Do You Need a Data Protection Officer in Saudi Arabia? DPO Rules Under the PDPL
A Data Protection Officer (DPO) is mandatory under the Saudi PDPL in three cases set by Article 32 of the Implementing Regulations: a public entity providing services that involve large-scale processing of personal data; a controller whose core activities are based on processing that by its nature requires regular and systematic monitoring of individuals; or a controller whose core activities involve processing sensitive data. SDAIA's Rules for Appointing a Personal Data Protection Officer, published in August 2024, add the details. The DPO can be an employee or an external contractor, and the controller must give SDAIA the DPO's contact details through the National Data Governance Platform.
| Arabic term | مسؤول حماية البيانات الشخصية |
|---|---|
| Legal basis | PDPL Article 30(2); Implementing Regulations Article 32 |
| Detailed rules | SDAIA Rules for Appointing a Personal Data Protection Officer (published August 2024) |
| Mandatory cases | 3: large-scale public entity services, regular and systematic monitoring, sensitive data as core activity |
| Who can be DPO | An employee of the controller or an external contractor |
| Appointment | Documented in writing; staff informed |
| Notify SDAIA | DPO contact details through the National Data Governance Platform, kept up to date |
| SDAIA tool | Online tool to help determine whether a DPO is required |
When is a Data Protection Officer mandatory in Saudi Arabia?
Article 30(2) of the PDPL leaves it to the Implementing Regulations to set the cases in which a controller must appoint a DPO. Article 32 of the Regulations names three. Meeting any one of them is enough:
| # | Case | Applies to |
|---|---|---|
| 1 | A public entity that provides services involving the processing of personal data on a large scale | Government and public bodies only |
| 2 | Core activities based on processing operations that by their nature require regular and systematic monitoring of individuals | Any controller, private or public |
| 3 | Core activities based on processing sensitive personal data | Any controller, private or public |
Only the first case is limited to public bodies. A private company is caught by cases 2 and 3 if monitoring or sensitive data sits at the heart of what it does. Companies outside these cases may still appoint a DPO voluntarily.
What do "core activity" and "large scale" mean?
A core activity is processing that is central to your business model, not a support function. Every company processes staff data for payroll; that alone does not make HR data a core activity. A hospital processing patient health data, a ride-hailing app tracking passenger locations, or an adtech platform tracking users is different, because the business cannot run without that processing.
SDAIA's rules do not set a numeric threshold for large scale. Law-firm commentary on the rules (CMS) lists factors such as the number of individuals, the volume and type of data, the geographic reach and the variety of data subject categories. For "regular and systematic monitoring", the same commentary points to tracking technologies and monitoring at set intervals or through technical means, such as behavioral tracking, location tracking and connected devices.
Quick decision test, with examples
- Are you a public entity offering services that involve large-scale processing? If yes, appoint a DPO.
- Is processing sensitive data (health, genetic, biometric, criminal or security data, religious or political belief, ethnic origin) part of your core business? If yes, appoint a DPO.
- Does your core business depend on regular and systematic monitoring of people, for example through tracking, profiling or location data? If yes, appoint a DPO.
- None of the above? A DPO is not mandatory, but you still need a named owner for PDPL compliance.
| Example | Likely outcome | Why |
|---|---|---|
| Clinic group or medical lab | DPO required | Health data is sensitive and is the core activity |
| App that tracks users' location or behavior to sell targeted services | DPO likely required | Regular and systematic monitoring is the core activity |
| B2B software firm whose only personal data is staff and client contacts | DPO usually not required | No sensitive data or monitoring at the core |
| Retailer with a loyalty programme | Assess carefully | Depends on how far the programme profiles and tracks customers |
SDAIA offers an online tool on the National Data Governance Platform to help you check whether a DPO is required. Keep a short written record of your assessment either way.
Who can be the DPO? Employee or outsourced
The Implementing Regulations and SDAIA's rules allow the DPO to be one of the controller's own officials or employees, or an external contractor. The rules require the appointment to be made in writing and announced inside the organization.
