The Personal Data Protection Law was enacted by Royal Decree M/19 of 2021, with implementing regulations in September 2023 and full enforcement from 14 September 2024. It is overseen by SDAIA through the National Data Management Office, which audits, investigates and fines.
In Saudi Arabia, your privacy regulator also sets the AI policy.
SDAIA runs both the data regulator and the AI authority, so an AI question can arrive attached to an ordinary privacy filing at any time.
Our promise
“Saying so is easy. Showing it is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditThe PDPL, in three chapters
Most programmes were written during the transition and never revisited once it ended. The eighth principle asks you to demonstrate compliance rather than assert it, and a record drafted from a questionnaire two years ago demonstrates nothing about the estate as it runs today.
We build the inventory from the systems inwards, test all eight principles and all seven rights the way somebody outside would have to exercise them, and answer the automated-decision question in writing - because the regulator asking it also sets the national AI strategy.
Whose data, not where you are.
Processing inside the Kingdom, and processing Saudi residents’ data from outside it, are both caught.
- Anyone processing personal data in the Kingdom
- Overseas entities holding residents’ data
- Controllers and processors, both directly
- Government bodies, healthcare and finance
- At collection - the notice comes first
- Within 72 hours of becoming aware of a breach
- Within 30 days of a rights request arriving
- Before data is transferred out of the Kingdom
The duty is yours. So is the AI question.
Anyone processing in the Kingdom
Any entity processing personal data within the territory of Saudi Arabia, as controller or as processor. Every duty on this page lands on you - the basis per purpose, the notices, the record, the rights route and the breach path - whoever actually runs the systems, and wherever in the world they run them.
Anyone processing residents’ data
Organisations established outside the Kingdom that process the personal data of Saudi residents. The test is whose data it is rather than where you are, which is the limb that overseas platforms and cloud vendors most often discover late, and usually discover expensively at the same time.
Your regulator also writes AI policy
SDAIA oversees data protection through the National Data Management Office and sets national AI strategy. It is the only Gulf regulator where those two sit in one authority - so an automated-decision question can arrive attached to an ordinary privacy filing, with no warning and no separate process.
“It is a privacy filing. AI is a separate thing.”
One authority. Expect one question.
It is the first thing we have to correct.
- Who it is for
- Banks & fintech
- Healthcare providers
- Government suppliers
- Retail & telecoms
- Cloud & AI vendors
The transition period ended on 14 September 2024. Audits, investigations and complaint responses have all been in active use since then.
SDAIA acts on its own initiative as well as on complaint, and a violation can be disclosed publicly. That last part is not a fine at all.
Bahrain, Qatar and the UAE each run their own regime. The principles align across all four of them and almost none of the thresholds do.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your scope check
Four clocks, and the first one already ran.
Each of these runs from an event you do not choose - so they cannot be added up, and they cannot be run in parallel.
-
Enforcement
Already runningFull enforcement began on 14 September 2024. The transition period is over, and audits and investigations are both in use.
-
Notify SDAIA
72 hoursFrom becoming aware of a personal data breach, not from the day the investigation closes or the cause is finally understood.
-
Answer the person
30 daysThe window for a rights request. What fails is almost never willingness - it is a search that does not reach every copy.
-
Demonstrate
ContinuouslyThe eighth principle is not an annual exercise. Records and notices have to describe the estate on the day, not when written.
Programmes written during the transition are still being maintained as though there is one. There is not: enforcement has been live since 14 September 2024, and a record of processing drafted two years ago describes an estate that no longer exists.
What the law says, what we ship
12 duties across the eight principles and the seven rights, each with what it produces.
- Lawfulness A basis per purpose
- A legal ground identified for each processing purpose rather than for each system, with the justification written down and the processing aligned to the purpose it was named for.
- Transparency Notices at collection
- What you tell people, in plain language rather than legal drafting, given where the data is actually handed over rather than linked from a footer.
- Purpose limitation Written before use
- Purposes defined before collection and a compatibility test for any new use - which is where secondary model training most often fails.
- Data minimisation Necessity per field
- A necessity assessment at field level, reviewed rather than assumed, so collection is proportionate to the purpose instead of to what the form can capture.
- Storage limitation Retention that runs
- A schedule per category with a deletion route that actually deletes, and a periodic review of what is still being held and why.
- Records of processing The first thing asked
- A record covering every purpose, category, recipient and transfer - built from the systems inwards rather than from a questionnaire outwards.
- Right to be informed Before it starts
- The privacy notice at the point of collection, with the purpose disclosed and the recipients identified rather than described in general terms.
- Access and correction 30-day window
- A documented request route a person outside can find, identity verification that works, and a correction that propagates to the third parties told earlier.
- Deletion and portability Reaching every copy
- A deletion route that checks the basis first and then reaches the backups, plus a structured machine-readable export where the data is asked for back.
- Withdrawal of consent As easy as giving
- A withdrawal mechanism as easy to use as the one that took the consent, which actually stops the processing rather than flagging the record.
