WaqiSecWaqiSec

Saudi PDPL Privacy Policy Requirements: What Your Privacy Notice Must Include

WaqiSec Compliance Team · Last reviewed:

SHORT ANSWER

Under Saudi Arabia's Personal Data Protection Law, a controller must publish a privacy policy before collecting personal data (Article 12) and tell individuals specific information at the moment of collection (Article 13). Together they must cover: who you are and how to contact you; the purpose and legal basis; what data you collect, and which fields are mandatory or optional; how data is collected, stored and destroyed; who receives it and whether it leaves Saudi Arabia; the consequences of not providing data; and the individual's rights, including complaining to SDAIA. SDAIA published a dedicated privacy policy guideline on 30 August 2024.

Legal basisPDPL Article 12 (privacy policy) and Article 13 (information at collection)
WhenPolicy available before collection; notice given upon collection
SDAIA guidanceElaboration and Developing Privacy Policy Guideline (30 August 2024)
LanguageNo explicit Arabic requirement in the law; clear, readable language expected. Arabic + English is best practice in Saudi Arabia
CookiesNo specific Saudi cookie law; cookie data is still personal data under the PDPL
PenaltyWarning or fine up to SAR 5 million, doubled for repeat violations

What the law requires

The PDPL has two transparency obligations that work together:

In practice most companies meet both with one well-structured privacy notice on the website or app, linked from every form that collects data.

Required contents: the full list

Combining Articles 12 and 13 with SDAIA's August 2024 guideline, your notice should include:

  1. Controller identity: your entity's name and activity, contact details, and your DPO's contact details if you have appointed one.
  2. Personal data collected: categories of data, and which items are mandatory and which are optional.
  3. Purpose of each processing activity.
  4. Legal basis for each purpose: consent, contract, legal obligation, legitimate interest and so on.
  5. How data is collected and the processing methods.
  6. Recipients: who you disclose data to and in what capacity.
  7. Transfers outside Saudi Arabia, if any.
  8. Retention and destruction: how long you keep data and how it is destroyed.
  9. Consequences of not providing data.
  10. Data subject rights: to be informed, to access, to obtain a copy in a clear and readable format, to correction, to destruction, to withdraw consent, to complain, and to claim compensation.
  11. How to exercise rights and your complaints mechanism, including the right to complain to SDAIA.
  12. Effective date and how you will communicate updates.

SDAIA's guideline also asks for clear, legible language in a suitable format, and periodic review of the policy.

A section-by-section structure you can follow

SectionWhat to write
1. Who we areLegal name, activity, address, email, DPO contact
2. Data we collectTable of data categories, source, mandatory or optional
3. Why we use itEach purpose with its legal basis
4. How we collect and process itForms, apps, cookies, third parties; how it is stored and secured
5. Who we share it withCategories of recipients and why
6. Transfers outside Saudi ArabiaCountries or regions and the safeguards used
7. How long we keep itRetention period per category and destruction method
8. If you don't provide dataWhat happens (for example, the service cannot be delivered)
9. Your rightsPDPL rights, how to request, response time (30 days), right to complain to SDAIA
10. MarketingConsent and how to opt out
11. ChangesEffective date and how updates are notified

Data you collect indirectly

If you receive personal data from a third party, such as a partner, a data provider or a group company, the Implementing Regulations require you to inform the individual without undue delay, including the source of the data. Law-firm commentary cites a 30-day limit for this. Build it into your onboarding and partner data flows.

Cookies, marketing, sensitive data and automated decisions

7 common mistakes in Saudi privacy notices

  1. Copying a GDPR notice. The PDPL is not the GDPR. For example, it does not include the GDPR-style right to data portability or the GDPR framing of the right to object. It does give a right to obtain a copy of your data in a clear, readable format.
  2. No mention of SDAIA or the right to complain and claim compensation.
  3. No mandatory or optional distinction for data fields.
  4. Silence on transfers outside the Kingdom, even though cloud tools and overseas support teams count.
  5. No retention periods, or a vague "as long as necessary".
  6. A notice dated before September 2024, when the PDPL became fully enforceable.
  7. English only for an Arabic-speaking audience. This is not strictly required by law, but it undermines "clear and understandable".

PDPL privacy notice checklist

Frequently Asked Questions

Is a privacy policy mandatory under the Saudi PDPL?

Yes. Article 12 requires controllers to have a privacy policy and make it available to data subjects before collecting their personal data.

What must a Saudi privacy notice include?

The controller's identity and contact details, the purpose and legal basis, the data collected (mandatory or optional), how it is collected, stored and destroyed, recipients and transfers outside Saudi Arabia, retention, consequences of not providing data, and the data subject's rights including complaining to SDAIA.

Does the privacy policy have to be in Arabic?

The PDPL does not explicitly require Arabic, but it expects clear, understandable language. Publishing Arabic and English versions is best practice for Saudi audiences.

Did SDAIA publish privacy policy guidance?

Yes. SDAIA published the Elaboration and Developing Privacy Policy Guideline on 30 August 2024.

Can I reuse my GDPR privacy policy?

Not as-is. The PDPL has different rights, legal bases and transfer rules, and a GDPR notice usually misses PDPL items such as the right to complain to SDAIA and the mandatory-or-optional data distinction.

Is there a cookie law in Saudi Arabia?

There is no specific Saudi cookie law, but personal data collected through cookies is covered by the PDPL and should be described in your privacy notice.

Related guides

Sources

  1. SDAIA — Elaboration and Developing Privacy Policy Guideline (PDF)
  2. SDAIA National Data Governance Platform — privacy policy guideline page
  3. Digital Policy Alert — SDAIA privacy policy guideline (30 Aug 2024)
  4. CMS — New SDAIA rules and guidelines as PDPL becomes enforceable
  5. Akin — PDPL and Implementing Regulations: key obligations
  6. Cleary Gottlieb — Saudi PDPL and Regulations come into effect
  7. DLA Piper — Data Protection Laws: Saudi Arabia
  8. PDPL Article 12 — privacy policy (text)
  9. PDPL Article 13 — collection from the data subject (text)

This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.

💬