SDAIA registration is the obligation most likely to be missing from a Saudi data protection programme built on a foreign template, because no other major privacy law has it. Under the Personal Data Protection Law and the Rules Governing the National Register of Controllers, many controllers must register on the National Data Governance Platform, SDAIA’s portal for the controllers it supervises, appoint a representative, enter their data protection officer’s details, and hold a registration certificate that runs for up to five years.
The platform is also where breaches are notified, so a controller that is not registered cannot meet the 72-hour clock when the day comes. This guide explains who must register, how, what the certificate is, and what the platform does.
What this guide covers
- Where SDAIA registration comes from
- Who must complete SDAIA registration
- The representative
- The DPO determination and the DPO’s details
- The SDAIA registration certificate
- Ongoing obligations after SDAIA registration
- What the platform does after SDAIA registration
- Common mistakes in SDAIA registration
- Building SDAIA registration into the programme
- Frequently asked questions about SDAIA registration

Where SDAIA registration comes from
Article 30(4)(c) of the law lets the Competent Authority specify tools and mechanisms for monitoring controllers’ compliance, including a national register of controllers. Article 34 of the Implementing Regulation provides for registration rules. SDAIA issued the Rules Governing the National Register of Controllers Within the Kingdom under those provisions, and has said that separate rules will follow for controllers located outside the Kingdom. The rules, the law and the Regulation are all published in English on SDAIA’s laws and regulations page; the platform itself is at dgp.sdaia.gov.sa.
Who must complete SDAIA registration
Article 2 of the rules sets four conditions. A controller must register on the platform if it is a public entity; if its main activity is based on personal data processing; if it processes sensitive data; or, for an individual, if they process personal data for purposes exceeding personal or family use. Any one condition is enough.
The third condition catches more organisations than it appears to. Sensitive data under the law includes health data, biometric and genetic data used to identify a person, data on criminal convictions, and data revealing religious, intellectual or political belief or racial or ethnic origin. An employer that holds sick notes, a building that uses fingerprint access, a school that records a pupil’s religion for timetabling, all process sensitive data. The second condition catches any business whose service is the processing: marketing agencies, data analytics firms, recruitment platforms, credit information providers.
| Condition | Typical organisations |
|---|---|
| Public entity | Ministries, authorities, public institutions and their affiliates |
| Main activity is personal data processing | Marketing and analytics firms, recruitment and HR platforms, credit bureaux, customer data platforms, health information services |
| Processes sensitive data | Healthcare providers and insurers, employers holding health data, organisations using biometric access, schools, financial institutions holding criminal-record checks |
| Individual processing beyond personal use | Sole practitioners, freelancers and individual traders holding client data |
The representative
SDAIA registration is done by a representative: a natural person the controller designates to complete the process and maintain the account. A private entity appoints the representative through the platform via its authorised person; a public entity appoints through the registration form SDAIA sends; an individual is their own representative and may not delegate. The representative’s official email and contact number are entered with the entity’s logo, official email, contact number and headquarters.
The DPO determination and the DPO’s details
At registration the representative must determine whether the controller is required to appoint a personal data protection officer, applying the three cases in Article 32 of the Implementing Regulation and SDAIA’s DPO rules: a public entity providing services involving large-scale processing; a controller whose core activities require regular and systematic monitoring of data subjects; and a controller whose core activities are based on sensitive data.
Where a DPO is appointed, the representative enters their details: for an employee or a contractor in the Kingdom, the national ID or residency number, date of birth for verification, and official contacts; for a contractor outside the Kingdom, name, official email and number. The representative may be the DPO. The Chief Data Officer’s details are entered where the organisation has one.
SDAIA’s DPO rules also require the DPO’s contact details to be provided to the authority through the platform immediately on appointment and updated on change, so a DPO appointment made after registration is itself a platform task.
