SAUDI PDPL · SDAIA · ENFORCED SINCE SEPT 2024

In Saudi Arabia, your privacy regulator also sets the AI policy.

SDAIA runs both the data regulator and the AI authority, so an AI question can arrive attached to an ordinary privacy filing at any time.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Live law since September 2024, not a transition
Royal Decree M/19 8 principles 7 rights 72-hour clock SAR 5M ceiling

Our promise

“Saying so is easy. Showing it is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

The PDPL, in three chapters

The Law

The Personal Data Protection Law was enacted by Royal Decree M/19 of 2021, with implementing regulations in September 2023 and full enforcement from 14 September 2024. It is overseen by SDAIA through the National Data Management Office, which audits, investigates and fines.

The Gap

Most programmes were written during the transition and never revisited once it ended. The eighth principle asks you to demonstrate compliance rather than assert it, and a record drafted from a questionnaire two years ago demonstrates nothing about the estate as it runs today.

The Office

We build the inventory from the systems inwards, test all eight principles and all seven rights the way somebody outside would have to exercise them, and answer the automated-decision question in writing - because the regulator asking it also sets the national AI strategy.

Who is caught

Whose data, not where you are.

Processing inside the Kingdom, and processing Saudi residents’ data from outside it, are both caught.

Who owes these duties № 01
  • Anyone processing personal data in the Kingdom
  • Overseas entities holding residents’ data
  • Controllers and processors, both directly
  • Government bodies, healthcare and finance
PDPL · iDharma · Presented for review
When the duties bite № 02
  • At collection - the notice comes first
  • Within 72 hours of becoming aware of a breach
  • Within 30 days of a rights request arriving
  • Before data is transferred out of the Kingdom
PDPL · iDharma · Presented for review
Whose duty is it

The duty is yours. So is the AI question.

You

Anyone processing in the Kingdom

Any entity processing personal data within the territory of Saudi Arabia, as controller or as processor. Every duty on this page lands on you - the basis per purpose, the notices, the record, the rights route and the breach path - whoever actually runs the systems, and wherever in the world they run them.

And from outside

Anyone processing residents’ data

Organisations established outside the Kingdom that process the personal data of Saudi residents. The test is whose data it is rather than where you are, which is the limb that overseas platforms and cloud vendors most often discover late, and usually discover expensively at the same time.

The catch

Your regulator also writes AI policy

SDAIA oversees data protection through the National Data Management Office and sets national AI strategy. It is the only Gulf regulator where those two sit in one authority - so an automated-decision question can arrive attached to an ordinary privacy filing, with no warning and no separate process.

What most teams assume

“It is a privacy filing. AI is a separate thing.”

What the regulator is

One authority. Expect one question.

It is the first thing we have to correct.

  • Who it is for
  • Banks & fintech
  • Healthcare providers
  • Government suppliers
  • Retail & telecoms
  • Cloud & AI vendors
Why this matters
A bound statute volume standing open on a dark desk under a low lamp, a ribbon and paper tabs marking several pages, with a fountain pen and reading glasses laid beside it.
01 Administrative fines reach SAR 5 million, scaled to severity, with multipliers for repeat violations - and certain offences carry criminal exposure on top.
02

The transition period ended on 14 September 2024. Audits, investigations and complaint responses have all been in active use since then.

03

SDAIA acts on its own initiative as well as on complaint, and a violation can be disclosed publicly. That last part is not a fine at all.

04

Bahrain, Qatar and the UAE each run their own regime. The principles align across all four of them and almost none of the thresholds do.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a determination.

0 of 3

Saudi personal data -

Whose data, not where you are. Processing inside the Kingdom and processing Saudi residents’ data from outside it are both caught. Customers, employees and users of an overseas service all count.

Automated decisions -

This is not a second scope test. It sorts the exposure that matters most here - the seventh right is objection to exactly this, and SDAIA also sets the national AI strategy.

Record of processing -

The eighth principle turns on it. Demonstrating compliance is a different thing from achieving it, and the record is what a compliance audit opens first.

The calendar

Four clocks, and the first one already ran.

Each of these runs from an event you do not choose - so they cannot be added up, and they cannot be run in parallel.

  1. Enforcement

    Already running

    Full enforcement began on 14 September 2024. The transition period is over, and audits and investigations are both in use.

  2. Notify SDAIA

    72 hours

    From becoming aware of a personal data breach, not from the day the investigation closes or the cause is finally understood.

  3. Answer the person

    30 days

    The window for a rights request. What fails is almost never willingness - it is a search that does not reach every copy.

  4. Demonstrate

    Continuously

    The eighth principle is not an annual exercise. Records and notices have to describe the estate on the day, not when written.

The trap

Programmes written during the transition are still being maintained as though there is one. There is not: enforcement has been live since 14 September 2024, and a record of processing drafted two years ago describes an estate that no longer exists.

Requirement & coverage

What the law says, what we ship

12 duties across the eight principles and the seven rights, each with what it produces.

Lawfulness A basis per purpose
A legal ground identified for each processing purpose rather than for each system, with the justification written down and the processing aligned to the purpose it was named for.
Transparency Notices at collection
What you tell people, in plain language rather than legal drafting, given where the data is actually handed over rather than linked from a footer.
Purpose limitation Written before use
Purposes defined before collection and a compatibility test for any new use - which is where secondary model training most often fails.
Data minimisation Necessity per field
A necessity assessment at field level, reviewed rather than assumed, so collection is proportionate to the purpose instead of to what the form can capture.
Storage limitation Retention that runs
A schedule per category with a deletion route that actually deletes, and a periodic review of what is still being held and why.
Records of processing The first thing asked
A record covering every purpose, category, recipient and transfer - built from the systems inwards rather than from a questionnaire outwards.
Right to be informed Before it starts
The privacy notice at the point of collection, with the purpose disclosed and the recipients identified rather than described in general terms.
Access and correction 30-day window
A documented request route a person outside can find, identity verification that works, and a correction that propagates to the third parties told earlier.
Deletion and portability Reaching every copy
A deletion route that checks the basis first and then reaches the backups, plus a structured machine-readable export where the data is asked for back.
Withdrawal of consent As easy as giving
A withdrawal mechanism as easy to use as the one that took the consent, which actually stops the processing rather than flagging the record.
Automated decisions A human who can act
A register of decisions made solely by automated processing, the logic explained, and a named human with the authority to change an outcome.
Transfers and security Condition per route
The condition relied on for each transfer out of the Kingdom, with the technical and organisational measures evidenced rather than asserted.
The engagement

Personal data, independently reviewed

From the CRM to the model in the decision path.

  1. Intake

    Which systems hold Saudi personal data, and what each one is for.

  2. Test

    The eight principles and the seven rights against the estate as it runs.

  3. Sign off and evidence

    You see the draft first. Then the records, notices and drills - dated.

Request a Saudi review
An auditor in a charcoal suit and open-collared white shirt, with dark curly hair, standing against a warm pale wall and pointing into the open space alongside.
The record is the evidence - that is what you are buying.
Struck in your favour

Why teams choose iDharma for their PDPL review

Rights tested from outside

Every one of the seven exercised from outside, the way a member of the public would have to.

The AI question, answered

Automated decisions read against the seventh right, because SDAIA will ask you about them.

Evidence, not attestation

Each principle tested where it is meant to bite, and every finding dated, owned and tracked.

The Gulf in one scope

Bahrain, Qatar and UAE obligations overlap enough to scope them all in the same review.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Saudi PDPL review report

The full review: what you process, on what basis, under which duty - and where each one is evidenced or is not, written principle by principle and right by right. Findings are ranked by consequence to people rather than by ease of fixing, with the automated-decision and transfer positions stated separately rather than folded in.

