Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

PDPL compliance checklist — PDPL Compliance Checklist: 20 Items in Order for Saudi Arabia

PDPL Compliance Checklist: 20 Items in Order for Saudi Arabia

A PDPL compliance checklist for Saudi Arabia has to do more than list the law’s obligations. It has to put them in the order they depend on each other, because a privacy policy written before the records of processing exist describes processing nobody has inventoried, and a transfer risk assessment written before the legal basis is settled assesses a transfer that may not be lawful at all. This checklist follows the Personal Data Protection Law, its Implementing Regulation and SDAIA’s rules as published, in twenty items across three stages, with the article each item rests on and the evidence SDAIA would expect to see.

What this guide covers

PDPL compliance checklist explained
PDPL Compliance Checklist: 20 Items in Order for Saudi Arabia

How to use this PDPL compliance checklist

Work the items in order within each stage; stages can overlap. For each item, the question is not “do we have a policy” but “can we produce the record”. SDAIA has been issuing enforcement decisions since 2025, and the questions it asks are answered with records: consent entries, records of processing, notification submissions. The Saudi PDPL is enforced by the Saudi Data and AI Authority through the National Data Governance Platform, and several items on the list are things you do on that platform rather than in a document.

PDPL compliance checklist stage one: foundations (items 1 to 7)

The first stage puts in place the things everything else depends on: who is responsible, whether SDAIA knows the organisation exists, what processing there is, on what basis, and the two procedures whose clocks start whether or not the organisation is ready for them.

# Item Provision Evidence
1 Confirm scope: processing in the Kingdom, or of residents’ data from outside it; sector regulators (Central Bank, health bodies) identified Law Art 2, 3, 30(1) Scope statement in the data protection policy
2 Appoint a data protection lead; decide whether a DPO is mandatory under the three cases (public entity at large scale; core activities with regular and systematic monitoring; core activities on sensitive data) IR Art 32; DPO Rules Art 5 Decision record with the three tests; appointment letter
3 Register on the National Data Governance Platform if a public entity, if the main activity is processing, or if sensitive data is processed; enter the DPO’s details Law Art 30(4)(c); National Register Rules Art 2, 7 Registration certificate (valid up to five years)
4 Inventory every processing activity into the records of processing on SDAIA’s template, with the eight minimum fields Law Art 31; IR Art 33 The register, kept five years after each activity ends
5 Record a legal basis for every purpose: consent by default, or one of the Article 6 cases with its evidence Law Art 5, 6; IR Art 14, 16 Legal basis register; legitimate interest assessments
6 Stand up the breach procedure: awareness time logged, 72-hour notification to SDAIA through the platform, data subject notice Law Art 20; IR Art 24; Breach Guide Procedure; breach register; notification form
7 Stand up the rights procedure on 30 days plus 30, with the Regulation’s channels and documentation of every request Law Art 4, 21; IR Art 3, 10 Procedure; rights request log

The second stage is where a GDPR-shaped programme needs the most rework. Consent is rebuilt to the Implementing Regulation’s conditions, the privacy policy is rewritten to SDAIA’s own published guideline, processor agreements gain the seven mandatory items, and every transfer outside the Kingdom is placed on a safeguard the Transfer Regulation recognises.

# Item Provision Evidence
8 Rebuild consent: separate per purpose, documented with time and means, explicit for sensitive data, credit data and automated decisions, withdrawal as easy as giving Law Art 5, 7; IR Art 11, 12 Consent register; consent wording versions
9 Publish a privacy policy before collection on SDAIA’s ten elements, with the update record and the complaint route Law Art 12, 13; IR Art 4; Privacy Policy Guideline Dated policy versions; collection notices
10 Put every processor on an agreement carrying the Regulation’s seven items, with sub-processor acceptance and a breach clock Law Art 8; IR Art 17 Signed agreements; processor register
11 Map every transfer outside the Kingdom; with no adequacy list published, place each on an exemption case with SDAIA’s clauses, binding common rules or an accreditation certificate Law Art 29; TR Art 3, 4 Transfer register; executed safeguards
12 Complete a transfer risk assessment for every exempted transfer and for continuous sensitive-data transfers TR Art 7; TRA Guideline Assessments on the four phases
13 Align security to the National Cybersecurity Authority’s controls where applicable, otherwise a recognised standard; encryption, access, logging, backup Law Art 19; IR Art 23 Security policies; NCA determination
14 Adopt a retention schedule and a destruction procedure that reaches backups and notifies recipients Law Art 18; IR Art 8, 9 Schedule; destruction records

Stage three: assessment, marketing, assurance (items 15 to 20)

The third stage of the PDPL compliance checklist closes the remaining obligations and installs the assurance loop that keeps the programme current as SDAIA issues new instruments.

