Saudi PDPL breach notification runs on a 72-hour clock to a regulator’s platform, and it is the obligation a GDPR-trained team most often gets right in principle and wrong in detail. Article 20 of the Personal Data Protection Law requires a controller to notify the competent authority — the Saudi Data and AI Authority, SDAIA — of any breach, damage or illegal access to personal data, and to notify data subjects where the breach may cause damage to their data or rights.
Article 24 of the Implementing Regulation sets the mechanics: notification to SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the data subjects or conflict with their rights, through the National Data Governance Platform, with five content items, any missing items following as soon as possible with reasons for the delay — and notice to affected data subjects without undue delay, in simple language, with four content items.
Two things differ from Europe. There is no risk threshold that lets a controller decide not to notify SDAIA at all; and the platform is the channel, so a controller that is not registered cannot meet the deadline. This guide sets out the law and the Regulation’s text, the two notices and their content, the definitions that decide when the clock starts, the NCA and sector obligations that run alongside, and the procedure a controller needs before the first incident.

Saudi PDPL breach notification: what the Law and the Regulation say
| Provision | Requirement | Note |
|---|---|---|
| Law Article 19 | The controller takes the organisational, administrative and technical measures necessary to protect personal data, including during transfer, in accordance with the Regulation | The security duty the breach exposes |
| Law Article 20(1) | The controller notifies the competent authority of any breach, damage or illegal access to personal data, in the manner and within the period the Regulation specifies | The regulator notice |
| Law Article 20(2) | The controller notifies the data subject where the breach may cause damage to their data or rights or conflict with their interests, in the manner the Regulation specifies | The data subject notice |
| IR Article 1 | Personal data breach: any incident that leads to the disclosure, destruction of or unauthorised access to personal data, whether intentional or accidental | Accidental and availability incidents count |
| IR Article 24(1) | Notify SDAIA within 72 hours of becoming aware of a breach that potentially harms the personal data or the data subjects or conflicts with their rights, with the specified content | The 72-hour clock |
| IR Article 24(2) | Where all items cannot be provided within 72 hours, provide them as soon as possible with the reasons for the delay | Phased notification is allowed; silence is not |
| IR Article 24(3) | Notify data subjects without undue delay where the breach may damage their data or conflict with their rights or interests, in simple and clear language, with the specified content | The individual notice |
| IR Article 17 | The processor agreement includes the processor’s commitment to notify the controller of a breach without undue delay | The processor clock feeds the controller’s 72 hours |
Our guide to the Saudi PDPL covers the law; the Saudi PDPL Implementing Regulations guide maps all 38 articles.
Saudi PDPL breach notification to SDAIA: five items, 72 hours, one platform
| Item | Content | Source in the response |
|---|---|---|
| 1 | A description of the breach, including its nature, the time and date it occurred and the circumstances, and when the controller became aware of it | Incident record; the awareness log |
| 2 | The categories of personal data affected, and the numbers and types of data subjects | Data inventory; records of processing |
| 3 | The risks and likely impact on the data subjects, the measures taken and the measures proposed to address the breach and mitigate its effects | Containment and remediation record |
| 4 | Whether the data subjects have been notified, and if not, why and when they will be | The data subject notice decision |
| 5 | The contact details of the data protection officer or the person responsible | DPO or responsible person |
The notice is submitted through the breach notification service on the National Data Governance Platform, which is available to registered controllers. Registration is mandatory for public entities, controllers whose core activity is processing and any controller processing sensitive data, and a registration certificate is valid for up to five years. A controller that has not registered discovers, at hour 60, that the channel does not exist for it. Our guide to SDAIA registration covers the process.
Saudi PDPL breach notification to data subjects: four items, without undue delay
| What the four items cover | In practice |
|---|---|
| The breach and its likely effects on the data subject | Plain description; no technical detail the reader cannot act on |
| What the controller has done and will do | Containment, remediation, monitoring |
| What the data subject can do to reduce the effects | Password changes, fraud monitoring, caution against phishing |
| How to reach the controller for more information | A named contact route, not a generic address |
The trigger is the possibility of damage to the data subject’s data, rights or interests; the standard is simple, clear language; the timing is without undue delay — which in practice means alongside or shortly after the SDAIA notice, not after the investigation closes. Where the controller decides not to notify data subjects, item 4 of the SDAIA notice asks why.
When the clock starts
- Awareness, not confirmation. The 72 hours run from becoming aware of a breach that potentially harms the data or the data subjects — a reasonable belief that a qualifying incident has occurred, not a completed forensic report. Item 1 of the SDAIA notice asks when the controller became aware, so the date is examined.
- Processors start the clock when they tell you. IR Article 17 requires the processor to notify without undue delay; the controller’s awareness follows. A processor contract with an hours-based clock is the control.
