Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Saudi PDPL consent requirements infographic

Saudi PDPL Consent Requirements: The Essential 2026 Guide to Lawful Processing

Saudi PDPL consent requirements determine when an organization can process personal data because the individual agreed, and what that agreement must look like. The Personal Data Protection Law, supervised by the Saudi Data and Artificial Intelligence Authority (SDAIA), became enforceable after a transition period that ended on 14 September 2024.

Consent is one of several legal bases. The law and its implementing regulations also allow processing on other grounds in defined cases, so the first question is whether consent is the right basis at all. Where consent is needed, it has to be documented, specific and capable of being withdrawn.

This guide explains the rules as summarized in published legal commentary, shows how to handle sensitive data and outlines a practical process. It is general information, not legal advice, so check the text of the law, the regulations and SDAIA’s guidance.

Free gap assessment

Could you demonstrate GDPR compliance today?

Score yourself against what a supervisory authority actually asks for, free — the records, not the policy.

Run the free GDPR gap assessment →  or  View premium report sample

Under the regulations, as summarized by law firms, consent may be given in writing, verbally or by electronic means, but it must be documented so that it can be verified later. For sensitive personal data and credit data, consent must be explicit. If a person withdraws consent, the controller must stop processing without undue delay.

The details are in the law and its implementing regulations, which also describe what the controller must tell the individual. The summary at Akin Gump summary of the PDPL and its implementing regulations gives a good overview of key obligations. For the regulations themselves, see Saudi PDPL implementing regulations.

Because the regulations have been updated, check for the latest versions and SDAIA guidance before finalizing your forms.

Many organizations assume consent is always required. It is not. The law recognizes other grounds, such as the actual interest of the individual, performance of a contract or prior legal obligation, public interest in limited cases and the legitimate interests of the controller where they do not harm the individual and sensitive data is not involved. The conditions matter, so review them for each purpose.

Consent is a poor basis where the individual has no real choice, for example where a service cannot be provided without the processing. In those cases, another basis is more honest and more stable, because consent can be withdrawn at any time.

Record the basis for each processing activity in your records of processing, along with the reason. The comparison with European rules is in Saudi PDPL vs GDPR.

ScenarioConsent approachNotes
General personal data, consent basisConsent may be written, verbal or electronic, and must be documentedKeep proof for verification
Sensitive dataExplicit consentHigher standard, clear wording
Credit dataExplicit consentSpecific, documented
WithdrawalStop processing without undue delayProvide an easy method
Other legal basesInterests, contract, legal requirement, legitimate interests in defined casesCheck conditions and exceptions

Consent should be tied to a specific purpose, given freely, and based on clear information. Tell the individual who you are, what you will do with the data, which categories you collect, who will receive it, whether it will leave the Kingdom and how to withdraw. The details of the privacy policy are described in Saudi PDPL privacy policy.

Avoid bundling. Separate consent for different purposes, such as service delivery and marketing, so people can agree to one and refuse the other. Avoid pre-ticked boxes and vague statements.

Use plain Arabic and English where your audience needs both. A statement that individuals cannot understand is unlikely to count as meaningful consent.

Sensitive personal data, such as health, genetic, religious and certain other categories defined in the law, and credit data require explicit consent. That means a clear statement or affirmative action that leaves no doubt about what the person has agreed to.

Design the interface so the person sees the exact purpose and must take a positive step, such as ticking a dedicated box or signing a specific form. Keep the wording for this consent separate from general terms.

Impact assessments are also required in certain cases, such as processing of sensitive data. Combine the consent design with the assessment so risks are addressed before launch.

Keep a record for each consent: who agreed, when, how, to what wording and to which purposes, along with the version of the notice shown. Store it in a way that lets you retrieve the record if the individual or SDAIA asks.

A consent log should link to your records of processing and to the systems that use the data. If a person withdraws, you need to find every system that relies on that consent.

Keep records for the period required by the regulations and your policies. A consent that cannot be proved may be treated as if it was never given.

Handle withdrawal and data subject rights

Give people an easy way to withdraw, as easy as it was to give consent. When consent is withdrawn, stop the processing that relied on it without undue delay and inform recipients where required. You may keep data needed for another legal basis, but tell the person what you are keeping and why.

Withdrawal is one of several data subject rights under the law, along with access, correction and deletion, among others. See Saudi PDPL data subject rights for the full set and the response process.

Test the process. Submit a withdrawal yourself and track it through marketing, analytics and any processors.

Consent interacts with transfer rules. Transfers outside the Kingdom are permitted on defined grounds, such as adequacy, appropriate safeguards like standard contractual clauses, and certain other cases. Do not assume that consent alone makes a transfer lawful. Check the Transfer Regulation.

The safeguards and templates are described in Saudi standard contractual clauses. Keep the list of destinations and recipients in your records of processing.

Tell people in your notice if their data will be transferred, where and on what basis.

A fitness app collects names, contact details and health measurements. Delivering the service relies on a contract. Sending marketing emails relies on consent. Sharing health measurements with a partner clinic for research relies on explicit consent, because health data is sensitive.

The app shows three separate choices, each with its own explanation. It records the user’s choices with a timestamp and notice version, and offers a settings page to withdraw each one. When a user withdraws research consent, the app stops sharing within hours and informs the partner. The example is invented, but it shows how the Saudi PDPL consent requirements shape design.

Then it updates its records of processing and its privacy policy to match.

Penalties and enforcement

The law provides for penalties for violations, including for unlawful disclosure of sensitive data. The details are covered in Saudi PDPL penalties. SDAIA has supervisory and enforcement powers, and organizations should treat consent compliance as an area of regulatory attention.

Register as a controller where required. See SDAIA registration. Breach notification duties are in Saudi PDPL breach notification.

Use the PDPL compliance checklist to confirm that consent is only one part of your program.

The most common mistakes are bundling several purposes in one consent, relying on consent where another basis would be more suitable, and failing to keep proof. Another is treating consent as a one-time banner and forgetting the withdrawal path. Teams also forget processors: if a vendor sends marketing on your behalf, your consent records must reach it, and withdrawals must flow back.

Finally, avoid copying a European cookie banner without adjusting it. The concepts overlap, but the legal bases, the sensitive data categories and the regulator differ. Review each consent flow against the Saudi text and record the review date.

Every quarter, sample a few consents from each system and check the record, the notice version and the purpose. Test withdrawals and check that marketing lists and partner feeds were updated. Report the results, such as the number of consents sampled and exceptions found, to the privacy lead and track fixes to completion.

Drafting consent forms, notices, logs and withdrawal procedures from scratch is slow. A prepared template set gives you consistent wording and structure to adapt.

The Saudi PDPL Toolkit provides 75 editable templates for the Saudi Personal Data Protection Law, its Implementing Regulation, the Transfer Regulation and SDAIA’s rules, including consent, privacy policy, rights, records, processors and cross-border transfers. Adapt them to your services.

Before you publish, have a qualified Saudi lawyer review the final documents. The Saudi PDPL consent requirements depend on the facts of each processing activity.

Is consent always required under the Saudi PDPL?

No. The law allows other legal bases in defined cases, so you should choose the basis that fits each purpose and meet its conditions.

What form can consent take?

According to published summaries, consent may be written, verbal or electronic, but it must be documented so it can be verified.

When is explicit consent needed?

For sensitive personal data and credit data, consent must be explicit.

What happens if consent is withdrawn?

The controller must stop the processing that relied on it without undue delay.

Who enforces the law?

SDAIA, the Saudi Data and Artificial Intelligence Authority, supervises compliance.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.