Saudi PDPL, under a regulator that also leads AI policy.
The Personal Data Protection Law sets data privacy obligations for anyone processing personal data in the Kingdom, and it has been fully enforceable since 14 September 2024. Saudi Arabia is also the Gulf jurisdiction most likely to ask AI-specific questions about an ordinary privacy filing, because the authority overseeing data protection is the same one setting national AI strategy.
What is Saudi PDPL?
The Personal Data Protection Law is the Kingdom's data privacy regulation, enacted by Royal Decree M/19 of 2021. Implementing regulations were issued in September 2023 and full enforcement began on 14 September 2024. It is now live law rather than a transition: SDAIA conducts compliance audits and investigations, administrative fines reach SAR 5 million, and certain offences carry criminal exposure.
- Regulator SDAIA, through the NDMO The same authority that sets national AI strategy, which is why an AI question can arrive attached to an ordinary privacy filing.
- Enforcement Active since Sept 2024 The transition period is over. Audits, investigations and complaint responses are all in use.
- Regionally One of four GCC regimes Bahrain, Qatar and the UAE each have their own. The principles align; the thresholds, regulators and transfer conditions do not.
Who needs to comply?
The test is whose personal data you process, not where you are established. Five populations are caught, and the last three are where sector rules start to bite on top.
- Organisations in Saudi Arabia Any entity processing personal data within the territory of the Kingdom, as controller or as processor.
- Processors of KSA resident data Organisations established outside the Kingdom that process the personal data of Saudi residents.
- Government entities Public sector organisations handling citizen data, alongside the national data management framework.
- Healthcare providers Medical facilities processing patient information, where sector rules sit on top of the general regime.
- Financial institutions Banks and fintechs handling financial data, where localisation questions are usually answered by the sector regulator rather than by the PDPL alone.
Operating across the Gulf? The Bahrain, Qatar and UAE regimes share most of these principles and almost none of the thresholds. Scope one assessment across all four and the overlap does the work; scope four separately and you pay for the same data mapping every time.
How iDharma supports Saudi PDPL compliance
Six workstreams against the duties themselves, with records of processing treated as the obligation it is rather than as documentation hygiene.
Personal data inventory and mapping
A complete record of processing activities: categories, purposes, legal bases and retention. Built from the systems inwards, which is how prompts, retrieval indexes and logs get onto it rather than being discovered later.
Data subject rights management
Access, correction, deletion and portability request routes, tested from the outside in rather than described from the inside out, against the response window the law actually allows.
Security and confidentiality controls
The technical and organisational measures documented where they are meant to bite, plus a breach procedure with a named decision-maker and a notification path that has been rehearsed rather than written.
Cross-border transfer tracking
Where the data physically lands, the condition relied on, the authorisation position, and whether all three match what your privacy notice already says.
Consent and legal basis documentation
The basis relied on for each purpose, and whether the record of it would survive a regulator asking. Including whether a withdrawal actually propagates downstream, which is where most consent records fail.
DPO appointment and governance
Whether the appointment is required in your case, who holds it, and the accountability framework behind them, including the model estate a regulator with an AI remit is liable to ask about.
Hosting decisions are hard to retrofit. The general transfer position and any sector-specific localisation requirement are not the same question, and both belong in the architecture conversation rather than in the compliance review that follows it.
Complete PDPL requirements coverage
The assessment tests against every PDPL control requirement, grouped into four families. Nothing in scope is left to a follow-up engagement.
- Lawfulness and transparency Legal basis per purpose, consent and withdrawal, and the transparency notices that go with them.
- 8 of 8 by the assessment
- Data subject rights Information, access, correction, deletion, portability, withdrawal and objection to automated decisions.
- 7 of 7 by the assessment
- Cross-border transfers Adequate protection, the authorisation position, safeguards and the sector localisation question.
- 5 of 5 by the assessment
- Security and confidentiality Technical and organisational safeguards, the breach procedure and the notification path behind it.
