Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Saudi PDPL penalties explained

Saudi PDPL Penalties: The 2 Tiers up to SAR 5 Million Explained

Saudi PDPL penalties are fixed in riyals, doubled on repeat and, for one offence, criminal — and none of them is calculated from turnover, which is the first thing a GDPR-trained programme has to unlearn. The Personal Data Protection Law, Royal Decree M/19 as amended by M/148 and enforceable since 14 September 2024, sets two tiers. Article 35 makes the disclosure or publication of sensitive data, with intent to harm the data subject or to achieve a personal benefit, a crime punishable by imprisonment for up to two years, a fine of up to SAR 3 million, or both.

Article 36 makes every other violation of the Law or its Regulations punishable by a warning or a fine of up to SAR 5 million, imposed by a committee formed by SDAIA’s president and appealable to the competent court, with the fine doubled for a repeat violation. Around the two tiers sit the court’s power to confiscate proceeds and order publication of the judgment at the violator’s expense, and Article 40’s right for anyone harmed to claim compensation.

This guide sets out both tiers with the text they rest on, the committee process and the appeal, the aggravating and mitigating considerations, what publication and confiscation add, how the scale compares with the GDPR and the DPDP Act, and the violations most likely to draw a fine in a programme’s first years.

Saudi PDPL penalties: the two tiers
Article 35 — criminal: disclosure or publication of sensitive data with intent to harm or for personal benefit → up to 2 years’ imprisonment and/or up to SAR 3 million · Article 36 — administrative: any other violation → warning or fine up to SAR 5 million, doubled on repeat, imposed by a SDAIA committee, appealable · plus confiscation of proceeds, publication of the judgment, and compensation claims under Article 40.

The two tiers of Saudi PDPL penalties

Provision Conduct Penalty Who imposes it
Article 35 Disclosing or publishing sensitive data in violation of the Law, with the intent to harm the data subject or to achieve a personal benefit Imprisonment for up to two years, a fine of up to SAR 3 million, or both; doubled for a repeat offence The criminal court, on prosecution by the Public Prosecution
Article 36 Any other violation of the Law or the Regulations A warning, or a fine of up to SAR 5 million; the fine may be doubled for a repeat violation A committee formed by decision of SDAIA’s president, with at least three members including a legal specialist; the decision is appealable to the competent court within the period the Law sets
Article 38 (confiscation and publication) Any violation The court may confiscate funds obtained from the violation and order publication of the judgment’s summary at the violator’s expense in one or more local newspapers or other appropriate means, after the judgment becomes final The court
Article 40 (compensation) Material or moral damage caused by a violation Compensation claimed before the competent court The court, on the harmed person’s claim

Sensitive data — the trigger for the criminal tier — is defined in Article 1: data revealing racial or ethnic origin, religious, intellectual or political belief, security or criminal data, biometric data, genetic data, credit data, health data, location data, and data indicating that both or one of the individual’s parents are unknown. Our guide to the Saudi PDPL covers the definitions and the rest of the law.

How Saudi PDPL penalties under Article 36 are decided

  1. Detection. A complaint to SDAIA — data subjects may complain within 90 days of the incident or of the controller’s response — a breach notification, an audit, or SDAIA’s own monitoring through the National Data Governance Platform.
  2. Investigation. Employees designated under Article 37 inspect and detect violations and gather evidence; the controller responds.
  3. The committee. The committee formed under Article 36 considers the violation and the controller’s submissions and decides on a warning or a fine within the SAR 5 million ceiling.
  4. Considerations. The Regulations and SDAIA’s enforcement practice weigh the nature and gravity of the violation, the categories and volume of data, the harm or potential harm to data subjects, the controller’s cooperation and remediation, whether the violation was intentional or negligent, and whether it is a repeat — which doubles the ceiling.
  5. Appeal. The controller may appeal the committee’s decision to the competent court.
  6. Publication and confiscation. Where a court judgment becomes final, it may order publication at the violator’s expense and confiscation of funds obtained from the violation.

Our guide to the Saudi PDPL Implementing Regulations covers the complaint procedure in Article 37 of the Regulation.

