Description
The Saudi PDPL Toolkit is written for the Kingdom’s law, not adapted from the GDPR
The Personal Data Protection Law has been fully enforceable since 14 September 2024, and the Saudi Data and AI Authority is enforcing it. It shares vocabulary with the GDPR and differs where it matters: consent is the default basis, legitimate interest is a narrow exception barred for sensitive data, rights requests run on 30 days plus 30, controllers register on the National Data Governance Platform, breaches go to SDAIA through that platform within 72 hours, penalties are in riyals, and there is no adequacy list yet. A GDPR template set applied in the Kingdom is wrong in each of those places.
The Saudi PDPL Toolkit is 75 editable templates, 57 Word documents and 18 Excel workbooks, across 12 sections, written against the Law as amended by Royal Decree M/148, its Implementing Regulation, the Regulation on Personal Data Transfer Outside the Kingdom (August 2024), the Rules for Appointing a Personal Data Protection Officer, the Rules Governing the National Register of Controllers, SDAIA’s Standard Contractual Clauses and BCR Guidelines (September 2024), the Breach Incidents Procedural Guide (October 2024) and SDAIA’s guidelines, every one read on SDAIA’s own site.
What the Saudi PDPL Toolkit maps to
The Saudi PDPL Toolkit claims 111 provisions, and the legal crosswalk workbook lists every one against the document that answers it:
- the Personal Data Protection Law: 44 provisions of the Law, covering every live article from the definitions and scope through the five rights, consent and its exceptions, collection, the privacy policy, disclosure, destruction, security, breach, the impact assessment, health and credit data, marketing, transfers, the Competent Authority, records, and the penalties and compensation provisions;
- the Implementing Regulation: 37 articles, including the 30-day request period, the consent conditions, the seven processor contract items, the 72-hour breach notification, the impact assessment triggers and content, the DPO cases and the five-year records rule;
- the Transfer Regulation: 7 articles, the exemption cases, the safeguards, the risk assessment, revocation and onward transfers;
- SDAIA’s rules: 13 provisions from the DPO appointment rules and the National Register rules, including the five-year registration certificate;
- SDAIA’s guidance: 10 documents, from the privacy policy guideline’s ten elements to the breach guide’s three stages and the transfer risk assessment guideline’s four phases.
Every Word document in the Saudi PDPL Toolkit carries a Requirements-addressed table naming the provisions it answers, and a Legal basis panel that says what the law requires.
Built on SDAIA’s own instruments
- The Saudi PDPL Toolkit’s privacy policy follows SDAIA’s ten key elements and detailed model, with the update record, the response times and the complaint route the guideline asks for.
- The records of processing register follows SDAIA’s template in its three tiers, with the impact-assessment fields that become mandatory when a trigger applies, and the five-year retention rule.
- The consent procedure meets every condition in Implementing Regulation Article 11: separate consent per purpose, documented with time and means, explicit for sensitive data, credit data and automated decisions, and as easy to withdraw as to give.
- The Saudi PDPL Toolkit’s processor agreement carries the seven items in Article 17, the foreign-law statement, sub-processor acceptance, the breach clock and the transfer clause.
- The breach procedure follows the three stages in SDAIA’s guide and the platform’s breach service; the notification form carries the five required items in order.
- The Saudi PDPL Toolkit’s transfer procedure is written for the position as it stands: no adequacy list has been published, so every transfer runs on an exemption case with SDAIA’s clauses, binding common rules or an accreditation certificate, plus the Article 7 risk assessment on the guideline’s four phases. The SCC guide covers the four templates and the rule that any edit to the approved text is itself a violation.
- The DPO procedure applies SDAIA’s tests for large scale, regular and systematic monitoring, and core activities, and registers the DPO on the platform.
Registers in the Saudi PDPL Toolkit that ship populated
8 of the 18 workbooks arrive filled in rather than empty. The legal crosswalk carries every provision and every document. The gap assessment tool lists all 111 provisions with the document that closes each. The internal audit checklist carries 111 checks, one per provision. The SDAIA change register carries 15 instruments with their dates, including the 2025 amendment consultation and the adequacy list as pending items. The retention schedule carries 17 record types, each with its Article 18 basis for retention. The risk register carries 18 starter risks. The severity matrix maps to the Regulation’s harm test. The document index carries all 75 documents.
6 transparency documents and 8 security policies
The Saudi PDPL Toolkit ships a privacy policy procedure and template, a collection notice with consent statement, and employee, website and CCTV notices. Security policies aligned to the National Cybersecurity Authority’s controls where the organisation is subject to them: information security, access control with the health data minimum-access rule, encryption and pseudonymisation, destruction and anonymisation on SDAIA’s guideline, retention, backup, logging, and data accuracy.
Written against the primary texts, and dated
Every provision the Saudi PDPL Toolkit cites was read on sdaia.gov.sa on 13 September 2026: the Law, the Implementing Regulation, the Transfer Regulation v2.0, the DPO and National Register rules, the SCCs and BCR guidelines, the breach guide and the guidelines. Where SDAIA has consulted but not published, the Saudi PDPL Toolkit says so. Where a power exists but has not been used, the pack says that too.
Where the Saudi PDPL Toolkit sits beside the rest of the catalogue
The NCA Cybersecurity Toolkit carries the security controls the Implementing Regulation points to; the SAMA Toolkit carries the Saudi Central Bank’s requirements for regulated firms; the GDPR Toolkit and UK GDPR Toolkit serve organisations subject to those regimes as well. The Saudi PDPL Toolkit is the data protection layer for the Kingdom, written on the same house structure so the packs run side by side.
Honest about the boundaries
- The Saudi PDPL Toolkit is a set of templates, not legal advice; agreements and notices need review for the organisation’s facts.
