Saudi PDPL penalties are fixed in riyals, doubled on repeat and, for one offence, criminal — and none of them is calculated from turnover, which is the first thing a GDPR-trained programme has to unlearn. The Personal Data Protection Law, Royal Decree M/19 as amended by M/148 and enforceable since 14 September 2024, sets two tiers. Article 35 makes the disclosure or publication of sensitive data, with intent to harm the data subject or to achieve a personal benefit, a crime punishable by imprisonment for up to two years, a fine of up to SAR 3 million, or both.
Article 36 makes every other violation of the Law or its Regulations punishable by a warning or a fine of up to SAR 5 million, imposed by a committee formed by SDAIA’s president and appealable to the competent court, with the fine doubled for a repeat violation. Around the two tiers sit the court’s power to confiscate proceeds and order publication of the judgment at the violator’s expense, and Article 40’s right for anyone harmed to claim compensation.
This guide sets out both tiers with the text they rest on, the committee process and the appeal, the aggravating and mitigating considerations, what publication and confiscation add, how the scale compares with the GDPR and the DPDP Act, and the violations most likely to draw a fine in a programme’s first years.

The two tiers of Saudi PDPL penalties
| Provision | Conduct | Penalty | Who imposes it |
|---|---|---|---|
| Article 35 | Disclosing or publishing sensitive data in violation of the Law, with the intent to harm the data subject or to achieve a personal benefit | Imprisonment for up to two years, a fine of up to SAR 3 million, or both; doubled for a repeat offence | The criminal court, on prosecution by the Public Prosecution |
| Article 36 | Any other violation of the Law or the Regulations | A warning, or a fine of up to SAR 5 million; the fine may be doubled for a repeat violation | A committee formed by decision of SDAIA’s president, with at least three members including a legal specialist; the decision is appealable to the competent court within the period the Law sets |
| Article 38 (confiscation and publication) | Any violation | The court may confiscate funds obtained from the violation and order publication of the judgment’s summary at the violator’s expense in one or more local newspapers or other appropriate means, after the judgment becomes final | The court |
| Article 40 (compensation) | Material or moral damage caused by a violation | Compensation claimed before the competent court | The court, on the harmed person’s claim |
Sensitive data — the trigger for the criminal tier — is defined in Article 1: data revealing racial or ethnic origin, religious, intellectual or political belief, security or criminal data, biometric data, genetic data, credit data, health data, location data, and data indicating that both or one of the individual’s parents are unknown. Our guide to the Saudi PDPL covers the definitions and the rest of the law.
How Saudi PDPL penalties under Article 36 are decided
- Detection. A complaint to SDAIA — data subjects may complain within 90 days of the incident or of the controller’s response — a breach notification, an audit, or SDAIA’s own monitoring through the National Data Governance Platform.
- Investigation. Employees designated under Article 37 inspect and detect violations and gather evidence; the controller responds.
- The committee. The committee formed under Article 36 considers the violation and the controller’s submissions and decides on a warning or a fine within the SAR 5 million ceiling.
- Considerations. The Regulations and SDAIA’s enforcement practice weigh the nature and gravity of the violation, the categories and volume of data, the harm or potential harm to data subjects, the controller’s cooperation and remediation, whether the violation was intentional or negligent, and whether it is a repeat — which doubles the ceiling.
- Appeal. The controller may appeal the committee’s decision to the competent court.
- Publication and confiscation. Where a court judgment becomes final, it may order publication at the violator’s expense and confiscation of funds obtained from the violation.
Our guide to the Saudi PDPL Implementing Regulations covers the complaint procedure in Article 37 of the Regulation.
Saudi PDPL penalties vs GDPR vs DPDP
| Saudi PDPL | EU GDPR | India DPDP Act | |
|---|---|---|---|
| Highest administrative penalty | SAR 5 million (≈ US$1.3 million), doubled on repeat to SAR 10 million | €20 million or 4% of worldwide annual turnover, whichever is higher | ₹250 crore (≈ US$28–30 million) for security safeguard failures |
| Turnover link | None | Yes | None |
| Criminal tier | Yes — Article 35, up to two years and SAR 3 million for intentional sensitive-data disclosure | Left to Member States | None in the Act |
| Repeat multiplier | Fine doubled | Considered as an aggravating factor | Considered as a factor |
| Who imposes | A SDAIA committee; criminal court for Article 35 | Supervisory authorities | The Data Protection Board |
| Compensation | Article 40 claim before the court | Article 82 | Not through the Board |
| Publication | Court may order publication of the judgment at the violator’s expense | Authorities publish decisions as a matter of practice | — |
The Saudi scale is small by GDPR standards for a large multinational and large for a Saudi SME, and the criminal tier has no European equivalent at the federal level. Our guide to Saudi PDPL vs GDPR covers the wider comparison.
