Saudi PDPL Privacy Policy Requirements: What Your Privacy Notice Must Include
Under Saudi Arabia's Personal Data Protection Law, a controller must publish a privacy policy before collecting personal data (Article 12) and tell individuals specific information at the moment of collection (Article 13). Together they must cover: who you are and how to contact you; the purpose and legal basis; what data you collect, and which fields are mandatory or optional; how data is collected, stored and destroyed; who receives it and whether it leaves Saudi Arabia; the consequences of not providing data; and the individual's rights, including complaining to SDAIA. SDAIA published a dedicated privacy policy guideline on 30 August 2024.
| Legal basis | PDPL Article 12 (privacy policy) and Article 13 (information at collection) |
|---|---|
| When | Policy available before collection; notice given upon collection |
| SDAIA guidance | Elaboration and Developing Privacy Policy Guideline (30 August 2024) |
| Language | No explicit Arabic requirement in the law; clear, readable language expected. Arabic + English is best practice in Saudi Arabia |
| Cookies | No specific Saudi cookie law; cookie data is still personal data under the PDPL |
| Penalty | Warning or fine up to SAR 5 million, doubled for repeat violations |
What the law requires
The PDPL has two transparency obligations that work together:
- Article 12 — privacy policy. The controller must have a privacy policy and make it available to data subjects before collecting their data. It must state the purpose of collection, the personal data collected, how the data is collected, processed, stored and destroyed, and the data subject's rights and how to exercise them.
- Article 13 — information at collection. When you collect data directly from a person, you must tell them the legal basis and purpose, and which data is mandatory or optional. You must also tell them who is collecting it, who it will be disclosed to and whether it will be transferred or processed outside the Kingdom, the consequences of not providing it, and their rights.
In practice most companies meet both with one well-structured privacy notice on the website or app, linked from every form that collects data.
Required contents: the full list
Combining Articles 12 and 13 with SDAIA's August 2024 guideline, your notice should include:
- Controller identity: your entity's name and activity, contact details, and your DPO's contact details if you have appointed one.
- Personal data collected: categories of data, and which items are mandatory and which are optional.
- Purpose of each processing activity.
- Legal basis for each purpose: consent, contract, legal obligation, legitimate interest and so on.
- How data is collected and the processing methods.
- Recipients: who you disclose data to and in what capacity.
- Transfers outside Saudi Arabia, if any.
- Retention and destruction: how long you keep data and how it is destroyed.
- Consequences of not providing data.
- Data subject rights: to be informed, to access, to obtain a copy in a clear and readable format, to correction, to destruction, to withdraw consent, to complain, and to claim compensation.
- How to exercise rights and your complaints mechanism, including the right to complain to SDAIA.
- Effective date and how you will communicate updates.
SDAIA's guideline also asks for clear, legible language in a suitable format, and periodic review of the policy.
A section-by-section structure you can follow
| Section | What to write |
|---|---|
| 1. Who we are | Legal name, activity, address, email, DPO contact |
| 2. Data we collect | Table of data categories, source, mandatory or optional |
| 3. Why we use it | Each purpose with its legal basis |
| 4. How we collect and process it | Forms, apps, cookies, third parties; how it is stored and secured |
| 5. Who we share it with | Categories of recipients and why |
| 6. Transfers outside Saudi Arabia | Countries or regions and the safeguards used |
| 7. How long we keep it | Retention period per category and destruction method |
| 8. If you don't provide data | What happens (for example, the service cannot be delivered) |
| 9. Your rights | PDPL rights, how to request, response time (30 days), right to complain to SDAIA |
| 10. Marketing | Consent and how to opt out |
| 11. Changes | Effective date and how updates are notified |
Data you collect indirectly
If you receive personal data from a third party, such as a partner, a data provider or a group company, the Implementing Regulations require you to inform the individual without undue delay, including the source of the data. Law-firm commentary cites a 30-day limit for this. Build it into your onboarding and partner data flows.
Cookies, marketing, sensitive data and automated decisions
- Cookies: Saudi Arabia has no specific cookie law, but data collected through cookies and trackers is still personal data. Describe it in your notice, and use consent where it is your legal basis.
- Marketing: marketing messages need prior consent and an easy opt-out. Unsolicited marketing is one of the violation types SDAIA has already acted on.
- Sensitive data (for example health, biometric or genetic data): requires explicit consent and an impact assessment. Say so clearly in the notice.
- Automated decisions: if decisions are made solely by automated processing, the notice should disclose this, and an impact assessment is required.
7 common mistakes in Saudi privacy notices
- Copying a GDPR notice. The PDPL is not the GDPR. For example, it does not include the GDPR-style right to data portability or the GDPR framing of the right to object. It does give a right to obtain a copy of your data in a clear, readable format.
- No mention of SDAIA or the right to complain and claim compensation.
- No mandatory or optional distinction for data fields.
- Silence on transfers outside the Kingdom, even though cloud tools and overseas support teams count.
- No retention periods, or a vague "as long as necessary".
- A notice dated before September 2024, when the PDPL became fully enforceable.
- English only for an Arabic-speaking audience. This is not strictly required by law, but it undermines "clear and understandable".
PDPL privacy notice checklist
- Available before any data is collected, and linked from every form
- Controller name, activity and contact details (and DPO if appointed)
- Data categories, with mandatory and optional fields marked
- Purpose and legal basis for each processing activity
- Collection methods, including cookies and third-party sources
- Recipients and transfers outside Saudi Arabia
- Retention periods and destruction method
- Consequences of not providing data
- All PDPL rights, how to exercise them and the 30-day response time
- Right to complain to SDAIA and to claim compensation
- Marketing consent and opt-out
- Arabic and English versions, dated and reviewed periodically
Frequently Asked Questions
Is a privacy policy mandatory under the Saudi PDPL?
Yes. Article 12 requires controllers to have a privacy policy and make it available to data subjects before collecting their personal data.
What must a Saudi privacy notice include?
The controller's identity and contact details, the purpose and legal basis, the data collected (mandatory or optional), how it is collected, stored and destroyed, recipients and transfers outside Saudi Arabia, retention, consequences of not providing data, and the data subject's rights including complaining to SDAIA.
Does the privacy policy have to be in Arabic?
The PDPL does not explicitly require Arabic, but it expects clear, understandable language. Publishing Arabic and English versions is best practice for Saudi audiences.
Did SDAIA publish privacy policy guidance?
Yes. SDAIA published the Elaboration and Developing Privacy Policy Guideline on 30 August 2024.
Can I reuse my GDPR privacy policy?
Not as-is. The PDPL has different rights, legal bases and transfer rules, and a GDPR notice usually misses PDPL items such as the right to complain to SDAIA and the mandatory-or-optional data distinction.
Is there a cookie law in Saudi Arabia?
There is no specific Saudi cookie law, but personal data collected through cookies is covered by the PDPL and should be described in your privacy notice.
Related guides
Sources
- SDAIA — Elaboration and Developing Privacy Policy Guideline (PDF)
- SDAIA National Data Governance Platform — privacy policy guideline page
- Digital Policy Alert — SDAIA privacy policy guideline (30 Aug 2024)
- CMS — New SDAIA rules and guidelines as PDPL becomes enforceable
- Akin — PDPL and Implementing Regulations: key obligations
- Cleary Gottlieb — Saudi PDPL and Regulations come into effect
- DLA Piper — Data Protection Laws: Saudi Arabia
- PDPL Article 12 — privacy policy (text)
- PDPL Article 13 — collection from the data subject (text)
This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.