شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Insights

PDPL for mid-sized companies: where to start

The scope and core obligations of the PDPL, with a practical checklist a mid-sized company can start on without a dedicated privacy team.

DataSec teamPublished 28 September 20266 min read

Does the law apply to you?

The Personal Data Protection Law (PDPL) is the Saudi law governing how personal data is collected, processed, stored and transferred. It was issued in 2021, amended in 2023, and is in force together with its Implementing Regulations under the supervision of the Saudi Data and Artificial Intelligence Authority (SDAIA). The short answer to the question above is yes. The law sets no minimum company size or headcount. Any processing of personal data about individuals in the Kingdom falls within scope, whether it concerns customers, employees, job applicants or visitors to your website.

The difference between a large company and a mid-sized one is not the set of obligations. It is the resources. So you need a realistic order: what must be ready today, and what can be built gradually.

The core obligations

  • Record of processing activities: a list of every operation in which you collect personal data: what data, why, on what legal basis, who can reach it, where it is stored, how long it is kept and with whom it is shared. This record is the foundation of everything else.
  • Privacy notice: before collecting any data, the individual must be told who you are, why you are collecting it, what their rights are and how to reach you. The Implementing Regulations specify what a privacy policy must contain, so match yours to the current version and publish it in Arabic.
  • Legal basis and consent: consent is the default basis, with specific exceptions defined in the law, such as performing a contract or meeting a legal obligation. Consent must be separate for each purpose, withdrawable and documented. Do not make a service conditional on consent to a purpose the service does not need.
  • Sensitive data: health, credit, biometric, location and belief data, among others. It requires explicit consent and stronger safeguards. A mid-sized company is best served by not collecting it unless necessary.
  • Data subject requests: individuals have the right to know what you hold about them, to obtain a copy, to correct it and to have it destroyed. You need a clear intake channel, a procedure to verify the requester's identity, and a response within the period set by the Implementing Regulations (thirty days at the time of writing, with defined extension cases; refer to the current version).
  • Breach notification: when an incident affects personal data and may cause harm, you must notify SDAIA within 72 hours of becoming aware of it under the Implementing Regulations, and notify the affected individuals where required. The precondition is that you know about the incident at all, which brings us back to monitoring.
  • Transfers outside the Kingdom: transfers are allowed under conditions, including an adequate level of protection in the receiving country as determined by SDAIA, or appropriate safeguards such as standard contractual clauses or binding corporate rules, with a risk assessment in defined cases. Review the current transfer regulation before adopting any cloud service hosted outside the Kingdom.
  • Minimisation and deletion: collect only what you need, delete data when the purpose ends, and retain records for the period the Regulations set.
  • Registration: certain categories of controller must register on SDAIA's national data governance platform. Check whether you fall within them.
  • Data protection officer: appointment is required in cases defined by the law and its regulations, such as processing that involves regular monitoring or sensitive data at scale. Even if you are not obliged, name one accountable person.

A practical checklist

  • Week one: name an owner and list the systems that hold personal data: HR, CRM, the website, email and shared drives.
  • Week two: build the record of processing activities in a simple spreadsheet. Do not wait for a tool.
  • Week three: review the privacy policy and the consent forms on the website, in contracts and in recruitment forms.
  • Week four: open a channel for data subject requests and write the response and verification procedure.
  • Month two: write the breach response plan around the 72-hour window: who decides, who notifies, using which template.
  • Month two: review contracts with suppliers who process data on your behalf and add processing and transfer clauses.
  • Month three: implement periodic deletion, and run an impact assessment for any new product that processes personal data.

Tooling worth the investment

Tools do not create compliance on their own, but they make it repeatable:

  • Data classification: labelling files and messages by sensitivity so systems know what to protect.
  • Data loss prevention (DLP): rules that stop classified data leaving through email, cloud storage or removable media, and log the attempts.
  • Encryption and access control: encryption at rest and in transit, multi-factor authentication and need-to-know permissions.
  • Automated deletion: retention policies enforced by the system rather than by memory.
  • Audit logging: who accessed what and when, which is what any request or incident response depends on.

Where a partner helps

A mid-sized company rarely needs a full-time privacy team, but it does need someone to start it correctly. DataSec helps in three places: a compliance assessment to establish your gap against the law and its regulations, GRC advisory to draft the policies, records and procedures, and our data security service to implement classification, DLP and encryption on your actual systems. The goal is a position you run yourselves, not permanent dependence on an outside party.

Illustrative example: a mid-sized retailer building its processing record discovered it still held job applications from years ago with no purpose. Deleting them reduced its sensitive-data footprint and closed a question that would have surfaced with the first data subject request.

This article is general awareness content, not legal advice. Refer to the current version of the regulations and frameworks mentioned.

All articles
  • Data security

    Data classification, loss prevention and encryption aligned with PDPL.

  • GRC advisory

    Policies, procedures and risk management built on NCA, SAMA and ISO 27001 controls.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.