- 6 of 6 by the assessment
Scoped for Saudi PDPL compliance
SDAIA-ready documentation
The processing record produced as an artefact you can hand over, not described as something you could assemble.
Rights inside the window
Request routes with owners and a clock, so a 30-day response is a process rather than an escalation.
Transfer and localisation
The general position and the sector position answered separately, because they are separate questions.
Gulf-wide mapping
Tagged to the Bahrain, Qatar and UAE regimes for a programme that spans the region.
Eight key PDPL principles
The foundation for lawful processing, broadly common across the Gulf regimes. Each is stated here as something that produces evidence rather than something to agree with.
Lawfulness
Process personal data only on a valid legal ground.
- A basis identified per purpose
- The justification documented
- Processing aligned to that purpose
Transparency
Tell people what you are doing with their data, before you do it.
- Privacy notices at collection
- Plain language, not legal drafting
- Accessible where the data is given
Purpose limitation
Collect for specific, explicit purposes and resist secondary use.
- Purposes defined before collection
- No quiet scope creep
- The purpose written down
Data minimisation
Limit collection to what the stated purpose actually needs.
- A necessity assessment per field
- Proportionate collection
- Reviewed rather than assumed
Accuracy
Keep personal data accurate and current.
- Verification at the point of entry
- A working update mechanism
- A correction process that propagates
Storage limitation
Retain only for as long as the purpose requires.
- Retention schedules per category
- Deletion that actually deletes
- Periodic review of what is held
Confidentiality and security
Protect the data with appropriate technical and organisational measures.
- Security controls, evidenced
- Access restricted and reviewed
- Encryption to a stated standard
Accountability
Be able to demonstrate compliance, not merely to assert it.
- Documentation kept current
- Evidence of compliance retained
- Audit readiness as a standing state
Data subject rights under PDPL
Seven rights granted to individuals. We test each one from the outside in, because a right that exists in a policy and not in the request queue is a finding waiting to happen.
Right to be informed
Clear information about the processing, given at the point it starts.
- Privacy notice at collection
- Purpose disclosed
- Recipients identified
Right of access
A person can ask what you hold about them, and be answered.
- A documented request route
- A 30-day response window
- Identity verification that works
Right to correction
Inaccurate data corrected, and the correction passed on.
- A correction workflow
- Verification before change
- Third parties notified
Right to deletion
Deletion when the legal basis for holding the data ceases.
- A deletion request route
- Legal basis checked first
- Erasure that reaches backups
Right to obtain data
The data handed back in a form the person can actually use.
- Structured export
- Machine-readable format
- Direct transmission where asked
Right to withdraw consent
Withdrawal as easy as giving consent was, without unpicking what came before.
- A working withdrawal mechanism
- The same ease as granting
- Processing actually stops
Right to object to automated decisions
Objection to a decision made solely by automated processing. This is the right an AI programme is most likely to fail.
- A human review route
- The logic explained
- A way to contest the outcome
The last of the seven is the one to test first if you run models in a decision path. It requires a named human with the authority to change an outcome, reachable by someone outside your organisation, within the response window — and that is a process question long before it is a model question.
18-week implementation roadmap
A practical path to PDPL compliance with clear milestones. The weeks are indicative — the variable is how much of the data inventory already exists.
-
Weeks 1-4
Data mapping and gap analysis
Find out what you process before deciding what to build.
- Inventory every personal data processing activity
- Document the legal basis and purpose for each
- Identify cross-border transfers already happening
- Assess the gap against PDPL as it stands
-
Weeks 5-8
Governance and policies
The framework the rest of the work hangs from.
- Appoint a DPO where one is required
- Draft the PDPL-aligned policy set
- Rewrite privacy notices and consent forms
- Establish the data subject rights procedure
-
Weeks 9-14
Security and controls
Where the duties stop being documents and start being controls.
- Implement the technical security measures
- Put the organisational safeguards in place
- Write and rehearse the breach procedure
- Evidence the security controls claimed
-
Weeks 15-18
Monitoring and continuous compliance
The stage most programmes skip, and the one SDAIA will ask about.