- Accidental counts. The IR Article 1 definition includes accidental incidents and destruction, so a misdirected export or a ransomware event is a breach.
- Harm potential, not confirmed harm. The test is whether the breach may harm the data or data subjects or conflict with their rights — a low bar that most breaches of identifiable data will meet.
The obligations that run alongside Saudi PDPL breach notification
| Regime | Requirement | Relationship |
|---|---|---|
| NCA — Essential Cybersecurity Controls and incident reporting | Organisations within the NCA’s scope report cyber incidents to the NCA under its controls and directives; IR Article 23 ties PDPL security measures to the NCA’s controls where applicable | A cyber incident is reported to the NCA and, if personal data is involved, to SDAIA — two notices, two clocks |
| SAMA — financial institutions | Cyber security incident management under the Cyber Security Framework, with reporting to SAMA | A third notice for banks, insurers and financing companies |
| CST — telecommunications | Sector incident reporting | Sector notice alongside SDAIA |
| Contractual | Customer and processor contracts with notification clauses | Often shorter than 72 hours |
| Cross-border | Where data subjects are abroad, the foreign law’s notice regime — GDPR, DPDP — may also apply | Separate notices, separate content |
Our guide to Saudi PDPL vs GDPR covers how the two regimes’ breach rules differ for multinational controllers.
The Saudi PDPL breach notification procedure
- Register on the platform first. If registration is mandatory or the controller processes sensitive data, the breach service depends on it; verify the certificate is current.
- Define awareness and log it. A named incident lead decides that a qualifying breach has occurred and records the date and time; the 72 hours run from there.
- Pre-draft both notices. The five SDAIA items and the four data subject items as templates with placeholders; items 5 and 4 respectively filled in advance.
- Keep the data inventory able to answer item 2. Categories of data, numbers and types of data subjects per system — the records of processing under IR Article 33 are the source.
- Put hours into processor contracts. IR Article 17’s “without undue delay” becomes a number in the agreement.
- Plan the phased notice. Decide in advance what goes in the first 72-hour submission and how missing items are followed up with reasons.
- Coordinate the parallel notices. NCA, SAMA or sector regulator, contractual counterparties and any foreign regulator on one timeline owned by the incident lead.
- Record the decision on data subjects. Notify or not, with the reasoning — because the SDAIA notice asks.
Penalties for failing to notify
Failure to notify SDAIA or data subjects is a violation of Article 20 and the Regulation, punishable under Article 36 by a warning or a fine of up to SAR 5 million, doubled for repeat violations, imposed by a committee formed by SDAIA’s president and appealable to the competent court. Our guide to Saudi PDPL penalties covers the full scale.
Frequently asked questions
What is the Saudi PDPL breach notification deadline?
Under Implementing Regulation Article 24, notification to SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the data subjects or conflict with their rights, through the National Data Governance Platform, with five content items; missing items follow as soon as possible with reasons. Data subjects are notified without undue delay where the breach may damage their data or rights.
Is there a risk threshold for notifying SDAIA?
Only the potential for harm to the data or the data subjects or conflict with their rights — a low bar. There is no GDPR-style ‘unlikely to result in a risk’ exemption from the regulator notice.
What must the notice to SDAIA contain?
Five items: a description of the breach with its nature, time, date, circumstances and when the controller became aware; the categories of data and the numbers and types of data subjects; the risks, impact and measures taken and proposed; whether data subjects were notified and, if not, why and when; and the DPO’s or responsible person’s contact details.
How is the notice submitted?
Through the breach notification service on SDAIA’s National Data Governance Platform, which is available to registered controllers — so registration is a precondition of meeting the deadline.
Do we also have to notify the NCA or SAMA?
Where the organisation is within their scope, yes: NCA incident reporting for cyber incidents, SAMA reporting for financial institutions — in parallel with, not instead of, the SDAIA notice.
Where this leaves you
Build Saudi PDPL breach notification around the platform and the clock: register before the incident, define and log awareness, pre-draft the five-item SDAIA notice and the four-item data subject notice, keep the inventory that answers the numbers, put hours into processor contracts, and run the NCA, sector and contractual notices on the same timeline — because the 72 hours run from awareness, the channel is the platform, and the fine for silence is up to SAR 5 million.
References
- SDAIA — Personal Data Protection Law and Implementing Regulations (laws and regulations page) — The Law (Articles 19, 20, 36) and the Implementing Regulation (Articles 1, 17, 23, 24, 33).
More on the Saudi PDPL
- Saudi PDPL breach notification — you are here
- The Saudi PDPL: the complete guide
- The Saudi PDPL Implementing Regulations: 38 articles
- SDAIA registration
- Saudi PDPL penalties
- The PDPL compliance checklist
The breach procedure wired to the platform, the SDAIA five-item notification form, the data subject notice template, the awareness log and the processor breach clause are in the Saudi PDPL Toolkit, or start with the free templates.