# Item Provision Evidence
15 Screen every product and service; complete a written impact assessment where any of the four triggers applies; share it with processors Law Art 22; IR Art 25 Screenings; assessments; register
16 Apply the disclosure rules: six permitted cases, nine bars, documented requests, every disclosure recorded Law Art 15, 16; IR Art 20 Disclosure forms; records of processing entries
17 Fix marketing: consent before advertising or awareness material, sender named, free and immediate stop; marketing only on directly collected data, never sensitive data Law Art 25, 26; IR Art 28, 29 Marketing consent register; suppression list
18 Stop copying identity documents except where the law or a public authority requires; protect and destroy any copies Law Art 28; IR Art 31 Process inventory; destruction records
19 Train staff and take the Article 41 confidentiality undertaking that survives employment Law Art 41; DPO Rules Art 8 Training records; signed undertakings
20 Audit against every provision; review annually; track SDAIA’s issuances, including the pending amendments to the Implementing Regulation and the adequacy list Law Art 30, 33; IR Art 36 Audit checklist; annual review; change register

The five items on this PDPL compliance checklist that most often fail

Consent records without time and means. A tick in a database with no timestamp, no wording version and no channel is not the documented consent the Regulation requires. Rebuild the capture, not just the form.

The 30-day clock started late. The period runs from receipt anywhere in the organisation, including a shop counter or a social media inbox. Staff who do not recognise a request are the usual cause.

Transfers on EU standard contractual clauses. The Kingdom has its own clauses, in four templates, which may not be edited outside the blank fields. Foreign clauses are not a safeguard under the Transfer Regulation. Our guide to Saudi standard contractual clauses explains the mechanism.

Not registered on the platform. An organisation that processes any health or biometric data about anyone processes sensitive data and must register. The breach notification service is only available to registered controllers, so an unregistered controller cannot meet the 72 hours when the day comes. See SDAIA registration.

Records of processing destroyed with the data. This PDPL compliance checklist item is the one internal audits find most often. The register for an activity is kept for five years after the activity ends, whatever happens to the data itself.

What the PDPL compliance checklist does not cover

Sector rules: the Saudi Central Bank’s requirements for the entities it regulates, the health regulators’ requirements for health data, and the Credit Information Law for credit data. The National Cybersecurity Authority’s controls themselves, which are a separate programme with their own evidence; our guide to NCA ECC compliance covers them. And the retention periods set by labour, tax and commercial law, which the organisation identifies with its lawyers. The Saudi PDPL implementing regulations guide gives the article-level detail behind each item above.

Turning the checklist into a programme

Each item on this PDPL compliance checklist corresponds to a document or register that produces the evidence in the right-hand column.

The Saudi PDPL Toolkit ships all of them as 75 templates: the registration and DPO procedures, the consent procedure and register, the privacy policy on SDAIA’s ten elements, the rights procedure on the 30-day clock, the records of processing register on SDAIA’s template, the Article 17 processor agreement, the transfer procedure written for a world without an adequacy list, the breach procedure wired to the platform, and a gap assessment tool and audit checklist that carry every one of the law’s provisions. For the differences that trip GDPR-trained teams, see Saudi PDPL vs GDPR.

Frequently asked questions about the PDPL compliance checklist

How long does the PDPL compliance checklist take to complete?

The checklist above is built to run in three thirty-day stages for an organisation starting from an inventory. The pacing item is usually consent capture, because it requires changes to systems rather than documents.

Do we need a DPO to comply?

Only in the three mandatory cases. Every controller needs someone responsible for the programme, and SDAIA’s rules expressly allow a voluntary appointment.

Is the PDPL compliance checklist the same for processors?

Processors carry the security, breach notification, confidentiality and sub-processor items directly, and support the controller on rights, impact assessments and transfers. Their own records of processing cover the processing they perform for each controller.

Where do we start if we already have a GDPR programme?

Items 3, 5, 8, 11 and 20: the platform, the legal basis, consent, transfers and the change register are where a GDPR programme is wrong for the Kingdom, not merely incomplete.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.