WaqiSecWaqiSec

PDPL Records of Processing Activities (RoPA): What to Include and How to Structure the Template

WaqiSec Compliance Team · Last reviewed:

SHORT ANSWER

Under Article 31 of the Saudi PDPL and Article 33 of its Implementing Regulations, every controller must keep a written, accurate and up-to-date record of its personal data processing activities. The record must cover at least eight items: controller details, DPO details where one is required, purposes, categories of data and data subjects, retention periods, recipients, transfers outside the Kingdom and security measures. It must be kept for as long as the processing continues plus five years after it ends, and handed to SDAIA on request.

Legal basisPDPL Article 31; Implementing Regulations Article 33
Who must keep itThe controller (جهة التحكم)
FormWritten, accurate and kept up to date
Minimum content8 items listed in Article 33 (see the table below)
RetentionFor the whole processing period plus 5 years after the processing activity ends
Regulator accessMust be made available to SDAIA on request; no routine filing
Official helpSDAIA guideline on records of processing activities, with a template model
Penalty for gapsGeneral PDPL fines: warning or up to SAR 5 million, doubled for repeat violations

What is a record of processing activities under the PDPL?

A record of processing activities (RoPA) is an internal register that lists each way your organization uses personal data: why, about whom, which data, who receives it, where it goes and how long you keep it. In Arabic regulatory language it is سجل أنشطة معالجة البيانات الشخصية.

The duty sits in two places. Article 31 of the PDPL requires the controller to keep the record. Article 33 of the Implementing Regulations sets the detail: the minimum fields, the retention period and SDAIA's right to see it. Keep the two numbers apart, since some summaries cite "Article 31 of the Regulations" for this, which is a different provision.

The RoPA is also the base layer for most other PDPL documents. Your PDPL privacy notice, your transfer safeguards and your breach assessments all draw on the same facts. If the record is wrong, those documents are usually wrong too.

What must a PDPL RoPA include? The 8 Article 33 fields

Article 33 lists the minimum content. You can add more columns, but not fewer.

#Required field (Article 33)What to write in practice
1Controller name and contact detailsLegal entity name, address, a monitored privacy email
2Data Protection Officer details, where a DPO is requiredName or role and contact channel of the DPO
3Purposes of processingOne specific purpose per activity, such as "running payroll", not "HR purposes"
4Categories of personal data and categories of data subjectsE.g. ID number, IBAN, salary · employees and their dependants. Flag sensitive data
5Retention period for each data category, where possibleA period or a trigger ("7 years after end of employment"), with its reason
6Categories of recipientsInternal teams, processors, banks, government bodies
7Description of transfers outside the Kingdom, including the legal justification and the recipientsDestination country, recipient and the transfer mechanism relied on
8Organizational, administrative and technical security measures, where possibleAccess control, MFA, encryption, logging, staff training

SDAIA's guideline includes a template model. It is guidance, not a mandatory form, so you may use your own layout as long as it covers all eight fields.

RoPA template structure that works

The most usable RoPA is organized by processing activity, one row each. A row per system ("Salesforce", "Google Drive") hides the purpose, and the purpose is what the law asks about. A spreadsheet with these columns covers Article 33 and the questions SDAIA, auditors and enterprise clients usually ask next:

  1. Activity ID and name
  2. Business owner (department and person)
  3. Purpose
  4. Legal basis (consent, contract, legal obligation, vital interest, public interest or legitimate interest)
  5. Data subject categories
  6. Personal data categories, with a sensitive data flag
  7. Source of the data
  8. Systems and storage locations
  9. Recipients (internal and external)
  10. Processors used, and whether a data processing agreement is signed
  11. Transfers outside Saudi Arabia: country, recipient, mechanism
  12. Retention period and deletion method
  13. Security measures
  14. DPIA needed? (yes/no and reference)
  15. Date of last review

Columns 4, 7, 10, 14 and 15 go beyond the Article 33 minimum. They are worth the effort: the legal basis feeds your privacy notice, and the DPIA flag links the record to Article 25 of the Regulations, which requires an impact assessment for sensitive data and other higher-risk processing.

Worked example: one RoPA row

An illustrative entry for a mid-sized Saudi company's payroll activity:

ActivityMonthly payroll
OwnerHR manager
Purpose / legal basisPaying salaries and meeting employer obligations · contract and legal obligation
Data subjects / dataEmployees · name, national ID or Iqama number, IBAN, salary, attendance
RecipientsPayroll processor, the company's bank, government bodies where the law requires
TransfersPayroll SaaS hosted outside the Kingdom · SDAIA standard contractual clauses
RetentionSet per category based on labour and tax record-keeping rules, then secure deletion
SecurityRole-based access, MFA, encryption at rest, quarterly access review

How long must the record be kept?

Article 33 requires the record to be kept for as long as the processing continues, plus five years counted from the end of that processing activity. The clock runs from when the activity stops, not from when data was collected. If you retire a recruitment system in 2027, keep its RoPA entry until 2032.

In practice, never delete rows. Mark them "closed" with an end date so the five-year history stays visible.

Do processors and small companies need a RoPA?

How to build your PDPL RoPA in 6 steps

  1. List departments. HR, sales, marketing, customer service, finance, IT, operations.
  2. Interview each owner for 30–45 minutes. Ask what personal data they collect, why, in which tools, and who they send it to.
  3. Pull the system list from IT and finance. SaaS invoices reveal tools that interviews miss.
  4. Fill one row per activity and mark the sensitive data (health, biometric, genetic, criminal and security data, religious or political belief, ethnic origin).
  5. Check each transfer. Any tool hosted outside the Kingdom needs a transfer mechanism. See our guide to transferring personal data outside Saudi Arabia.
  6. Assign a review cycle. Update the record when a new tool, vendor or purpose is added, and review it in full at least once a year.

Common RoPA mistakes

PDPL RoPA checklist

The RoPA is one of the five core documents in our Saudi PDPL compliance guide.

Frequently Asked Questions

Is a record of processing activities mandatory under the Saudi PDPL?

Yes. Article 31 of the PDPL requires controllers to keep a record of processing activities, and Article 33 of the Implementing Regulations sets the minimum content, the retention period and SDAIA's right to request it.

What must a PDPL RoPA contain?

At least the controller's name and contact details, DPO details where a DPO is required, the purposes of processing, categories of personal data and data subjects, retention periods per data category, categories of recipients, transfers outside the Kingdom, and the organizational, administrative and technical security measures.

How long must the RoPA be kept in Saudi Arabia?

For as long as the processing activity continues, plus five years from the date the activity ends.

Do I have to submit my RoPA to SDAIA?

No routine submission is required. The controller must keep the record and provide it to SDAIA when SDAIA requests it.

Is there an official SDAIA RoPA template?

SDAIA has published a guideline on records of processing activities that includes a template model. It is guidance, so you can use your own format if it covers every field Article 33 requires.

Does a small company need a RoPA under the PDPL?

Yes. Unlike GDPR, the PDPL does not exempt organizations below a headcount threshold, so any controller processing personal data should keep a record.

Related guides

Sources

  1. Umm Al-Qura — PDPL Implementing Regulations (Arabic, Art. 33)
  2. SDAIA National Data Governance Platform — Implementing Regulations
  3. SDAIA National Data Governance Platform — Personal Data Protection Law (Art. 31)
  4. SDAIA — Guideline on records of personal data processing activities
  5. Akin — PDPL and Implementing Regulations: key obligations
  6. Saudi Press Agency — SDAIA enforcement decisions (Jan 2026)

This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.

💬