Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Saudi PDPL vs GDPR — Saudi PDPL vs GDPR: The 11 Differences That Change What You Do

Saudi PDPL vs GDPR: The 11 Differences That Change What You Do

Saudi PDPL vs GDPR is the comparison every multinational privacy team ends up making, usually after discovering that the GDPR programme it planned to extend to the Kingdom does not fit. The two laws share a vocabulary: personal data, controller, processor, consent, data subject rights, breach notification, impact assessment, cross-border transfer. Under the shared words, the Saudi Personal Data Protection Law makes different choices about the legal basis, the clocks, the regulator’s role, the transfer mechanism and the penalties. This guide sets out the differences that change what an organisation has to do, and the places where the two laws still agree closely enough that one set of documents can serve both.

What this guide covers

Saudi PDPL vs GDPR explained
Saudi PDPL vs GDPR: The 11 Differences That Change What You Do

Saudi PDPL vs GDPR at a glance

Topic GDPR Saudi PDPL
Regulator National supervisory authorities; lead-authority mechanism The Saudi Data and AI Authority (SDAIA), through the National Data Governance Platform; the Central Bank keeps its sector powers
Legal basis Six bases of equal standing Consent by default; four exceptions in Article 6; legitimate interest barred for sensitive data and for public entities
Consent Freely given, specific, informed, unambiguous; explicit for special categories Free, per purpose, documented with time and means; explicit for sensitive data, credit data and automated decisions
Rights clock One month, extendable by two 30 days, extendable once by 30
Records of processing Kept while processing; small-organisation exemption Kept five years after each activity ends; no size exemption; SDAIA template
Registration None (fees in some states) Mandatory on the platform for public entities, processing-led businesses and sensitive-data controllers; five-year certificate
DPO Public authorities; large-scale monitoring; large-scale special categories Public entities at large scale; core activities with regular and systematic monitoring; core activities on sensitive data; registered on the platform
Breach 72 hours to the authority where risk; individuals where high risk 72 hours to SDAIA via the platform where harm is possible; individuals without undue delay where their data or rights are affected
Impact assessment DPIA where high risk Assessment for any product or service; written assessment mandatory in four cases
Transfers Adequacy decisions; SCCs; BCRs SDAIA adequacy list (none published yet); SDAIA’s own SCCs in four templates; binding common rules; accreditation certificates; risk assessment
Penalties Up to 20 million euros or 4 per cent of turnover Up to SAR 5 million per violation, doubled on repeat; up to SAR 3 million and two years’ imprisonment for intentional disclosure of sensitive data

The GDPR offers six lawful bases and treats legitimate interests as an ordinary one. The Saudi law starts from consent. Article 5 requires it for processing and for any change of purpose, and Article 6 lists the exceptions: the data subject’s actual interest where they cannot be reached; another law or a prior agreement to which the data subject is party; a public entity’s security or judicial purposes; and the controller’s legitimate interest, only where no sensitive data is involved. The Implementing Regulation adds that public entities may not use legitimate interest at all, that it must sit within the data subject’s reasonable expectations, and that a documented assessment must precede it.

In practice a GDPR legal basis register maps across badly. Rows resting on “contract” survive as “prior agreement to which the data subject is party”; rows resting on “legal obligation” survive where a Saudi law applies; rows resting on legitimate interests for anything touching health, biometric, religious, ethnic or criminal data do not survive at all and must move to explicit consent. Our guide to the Saudi PDPL sets out the full basis structure.

Both laws require consent to be free, specific and informed. The Saudi Implementing Regulation goes further on evidence: consent must be documented in a way that allows future verification, recording the time and the means, and a separate consent is needed for each purpose. It also names three cases where consent must be explicit: sensitive data, credit data and decisions based solely on automated processing. The GDPR’s explicit-consent cases overlap but are not identical, and the GDPR has no credit-data category. A consent capture designed for the GDPR usually records the fact of consent; a Saudi one must record how and when.

Rights and clocks

On Saudi PDPL vs GDPR rights, the substance is similar in substance: information, access, a copy, correction, destruction. The GDPR adds portability, restriction and objection as separate rights; the Saudi law folds restriction into the correction procedure and has no portability right beyond the readable copy. The clock differs: one month extendable by two under the GDPR, 30 days extendable once by up to 30 under the Saudi Regulation, with the extension justified by disproportionate effort or multiple requests from the same person and notified in advance. The Saudi Regulation also names the channels a controller must offer: email, text message, the national address and electronic applications.