On nationality and location, Clyde & Co noted that the Regulations do not specify whether a DPO must be based in the Kingdom, and the sources we reviewed do not set a nationality requirement. Check the current text of SDAIA's rules before appointing someone abroad, and make sure the DPO can deal with SDAIA in Arabic.
What does a DPO do under the PDPL?
Article 8 of SDAIA's DPO rules lists the DPO's tasks, including:
- advising the organization on PDPL compliance;
- running awareness and training;
- reviewing the personal data breach response plan;
- preparing periodic compliance reports;
- tracking regulatory updates;
- advising when new technical systems are developed.
In practice the DPO also usually owns the data subject request procedure and day-to-day contact with SDAIA.
The DPO also oversees the records of processing activities and impact assessments, which are usually the first documents a new DPO asks for.
Qualifications and independence
- Knowledge: relevant academic qualifications and experience in personal data protection, knowledge of the PDPL requirements, and enough risk management knowledge to handle breaches.
- Integrity: SDAIA's rules require honesty and integrity, with no conviction for a crime involving dishonour or breach of trust.
- Independence: under Article 9 of the rules, the controller must not give the DPO tasks that conflict with the role or affect their independence. A head of marketing or IT acting as DPO over their own processing is an obvious risk.
- Support: the controller must enable the DPO and provide the resources needed. The rules link the DPO organizationally to the controller's data management office, or to another department where there is none.
How to appoint a DPO: 6 steps
- Run the three-case test and record the result.
- Choose an internal or external DPO and check for conflicts of interest.
- Issue a written appointment that sets out duties, reporting line and resources.
- Tell staff and publish a contact channel, for example in your privacy notice.
- Submit the DPO's contact details to SDAIA through the National Data Governance Platform and update them on any change.
- Give the DPO a first-90-day plan: RoPA review, breach plan review, rights procedure and training.
If you don't need a DPO
Most small and mid-sized private companies will not meet the three cases. They still carry every other PDPL duty: privacy notice, records, breach notification within 72 hours, data subject requests within 30 days and lawful transfers. Name a privacy lead with clear authority, even if the role is part-time.
DPO checklist
- Written three-case assessment, kept on file
- DPO appointed in writing (if required), internal or external
- No conflicting role for the DPO
- Qualifications and integrity requirements checked
- DPO contact details registered with SDAIA and kept current
- Contact channel published to individuals
- Reporting line and resources defined
- Periodic compliance reports scheduled
Frequently Asked Questions
Is a Data Protection Officer mandatory in Saudi Arabia?
Only in three cases under Article 32 of the PDPL Implementing Regulations: a public entity providing services involving large-scale processing, a controller whose core activities are based on processing that by its nature requires regular and systematic monitoring of individuals, or a controller whose core activities involve processing sensitive data.
Can the DPO be outsourced in Saudi Arabia?
Yes. The DPO can be an employee or official of the controller or an external contractor, provided the appointment is documented and the DPO meets SDAIA's requirements.
Does the DPO have to be Saudi or based in Saudi Arabia?
The sources we reviewed do not set a nationality requirement, and law-firm commentary notes the Regulations do not specify that the DPO must be in the Kingdom. Check SDAIA's current rules before appointing someone abroad.
Do I have to register my DPO with SDAIA?
The controller must provide the DPO's contact details to SDAIA through the National Data Governance Platform and update them whenever they change.
What are the main duties of a DPO under the PDPL?
Monitoring PDPL compliance, advising the organization, training staff, reviewing the breach response plan, handling data subject requests, preparing compliance reports and acting as the contact point with SDAIA.
What if my company does not need a DPO?
You still have every other PDPL obligation. Name an internal privacy lead responsible for the privacy notice, records of processing, breach notification and data subject requests.
Related guides
Sources
- SDAIA — Rules for Appointing a Personal Data Protection Officer
- SDAIA — Tool for determining whether a DPO is required
- SDAIA National Data Governance Platform — Implementing Regulations (Art. 32)
- Saudi Press Agency — SDAIA publishes DPO appointment rules (Aug 2024)
- CMS — New SDAIA rules and guidelines as the PDPL becomes enforceable
- Clyde & Co — Saudi Arabia issues Implementing Regulations
This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.