must not prejudice national security or the Kingdom's vital interests.
- There must be an adequate level of protection outside the Kingdom, at least equivalent to the law, based on SDAIA's assessment. SDAIA publishes a list of countries and international organisations it considers adequate and reviews it every four years or as needed.
- The transfer must be limited to the minimum data needed.
Without adequacy
In the exemption cases the Transfer Regulation defines, such as transfers within a multinational group for central operations, the controller must apply appropriate safeguards: standard contractual clauses, binding common rules, or a certificate of accreditation from a body licensed by SDAIA. Some of these routes are limited to data that is not sensitive.
Risk assessment
A documented risk assessment is required before transfers under the exemption cases, and before continuous or widespread transfers of sensitive data outside the Kingdom. Onward transfers by the recipient remain subject to the law.
Cloud hosting, backups and technical support from abroad can involve a transfer or disclosure, so review them with your legal adviser.
Penalties and enforcement
The law sets two penalty tracks.
Disclosing sensitive data (Article 35)
Anyone who discloses or publishes sensitive data in violation of the law, with the intention of harming the individual or achieving a personal benefit, faces imprisonment of up to two years, a fine of up to SAR 3 million, or both. The Public Prosecution investigates and prosecutes before the competent court, which may double the fine for a repeat offence, up to twice the maximum.
Other violations (Article 36)
Any other violation of the law or its regulations can lead to a warning or a fine of up to SAR 5 million, which may be doubled for a repeat violation, up to twice the maximum. A committee formed by SDAIA's president examines violations, weighing their type, seriousness and impact, and its decisions can be appealed before the competent court.
Further consequences
- The court may order the confiscation of funds obtained through a violation.
- The court or the committee may order a summary of the judgment or decision to be published at the violator's expense.
- Public entities discipline employees who violate the law.
- Anyone harmed by a violation may seek proportionate compensation for material or moral damage before the competent court.
- Staff appointed by SDAIA's president inspect violations, and SDAIA may seize the means or tools used until a decision is made.
These are the maximums the law sets. How they apply to your situation is a question for your legal adviser.
How DataSec helps
DataSec helps you build the law's requirements into how you work, alongside your cybersecurity obligations:
- Compliance assessment: a gap review against the law and its regulations, covering legal bases, consent, records of processing, data subject requests, transfers outside the Kingdom and breach notification.
- GRC advisory: records of processing activities, impact assessments, privacy notices, request-handling procedures and support for the data protection officer.
- Data security: data discovery and classification, loss prevention and encryption where the data actually lives.
- Incident response: preparing and running the response that a 72-hour notification depends on.
- Awareness and training: staff who recognise personal data and report incidents early.
Where to start
- List the systems that hold personal data and build the record of processing activities.
- Check whether you must register on the National Data Governance Platform or appoint a data protection officer.
- Review consents, privacy notices and processor agreements.
- Write a breach procedure around the 72-hour deadline and rehearse it.
- List every transfer outside the Kingdom, including cloud hosting and technical support, and its legal basis.
We do not give legal advice; we work alongside your legal adviser, who handles legal interpretation. If you are a financial institution, see also our guide to the SAMA Cyber Security Framework.
How DataSec helps
Compliance assessment
Gap assessment against ECC, CSCC, SAMA CSF and PDPL with a remediation plan.
GRC advisory
Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.
Data security
Data classification, loss prevention and encryption aligned with PDPL.
Incident response
Contain, investigate and recover from incidents with documented procedures.
Awareness & training
Awareness programmes and phishing simulations with measurable results.
Frequently asked questions
When did the PDPL come into force?
The law came into force on 14 September 2023, and organisations had a one-year grace period to comply, which ended on 14 September 2024. Since then, organisations in scope are evaluated periodically through the National Data Governance Platform.
Who regulates the PDPL?
The Saudi Data and AI Authority (SDAIA) is the competent authority. It issues the regulations and rules, receives breach notifications and complaints, and examines violations through a committee formed by its president.
What are the PDPL penalties?
Disclosing or publishing sensitive data unlawfully with intent to harm or for personal benefit can lead to up to two years' imprisonment, a fine of up to SAR 3 million, or both. Other violations can lead to a warning or a fine of up to SAR 5 million. In both cases the fine can be doubled for a repeat violation, up to twice the maximum.
How fast must a personal data breach be reported?
The controller must notify SDAIA within 72 hours of becoming aware of an incident that could harm the data or the individuals or conflict with their rights or interests. Affected individuals must be notified without undue delay where the breach may damage their data or conflict with their rights or interests.
Do we need to appoint a DPO?
You must appoint one if you are a public entity providing services that involve large-scale processing, or if your core activities require regular and systematic monitoring of individuals or are based on processing sensitive data. SDAIA's examples include insurers processing health data and finance companies processing credit data. The DPO may be an employee or an external contractor.
Can we store personal data outside Saudi Arabia?
Transfers outside the Kingdom are allowed for defined purposes and under conditions: no prejudice to national security or vital interests, an adequate level of protection at the destination, and only the minimum data needed. Without adequacy, the defined exemption cases require safeguards such as standard contractual clauses or binding common rules, with a risk assessment. Review your hosting and support arrangements with your legal adviser.
Does the PDPL apply to companies outside Saudi Arabia?
Yes, where they process personal data of individuals residing in the Kingdom. Article 2 extends the law to that processing by any party outside the Kingdom.
How long do we have to answer a data subject request?
The Implementing Regulation requires you to act on a request within 30 days and without delay. The period can be extended by up to 30 more days where the request requires disproportionate effort or the individual makes multiple requests, provided the individual is told in advance with the reasons.
Official sources
- Personal Data Protection Law (PDF), Saudi Data and AI Authority
- Implementing Regulation of the Personal Data Protection Law (PDF), Saudi Data and AI Authority
- Regulation on Personal Data Transfer outside the Kingdom (PDF), Saudi Data and AI Authority
- Data protection, Saudi Data and AI Authority
This guide is general information, not legal advice, and regulators update their requirements; always refer to the version currently published by the regulator.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