- Stand up compliance monitoring
- Train staff on the obligations that touch them
- Run vendor and processor due diligence
- Prepare the pack for an SDAIA inquiry
Penalties and enforcement
SDAIA's enforcement powers, and what a violation actually costs.
Up to SAR 5 million
Administrative fines, scaled to the severity of the violation.
- Severity-based penalties
- Multipliers for repeat violations
- Public disclosure of the violation
Up to 2 years imprisonment
For certain offences, on top of any administrative fine.
- Unlawful disclosure
- Processing without a legal basis
- Failure to notify a breach
SDAIA, through the NDMO
Investigation and enforcement powers, exercised on its own initiative as well as on complaint.
- Investigation powers
- Compliance audits
- Corrective action orders
Restrictions and reputation
The consequences that land before any fine is finalised.
- Suspension of operations
- Public enforcement notices
- Loss of customer trust
This is an actively enforced regime. SDAIA monitors compliance through audits, investigations and complaint responses, so readiness has to be a standing state rather than a project. Three numbers are worth committing to memory: 72 hours to notify a breach, 30 days to answer a rights request, and SAR 5 million as the administrative ceiling.
Complete PDPL policy repository
Ready-to-use data protection policy templates aligned to Saudi PDPL, and mapped across to GDPR and the other GCC privacy laws so one document set answers the region.
Core compliance
- Data Protection Policy
- Privacy Notice Template
- Consent Management Policy
- Legal Basis Documentation
- Record of Processing Activities
- DPO Appointment Charter
+ 3 more policies
Rights and transfers
- Data Subject Rights Procedure
- Access Request Process
- Deletion and Correction Policy
- Cross-Border Transfer Policy
- Third-Party Sharing Policy
- Data Portability Standards
+ 2 more policies
Security and breach
- Data Security Policy
- Breach Response Plan
- Incident Notification Procedure
- Retention and Deletion Policy
- Vendor Due Diligence
- Employee Training Programme
+ 2 more policies
How Saudi PDPL compares
The relationship between the regional regimes and the international one most programmes already run. The principles align; the thresholds, regulators and transfer conditions do not.
| Aspect | Saudi PDPL | GDPR | Bahrain PDPL | UAE PDPL |
|---|---|---|---|---|
| Scope | KSA and Saudi residents | EU and EEA data subjects | Bahrain and Bahraini residents | UAE and UAE residents |
| Enforcement from | 14 September 2024 | 25 May 2018 | 1 August 2019 | 2 January 2022 |
| Regulator | SDAIA, through the NDMO | National DPAs and the EDPB | PDPO | TDRA and local authorities |
| Maximum fine | SAR 5M | EUR 20M or 4% of turnover | BHD 20K | AED 5M |
| DPO requirement | Risk-based, in certain cases | Risk-based, mandatory for many | Optional but recommended | Risk-based |
| Consent standard | Explicit for sensitive data | Explicit for sensitive data | Explicit for sensitive data | Explicit for sensitive data |
| Cross-border | Adequate protection plus authorisation | Adequacy or safeguards | Notification to the PDPO | Adequate protection required |
| Breach notification | 72 hours to SDAIA | 72 hours to the DPA | 72 hours to the authority | Without undue delay |
| Best for | KSA market operations | EU market access | Bahrain operations | UAE market presence |
A programme operating across the Gulf should scope one compliance approach rather than four. Bahrain, Qatar and UAE share most of these principles with jurisdiction-specific nuances — the data mapping is common, and it is the expensive part.
Frequently asked questions
Scope, the DPO question, transfers, breach timing and how the PDPL treats automated decisions.
What is Saudi Arabia's PDPL?
The Personal Data Protection Law, the Kingdom's data privacy regulation, enacted by Royal Decree M/19 of 2021. Implementing regulations were issued in September 2023 and full enforcement began on 14 September 2024 after a transition period. It is regulated by the Saudi Data and Artificial Intelligence Authority, SDAIA, through the National Data Management Office.
