The Saudi PDPL implementing regulations are where the Personal Data Protection Law becomes operational. The law itself is 43 short articles that delegate the detail: how long a controller has to answer a request, what consent must look like, what a processor contract must contain, when a breach must be reported and with what content, when an impact assessment is required, when a data protection officer must be appointed, how long records are kept.
The Implementing Regulation, 38 articles issued by the Saudi Data and AI Authority and in force with the law, answers every one of those questions. This guide maps the articles a controller actually operates, in the order a programme meets them, and notes the 2025 amendment consultation that had not produced a published text at the time of writing.
What this guide covers
- What the Saudi PDPL implementing regulations are
- Articles 1 to 2 of the Saudi PDPL implementing regulations: definitions and scope
- Articles 3 to 10: data subject rights
- Articles 11 to 16: consent and the legal bases
- Article 17 of the Saudi PDPL implementing regulations: processors
- Articles 18 to 22: purpose, minimisation, disclosure, accuracy
- Articles 23 to 25: security, breach and impact assessment
- Articles 26 to 31: health, credit, marketing, research, documents
- Articles 32 to 38 of the Saudi PDPL implementing regulations: DPO, records, register, audit, complaints
- The Saudi PDPL implementing regulations in one table
- Operating the Saudi PDPL implementing regulations
- Frequently asked questions about the Saudi PDPL implementing regulations

What the Saudi PDPL implementing regulations are
Article 42 of the law required SDAIA’s president to issue the Regulation within 720 days of the law’s publication, after coordinating with the communications, foreign affairs, digital government, cybersecurity, health and central-bank authorities. The Regulation took effect with the law on 14 September 2023. A second instrument, the Regulation on Personal Data Transfer Outside the Kingdom, was reissued as version 2.0 in August 2024 and is treated separately in our guide to Saudi standard contractual clauses. Both are published in English on SDAIA’s laws and regulations page.
Between 27 April and 27 May 2025 SDAIA consulted on amendments to the Saudi PDPL implementing regulations, covering registration criteria, privacy policy content and controller obligations. No amended text had been published on SDAIA’s site when this guide was written; the 2023 text remains the one to apply, and a programme should track the outcome.
Articles 1 to 2 of the Saudi PDPL implementing regulations: definitions and scope
Article 1 adds definitions the law leaves open: direct marketing; personal data breach (any incident leading to disclosure, destruction or unauthorised access, intentional or accidental); vital, actual and legitimate interest; pseudonymisation; anonymisation; and explicit consent. Article 2 defines personal and family use and says what is not: publishing personal data to the public, and using it for professional, commercial or non-profit purposes.
Articles 3 to 10: data subject rights
| Article | What it requires |
|---|---|
| 3 | Act on rights requests within 30 days; one extension of up to 30 days for disproportionate effort or multiple requests, notified in advance with reasons; verify identity; document every request including oral ones; refuse repetitive, unfounded or disproportionate requests with reasons; guardians act for those lacking capacity |
| 4 | The right to be informed: identity and contacts, DPO contact, legal basis and purpose, retention period or criteria, rights and mechanisms, withdrawal, mandatory versus optional; within 30 days for indirect collection; extra items for large-scale, monitoring, new-technology and automated-decision controllers; information before further processing |
| 5 and 6 | Access, and a copy in a commonly used electronic format or hard copy where feasible, without disclosing other individuals’ data or prejudicing others’ rights |
| 7 and 8 | Correction with restriction while accuracy is contested; destruction in four cases, reaching backups, with recipients notified |
| 9 | Anonymisation must be irreversible, impact-assessed and kept current; anonymised data is not personal data |
| 10 | Channels for requests: email, text message, the national address, applications, other lawful means |
Articles 11 to 16: consent and the legal bases
Article 11 of the Saudi PDPL implementing regulations is the one GDPR-trained teams most need to read. Consent must be free and not obtained by misleading means; the purposes must be clear, specific and explained before or when consent is requested; the person must have full legal capacity; consent must be documented in a way that allows future verification, recording its time and means; and a separate consent is required for each purpose. Consent must be explicit for sensitive data, credit data, and decisions based solely on automated processing.
Article 12 governs withdrawal: any time, through any available channel, as easy as giving consent, with processing ceased without undue delay and recipients notified. Article 13 governs guardians. Article 14 requires evidence for the “actual interest” exception. Article 15 sets the conditions for collecting from third parties and public sources. Article 16 sets the legitimate-interest conditions: not for public entities, not for sensitive data, a lawful purpose, a balance in the data subject’s favour, reasonable expectations, and a documented assessment before processing, with fraud detection and network security given as examples.
Article 17 of the Saudi PDPL implementing regulations: processors
The processor agreement must include the purpose of processing, the categories of data, the duration, the processor’s commitment to notify the controller of a breach without undue delay, a statement of whether the processor is subject to other countries’ laws and the effect on its compliance, provision that the processor need not seek the data subject’s consent for a disclosure a Saudi law compels but must notify the controller, and identification of sub-processors and other recipients.
The controller issues clear instructions; the processor notifies any violation in writing; the controller assesses the processor periodically, directly or through an independent third party; a processor that breaches the instructions is treated as a controller; and sub-processors require the controller’s prior acceptance after notice, with an agreed objection period.
