SAUDI PDPL · SDAIA · FULLY ENFORCEABLE SINCE SEPTEMBER 2024

Saudi PDPL, under a regulator that also leads AI policy.

The Personal Data Protection Law sets data privacy obligations for anyone processing personal data in the Kingdom, and it has been fully enforceable since 14 September 2024. Saudi Arabia is also the Gulf jurisdiction most likely to ask AI-specific questions about an ordinary privacy filing, because the authority overseeing data protection is the same one setting national AI strategy.


A black legal binder with a brass plate and a red wax seal on a dark desk, beside a stamp bearing a set of scales Illustrative materials
One authority for data protection and for AI
SDAIA Records of processing Seven rights Cross-border transfers 72-hour breach duty

What is Saudi PDPL?

The Personal Data Protection Law is the Kingdom's data privacy regulation, enacted by Royal Decree M/19 of 2021. Implementing regulations were issued in September 2023 and full enforcement began on 14 September 2024. It is now live law rather than a transition: SDAIA conducts compliance audits and investigations, administrative fines reach SAR 5 million, and certain offences carry criminal exposure.

  • Regulator SDAIA, through the NDMO The same authority that sets national AI strategy, which is why an AI question can arrive attached to an ordinary privacy filing.
  • Enforcement Active since Sept 2024 The transition period is over. Audits, investigations and complaint responses are all in use.
  • Regionally One of four GCC regimes Bahrain, Qatar and the UAE each have their own. The principles align; the thresholds, regulators and transfer conditions do not.

Who needs to comply?

The test is whose personal data you process, not where you are established. Five populations are caught, and the last three are where sector rules start to bite on top.

  • Organisations in Saudi Arabia Any entity processing personal data within the territory of the Kingdom, as controller or as processor.
  • Processors of KSA resident data Organisations established outside the Kingdom that process the personal data of Saudi residents.
  • Government entities Public sector organisations handling citizen data, alongside the national data management framework.
  • Healthcare providers Medical facilities processing patient information, where sector rules sit on top of the general regime.
  • Financial institutions Banks and fintechs handling financial data, where localisation questions are usually answered by the sector regulator rather than by the PDPL alone.

Operating across the Gulf? The Bahrain, Qatar and UAE regimes share most of these principles and almost none of the thresholds. Scope one assessment across all four and the overlap does the work; scope four separately and you pay for the same data mapping every time.

How we help

How iDharma supports Saudi PDPL compliance

Six workstreams against the duties themselves, with records of processing treated as the obligation it is rather than as documentation hygiene.

Art. 7 · Art. 4

Personal data inventory and mapping

A complete record of processing activities: categories, purposes, legal bases and retention. Built from the systems inwards, which is how prompts, retrieval indexes and logs get onto it rather than being discovered later.

Art. 5-11 · Art. 27

Data subject rights management

Access, correction, deletion and portability request routes, tested from the outside in rather than described from the inside out, against the response window the law actually allows.

Art. 22 · Art. 23

Security and confidentiality controls

The technical and organisational measures documented where they are meant to bite, plus a breach procedure with a named decision-maker and a notification path that has been rehearsed rather than written.

Art. 32 · Art. 33

Cross-border transfer tracking

Where the data physically lands, the condition relied on, the authorisation position, and whether all three match what your privacy notice already says.

Art. 6 · Art. 12

Consent and legal basis documentation

The basis relied on for each purpose, and whether the record of it would survive a regulator asking. Including whether a withdrawal actually propagates downstream, which is where most consent records fail.

Art. 17 · Art. 29

DPO appointment and governance

Whether the appointment is required in your case, who holds it, and the accountability framework behind them, including the model estate a regulator with an AI remit is liable to ask about.

Hosting decisions are hard to retrofit. The general transfer position and any sector-specific localisation requirement are not the same question, and both belong in the architecture conversation rather than in the compliance review that follows it.

Coverage

Complete PDPL requirements coverage

The assessment tests against every PDPL control requirement, grouped into four families. Nothing in scope is left to a follow-up engagement.

26
PDPL control requirements
26
Covered by the assessment
100%
Coverage across all families
Lawfulness and transparency Legal basis per purpose, consent and withdrawal, and the transparency notices that go with them.
8 of 8 by the assessment
Data subject rights Information, access, correction, deletion, portability, withdrawal and objection to automated decisions.
7 of 7 by the assessment
Cross-border transfers Adequate protection, the authorisation position, safeguards and the sector localisation question.
5 of 5 by the assessment
Security and confidentiality Technical and organisational safeguards, the breach procedure and the notification path behind it.
6 of 6 by the assessment
Built for the Saudi regime

Scoped for Saudi PDPL compliance

SDAIA-ready documentation

The processing record produced as an artefact you can hand over, not described as something you could assemble.

Rights inside the window

Request routes with owners and a clock, so a 30-day response is a process rather than an escalation.

Transfer and localisation

The general position and the sector position answered separately, because they are separate questions.

Gulf-wide mapping

Tagged to the Bahrain, Qatar and UAE regimes for a programme that spans the region.

The principles

Eight key PDPL principles

The foundation for lawful processing, broadly common across the Gulf regimes. Each is stated here as something that produces evidence rather than something to agree with.

Lawfulness

Process personal data only on a valid legal ground.

  • A basis identified per purpose
  • The justification documented
  • Processing aligned to that purpose

Transparency

Tell people what you are doing with their data, before you do it.

  • Privacy notices at collection
  • Plain language, not legal drafting
  • Accessible where the data is given

Purpose limitation

Collect for specific, explicit purposes and resist secondary use.

  • Purposes defined before collection
  • No quiet scope creep
  • The purpose written down

Data minimisation

Limit collection to what the stated purpose actually needs.

  • A necessity assessment per field
  • Proportionate collection
  • Reviewed rather than assumed

Accuracy

Keep personal data accurate and current.

  • Verification at the point of entry
  • A working update mechanism
  • A correction process that propagates

Storage limitation

Retain only for as long as the purpose requires.

  • Retention schedules per category
  • Deletion that actually deletes
  • Periodic review of what is held

Confidentiality and security

Protect the data with appropriate technical and organisational measures.

  • Security controls, evidenced
  • Access restricted and reviewed
  • Encryption to a stated standard

Accountability

Be able to demonstrate compliance, not merely to assert it.

  • Documentation kept current
  • Evidence of compliance retained
  • Audit readiness as a standing state
Individual rights

Data subject rights under PDPL

Seven rights granted to individuals. We test each one from the outside in, because a right that exists in a policy and not in the request queue is a finding waiting to happen.

Right to be informed

Clear information about the processing, given at the point it starts.

  • Privacy notice at collection
  • Purpose disclosed
  • Recipients identified

Right of access

A person can ask what you hold about them, and be answered.

  • A documented request route
  • A 30-day response window
  • Identity verification that works

Right to correction

Inaccurate data corrected, and the correction passed on.

  • A correction workflow
  • Verification before change
  • Third parties notified

Right to deletion

Deletion when the legal basis for holding the data ceases.

  • A deletion request route
  • Legal basis checked first
  • Erasure that reaches backups

Right to obtain data

The data handed back in a form the person can actually use.

  • Structured export
  • Machine-readable format
  • Direct transmission where asked

Right to withdraw consent

Withdrawal as easy as giving consent was, without unpicking what came before.

  • A working withdrawal mechanism
  • The same ease as granting
  • Processing actually stops

Right to object to automated decisions

Objection to a decision made solely by automated processing. This is the right an AI programme is most likely to fail.

  • A human review route
  • The logic explained
  • A way to contest the outcome

The last of the seven is the one to test first if you run models in a decision path. It requires a named human with the authority to change an outcome, reachable by someone outside your organisation, within the response window — and that is a process question long before it is a model question.

The engagement

18-week implementation roadmap

A practical path to PDPL compliance with clear milestones. The weeks are indicative — the variable is how much of the data inventory already exists.

  1. Weeks 1-4

    Data mapping and gap analysis

    Find out what you process before deciding what to build.

    • Inventory every personal data processing activity
    • Document the legal basis and purpose for each
    • Identify cross-border transfers already happening
    • Assess the gap against PDPL as it stands
  2. Weeks 5-8

    Governance and policies

    The framework the rest of the work hangs from.

    • Appoint a DPO where one is required
    • Draft the PDPL-aligned policy set
    • Rewrite privacy notices and consent forms
    • Establish the data subject rights procedure
  3. Weeks 9-14

    Security and controls

    Where the duties stop being documents and start being controls.

    • Implement the technical security measures
    • Put the organisational safeguards in place
    • Write and rehearse the breach procedure
    • Evidence the security controls claimed
  4. Weeks 15-18

    Monitoring and continuous compliance

    The stage most programmes skip, and the one SDAIA will ask about.

    • Stand up compliance monitoring
    • Train staff on the obligations that touch them
    • Run vendor and processor due diligence
    • Prepare the pack for an SDAIA inquiry
Consequences

Penalties and enforcement

SDAIA's enforcement powers, and what a violation actually costs.

Administrative

Up to SAR 5 million

Administrative fines, scaled to the severity of the violation.

  • Severity-based penalties
  • Multipliers for repeat violations
  • Public disclosure of the violation
Criminal

Up to 2 years imprisonment

For certain offences, on top of any administrative fine.

  • Unlawful disclosure
  • Processing without a legal basis
  • Failure to notify a breach
Authority

SDAIA, through the NDMO

Investigation and enforcement powers, exercised on its own initiative as well as on complaint.

  • Investigation powers
  • Compliance audits
  • Corrective action orders
Knock-on

Restrictions and reputation

The consequences that land before any fine is finalised.

  • Suspension of operations
  • Public enforcement notices
  • Loss of customer trust

This is an actively enforced regime. SDAIA monitors compliance through audits, investigations and complaint responses, so readiness has to be a standing state rather than a project. Three numbers are worth committing to memory: 72 hours to notify a breach, 30 days to answer a rights request, and SAR 5 million as the administrative ceiling.

Policy templates

Complete PDPL policy repository

Ready-to-use data protection policy templates aligned to Saudi PDPL, and mapped across to GDPR and the other GCC privacy laws so one document set answers the region.

Core compliance

  • Data Protection Policy
  • Privacy Notice Template
  • Consent Management Policy
  • Legal Basis Documentation
  • Record of Processing Activities
  • DPO Appointment Charter

+ 3 more policies

Rights and transfers

  • Data Subject Rights Procedure
  • Access Request Process
  • Deletion and Correction Policy
  • Cross-Border Transfer Policy
  • Third-Party Sharing Policy
  • Data Portability Standards

+ 2 more policies

Security and breach

  • Data Security Policy
  • Breach Response Plan
  • Incident Notification Procedure
  • Retention and Deletion Policy
  • Vendor Due Diligence
  • Employee Training Programme

+ 2 more policies

In context

How Saudi PDPL compares

The relationship between the regional regimes and the international one most programmes already run. The principles align; the thresholds, regulators and transfer conditions do not.

Aspect Saudi PDPL GDPR Bahrain PDPL UAE PDPL
Scope KSA and Saudi residents EU and EEA data subjects Bahrain and Bahraini residents UAE and UAE residents
Enforcement from 14 September 2024 25 May 2018 1 August 2019 2 January 2022
Regulator SDAIA, through the NDMO National DPAs and the EDPB PDPO TDRA and local authorities
Maximum fine SAR 5M EUR 20M or 4% of turnover BHD 20K AED 5M
DPO requirement Risk-based, in certain cases Risk-based, mandatory for many Optional but recommended Risk-based
Consent standard Explicit for sensitive data Explicit for sensitive data Explicit for sensitive data Explicit for sensitive data
Cross-border Adequate protection plus authorisation Adequacy or safeguards Notification to the PDPO Adequate protection required
Breach notification 72 hours to SDAIA 72 hours to the DPA 72 hours to the authority Without undue delay
Best for KSA market operations EU market access Bahrain operations UAE market presence

A programme operating across the Gulf should scope one compliance approach rather than four. Bahrain, Qatar and UAE share most of these principles with jurisdiction-specific nuances — the data mapping is common, and it is the expensive part.

Questions

Frequently asked questions

Scope, the DPO question, transfers, breach timing and how the PDPL treats automated decisions.