Workbook

Processing inventory

Every purpose, category, recipient and transfer - built from the systems inwards rather than from a questionnaire sent round the business.

Register

Lawful basis register

A ground identified per purpose with the justification beside it, so the record answers a question rather than restating that one was asked.

Templates

Privacy notice set

Notices per audience in plain language, placed where the data is actually handed over rather than linked from a page footer nobody opens.

Runbooks

Rights and breach runbooks

One intake route with identity verification and the thirty-day clock, plus a breach path written against the seventy-two-hour duty to SDAIA.

Register

Automated decision register

Where a decision is made solely by machine: the logic explained, the human review route named, and the way to contest an outcome written down.

Documents

Policy template pack

The core set, the rights and consent set and the security and breach set - written to the PDPL rather than handed over as a generic pack.

Format & fee

Real numbers, upfront.

Scope
Set by the law
Inputs
Your systems and your records
Re-review
Every twelve months - $10,500 against your known baseline

The law fixed the duties, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request this review
PDPL · Named engagement $12,500 flat
  • All eight principles tested
  • All seven rights, from outside in
  • Automated decision register
  • 26 policy templates, tailored
Show your hand

Four things you have to be able to produce

The PDPL is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.

The record,
current

A record of processing that matches what the systems do. It is the first thing a compliance audit opens, and the document every other position is argued out of.

The basis,
written

A legal ground identified per purpose rather than per system, with the justification recorded at the time rather than reconstructed under a regulator’s question.

The route,
findable

A rights route that a person outside can find without asking you, answering inside thirty days - and a breach path that reaches SDAIA inside the seventy-two hours.

The human,
named

For any decision made solely by automated processing: someone with the authority to change the outcome, reachable from outside, inside the response window.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

What the law is, whether it reaches you, the clocks, and where AI lands. Answered straight.

Request this review
What is Saudi Arabia’s PDPL?

The Kingdom’s data privacy regulation, enacted by Royal Decree M/19 of 2021. Implementing regulations were issued in September 2023 and full enforcement began on 14 September 2024. It is overseen by SDAIA through the National Data Management Office.

Who does the PDPL apply to?

Any organisation processing personal data within the Kingdom, as controller or processor - and organisations established outside it that process the personal data of Saudi residents. The test is whose data you process, not where you are established.

What is the breach notification timeline?

Seventy-two hours to notify SDAIA from becoming aware of a personal data breach - not from the day the investigation closes. Individual rights requests run to a separate thirty-day window.

How does the PDPL apply to automated decision-making and AI?

The seventh right is objection to a decision made solely by automated processing, which needs a named human with authority to change the outcome. Note the regulator: SDAIA also sets national AI strategy, so an AI question can arrive attached to an ordinary privacy filing.

What does an iDharma PDPL review cost, and what do we get?

A flat fee for the named engagement, agreed before anything is charged. What lands is the review report, the processing inventory, the lawful basis register, the notice set, the rights and breach runbooks, the automated decision register and the policy template pack.

Get started

Request your PDPL review

Tell us where the Saudi data lives and we come back with a call in a day.

What we need from you

Nothing you do not already have. Most of this comes out of a morning with your engineering, data and legal teams, and we tell you which extracts before you commit.

  1. Which systems hold Saudi personal data, and what for
  2. Whether you process inside the Kingdom, outside, or both
  3. Your record of processing, if one already exists
  4. Where any decision is made solely by machine
  5. Where data leaves the Kingdom, and on what condition

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request a Saudi review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • The Personal Data Protection Law and its regulations
  • SDAIA, and the National Data Management Office
Enacted
Royal Decree M/19, 2021
Enforced from
14 September 2024

What it means

  • General information about what the law requires — not legal advice, and no professional relationship.
  • Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • This reading has not been checked article by article against the law, so no article number appears anywhere on the page. For a citation, go to SDAIA’s own publication of the text.
  • Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.

Something on this page out of date?

Tell us