The SDAIA registration certificate
The certificate issues as soon as registration is complete, and it is the artefact that proves SDAIA registration to anyone who asks. It carries a serial number, the entity’s or individual’s name, the logo, the address, the official email and number, the issue and end dates, and a QR code. It is valid for at most five years. SDAIA notifies the controller at least 30 days before expiry; after expiry, access to the platform’s services continues for a grace period of up to five days, and thereafter depends on a renewal request. The certificate is public: anyone may verify a controller’s registration against the national register without any requirement, which SDAIA describes as a trust measure.
The practical consequences of SDAIA registration: diarise the end date well ahead of the 30-day notice; treat the five-day grace period as no grace at all for breach purposes; and expect customers and partners to check the certificate.
Ongoing obligations after SDAIA registration
The representative must keep the entity’s data current, enter and update the DPO’s and Chief Data Officer’s details, view the results of the compliance assessment the platform provides, and use the platform’s services where no DPO has been appointed. Replacing the representative is done through the platform form for private entities and through SDAIA’s official channel for public entities. The DPO, if appointed, is obliged to use the platform services.
What the platform does after SDAIA registration
The platform is not a filing cabinet. Article 12 of the rules lists four services, and two of them are things a controller will need under time pressure.
| Service | What it is for |
|---|---|
| Personal data breach notification | Notifying SDAIA of a breach within 72 hours of awareness where it may harm the data or the data subjects, as Article 24 of the Implementing Regulation requires. Registration is a precondition. |
| Privacy impact assessment tool | A tool that works through the scope, purposes, legal basis and risks of processing for a product or service, supporting the Article 25 assessment |
| Legal support | Guidance for public entities on the law and its instruments |
| Compliance assessment | Periodic self-evaluation against the law’s requirements, with results the representative reviews and acts on |
The breach service is the reason registration cannot wait for a convenient quarter. A controller that discovers a breach on a Thursday and is not registered has no route to SDAIA within the 72 hours. Our guide to the Saudi PDPL covers the breach duty; the PDPL compliance checklist places registration at item three for that reason.
Common mistakes in SDAIA registration
The registration itself takes an afternoon. The mistakes are in the decisions around it.
- Deciding the organisation does not process sensitive data without checking HR, security and insurance processing.
- Registering without deciding the DPO question, or entering a DPO who does not meet SDAIA’s requirements (qualifications, risk and breach knowledge, regulatory knowledge, integrity).
- Letting the certificate lapse. Five years is long enough for the representative to have left; the calendar entry needs an owner role, not a person.
- Treating registration as compliance. The certificate says SDAIA knows you exist; the compliance assessment on the platform is the tool that says how you are doing.
- Assuming a foreign controller is outside it. The law applies to processing of residents’ data from abroad, and SDAIA has announced separate registration rules for controllers outside the Kingdom.
Building SDAIA registration into the programme
A registration procedure that tests the four conditions and records the answer; a DPO procedure that applies the three cases with SDAIA’s tests for large scale, regular and systematic monitoring, and core activities; a compliance calendar with the certificate’s end date at twelve, three and one months out; and a breach procedure that assumes the platform is already available. The Saudi PDPL Toolkit ships all four, with the platform’s services mapped to the documents that feed them. For how the platform obligation compares with the rest of the world’s privacy laws, see Saudi PDPL vs GDPR; for the article-level rules behind the DPO cases, the Saudi PDPL implementing regulations guide.
Frequently asked questions about SDAIA registration
Is SDAIA registration mandatory for every company?
No. It is mandatory for public entities, controllers whose main activity is personal data processing, and controllers that process sensitive data, and for individuals processing beyond personal use. Other controllers are not required to register, though a controller holding health or biometric data through HR or security processing meets the sensitive-data condition.
How long is the certificate valid?
Up to five years, with a 30-day expiry notice from SDAIA and a five-day grace period for platform access after expiry.
Can a processor complete SDAIA registration?
The rules address controllers. A processor that is also a controller for its own processing, for example of its employees’ data, registers in that capacity where a condition applies.
Is there a fee?
Article 30(4)(d) of the law allows the Competent Authority to collect a fee for the personal data protection services it provides. Check the platform for the current position.