PDPL Data Subject Rights: A 30-Day Procedure for Handling Access, Correction and Deletion Requests
Under the Saudi PDPL, individuals can ask a controller to inform them, give them access to and a copy of their personal data, correct it, destroy it, or stop processing based on consent they withdraw. Article 3 of the Implementing Regulations requires the controller to act on each request within 30 days, extendable once by up to 30 more days with advance notice if the request needs unexpected effort or several requests arrive together. The controller must verify the requester's identity and keep a record of every request, including oral ones.
| Rights in the law | PDPL Article 4 (information, access, copy, correction, destruction) and Article 5 (withdrawing consent) |
|---|---|
| Detailed rules | Implementing Regulations Articles 3–8 and 12 |
| Deadline | Without delay, within 30 days |
| Extension | Up to 30 more days, with advance notice, if the request needs unexpected or unusual effort or the same person sends several requests |
| Refusal | Allowed for unjustifiably repetitive requests or those needing extraordinary effort, with reasons given |
| Identity check | Required before acting on a request |
| Record keeping | Document every request, including oral requests |
| Guardians | May exercise the rights of minors and people lacking capacity (Regulations Articles 3 and 13) |
| Complaints | To SDAIA within 90 days of the incident (Regulations Article 37) |
Which data subject rights does the PDPL give individuals?
Article 4 of the PDPL lists five rights, and Article 5 adds the right to withdraw consent. The Implementing Regulations then set out how each one works in practice.
| Right | Where it sits | What you must do |
|---|---|---|
| To be informed | Law Art. 4 · Regulations Art. 4 | Tell people, before or at collection, who you are, your DPO contact, the purpose, how long you keep data and how to use their rights. This is your privacy notice. |
| Access | Law Art. 4 · Regulations Art. 5 | Let the person see their personal data, as long as this does not harm others' rights such as intellectual property. |
| Copy | Law Art. 4 · Regulations Art. 6 | Provide a copy in a readable, clear format, normally a common electronic format, and on paper where feasible. |
| Correction | Law Art. 4 · Regulations Art. 7 | Correct, complete or update data. Restrict processing while you verify accuracy, and tell recipients who already received the data. |
| Destruction | Law Art. 4 · Regulations Art. 8 | Destroy data that is no longer needed, where consent was the only basis and is withdrawn, or where processing breaks the rules. Tell recipients and destroy all copies. |
| Withdraw consent | Law Art. 5 · Regulations Art. 12 | Withdrawal must be as easy as giving consent, or easier. Processing based on it stops; earlier lawful processing stays lawful. |
How long do you have to respond to a PDPL data subject request?
Article 3 of the Implementing Regulations sets the clock:
- 30 days to act on the request.
- One extension of up to 30 days if the request needs unexpected or unusual effort, or the same individual has sent several requests. You must tell the individual before the first 30 days run out.
The Regulations do not define the days; the safe reading is calendar days from receipt. If a request arrives through a channel nobody monitors, such as a sales rep's WhatsApp, the 30 days still run, which is why every customer-facing team needs to know where to forward requests.
The Regulations do not set a fee for handling requests. The safe practice is to handle them free of charge.
Can you refuse or limit a data subject request?
Yes, in narrow cases. Article 3 allows a controller to decline requests that are unjustifiably repetitive or that require extraordinary effort, and you must notify the individual with the reasons. Other limits come from the rights themselves:
- Access must not harm the rights of others, for example another customer's data or your intellectual property.
- Destruction does not override a legal duty to keep data, such as financial or employment records you must retain by law. Document the reason and the date when the data will be destroyed.
Keep every refusal in writing. If the person complains to SDAIA, your file is your evidence.
Step-by-step data subject request procedure
- Day 0 · Log it. Record the date, channel, requester and the right being exercised. Oral requests count and must be documented.
- Days 0–3 · Verify identity. Ask for proportionate proof: matching the email or phone on file is often enough; ask for ID only when the data is sensitive. Do not collect more data than you need for the check.
- Days 1–10 · Search. The request owner checks every system listed in your records of processing activities, including processors.
- Day 20 · Decide on an extension. If you cannot finish, send the extension notice now, stating the new date (no more than 30 extra days).
- Before day 30 · Respond. Provide the copy, confirm the correction or destruction, or send a reasoned refusal.
- Same day · Tell recipients. For corrections and destruction, notify the parties you disclosed the data to.
- Close the file. Store the request, the evidence and your response in the request log.
Prepare five templates in Arabic and English: acknowledgment, identity request, extension notice, response, and reasoned refusal. Most missed deadlines happen because staff draft each reply from scratch.
Guardians, processors and third-party data
- Guardians: under Articles 3 and 13 of the Regulations, the legal guardian of a minor or a person lacking full capacity may exercise their rights, acting in that person's interest. Verify the guardianship.
- Processors: the request reaches you, but the data may sit with a payroll provider or CRM vendor. Your processing agreements should oblige them to help you within a fixed time, for example 5 working days.
- Third-party data: redact other people's personal data from copies, such as names of colleagues in an email thread.
What the PDPL does not include compared with GDPR
Companies used to GDPR often over- or under-build. We found no general right to object and no GDPR-style right to data portability in the PDPL; the right to a copy in a common electronic format is the closest equivalent. The response window is also different: 30 days plus a 30-day extension under the PDPL, against one month plus up to two months under GDPR. Our PDPL vs GDPR comparison covers the rest.
Complaints to SDAIA
An individual who is unhappy with how you handled their data can complain to SDAIA. Article 37 of the Regulations sets a 90-day window from the date of the incident, and SDAIA may accept late complaints where there was a reasonable excuse. Violations can lead to a warning or a fine of up to SAR 5 million, doubled for repeat violations. On 16 January 2026 the Saudi Press Agency reported that SDAIA's committees had issued 48 decisions confirming PDPL violations over the previous year, so enforcement is under way.
Data subject request readiness checklist
- Written procedure approved by management, with a named owner
- Published request channels (email, form or app) in the privacy notice
- Request log that captures oral and written requests
- Proportionate identity verification steps
- 30-day tracker with a day-20 extension alert
- Arabic and English templates for each response type
- Processor contracts with a fixed assistance time
- Rules on redacting third-party data and on legal retention duties
- Consent withdrawal as easy as consent collection
- Annual test: run a mock request end to end
Frequently Asked Questions
How long does a company have to respond to a data subject request in Saudi Arabia?
30 days. Under Article 3 of the PDPL Implementing Regulations, the period can be extended by up to 30 more days if the request needs unexpected or unusual effort or the same individual sent several requests, provided the individual is notified in advance.
What rights do individuals have under the Saudi PDPL?
The right to be informed, to access their personal data, to obtain a copy in a readable format, to request correction, to request destruction of data no longer needed, and to withdraw consent.
Can a company charge a fee for a PDPL access request?
The Implementing Regulations do not set a fee for data subject requests, so the safest practice is to handle them free of charge.
Can a company refuse a PDPL data subject request?
Yes, if the request is unjustifiably repetitive or needs extraordinary effort, with the reasons given to the individual. Access must also not harm other people's rights.
Does the Saudi PDPL include a right to data portability?
There is no standalone portability right as in GDPR. The closest equivalent is the right to receive a copy of personal data in a readable, commonly used electronic format.
How long does an individual have to complain to SDAIA?
Article 37 of the Implementing Regulations allows complaints within 90 days of the incident, and SDAIA may accept later complaints if there was a reasonable excuse.
Related guides
Sources
- Umm Al-Qura — PDPL Implementing Regulations (Arabic, Arts. 3–13, 37)
- SDAIA National Data Governance Platform — Implementing Regulations
- SDAIA National Data Governance Platform — Personal Data Protection Law (Arts. 4–5)
- Akin — PDPL and Implementing Regulations: key obligations
- Addleshaw Goddard — Impact of the Regulations on the Saudi PDPL
- CMS — Data protection and cybersecurity laws in Saudi Arabia
- Saudi Press Agency — SDAIA enforcement decisions (Jan 2026)
This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.