Get privacy insights in your inbox.

Regulation

What is PDPL (Saudi Personal Data Protection Law)?

Share

Saudi Arabia's Personal Data Protection Law, issued under Royal Decree M/19 and enforced by SDAIA, governs the processing of personal data of individuals in the Kingdom, with fines reaching SAR 5 million and criminal liability for sensitive-data disclosure.

Source: IQWorks Glossary โ€” iqworks.ai | Last updated: 2026-08-09

Last verified: August 9, 2026

Saudi PDPL Regulation Guide

Requirements, penalties, individual rights, and enforcement details

The Personal Data Protection Law (PDPL) is Saudi Arabia's comprehensive data protection statute, issued under Royal Decree M/19 in 2021. Its Implementing Regulations and separate Personal Data Transfer Regulations were published on 7 September 2023, one week before the law came into force on 14 September 2023. A one-year grace period ended on 14 September 2024, after which the Saudi Data and Artificial Intelligence Authority (SDAIA) began active enforcement.

The PDPL applies to any processing of the personal data of individuals residing in the Kingdom, including processing carried out from outside Saudi Arabia. It uses Controller and Processor roles familiar from the GDPR, and requires a lawful basis for processing, a privacy notice before collection, and a record of processing activities. Controllers must register with SDAIA's national platform, appoint a Data Protection Officer where the criteria in the Implementing Regulations are met, conduct impact assessments for high-risk processing, and notify SDAIA of personal data breaches.

Cross-border transfer is one of the areas where the PDPL diverges most from other regimes. Transfers are permitted where the destination provides an adequate level of protection, or under specified safeguards, and are subject to a risk assessment where the transfer falls outside the adequacy route. Administrative fines reach SAR 5 million, doubling to SAR 10 million for repeat violations, and disclosure of sensitive personal data with intent to cause harm carries criminal liability including imprisonment of up to two years. Organizations operating in the Kingdom can meet these obligations with ComplyIQ for compliance operations and records of processing, ConsentIQ for consent capture and proof, and DiscoverIQ for locating personal data across the estate.

Explore More Terms

Browse our complete data protection glossary with 111+ terms.

View Full Glossary