WaqiSecWaqiSec

Do You Need a Data Protection Officer in Saudi Arabia? DPO Rules Under the PDPL

WaqiSec Compliance Team · Last reviewed:

SHORT ANSWER

A Data Protection Officer (DPO) is mandatory under the Saudi PDPL in three cases set by Article 32 of the Implementing Regulations: a public entity providing services that involve large-scale processing of personal data; a controller whose core activities are based on processing that by its nature requires regular and systematic monitoring of individuals; or a controller whose core activities involve processing sensitive data. SDAIA's Rules for Appointing a Personal Data Protection Officer, published in August 2024, add the details. The DPO can be an employee or an external contractor, and the controller must give SDAIA the DPO's contact details through the National Data Governance Platform.

Arabic termمسؤول حماية البيانات الشخصية
Legal basisPDPL Article 30(2); Implementing Regulations Article 32
Detailed rulesSDAIA Rules for Appointing a Personal Data Protection Officer (published August 2024)
Mandatory cases3: large-scale public entity services, regular and systematic monitoring, sensitive data as core activity
Who can be DPOAn employee of the controller or an external contractor
AppointmentDocumented in writing; staff informed
Notify SDAIADPO contact details through the National Data Governance Platform, kept up to date
SDAIA toolOnline tool to help determine whether a DPO is required

When is a Data Protection Officer mandatory in Saudi Arabia?

Article 30(2) of the PDPL leaves it to the Implementing Regulations to set the cases in which a controller must appoint a DPO. Article 32 of the Regulations names three. Meeting any one of them is enough:

#CaseApplies to
1A public entity that provides services involving the processing of personal data on a large scaleGovernment and public bodies only
2Core activities based on processing operations that by their nature require regular and systematic monitoring of individualsAny controller, private or public
3Core activities based on processing sensitive personal dataAny controller, private or public

Only the first case is limited to public bodies. A private company is caught by cases 2 and 3 if monitoring or sensitive data sits at the heart of what it does. Companies outside these cases may still appoint a DPO voluntarily.

What do "core activity" and "large scale" mean?

A core activity is processing that is central to your business model, not a support function. Every company processes staff data for payroll; that alone does not make HR data a core activity. A hospital processing patient health data, a ride-hailing app tracking passenger locations, or an adtech platform tracking users is different, because the business cannot run without that processing.

SDAIA's rules do not set a numeric threshold for large scale. Law-firm commentary on the rules (CMS) lists factors such as the number of individuals, the volume and type of data, the geographic reach and the variety of data subject categories. For "regular and systematic monitoring", the same commentary points to tracking technologies and monitoring at set intervals or through technical means, such as behavioral tracking, location tracking and connected devices.

Quick decision test, with examples

  1. Are you a public entity offering services that involve large-scale processing? If yes, appoint a DPO.
  2. Is processing sensitive data (health, genetic, biometric, criminal or security data, religious or political belief, ethnic origin) part of your core business? If yes, appoint a DPO.
  3. Does your core business depend on regular and systematic monitoring of people, for example through tracking, profiling or location data? If yes, appoint a DPO.
  4. None of the above? A DPO is not mandatory, but you still need a named owner for PDPL compliance.
ExampleLikely outcomeWhy
Clinic group or medical labDPO requiredHealth data is sensitive and is the core activity
App that tracks users' location or behavior to sell targeted servicesDPO likely requiredRegular and systematic monitoring is the core activity
B2B software firm whose only personal data is staff and client contactsDPO usually not requiredNo sensitive data or monitoring at the core
Retailer with a loyalty programmeAssess carefullyDepends on how far the programme profiles and tracks customers

SDAIA offers an online tool on the National Data Governance Platform to help you check whether a DPO is required. Keep a short written record of your assessment either way.

Who can be the DPO? Employee or outsourced

The Implementing Regulations and SDAIA's rules allow the DPO to be one of the controller's own officials or employees, or an external contractor. The rules require the appointment to be made in writing and announced inside the organization.

On nationality and location, Clyde & Co noted that the Regulations do not specify whether a DPO must be based in the Kingdom, and the sources we reviewed do not set a nationality requirement. Check the current text of SDAIA's rules before appointing someone abroad, and make sure the DPO can deal with SDAIA in Arabic.

What does a DPO do under the PDPL?

Article 8 of SDAIA's DPO rules lists the DPO's tasks, including:

In practice the DPO also usually owns the data subject request procedure and day-to-day contact with SDAIA.

The DPO also oversees the records of processing activities and impact assessments, which are usually the first documents a new DPO asks for.

Qualifications and independence

How to appoint a DPO: 6 steps

  1. Run the three-case test and record the result.
  2. Choose an internal or external DPO and check for conflicts of interest.
  3. Issue a written appointment that sets out duties, reporting line and resources.
  4. Tell staff and publish a contact channel, for example in your privacy notice.
  5. Submit the DPO's contact details to SDAIA through the National Data Governance Platform and update them on any change.
  6. Give the DPO a first-90-day plan: RoPA review, breach plan review, rights procedure and training.

If you don't need a DPO

Most small and mid-sized private companies will not meet the three cases. They still carry every other PDPL duty: privacy notice, records, breach notification within 72 hours, data subject requests within 30 days and lawful transfers. Name a privacy lead with clear authority, even if the role is part-time.

DPO checklist

Frequently Asked Questions

Is a Data Protection Officer mandatory in Saudi Arabia?

Only in three cases under Article 32 of the PDPL Implementing Regulations: a public entity providing services involving large-scale processing, a controller whose core activities are based on processing that by its nature requires regular and systematic monitoring of individuals, or a controller whose core activities involve processing sensitive data.

Can the DPO be outsourced in Saudi Arabia?

Yes. The DPO can be an employee or official of the controller or an external contractor, provided the appointment is documented and the DPO meets SDAIA's requirements.

Does the DPO have to be Saudi or based in Saudi Arabia?

The sources we reviewed do not set a nationality requirement, and law-firm commentary notes the Regulations do not specify that the DPO must be in the Kingdom. Check SDAIA's current rules before appointing someone abroad.

Do I have to register my DPO with SDAIA?

The controller must provide the DPO's contact details to SDAIA through the National Data Governance Platform and update them whenever they change.

What are the main duties of a DPO under the PDPL?

Monitoring PDPL compliance, advising the organization, training staff, reviewing the breach response plan, handling data subject requests, preparing compliance reports and acting as the contact point with SDAIA.

What if my company does not need a DPO?

You still have every other PDPL obligation. Name an internal privacy lead responsible for the privacy notice, records of processing, breach notification and data subject requests.

Related guides

Sources

  1. SDAIA — Rules for Appointing a Personal Data Protection Officer
  2. SDAIA — Tool for determining whether a DPO is required
  3. SDAIA National Data Governance Platform — Implementing Regulations (Art. 32)
  4. Saudi Press Agency — SDAIA publishes DPO appointment rules (Aug 2024)
  5. CMS — New SDAIA rules and guidelines as the PDPL becomes enforceable
  6. Clyde & Co — Saudi Arabia issues Implementing Regulations

This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.

💬