Saudi PDPL vs GDPR on records, registration and the DPO

The GDPR exempts organisations under 250 employees from records of processing in narrow circumstances; the Saudi law has no size exemption and requires the records to be kept for five years after each activity ends, on SDAIA’s template. The GDPR has no registration requirement; the Saudi regime requires public entities, processing-led businesses and any controller processing sensitive data to register on the National Data Governance Platform and hold a certificate. The DPO cases are close cousins, with the Saudi rules adding SDAIA’s own tests for “large scale”, “regular and systematic” and “core activities”, and requiring the DPO’s details on the platform. Our guide to SDAIA registration covers both.

Breach notification

Saudi PDPL vs GDPR breach rules both use 72 hours. The GDPR runs it to a supervisory authority where the breach is likely to result in a risk; the Saudi Regulation runs it to SDAIA through the platform’s breach service where the incident potentially harms the data or the data subjects or conflicts with their rights, with five specified content items and phased notification allowed with reasons. Individuals are told without undue delay under both, on similar triggers. The Saudi guide adds that a national-scale breach may be communicated through the website, social media and the media, and that NCA incident reporting runs alongside. Our breach notification guide covers the GDPR side.

Transfers: the sharpest Saudi PDPL vs GDPR difference in practice

The GDPR has a working adequacy system, standard contractual clauses in wide use, and a body of practice around transfer impact assessments. The Saudi law, published in English on SDAIA’s site, provides for the same three tools, but the position on the ground is different. SDAIA’s adequacy list, which the Transfer Regulation requires it to publish and review every four years, had not been published at the time of writing.

Every transfer therefore runs on one of the Regulation’s exemption cases, each tied to a safeguard: SDAIA’s Standard Contractual Clauses (four templates, three appendices, no edits to the approved text), binding common rules for a group, or an accreditation certificate from a body SDAIA has licensed. EU clauses are not a safeguard in the Kingdom. A risk assessment is mandatory before any exempted transfer and before continuous or widespread transfers of sensitive data. Our guide to Saudi standard contractual clauses works through the four templates.

Marketing, disclosure and identity documents

Three Saudi rules have no direct GDPR equivalent. Advertising or awareness material may not be sent to a person’s own channels without prior consent and a free stop mechanism, and where there has been no prior interaction consent comes first. Marketing processing is permitted only on data collected directly from the data subject. Copying official identity documents is prohibited except where the law or a public authority requires it. Disclosure is framed as a list of six permitted cases and nine bars rather than as a lawful-basis question.

Where the two laws agree

Much of the Saudi PDPL vs GDPR comparison is agreement. Purpose limitation, minimisation, accuracy, storage limitation and security are the same in substance. The content of the privacy notice overlaps heavily, and SDAIA’s ten-element guideline can be satisfied by a GDPR notice with a Saudi section.

Processor contracts under Article 17 of the Implementing Regulation carry seven items that a GDPR Article 28 agreement mostly contains, with two additions: a statement of the processor’s exposure to foreign law and the effect on its compliance, and notification of any disclosure a Saudi law compels. Impact assessments cover similar ground with a different trigger list. A programme built on the house structure of policy, register, procedure and record can serve both regimes with a Saudi layer on top.

Running both

A Saudi PDPL vs GDPR programme for a dual-regime organisation needs: a legal basis register with a regime column, because the same purpose may rest on legitimate interests in Europe and consent in the Kingdom; a consent capture that records time and means; a privacy policy with a Saudi section naming SDAIA and the platform; a rights procedure that applies the shorter of the two clocks; a transfer register that shows the safeguard for each direction, since data flowing from the Kingdom to Europe and from Europe to the Kingdom are two different transfers; and a change register, because SDAIA’s instruments are moving faster than the GDPR’s.

The Saudi PDPL Toolkit is the Saudi layer: 75 templates written to the law and every SDAIA instrument as published, on the same structure as the site’s GDPR packs so the two run side by side. The PDPL compliance checklist lists the order of work.

Frequently asked questions on Saudi PDPL vs GDPR

Is the Saudi PDPL stricter than the GDPR?

On a Saudi PDPL vs GDPR reading, stricter on the legal basis (consent by default), on consent evidence, on registration, on identity documents and on marketing; more permissive on the clocks in some respects (a single 30-day extension) and on penalties, which are fixed amounts rather than a share of turnover.

Does GDPR compliance mean PDPL compliance?

No. A GDPR programme is a good starting inventory, but the legal basis register, the consent capture, the transfer safeguards and the platform obligations have to be rebuilt for the Kingdom.

Can we use EU standard contractual clauses for transfers out of Saudi Arabia?

No. The Transfer Regulation’s safeguards are SDAIA’s own clauses, binding common rules and accreditation certificates. EU clauses may be used for the EU side of a flow, but not as the Saudi safeguard.

Is the Saudi PDPL vs GDPR comparison the same as the UAE comparison?

No. The UAE’s law shares the acronym PDPL and has its own regulator and rules. This guide is about the Kingdom of Saudi Arabia.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.