- Automated decisions A human who can act
- A register of decisions made solely by automated processing, the logic explained, and a named human with the authority to change an outcome.
- Transfers and security Condition per route
- The condition relied on for each transfer out of the Kingdom, with the technical and organisational measures evidenced rather than asserted.
Personal data, independently reviewed
From the CRM to the model in the decision path.
-
Intake
Which systems hold Saudi personal data, and what each one is for.
-
Test
The eight principles and the seven rights against the estate as it runs.
-
Sign off and evidence
You see the draft first. Then the records, notices and drills - dated.
Why teams choose iDharma for their PDPL review
Rights tested from outside
Every one of the seven exercised from outside, the way a member of the public would have to.
The AI question, answered
Automated decisions read against the seventh right, because SDAIA will ask you about them.
Evidence, not attestation
Each principle tested where it is meant to bite, and every finding dated, owned and tracked.
The Gulf in one scope
Bahrain, Qatar and UAE obligations overlap enough to scope them all in the same review.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Saudi PDPL review report
The full review: what you process, on what basis, under which duty - and where each one is evidenced or is not, written principle by principle and right by right. Findings are ranked by consequence to people rather than by ease of fixing, with the automated-decision and transfer positions stated separately rather than folded in.
Processing inventory
Every purpose, category, recipient and transfer - built from the systems inwards rather than from a questionnaire sent round the business.
Lawful basis register
A ground identified per purpose with the justification beside it, so the record answers a question rather than restating that one was asked.
Privacy notice set
Notices per audience in plain language, placed where the data is actually handed over rather than linked from a page footer nobody opens.
Rights and breach runbooks
One intake route with identity verification and the thirty-day clock, plus a breach path written against the seventy-two-hour duty to SDAIA.
Automated decision register
Where a decision is made solely by machine: the logic explained, the human review route named, and the way to contest an outcome written down.
Policy template pack
The core set, the rights and consent set and the security and breach set - written to the PDPL rather than handed over as a generic pack.
Real numbers, upfront.
- Scope
- Set by the law
- Inputs
- Your systems and your records
- Re-review
- Every twelve months - $10,500 against your known baseline
The law fixed the duties, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request this review- All eight principles tested
- All seven rights, from outside in
- Automated decision register
- 26 policy templates, tailored
Four things you have to be able to produce
The PDPL is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.
The record,
current
A record of processing that matches what the systems do. It is the first thing a compliance audit opens, and the document every other position is argued out of.
The basis,
written
A legal ground identified per purpose rather than per system, with the justification recorded at the time rather than reconstructed under a regulator’s question.
The route,
findable
A rights route that a person outside can find without asking you, answering inside thirty days - and a breach path that reaches SDAIA inside the seventy-two hours.
The human,
named
For any decision made solely by automated processing: someone with the authority to change the outcome, reachable from outside, inside the response window.
Four cards, and the date on each one is part of the card.
Plain answers
What the law is, whether it reaches you, the clocks, and where AI lands. Answered straight.
Request this reviewWhat is Saudi Arabia’s PDPL?
The Kingdom’s data privacy regulation, enacted by Royal Decree M/19 of 2021. Implementing regulations were issued in September 2023 and full enforcement began on 14 September 2024. It is overseen by SDAIA through the National Data Management Office.
Who does the PDPL apply to?
Any organisation processing personal data within the Kingdom, as controller or processor - and organisations established outside it that process the personal data of Saudi residents. The test is whose data you process, not where you are established.
What is the breach notification timeline?
Seventy-two hours to notify SDAIA from becoming aware of a personal data breach - not from the day the investigation closes. Individual rights requests run to a separate thirty-day window.
How does the PDPL apply to automated decision-making and AI?
The seventh right is objection to a decision made solely by automated processing, which needs a named human with authority to change the outcome. Note the regulator: SDAIA also sets national AI strategy, so an AI question can arrive attached to an ordinary privacy filing.
What does an iDharma PDPL review cost, and what do we get?
A flat fee for the named engagement, agreed before anything is charged. What lands is the review report, the processing inventory, the lawful basis register, the notice set, the rights and breach runbooks, the automated decision register and the policy template pack.
Request your PDPL review
Tell us where the Saudi data lives and we come back with a call in a day.
What we need from you
Nothing you do not already have. Most of this comes out of a morning with your engineering, data and legal teams, and we tell you which extracts before you commit.
- Which systems hold Saudi personal data, and what for
- Whether you process inside the Kingdom, outside, or both
- Your record of processing, if one already exists
- Where any decision is made solely by machine
- Where data leaves the Kingdom, and on what condition
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- The Personal Data Protection Law and its regulations
- SDAIA, and the National Data Management Office
- Enacted
- Royal Decree M/19, 2021
- Enforced from
- 14 September 2024
What it means
- General information about what the law requires — not legal advice, and no professional relationship.
- Where a scope question is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- This reading has not been checked article by article against the law, so no article number appears anywhere on the page. For a citation, go to SDAIA’s own publication of the text.
- Do not rest a binding decision on it; engage qualified counsel, and use it as the start of a scoping conversation rather than as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom