WaqiSecWaqiSec

PDPL Data Subject Rights: A 30-Day Procedure for Handling Access, Correction and Deletion Requests

WaqiSec Compliance Team · Last reviewed:

SHORT ANSWER

Under the Saudi PDPL, individuals can ask a controller to inform them, give them access to and a copy of their personal data, correct it, destroy it, or stop processing based on consent they withdraw. Article 3 of the Implementing Regulations requires the controller to act on each request within 30 days, extendable once by up to 30 more days with advance notice if the request needs unexpected effort or several requests arrive together. The controller must verify the requester's identity and keep a record of every request, including oral ones.

Rights in the lawPDPL Article 4 (information, access, copy, correction, destruction) and Article 5 (withdrawing consent)
Detailed rulesImplementing Regulations Articles 3–8 and 12
DeadlineWithout delay, within 30 days
ExtensionUp to 30 more days, with advance notice, if the request needs unexpected or unusual effort or the same person sends several requests
RefusalAllowed for unjustifiably repetitive requests or those needing extraordinary effort, with reasons given
Identity checkRequired before acting on a request
Record keepingDocument every request, including oral requests
GuardiansMay exercise the rights of minors and people lacking capacity (Regulations Articles 3 and 13)
ComplaintsTo SDAIA within 90 days of the incident (Regulations Article 37)

Which data subject rights does the PDPL give individuals?

Article 4 of the PDPL lists five rights, and Article 5 adds the right to withdraw consent. The Implementing Regulations then set out how each one works in practice.

RightWhere it sitsWhat you must do
To be informedLaw Art. 4 · Regulations Art. 4Tell people, before or at collection, who you are, your DPO contact, the purpose, how long you keep data and how to use their rights. This is your privacy notice.
AccessLaw Art. 4 · Regulations Art. 5Let the person see their personal data, as long as this does not harm others' rights such as intellectual property.
CopyLaw Art. 4 · Regulations Art. 6Provide a copy in a readable, clear format, normally a common electronic format, and on paper where feasible.
CorrectionLaw Art. 4 · Regulations Art. 7Correct, complete or update data. Restrict processing while you verify accuracy, and tell recipients who already received the data.
DestructionLaw Art. 4 · Regulations Art. 8Destroy data that is no longer needed, where consent was the only basis and is withdrawn, or where processing breaks the rules. Tell recipients and destroy all copies.
Withdraw consentLaw Art. 5 · Regulations Art. 12Withdrawal must be as easy as giving consent, or easier. Processing based on it stops; earlier lawful processing stays lawful.

How long do you have to respond to a PDPL data subject request?

Article 3 of the Implementing Regulations sets the clock:

The Regulations do not define the days; the safe reading is calendar days from receipt. If a request arrives through a channel nobody monitors, such as a sales rep's WhatsApp, the 30 days still run, which is why every customer-facing team needs to know where to forward requests.

The Regulations do not set a fee for handling requests. The safe practice is to handle them free of charge.

Can you refuse or limit a data subject request?

Yes, in narrow cases. Article 3 allows a controller to decline requests that are unjustifiably repetitive or that require extraordinary effort, and you must notify the individual with the reasons. Other limits come from the rights themselves:

Keep every refusal in writing. If the person complains to SDAIA, your file is your evidence.

Step-by-step data subject request procedure

  1. Day 0 · Log it. Record the date, channel, requester and the right being exercised. Oral requests count and must be documented.
  2. Days 0–3 · Verify identity. Ask for proportionate proof: matching the email or phone on file is often enough; ask for ID only when the data is sensitive. Do not collect more data than you need for the check.
  3. Days 1–10 · Search. The request owner checks every system listed in your records of processing activities, including processors.
  4. Day 20 · Decide on an extension. If you cannot finish, send the extension notice now, stating the new date (no more than 30 extra days).
  5. Before day 30 · Respond. Provide the copy, confirm the correction or destruction, or send a reasoned refusal.
  6. Same day · Tell recipients. For corrections and destruction, notify the parties you disclosed the data to.
  7. Close the file. Store the request, the evidence and your response in the request log.

Prepare five templates in Arabic and English: acknowledgment, identity request, extension notice, response, and reasoned refusal. Most missed deadlines happen because staff draft each reply from scratch.

Guardians, processors and third-party data

What the PDPL does not include compared with GDPR

Companies used to GDPR often over- or under-build. We found no general right to object and no GDPR-style right to data portability in the PDPL; the right to a copy in a common electronic format is the closest equivalent. The response window is also different: 30 days plus a 30-day extension under the PDPL, against one month plus up to two months under GDPR. Our PDPL vs GDPR comparison covers the rest.

Complaints to SDAIA

An individual who is unhappy with how you handled their data can complain to SDAIA. Article 37 of the Regulations sets a 90-day window from the date of the incident, and SDAIA may accept late complaints where there was a reasonable excuse. Violations can lead to a warning or a fine of up to SAR 5 million, doubled for repeat violations. On 16 January 2026 the Saudi Press Agency reported that SDAIA's committees had issued 48 decisions confirming PDPL violations over the previous year, so enforcement is under way.

Data subject request readiness checklist

Frequently Asked Questions

How long does a company have to respond to a data subject request in Saudi Arabia?

30 days. Under Article 3 of the PDPL Implementing Regulations, the period can be extended by up to 30 more days if the request needs unexpected or unusual effort or the same individual sent several requests, provided the individual is notified in advance.

What rights do individuals have under the Saudi PDPL?

The right to be informed, to access their personal data, to obtain a copy in a readable format, to request correction, to request destruction of data no longer needed, and to withdraw consent.

Can a company charge a fee for a PDPL access request?

The Implementing Regulations do not set a fee for data subject requests, so the safest practice is to handle them free of charge.

Can a company refuse a PDPL data subject request?

Yes, if the request is unjustifiably repetitive or needs extraordinary effort, with the reasons given to the individual. Access must also not harm other people's rights.

Does the Saudi PDPL include a right to data portability?

There is no standalone portability right as in GDPR. The closest equivalent is the right to receive a copy of personal data in a readable, commonly used electronic format.

How long does an individual have to complain to SDAIA?

Article 37 of the Implementing Regulations allows complaints within 90 days of the incident, and SDAIA may accept later complaints if there was a reasonable excuse.

Related guides

Sources

  1. Umm Al-Qura — PDPL Implementing Regulations (Arabic, Arts. 3–13, 37)
  2. SDAIA National Data Governance Platform — Implementing Regulations
  3. SDAIA National Data Governance Platform — Personal Data Protection Law (Arts. 4–5)
  4. Akin — PDPL and Implementing Regulations: key obligations
  5. Addleshaw Goddard — Impact of the Regulations on the Saudi PDPL
  6. CMS — Data protection and cybersecurity laws in Saudi Arabia
  7. Saudi Press Agency — SDAIA enforcement decisions (Jan 2026)

This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.

💬