1 Scope and timing
What is Saudi Arabia's PDPL?

The Personal Data Protection Law, the Kingdom's data privacy regulation, enacted by Royal Decree M/19 of 2021. Implementing regulations were issued in September 2023 and full enforcement began on 14 September 2024 after a transition period. It is regulated by the Saudi Data and Artificial Intelligence Authority, SDAIA, through the National Data Management Office.

Who does Saudi PDPL apply to?

Any organisation processing personal data within Saudi Arabia, and any organisation processing the personal data of Saudi residents wherever it is established. It covers controllers and processors alike, which means private companies, government entities and international organisations with Saudi operations or Saudi customers.

When do we need to appoint a Data Protection Officer?

Appointment is required where core activities involve large-scale processing of sensitive personal data, large-scale systematic monitoring, or where SDAIA determines it on a risk basis. Where it is not required, appointing one is still the cheapest way to have a single person who can answer a regulator without a week of internal archaeology.

How long does a PDPL implementation take?

Four to five months is typical, depending on the size of the organisation, the complexity of the processing and the privacy maturity already in place. Data mapping, the DPO decision, the policy set and the rights procedure belong in the first phases, because everything downstream is blocked until the inventory is trustworthy.

2 The duties themselves
What are the requirements for cross-border data transfers?

A transfer out of the Kingdom needs either a destination SDAIA regards as offering an adequate level of protection, or an authorisation. Either way you need appropriate safeguards and documentation of the mechanism, the destination and the legal ground. Sector rules can impose a localisation requirement on top, and that is a separate question with a separate answer.

What is the breach notification timeline?

Notify SDAIA within 72 hours of becoming aware of a personal data breach that poses a risk to data subjects. Where the breach carries high risk, the individuals affected must be told as well. Every breach has to be documented whether or not it was notifiable — the register is what demonstrates the judgement was made rather than avoided.

What are the key data subject rights?

Seven: to be informed, of access, to correction, to deletion, to obtain their data in a usable format, to withdraw consent, and to object to decisions based solely on automated processing. Requests have to be answered within 30 days, with an audit trail behind the answer.

Do we need consent for all processing?

No. Consent is one legal basis among several, alongside contractual necessity, legal obligation, vital interests, public interest and legitimate interests. Explicit consent is required for sensitive personal data — health, biometric, genetic, religious, political. The work is choosing the right basis per purpose and recording why, not defaulting everything to consent.

3 AI, the region and the engagement
How does the PDPL apply to automated decision-making and AI?

Individuals can object to a decision based solely on automated processing where it produces legal effects or significantly affects them, and you have to be able to describe the logic involved and offer human review. Worth taking seriously here in particular: the regulator enforcing the privacy law is the same authority setting national AI strategy, so an AI question can arrive attached to an ordinary privacy filing.

What are the penalties for a violation?

Administrative fines reach SAR 5 million depending on severity, and certain serious offences carry criminal penalties including imprisonment of up to two years. Beyond the figures there is suspension of operations, public disclosure of the violation, and the reputational cost that follows both.

How does Saudi PDPL compare to the GDPR?

It is recognisably in the same family — lawful basis, individual rights, security duties — but it is not a copy. The differences that matter are the authorisation route for cross-border transfers rather than adequacy decisions alone, a lower fine ceiling, and provisions written to sit inside the Saudi legal framework. A GDPR programme transfers most of its work here, and should not assume it transfers all of it.

How does the PDPL relate to the other GCC privacy laws?

It is part of a broader regional move toward stronger data protection. Bahrain, Qatar and the UAE each have their own regime, and the principles align closely while the thresholds, enforcement dates and regulators do not. Scope one assessment across the region and the shared data mapping does most of the work.

What does an iDharma PDPL assessment cover, and how long does it take?

It is scoped before you are charged. The variables are the size of the processing estate, whether a record of processing already exists, and whether models sit in a decision path. We tell you the shape of all three after a short scoping call.

Get started

Ready to achieve Saudi PDPL compliance?

Start with a gap assessment against every duty on this page — the processing record you owe, the seven rights, the transfers leaving the Kingdom and the 72-hour breach path.

This page is guidance on how we scope an assessment, not legal advice. The PDPL and its implementing regulations are published, and SDAIA issues its own guidance; where a scoping call turns on the wording, go to the source rather than to this page.