The violations most likely to draw Saudi PDPL penalties
| Violation | Provision | Why it is exposed |
|---|---|---|
| Processing without consent or a valid Article 6 basis | Law Articles 5–6; IR Articles 11–16 | Consent is the default basis and must be per purpose with time and means recorded; legitimate interest is barred for sensitive data |
| Failure to notify a breach within 72 hours, or at all | Law Article 20; IR Article 24 | The platform records what was notified and when |
| Transfer outside the Kingdom without an exemption case, safeguard and risk assessment | Law Article 29; Transfer Regulation | No adequacy list exists; every transfer needs its documentation |
| Not registering on the platform when required | National Register Rules | Public entities, processing-led businesses and sensitive-data controllers must register |
| Missing or non-compliant privacy policy and collection notice | Law Articles 12–13; IR Article 4 | SDAIA’s guideline sets ten elements |
| Rights requests unanswered within 30 days | IR Article 3 | The clock is fixed; one extension of up to 30 days |
| No processor agreement with the seven mandatory items | Law Article 8; IR Article 17 | Contracts are inspected |
| No records of processing, or destroyed with the data | IR Article 33 | Kept for the processing period plus five years |
| Intentional disclosure of sensitive data for gain or harm | Article 35 | The criminal tier — usually an insider |
Our guide to the PDPL compliance checklist puts the twenty items in the order that closes these exposures; Saudi PDPL breach notification covers the one with the shortest clock.
Reducing the exposure to Saudi PDPL penalties
- Fix the legal basis first. Consent records per purpose, or an Article 6 case with evidence; the most common violation is the cheapest to prevent.
- Register and wire the breach procedure to the platform. The 72-hour notice cannot be met without the registration.
- Document every transfer. Exemption case, SDAIA standard contractual clauses or binding common rules or accreditation, and the risk assessment.
- Control sensitive data access. Article 35 is an insider offence; access logging and least privilege on health, credit, biometric and location data reduce both the crime and the controller’s Article 36 exposure for the failure of safeguards.
- Keep the evidence. The committee weighs cooperation and remediation; records of processing, impact assessments and the breach log are what show them.
- Treat a warning as the last cheap signal. A repeat doubles the ceiling.
Frequently asked questions
What are the penalties under the Saudi PDPL?
Two tiers. Article 35: disclosure or publication of sensitive data with intent to harm or for personal benefit is a crime punishable by up to two years’ imprisonment, a fine of up to SAR 3 million, or both. Article 36: any other violation of the Law or its Regulations carries a warning or a fine of up to SAR 5 million, doubled for a repeat, imposed by a committee formed by SDAIA’s president and appealable to the court.
Are Saudi PDPL fines based on turnover?
No. The ceilings are fixed amounts in riyals — SAR 5 million administrative, SAR 3 million criminal — with the administrative fine doubled for repeat violations.
Who imposes the fines?
For Article 36 violations, a committee formed by decision of SDAIA’s president, with at least three members including a legal specialist; decisions are appealable to the competent court. Article 35 offences are prosecuted before the criminal court.
Can individuals claim compensation?
Yes. Article 40 gives anyone who suffers material or moral damage from a violation the right to claim compensation before the competent court, independently of any fine.
Can the fine be published?
The court may order publication of a summary of a final judgment at the violator’s expense, and may confiscate funds obtained from the violation.
Where this leaves you
Read Saudi PDPL penalties as a fixed scale with one criminal edge: SAR 5 million per administrative violation, doubled on repeat, decided by a SDAIA committee and appealable; two years and SAR 3 million for intentional sensitive-data disclosure; confiscation, publication and compensation around both — and reduce the exposure where the violations actually arise: consent and legal basis, the 72-hour breach notice through the platform, documented transfers, sensitive-data access and the records that show cooperation.
References
- SDAIA — Personal Data Protection Law and Implementing Regulations (laws and regulations page) — The Law (Articles 1, 34–38, 40) and the Implementing Regulation (Article 37, complaints).
More on the Saudi PDPL
- Saudi PDPL penalties — you are here
- The Saudi PDPL: the complete guide
- Saudi PDPL breach notification
- Saudi PDPL vs GDPR
- The PDPL compliance checklist
- Saudi standard contractual clauses
The gap assessment tool carrying every provision of the Law and the Regulation, the consent procedure and register, the breach procedure wired to the platform, the transfer procedure and the sensitive-data access policy are in the Saudi PDPL Toolkit, or start with the free templates.