Articles 18 to 22: purpose, minimisation, disclosure, accuracy
Articles 18 and 19 require data maps that link each data item to a purpose, minimisation, and recording of further-processing purposes. Article 20 governs disclosure: specific purpose, due diligence, minimum data, documented requests from public authorities, protection of other individuals by balancing and pseudonymisation, and recording of every disclosure with date, method and purpose. Article 21 sets the public-interest controls for public entities. Article 22 defines correction, requires suspension of processing where inaccurate data may cause harm, and requires periodic accuracy review. Our guide to the Saudi PDPL sets these in the context of the law’s own articles.
Articles 23 to 25: security, breach and impact assessment
These three articles of the Saudi PDPL implementing regulations carry the clocks. Article 23 requires the measures necessary to secure personal data and, where the controller is subject to the National Cybersecurity Authority’s controls, adoption of those controls; otherwise recognised standards. Article 24 requires notification to SDAIA within 72 hours of becoming aware of a breach that potentially harms the data or the data subjects or conflicts with their rights, with five content items: a description including time, date and circumstances and when the controller became aware; data categories, numbers and types; risks, impact, measures taken and future measures; whether data subjects have been notified; and contact details.
Missing items follow as soon as possible with reasons for the delay. Data subjects are notified without undue delay where the breach may damage their data or conflict with their rights, in simple language, with four content items. Article 25 requires a written impact assessment in four cases (sensitive data; linking datasets from different sources; large-scale processing of those lacking capacity, constant monitoring, new technologies or automated decisions; products likely to cause serious harm), with eight content elements, a copy to processors, and a repeat where harm is indicated.
Articles 26 to 31: health, credit, marketing, research, documents
Article 26 sets six controls for health data, from sector requirements to segregated duties and minimum processing. Article 27 applies the Central Bank’s requirements and the Credit Information Law’s consent and notification rules to credit data. Article 28 requires consent before advertising or awareness material where there has been no prior interaction, a named sender, a free and easy stop mechanism, an immediate halt, and evidence of consent. Article 29 requires Article 11 consent before direct marketing. Article 30 sets the research controls. Article 31 restates the ban on copying official documents except on a public authority’s request or a legal requirement.
Articles 32 to 38 of the Saudi PDPL implementing regulations: DPO, records, register, audit, complaints
Article 32 makes a DPO mandatory in three cases (a public entity providing large-scale services; core activities requiring regular and systematic monitoring; core activities based on sensitive data), allows an executive, employee or contractor, and lists seven tasks; SDAIA’s separate DPO rules add the tests and six more tasks. Article 33 requires records of processing kept throughout processing and for five years after each activity ends, in writing, accurate, produced on request, with eight minimum fields, and provides for SDAIA’s template.
Article 34 provides for the national register of controllers, now operated through the National Data Governance Platform under separate rules; see our guide to SDAIA registration. Articles 35 and 36 provide for licensed accreditation bodies and auditors. Article 37 gives data subjects 90 days to complain to SDAIA. Article 38 brings the Regulation into force with the law.
The Saudi PDPL implementing regulations in one table
| Obligation | Article | The number to remember |
|---|---|---|
| Rights requests | IR 3 | 30 days, plus one extension of up to 30 |
| Indirect collection notice | IR 4(3) | Within 30 days |
| Consent | IR 11 | Per purpose; time and means recorded; explicit in three cases |
| Processor contract | IR 17 | Seven mandatory items |
| Breach to SDAIA | IR 24 | 72 hours from awareness; five content items |
| Impact assessment | IR 25 | Four triggers; eight elements |
| DPO | IR 32 | Three mandatory cases; seven tasks |
| Records of processing | IR 33 | Eight fields; kept five years after the activity ends |
| Complaint to SDAIA | IR 37 | Within 90 days |
Operating the Saudi PDPL implementing regulations
Every article of the Saudi PDPL implementing regulations above corresponds to a procedure, a register or a template. The Saudi PDPL Toolkit ships 75 of them, each citing the article it answers: the rights procedure on Article 3, the consent procedure and register on Articles 11 to 13, the processor agreement on Article 17, the breach procedure and notification form on Article 24, the impact assessment on Article 25, the DPO procedure on Article 32, and the records of processing register on Article 33 and SDAIA’s template.
Its change register tracks the 2025 amendment consultation so the documents can be revised when SDAIA publishes. The PDPL compliance checklist puts the articles in implementation order; Saudi PDPL vs GDPR shows where each differs from the European rule a team may already know.
Frequently asked questions about the Saudi PDPL implementing regulations
Have the Saudi PDPL implementing regulations been amended?
SDAIA consulted on amendments between 27 April and 27 May 2025. At the time of writing no amended text had been published on SDAIA’s site; the 2023 Regulation applies.
Is the Transfer Regulation part of the implementing regulations?
It is a separate regulation, reissued as version 2.0 in August 2024, though SDAIA’s clauses define “Regulations” to include both. Transfers are governed by it and by Article 29 of the law.
Which article of the Saudi PDPL implementing regulations sets the breach deadline?
Article 24: notification to SDAIA within 72 hours of becoming aware, through the National Data Governance Platform, where the breach may harm the data or the data subjects.
Which article sets the request deadline?
Article 3: 30 days, extendable once by up to 30 days with advance notice and reasons.