Who does Saudi PDPL apply to?
Any organisation processing personal data within Saudi Arabia, and any organisation processing the personal data of Saudi residents wherever it is established. It covers controllers and processors alike, which means private companies, government entities and international organisations with Saudi operations or Saudi customers.
When do we need to appoint a Data Protection Officer?
Appointment is required where core activities involve large-scale processing of sensitive personal data, large-scale systematic monitoring, or where SDAIA determines it on a risk basis. Where it is not required, appointing one is still the cheapest way to have a single person who can answer a regulator without a week of internal archaeology.
How long does a PDPL implementation take?
Four to five months is typical, depending on the size of the organisation, the complexity of the processing and the privacy maturity already in place. Data mapping, the DPO decision, the policy set and the rights procedure belong in the first phases, because everything downstream is blocked until the inventory is trustworthy.
What are the requirements for cross-border data transfers?
A transfer out of the Kingdom needs either a destination SDAIA regards as offering an adequate level of protection, or an authorisation. Either way you need appropriate safeguards and documentation of the mechanism, the destination and the legal ground. Sector rules can impose a localisation requirement on top, and that is a separate question with a separate answer.
What is the breach notification timeline?
Notify SDAIA within 72 hours of becoming aware of a personal data breach that poses a risk to data subjects. Where the breach carries high risk, the individuals affected must be told as well. Every breach has to be documented whether or not it was notifiable — the register is what demonstrates the judgement was made rather than avoided.
What are the key data subject rights?
Seven: to be informed, of access, to correction, to deletion, to obtain their data in a usable format, to withdraw consent, and to object to decisions based solely on automated processing. Requests have to be answered within 30 days, with an audit trail behind the answer.
Do we need consent for all processing?
No. Consent is one legal basis among several, alongside contractual necessity, legal obligation, vital interests, public interest and legitimate interests. Explicit consent is required for sensitive personal data — health, biometric, genetic, religious, political. The work is choosing the right basis per purpose and recording why, not defaulting everything to consent.
How does the PDPL apply to automated decision-making and AI?
Individuals can object to a decision based solely on automated processing where it produces legal effects or significantly affects them, and you have to be able to describe the logic involved and offer human review. Worth taking seriously here in particular: the regulator enforcing the privacy law is the same authority setting national AI strategy, so an AI question can arrive attached to an ordinary privacy filing.
What are the penalties for a violation?
Administrative fines reach SAR 5 million depending on severity, and certain serious offences carry criminal penalties including imprisonment of up to two years. Beyond the figures there is suspension of operations, public disclosure of the violation, and the reputational cost that follows both.
How does Saudi PDPL compare to the GDPR?
It is recognisably in the same family — lawful basis, individual rights, security duties — but it is not a copy. The differences that matter are the authorisation route for cross-border transfers rather than adequacy decisions alone, a lower fine ceiling, and provisions written to sit inside the Saudi legal framework. A GDPR programme transfers most of its work here, and should not assume it transfers all of it.
How does the PDPL relate to the other GCC privacy laws?
It is part of a broader regional move toward stronger data protection. Bahrain, Qatar and the UAE each have their own regime, and the principles align closely while the thresholds, enforcement dates and regulators do not. Scope one assessment across the region and the shared data mapping does most of the work.
What does an iDharma PDPL assessment cover, and how long does it take?
It is scoped before you are charged. The variables are the size of the processing estate, whether a record of processing already exists, and whether models sit in a decision path. We tell you the shape of all three after a short scoping call.
Ready to achieve Saudi PDPL compliance?
Start with a gap assessment against every duty on this page — the processing record you owe, the seven rights, the transfers leaving the Kingdom and the 72-hour breach path.
This page is guidance on how we scope an assessment, not legal advice. The PDPL and its implementing regulations are published, and SDAIA issues its own guidance; where a scoping call turns on the wording, go to the source rather than to this page.