Saudi PDPL penalties vs GDPR vs DPDP

Saudi PDPL EU GDPR India DPDP Act
Highest administrative penalty SAR 5 million (≈ US$1.3 million), doubled on repeat to SAR 10 million €20 million or 4% of worldwide annual turnover, whichever is higher ₹250 crore (≈ US$28–30 million) for security safeguard failures
Turnover link None Yes None
Criminal tier Yes — Article 35, up to two years and SAR 3 million for intentional sensitive-data disclosure Left to Member States None in the Act
Repeat multiplier Fine doubled Considered as an aggravating factor Considered as a factor
Who imposes A SDAIA committee; criminal court for Article 35 Supervisory authorities The Data Protection Board
Compensation Article 40 claim before the court Article 82 Not through the Board
Publication Court may order publication of the judgment at the violator’s expense Authorities publish decisions as a matter of practice

The Saudi scale is small by GDPR standards for a large multinational and large for a Saudi SME, and the criminal tier has no European equivalent at the federal level. Our guide to Saudi PDPL vs GDPR covers the wider comparison.

The violations most likely to draw Saudi PDPL penalties

Violation Provision Why it is exposed
Processing without consent or a valid Article 6 basis Law Articles 5–6; IR Articles 11–16 Consent is the default basis and must be per purpose with time and means recorded; legitimate interest is barred for sensitive data
Failure to notify a breach within 72 hours, or at all Law Article 20; IR Article 24 The platform records what was notified and when
Transfer outside the Kingdom without an exemption case, safeguard and risk assessment Law Article 29; Transfer Regulation No adequacy list exists; every transfer needs its documentation
Not registering on the platform when required National Register Rules Public entities, processing-led businesses and sensitive-data controllers must register
Missing or non-compliant privacy policy and collection notice Law Articles 12–13; IR Article 4 SDAIA’s guideline sets ten elements
Rights requests unanswered within 30 days IR Article 3 The clock is fixed; one extension of up to 30 days
No processor agreement with the seven mandatory items Law Article 8; IR Article 17 Contracts are inspected
No records of processing, or destroyed with the data IR Article 33 Kept for the processing period plus five years
Intentional disclosure of sensitive data for gain or harm Article 35 The criminal tier — usually an insider

Our guide to the PDPL compliance checklist puts the twenty items in the order that closes these exposures; Saudi PDPL breach notification covers the one with the shortest clock.

Reducing the exposure to Saudi PDPL penalties

  1. Fix the legal basis first. Consent records per purpose, or an Article 6 case with evidence; the most common violation is the cheapest to prevent.
  2. Register and wire the breach procedure to the platform. The 72-hour notice cannot be met without the registration.
  3. Document every transfer. Exemption case, SDAIA standard contractual clauses or binding common rules or accreditation, and the risk assessment.
  4. Control sensitive data access. Article 35 is an insider offence; access logging and least privilege on health, credit, biometric and location data reduce both the crime and the controller’s Article 36 exposure for the failure of safeguards.
  5. Keep the evidence. The committee weighs cooperation and remediation; records of processing, impact assessments and the breach log are what show them.
  6. Treat a warning as the last cheap signal. A repeat doubles the ceiling.

Frequently asked questions

What are the penalties under the Saudi PDPL?
Two tiers. Article 35: disclosure or publication of sensitive data with intent to harm or for personal benefit is a crime punishable by up to two years’ imprisonment, a fine of up to SAR 3 million, or both. Article 36: any other violation of the Law or its Regulations carries a warning or a fine of up to SAR 5 million, doubled for a repeat, imposed by a committee formed by SDAIA’s president and appealable to the court.

Are Saudi PDPL fines based on turnover?
No. The ceilings are fixed amounts in riyals — SAR 5 million administrative, SAR 3 million criminal — with the administrative fine doubled for repeat violations.

Who imposes the fines?
For Article 36 violations, a committee formed by decision of SDAIA’s president, with at least three members including a legal specialist; decisions are appealable to the competent court. Article 35 offences are prosecuted before the criminal court.

Can individuals claim compensation?
Yes. Article 40 gives anyone who suffers material or moral damage from a violation the right to claim compensation before the competent court, independently of any fine.

Can the fine be published?
The court may order publication of a summary of a final judgment at the violator’s expense, and may confiscate funds obtained from the violation.

Where this leaves you

Read Saudi PDPL penalties as a fixed scale with one criminal edge: SAR 5 million per administrative violation, doubled on repeat, decided by a SDAIA committee and appealable; two years and SAR 3 million for intentional sensitive-data disclosure; confiscation, publication and compensation around both — and reduce the exposure where the violations actually arise: consent and legal basis, the 72-hour breach notice through the platform, documented transfers, sensitive-data access and the records that show cooperation.

References

More on the Saudi PDPL

The gap assessment tool carrying every provision of the Law and the Regulation, the consent procedure and register, the breach procedure wired to the platform, the transfer procedure and the sensitive-data access policy are in the Saudi PDPL Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.