Saudi Arabia's Personal Data Protection Law, issued under Royal Decree M/19 and enforced by SDAIA, governs the processing of personal data of individuals in the Kingdom, with fines reaching SAR 5 million and criminal liability for sensitive-data disclosure.
Source: IQWorks Glossary โ iqworks.ai | Last updated: 2026-08-09
Last verified: August 9, 2026
Saudi PDPL Regulation Guide
Requirements, penalties, individual rights, and enforcement details
The Personal Data Protection Law (PDPL) is Saudi Arabia's comprehensive data protection statute, issued under Royal Decree M/19 in 2021. Its Implementing Regulations and separate Personal Data Transfer Regulations were published on 7 September 2023, one week before the law came into force on 14 September 2023. A one-year grace period ended on 14 September 2024, after which the Saudi Data and Artificial Intelligence Authority (SDAIA) began active enforcement.
The PDPL applies to any processing of the personal data of individuals residing in the Kingdom, including processing carried out from outside Saudi Arabia. It uses Controller and Processor roles familiar from the GDPR, and requires a lawful basis for processing, a privacy notice before collection, and a record of processing activities. Controllers must register with SDAIA's national platform, appoint a Data Protection Officer where the criteria in the Implementing Regulations are met, conduct impact assessments for high-risk processing, and notify SDAIA of personal data breaches.
Cross-border transfer is one of the areas where the PDPL diverges most from other regimes. Transfers are permitted where the destination provides an adequate level of protection, or under specified safeguards, and are subject to a risk assessment where the transfer falls outside the adequacy route. Administrative fines reach SAR 5 million, doubling to SAR 10 million for repeat violations, and disclosure of sensitive personal data with intent to cause harm carries criminal liability including imprisonment of up to two years. Organizations operating in the Kingdom can meet these obligations with ComplyIQ for compliance operations and records of processing, ConsentIQ for consent capture and proof, and DiscoverIQ for locating personal data across the estate.
How IQWorks Helps
Related Terms
UAE PDPL (Federal Decree-Law No. 45 of 2021)
The UAE's federal personal data protection law, in force since January 2022, establishes controller and processor obligations across the Emirates, though its executive regulations remain incomplete, leaving several operational details unresolved.
DIFC Data Protection Law (DIFC Law No. 5 of 2020)
The Dubai International Financial Centre's own GDPR-aligned data protection law, enforced by the DIFC Commissioner of Data Protection, substantially amended in July 2025 to add a private right of action.
Cross-Border Data Transfer
Cross-border data transfer refers to the movement of personal data from one country or jurisdiction to another, which is regulated by data protection laws that impose specific requirements to ensure adequate protection.
Consent Management
Consent management is the systematic process of obtaining, recording, tracking, and managing individuals' consent for the collection and processing of their personal data in compliance with privacy regulations.
Data Breach Notification
Data breach notification is the legal requirement for organizations to inform supervisory authorities and affected individuals when a security incident results in unauthorized access to, or loss of, personal data.