Get privacy insights in your inbox.

regulation guideintermediate

Complete Guide to Saudi PDPL Compliance

What the Personal Data Protection Law requires of organizations processing personal data in the Kingdom, now that SDAIA is actively enforcing it.

18 min readLast verified August 9, 2026Reviewed by IQWorks Research
Share

Key Takeaways

  • The PDPL applies to the processing of personal data of individuals residing in Saudi Arabia, including processing carried out by entities located outside the Kingdom.
  • The grace period ended on 14 September 2024. SDAIA is in an active enforcement phase, so a compliance gap is now an exposure rather than a future risk.
  • Controllers must register on SDAIA's national platform, maintain records of processing, and appoint a Data Protection Officer where the Implementing Regulations criteria are met.
  • Cross-border transfers outside the adequacy route require a documented transfer risk assessment under the separate Personal Data Transfer Regulations.
  • Administrative fines reach SAR 5 million and double for repeat violations, and disclosing sensitive personal data with intent to cause harm carries criminal liability of up to two years imprisonment.

Scope, Timeline and Enforcement Posture

Who the PDPL Applies To

The Personal Data Protection Law was issued under Royal Decree M/19 in 2021. Its Implementing Regulations and the separate Personal Data Transfer Regulations were published on 7 September 2023, and the law came into force on 14 September 2023 with a one-year grace period that ended on 14 September 2024.

The law reaches any processing of the personal data of individuals residing in the Kingdom. Critically, it applies extraterritorially: an organization with no Saudi establishment is still in scope if it processes the personal data of people in Saudi Arabia. This is the provision that pulls in regional headquarters structures, group service centres and offshore processing arrangements that were previously treated as out of scope.

The roles will be familiar. A Controller determines the purpose and means of processing; a Processor acts on the Controller's behalf. Where a group operates shared services across several Gulf markets, the first task is usually establishing which entity is the Controller for which processing activity, because that determines who registers, who notifies SDAIA of a breach, and who carries the penalty exposure.

Why the Enforcement Phase Changes the Calculation

Until the grace period ended, PDPL readiness was frequently deprioritised on the reasoning that the authority was still building capacity. That reasoning no longer holds. SDAIA has moved into active enforcement, and most violations are reviewed by dedicated committees constituted for the purpose under rules of procedure the authority has published.

SDAIA also holds a power that is easy to underweight when planning around fine ceilings: it can order the suspension of processing activities. For an organization whose core service depends on processing personal data, a suspension is a materially worse outcome than a monetary penalty, and it is not something a compliance budget can absorb after the fact.

The practical implication is sequencing. Registration, records of processing and breach procedures should be treated as the first tranche of work because they are the obligations most visible to the authority and most easily evidenced. Deeper programme work such as retention rationalisation can follow.

Checklist:

  • Confirm whether each group entity is a Controller or Processor for each processing activity
  • Determine whether extraterritorial application pulls any non-Saudi entity into scope
  • Register the in-scope Controllers on SDAIA's national platform
  • Assess whether the DPO appointment criteria in the Implementing Regulations are met
  • Establish a documented breach notification procedure with named owners

Building the Compliance Programme

Processing requires consent or one of the alternative bases the law sets out, including performance of a contract, compliance with a legal obligation, and a legitimate interest that does not involve sensitive personal data. The exclusion of sensitive data from the legitimate interest route is a meaningful constraint and is a common source of error for teams porting a GDPR analysis across without revisiting it.

Where consent is the basis, it must be freely given and specific, and the data subject must be able to withdraw it. That means consent has to be captured as evidence rather than as a checkbox state, because the question the authority asks after the fact is not whether consent was collected but whether the organization can prove what was consented to, when, and on what notice text.

ConsentIQ addresses that directly: it records consent as tamper-evident, verifiable proof rather than a mutable database field, which is the form that stands up when a regulator or a data subject disputes the record months later.

Records, Impact Assessments and Breach Response

Controllers must maintain records of processing activities. In practice the records requirement is the one that exposes how little most organizations know about their own estate, because it cannot be completed accurately without knowing where personal data actually lives. Reconstructing that from interviews and spreadsheets produces a document that is out of date the week it is signed off.

DiscoverIQ solves the underlying problem by scanning the estate directly and identifying where personal data resides, which turns the record of processing from a manual survey into something derived from the systems themselves. ComplyIQ then maintains it as a living artefact, along with impact assessments for high-risk processing and the breach register.

On breaches, controllers must notify SDAIA, and must inform affected data subjects where the breach is likely to cause them harm. Build the notification path before it is needed, including who makes the harm assessment and on what evidence, because that judgment is difficult to make well under time pressure.

Checklist:

  • Map lawful basis per processing activity, checking that sensitive data is not relying on legitimate interest
  • Capture consent as verifiable evidence, not a mutable flag
  • Derive the record of processing from an actual data discovery scan
  • Run impact assessments for large-scale and high-risk processing
  • Define the breach harm assessment and notification path in advance

Cross-Border Transfers

Transfers of personal data outside the Kingdom are governed by the Personal Data Transfer Regulations, which sit alongside the main Implementing Regulations. Transfers are permitted where the destination provides an adequate level of protection, or under appropriate safeguards. Where a transfer falls outside the adequacy route, a documented transfer risk assessment is required.

This matters for almost every multinational, because the cloud services, support functions and analytics platforms that ordinary business runs on will typically involve at least one transfer outside Saudi Arabia. The assessment is not a one-off exercise: it needs to be revisited when a vendor changes its processing locations or sub-processors, which is why keeping the vendor inventory current is part of transfer compliance rather than separate from it.

The practical approach is to enumerate transfers from the record of processing rather than from procurement records, since procurement rarely captures where data physically ends up.

Frequently Asked Questions

Does the Saudi PDPL apply to companies outside Saudi Arabia?

Yes. The law applies to the processing of personal data of individuals residing in the Kingdom regardless of where the processing entity is located, so an organization with no Saudi establishment can still be in scope if it processes the data of people in Saudi Arabia.

What are the penalties under the Saudi PDPL?

Administrative fines reach SAR 5 million and double to SAR 10 million for repeat violations. Disclosing sensitive personal data with intent to cause harm carries criminal liability including imprisonment of up to two years and individual fines of up to SAR 3 million. SDAIA can also order the suspension of processing activities.

Is a Data Protection Officer mandatory under the Saudi PDPL?

Not universally. A DPO must be appointed where the criteria in the Implementing Regulations are met, which include core activities involving regular systematic monitoring or the large-scale processing of sensitive personal data. Organizations should document the assessment even where the conclusion is that no DPO is required.

How does the Saudi PDPL differ from the GDPR?

The structure is similar, but the differences matter operationally: legitimate interest cannot be used for sensitive personal data, controllers must register with SDAIA, and cross-border transfers are governed by a separate set of transfer regulations with their own risk assessment requirement.