
Saudi Arabia’s PDPL is now fully enforceable and backed by detailed implementing regulations and transfer rules. It applies inside and outside the Kingdom (when processing data of individuals residing in the Kingdom), introduces breach-notification within 72 hours, requires registration of many controllers, mandates DPOs in defined cases, and sets structured gateways for cross-border data transfers. Penalties include administrative fines up to SAR 5 million and criminal sanctions for certain sensitive-data offences.
Successful compliance demands mapping processing, updating notices, setting up rights workflows, registering properly, and building a cross-border-transfer playbook.
The PDPL was issued by Royal Decree M/19 (2021) and amended by M/148 (2023). It took effect 14 September 2023 with a 12-month grace period ending 14 September 2024.
The competent authority is the Saudi Data & AI Authority (SDAIA), which administers the framework (including the National Data Governance Platform (NDGP) for registrations).
Territorial scope. The law applies to:
Thus, non-Saudi controllers who process data of Saudi residents are in scope.
Roles. The PDPL distinguishes between Controller and Processor:
Principles & transparency. While the PDPL text and guidance do not replicate the full GDPR principle list, controllers should operate on familiar bases: fairness, purpose limitation, minimisation, security, storage limitation, accountability.
Lawful bases. Entities must rely on one of the following for processing:
Individuals’ rights under PDPL include:
Controllers should maintain procedures: verification of identity, timely responses, documentation of decisions.
Controllers must register on the NDGP if they fall under the trigger categories (e.g., processing sensitive data, main activity is personal-data processing).
As part of registration, a representative (often a local entity or authorised person) must be appointed. For foreign controllers, representation obligations are evolving, so plan for a Saudi-based representative or authorised local agent.
Registration gives controllers access to services such as breach-notification submission, compliance-self-assessment tools, breach-reporting interface.
Yes — in specified cases defined by SDAIA’s “Rules for Appointing a Personal Data Protection Officer”. Typical triggers: large-scale processing, core business activity includes regular monitoring, core processing of sensitive data, or public entity.
Even where not mandatory, appointing a DPO is best practice and may help demonstrate accountability in audits.
Controllers must notify SDAIA of a “reportable incident” within 72 hours of becoming aware — the notification must include description of nature of breach, likely consequences, measures taken.
Controllers must also notify data subjects without undue delay if the breach is likely to result in high risk to individuals’ rights or freedoms.
Processors must notify their controller without undue delay; controllers should ensure contract terms reflect that duty.
Transfers/disclosures of personal data outside Saudi Arabia require compliance with the Regulation on Personal Data Transfer Outside the Kingdom (the “Transfer Regulation”). Key points:
Marketing & cookies: While the PDPL doesn’t have a standalone cookie law, controllers must seek prior consent for direct electronic marketing (especially when sensitive data is involved), provide opt-out mechanisms and align with related e-commerce/telecom regulation.
| Feature | GDPR | Saudi PDPL |
|---|---|---|
| Legal bases | Six (consent, contract, legal obligation, vital interests, public interest, legitimate interests) | Five (consent, contract, legal obligation, vital interests, legitimate interests) — but legitimate interests not allowed for sensitive data processing. |
| Cross-border transfers | Adequacy, SCCs, BCRs; adequacy list published for many countries | Adequacy list not yet published; controller must use safeguards (SCCs/BCRs) and run mandatory Transfer Risk Assessment (TRA) in many cases. |
| Criminal liability | Some member states have criminal sanctions; GDPR itself relies mainly on administrative fines | PDPL explicitly includes criminal sanctions for certain sensitive-data offences (up to 2 years’ imprisonment + SAR 3 million). |
| Registration requirement | Generally, only in certain EU Member States or by supervisory authority | Mandatory registration for many controllers under NDGP (for those processing sensitive data or whose core business is processing). |
| Representative / local presence | One-stop-shop mechanism for EU controllers outside EU; representative required in some non-EAA transfers | Appointment of local Saudi representative required for registration of controller; foreign-controller representation obligations still evolving. |
Controllers registered under NDGP must appoint a representative for the registration process. For foreign controllers processing data of Saudi residents, while the law does not yet publish detailed extra duties beyond registration, best practice is to assume a Saudi-based authorized representative or local agent. DNS-style obligations are still evolving.
For organisations operating in or processing data of Saudi residents, PDPL compliance is no longer optional — it is a strategic priority. Starting with a solid foundation (mapping, notices, rights processes), then layering registration, DPO, breach and transfer workflows, and maintaining robust evidence will position your organisation to meet SDAIA expectations and mitigate risk of enforcement.
Sources