- The Saudi PDPL Toolkit does not include SDAIA’s Standard Contractual Clauses or BCR text; it carries completion guides, because the clauses may not be edited and must be taken from SDAIA.
- Retention periods under labour, tax and commercial law are left for the organisation to name; the schedule carries the data protection basis for each.
- The Implementing Regulation is the 2023 text; the 2025 amendment consultation had not produced a published text at the date of writing, and the change register is built to take it.
- Sector requirements from the Ministry of Health, the Saudi Health Council, the Council of Health Insurance and the Saudi Central Bank are referenced, not reproduced.
What you get in the Saudi PDPL Toolkit
| Section | Documents | What it holds |
|---|---|---|
| 00 Programme Guide | 4 | Implementation guide, legal crosswalk, gap assessment tool, SDAIA change register |
| 01 Governance and Registration | 8 | Policy, roles, DPO procedure and letter, platform registration, accountability calendar, training, SDAIA engagement |
| 02 Lawful Processing and Consent | 8 | Legal basis procedure and register, consent procedure, forms and register, legitimate interest, purpose change and data maps, sensitive, health and credit data |
| 03 Transparency | 6 | Privacy policy procedure and template on SDAIA’s ten elements, collection notice, employee, website and CCTV notices |
| 04 Data Subject Rights | 7 | Rights procedure on 30 plus 30 days, verification and guardians, correction and destruction, letters, log, complaints procedure and log |
| 05 Records and Impact Assessment | 6 | Records of processing procedure and register on SDAIA’s template, impact assessment procedure, screening, template, register |
| 06 Processors and Disclosure | 7 | Due diligence, Article 17 processor agreement, sub-processors, register, disclosure procedure and form, official documents |
| 07 Cross-Border Transfers | 7 | Transfer procedure, risk assessment on the four phases, SCC and BCR guides, register, revocation, decision record |
| 08 Breach Management | 6 | Response procedure, SDAIA notification form, data subject notice, register, severity matrix, NCA interface |
| 09 Security and Retention | 8 | Information security, access, encryption, destruction and anonymisation, retention schedule, backup, logging, accuracy |
| 10 Marketing | 3 | Advertising and awareness material, direct marketing, consent and opt-out register |
| 11 Implementation and Assurance | 5 | 90-day plan, internal audit checklist, annual review, risk register, document index |
00 Programme Guide
- Saudi PDPL Toolkit Implementation Guide
- Legal Crosswalk Workbook (Excel)
- Saudi PDPL Gap Assessment Tool (Excel)
- SDAIA Regulatory Change Register (Excel)
01 Governance and Registration
- Personal Data Protection Policy
- Data Protection Roles and RACI Matrix
- DPO Appointment Procedure
- DPO Appointment Letter and Role Description
- National Data Governance Platform Registration Procedure
- Accountability Framework and Compliance Calendar
- Data Protection Training and Awareness Plan
- SDAIA Engagement and Enforcement Procedure
02 Lawful Processing and Consent
- Legal Basis Assessment Procedure
- Consent Management Procedure
- Consent Form and Withdrawal Templates
- Consent Register (Excel)
- Legitimate Interest Assessment Template
- Purpose Change and Data Map Procedure
- Sensitive Health and Credit Data Policy
- Legal Basis Register (Excel)
03 Transparency
- Privacy Policy Procedure
- Privacy Policy Template
- Collection Notice and Consent Statement
- Employee and Candidate Privacy Notice
- Website and App Privacy Notice
- CCTV and Monitoring Notice
04 Data Subject Rights
- Data Subject Rights Request Procedure
- Identity Verification and Guardian Procedure
- Correction and Destruction Request Procedure
- Rights Request Letter Templates
- Rights Request Log (Excel)
- Data Subject Complaints Procedure
- Complaints Log (Excel)
05 Records and Impact Assessment
- Records of Processing Procedure
- Records of Processing Register (Excel)
- Impact Assessment Procedure
- Impact Assessment Screening Questionnaire
- Impact Assessment Template
- Impact Assessment Register (Excel)
06 Processors and Disclosure
- Processor Due Diligence Checklist
- Processor Agreement (Implementing Regulation Article 17)
- Sub-Processor Approval Procedure
- Processor Register (Excel)
- Disclosure Procedure
- Disclosure Request and Decision Form
- Official Documents and Copies Procedure
07 Cross-Border Transfers
- Cross-Border Transfer Procedure
- Transfer Risk Assessment Template
- Standard Contractual Clauses Completion Guide
- Binding Common Rules Guide
- Transfer Register (Excel)
- Onward Transfer and Exemption Revocation Procedure
- Transfer Exemption Decision Record
08 Breach Management
- Personal Data Breach Response Procedure
- SDAIA Breach Notification Form
- Data Subject Breach Notice
- Personal Data Breach Register (Excel)
- Breach Severity Assessment Matrix (Excel)
- NCA Incident Reporting Interface Note
09 Security and Retention
- Information Security Policy
- Access Control Policy
- Encryption and Pseudonymisation Policy
- Data Destruction and Anonymisation Procedure
- Records Retention Schedule (Excel)
- Backup and Restoration Policy
- Logging and Monitoring Policy
- Data Accuracy and Quality Procedure
10 Marketing
- Advertising and Awareness Material Procedure
- Direct Marketing Policy
- Marketing Consent and Opt-Out Register (Excel)
11 Implementation and Assurance
- 90-Day Implementation Plan
- Internal Audit Checklist (Excel)
- Annual Compliance Review Record
- Data Protection Risk Register (Excel)
- Document Index (Excel)
ISO 22301 Assessment Tool - Premium Quality 




































Reviews
There are no reviews yet