Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Saudi PDPL — Saudi PDPL: The Complete 2026 Guide to the Personal Data Protection Law

Saudi PDPL: The Complete 2026 Guide to the Personal Data Protection Law

The Saudi PDPL, the Kingdom of Saudi Arabia’s Personal Data Protection Law, has been fully enforceable since 14 September 2024, and the Saudi Data and AI Authority is enforcing it. It was issued by Royal Decree M/19 in September 2021, amended by Royal Decree M/148 in March 2023, and came into force on 14 September 2023 with a one-year compliance period.

Organisations that reach for a GDPR template set find it is wrong in the places that matter most: the legal basis, the clocks, the regulator’s platform, the transfer rules and the penalties. This guide explains what the law is, who it applies to, what it requires, and where it parts company with what most privacy teams already know.

What this guide covers

Saudi PDPL explained
Saudi PDPL: The Complete 2026 Guide to the Personal Data Protection Law

What the Saudi PDPL is, and the instruments around it

The law is short, 43 articles, and delegates most of its detail to an Implementing Regulation of 38 articles issued by SDAIA. Three further instruments carry binding rules: the Regulation on Personal Data Transfer Outside the Kingdom (version 2.0, August 2024), the Rules for Appointing a Personal Data Protection Officer (August 2024), and the Rules Governing the National Register of Controllers, which set out who must register on the National Data Governance Platform.

Around those sit SDAIA’s Standard Contractual Clauses and Binding Common Rules guidelines (September 2024), a Breach Incidents Procedural Guide (October 2024), and guidelines on privacy policies, records of processing, minimum data, destruction and anonymisation, disclosure and transfer risk assessment. All are published in English on SDAIA’s laws and regulations page.

The Competent Authority is SDAIA, without prejudice to the Saudi Central Bank’s powers over the entities it regulates. Health data additionally follows the Ministry of Health, the Saudi Health Council and the Council of Health Insurance; credit data follows the Credit Information Law and the Central Bank.

Instrument Status What it governs
Personal Data Protection Law (M/19, amended M/148) In force 14 September 2023; enforceable 14 September 2024 Rights, consent, collection, disclosure, destruction, security, breach, transfers, penalties
Implementing Regulation In force with the Law The operating detail: 30-day requests, consent conditions, processor contracts, 72-hour breach notice, impact assessments, DPO, records
Transfer Regulation v2.0 August 2024 Adequacy list, exemption cases, safeguards, risk assessment
DPO Rules; National Register Rules 2024 When a DPO is mandatory; who registers on the platform
SCCs, BCR guidelines, breach guide, guidelines 2024 to 2025 The forms SDAIA expects compliance to take

Who the Saudi PDPL applies to

Article 2 applies the law to any processing of personal data that takes place in the Kingdom by any means, and to the processing of personal data of individuals residing in the Kingdom by any party outside it. It reaches the data of deceased persons where they or their family could be identified. Processing for purely personal or family use is outside it, but the Implementing Regulation is strict about the boundary: publishing personal data to the public, or using it for professional, commercial or non-profit purposes, is not personal use.

Public entities are expressly included and there is no small-organisation exemption. A processor that steps outside the controller’s instructions is treated as a controller and is directly accountable.

This is the first and largest difference from the GDPR. Article 5 requires the data subject’s consent for processing, and for any change of purpose, except in the cases the law states. Article 6 lists those cases: processing that serves the data subject’s actual interest where contacting them is impossible or difficult; processing under another law or a prior agreement to which the data subject is party; a public entity’s security or judicial purposes; and the controller’s legitimate interest, provided no sensitive data is processed.

Legitimate interest is a narrow exception, not one of six equal bases, and the Implementing Regulation bars public entities from using it and requires a documented assessment before anyone else does.

Consent itself has conditions. It must be free, for a purpose explained beforehand, given by someone with legal capacity, and documented so that it can be proven later, with the time and the means recorded; a separate consent is needed for each purpose; and consent must be explicit for sensitive data, credit data and decisions made solely by automated processing. Withdrawal must be as easy as giving consent. A service may not be conditioned on consent unless the processing is directly related to it.

Rights, records and the clocks

Article 4 gives five rights: to be informed of the legal basis and purpose, to access, to obtain a copy in a readable and clear format, to correction, and to destruction. Requests are answered within 30 days, extendable once by up to 30 days where the request requires disproportionate effort or the person has made several, with the data subject told in advance and given the reasons. Identity is verified, every request is documented, including oral ones, and channels must include the ones the Regulation names: email, text message, the national address and electronic applications.

Controllers keep records of processing activities with the Regulation’s eight minimum fields, in writing, accurate, and available to SDAIA on request, for the whole processing period and for five years after each activity ends. SDAIA publishes a template for them. Every product or service involving personal data is subject to an impact assessment, and a written assessment is mandatory where sensitive data is processed, where datasets from different sources are linked, where processing is large-scale or involves constant monitoring, new technologies or automated decisions, or where a product is likely to cause serious harm to privacy.

Registration, the DPO and the platform

Controllers that are public entities, whose main activity is personal data processing, or that process sensitive data must register on the National Data Governance Platform, SDAIA’s portal for controllers. Registration produces a certificate valid for up to five years and gives access to the platform’s services, including the breach notification service, an impact assessment tool and a compliance assessment. A DPO is mandatory in three cases: a public entity providing large-scale services, a controller whose core activities involve regular and systematic monitoring of data subjects, and a controller whose core activities are based on sensitive data. The DPO’s details are entered on the platform. Our guide to SDAIA registration covers the process step by step.

Security, breaches and disclosure

Article 19 requires organisational, administrative and technical measures, and the Implementing Regulation ties them to the National Cybersecurity Authority’s controls where the organisation is subject to them, and to recognised standards otherwise. A personal data breach that may harm the data or the data subjects is notified to SDAIA through the platform within 72 hours of awareness, with five specified items, and data subjects are told without undue delay where their data or rights are affected. NCA incident reporting runs alongside, not instead.

Disclosure of personal data to anyone outside the controller and its processors is permitted only in six cases, from consent to a public entity’s documented request, and is barred in nine situations, including threats to security, the privacy of another individual and the identity of a confidential source. Every disclosure is recorded in the records of processing. Copying identity documents is prohibited except where the law or a public authority requires it.

Transfers outside the Kingdom under the Saudi PDPL

Article 29 permits transfer or disclosure outside the Kingdom only for a permitted purpose and on three conditions: no prejudice to national security or vital interests, an adequate level of protection assessed by SDAIA, and the minimum data. The Transfer Regulation requires SDAIA to publish a list of adequate countries and review it every four years. No list had been published at the time of writing.

That means every transfer today runs on one of the Regulation’s exemption cases, each tied to a safeguard: SDAIA’s own Standard Contractual Clauses, binding common rules for a group, or an accreditation certificate from a body SDAIA has licensed, plus a documented risk assessment. Our guide to Saudi standard contractual clauses works through the mechanism.

Marketing, health data and credit data

Advertising or awareness material may not be sent to a person’s own communication channels without prior consent and a clear, free way to stop; where there has been no prior interaction, consent comes first. Marketing processing is allowed only on data collected directly from the data subject, with consent, and never on sensitive data. Health data is limited to the minimum staff and processing needed for the service; credit data needs explicit consent and notification of any disclosure request.

Enforcement: the Saudi PDPL’s penalties

Intentional disclosure or publication of sensitive data, with intent to harm or for personal gain, is a criminal offence: imprisonment of up to two years and a fine of up to SAR 3 million, or both, doubled on repeat. Any other violation of the law or the Regulation carries a warning or a fine of up to SAR 5 million, doubled on repeat, imposed by committees SDAIA’s president forms and appealable to the competent court.

Courts may confiscate proceeds and order publication of the decision at the violator’s expense, and individuals harmed may claim compensation for material or moral damage.

Ten places a GDPR template gets the Saudi PDPL wrong

  • Consent is the default; legitimate interest is an exception barred for sensitive data.
  • Consent is per purpose, recorded with time and means, explicit in three cases.
  • Rights requests: 30 days plus 30, not one month plus two.
  • Records of processing: kept five years after the activity ends.
  • Registration on the National Data Governance Platform is mandatory for public entities, processing-led businesses and any controller holding sensitive data.
  • The DPO is mandatory in three defined cases and is registered on the platform.
  • Breach notification goes to SDAIA through the platform within 72 hours.
  • No adequacy list exists yet; every transfer needs an exemption case, a safeguard and a risk assessment.
  • Penalties are in riyals, fixed, doubled on repeat; sensitive data disclosure is criminal.
  • Security follows the National Cybersecurity Authority’s controls where they apply.

The full comparison is in our guide to Saudi PDPL vs GDPR, and the article-level detail in our summary of the Saudi PDPL implementing regulations.

What a Saudi PDPL programme needs to contain

A policy that names SDAIA and the three instruments; a legal basis register built on consent by default; a consent register that records time and means; a privacy policy on SDAIA’s ten elements; a rights procedure on the 30-day clock; records of processing on SDAIA’s template; an impact assessment procedure; a processor agreement carrying the Regulation’s seven items; a transfer procedure that works without an adequacy list; a breach procedure wired to the platform; and the registers that evidence all of it.

The Saudi PDPL Toolkit ships those as 75 templates, each citing the article it answers, written against the law and every SDAIA instrument as published. The PDPL compliance checklist gives the order of work. For the security layer the Regulation points to, see our guide to NCA ECC cybersecurity compliance.

Frequently asked questions about the Saudi PDPL

Is the Saudi PDPL in force?

Yes. It came into force on 14 September 2023 and the one-year compliance period ended on 14 September 2024. SDAIA has been issuing enforcement decisions since.

Does the Saudi PDPL apply to companies outside Saudi Arabia?

Yes, where they process personal data of individuals residing in the Kingdom by any means. SDAIA has said it will issue separate registration rules for controllers outside the Kingdom.

Is the Saudi PDPL the same as the UAE PDPL?

No. The UAE’s Federal Decree-Law 45 of 2021 shares the acronym and nothing else. The Saudi law has its own regulator, instruments, clocks and penalties. Check which law a source is describing before relying on it.

Where is the official English text?

On SDAIA’s laws and regulations page, which carries the law, the Implementing Regulation, the Transfer Regulation, the DPO and registration rules, the SCCs and BCR guidelines, and the guidelines, all in English.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.