Saudi PDPL vs GDPR: Key Differences and What GDPR-Compliant Companies Still Need
The Saudi PDPL follows the same broad model as the EU GDPR (legal bases, data subject rights, breach notification, records and transfer controls), so a GDPR programme is a strong starting point. It is not enough on its own. The PDPL has a different sensitive data list, fewer rights, a 30-day response clock, a lower breach-reporting threshold to SDAIA, its own transfer instruments, registration on SDAIA's National Data Governance Platform for some controllers, and criminal penalties for unlawfully disclosing sensitive data.
| Saudi law | Personal Data Protection Law (PDPL), Royal Decree M/19 (1443H), amended by M/148 (1444H) |
|---|---|
| Saudi regulator | Saudi Data & AI Authority (SDAIA) |
| EU law | Regulation (EU) 2016/679 (GDPR) |
| PDPL fully enforceable | 14 September 2024 |
| Rights response | PDPL: 30 days + up to 30 · GDPR: 1 month + up to 2 months |
| Breach notice | Both 72 hours to the regulator, with different triggers |
| Max fines | PDPL: SAR 5 million, doubled for repeats · GDPR: €20 million or 4% of worldwide turnover, whichever is higher |
| Criminal sanction | PDPL: up to 2 years and/or SAR 3 million for disclosing sensitive data with intent to harm or for personal benefit |
PDPL vs GDPR comparison table
| Topic | Saudi PDPL | EU GDPR |
|---|---|---|
| Regulator | SDAIA | National supervisory authorities, coordinated by the EDPB |
| Territorial scope | Processing in the Kingdom, and processing abroad of data relating to individuals in the Kingdom | EU establishment, or offering goods/services to or monitoring people in the EU |
| Legitimate interest | Available since the 2023 amendments; not for sensitive data; documented assessment required | Available (Art. 6(1)(f)) with balancing test |
| Sensitive data | Includes criminal and security data and data showing that one or both parents are unknown | Includes trade union membership and sex life or sexual orientation; criminal data handled separately (Art. 10) |
| Rights | Information, access, copy, correction, destruction, withdraw consent | Adds restriction, portability, objection and automated decision rights |
| Response deadline | 30 days, +30 with advance notice | 1 month, +2 months |
| Breach to regulator | 72 hours, when the breach may harm the data or individuals or conflict with their rights | 72 hours, unless unlikely to result in a risk |
| Breach to individuals | Without undue delay when it could harm them | Without undue delay when high risk |
| Records of processing | All controllers; kept for processing period + 5 years | Exemption below 250 employees, with exceptions |
| Registration | SDAIA National Data Governance Platform for certain controllers | None |
| Transfers | SDAIA SCCs (unmodifiable), binding common rules, accreditation; risk assessment | Adequacy, EU SCCs, BCRs; transfer impact assessment |
| Complaints window | 90 days from the incident (Regulations Art. 37); SDAIA may accept later complaints with a reasonable excuse | No fixed window in the GDPR |
| Fines | Up to SAR 5 million, doubled for repeats; criminal sanction for sensitive data disclosure | Up to €20 million or 4% of worldwide annual turnover, whichever is higher |
Scope: who does each law cover?
The PDPL applies to any processing in Saudi Arabia, and to processing outside the Kingdom of personal data relating to individuals in the Kingdom (Article 2). There is no GDPR-style "targeting" test to argue about. If you hold data about people in Saudi Arabia, assume you are covered. The GDPR applies to EU-established organizations and to non-EU organizations that offer goods or services to, or monitor, people in the EU.
A Dubai or US company with Saudi customers can therefore fall under both laws at once, and needs to meet the stricter rule on each point.
Legal bases and consent
Both laws recognize consent, contract, legal obligation, vital interests, public tasks and legitimate interest. The PDPL added legitimate interest in its 2023 amendments, with limits set by Article 16 of the Implementing Regulations: it cannot be used for sensitive data, the individual's rights must not be overridden, and the assessment must be documented. Under both laws, withdrawing consent must be as easy as giving it.
For marketing, Article 29 of the Regulations requires consent before direct marketing, a clear sender identity and an easy opt-out. Do not import GDPR habits such as relying on the ePrivacy "soft opt-in" without checking that it holds in Saudi Arabia.
How do the sensitive data definitions differ?
The PDPL's list covers racial or ethnic origin, religious, intellectual or political belief, security and criminal data, biometric or genetic data used for identification, health data, and data indicating that one or both parents are unknown. The GDPR's special categories include trade union membership and data on sex life or sexual orientation, which the PDPL list does not name, and the GDPR handles criminal data under a separate article. Re-run your sensitive data mapping against the Saudi list instead of reusing the GDPR one.
Data subject rights and response deadlines
The PDPL gives fewer rights: no standalone right to object and no GDPR-style portability right. The clock is shorter at the long end: 30 days plus one 30-day extension, against the GDPR's one month plus two. Requests can be refused when they are unjustifiably repetitive or need extraordinary effort. Our guide to PDPL data subject requests has the full procedure.
Breach notification: same 72 hours, different trigger
Both laws use 72 hours from awareness. The difference is the threshold. The GDPR lets you skip notification if the breach is unlikely to result in a risk. The PDPL requires notice to SDAIA when a breach may harm the data or individuals or conflict with their rights or interests, and requires telling individuals whenever it could harm them, not only when the risk is high. Expect to notify more often in Saudi Arabia. See the PDPL 72-hour breach guide.
International transfers
EU SCCs do not work for data leaving Saudi Arabia. SDAIA has its own standard contractual clauses in four modules, and they cannot be edited except to fill in the blanks. The alternatives are binding common rules or a certificate of accreditation. A documented transfer risk assessment is required for transfers that rely on these tools and for continuous or large-scale transfers of sensitive data. Details are in our guide to PDPL cross-border transfers.
DPO, records, DPIA and registration
- DPO: close to GDPR Article 37, with one difference: the GDPR covers every public authority (except courts acting in their judicial capacity), while Article 32 of the Regulations covers public entities whose services involve large-scale processing. Regular and systematic monitoring, or sensitive data as a core activity, triggers both laws. See our PDPL DPO guide.
- Records of processing: no small-company exemption, and the record itself must be kept for five years after processing ends.
- DPIA: Article 25 of the Regulations lists triggers, including sensitive data, combining datasets, systematic monitoring of people lacking capacity, new technologies and automated decisions.
- Registration: the GDPR has no general registration. Under the PDPL, SDAIA's register rules require certain controllers to register on the National Data Governance Platform; law-firm commentary lists public entities, controllers whose main activity is processing personal data and those processing sensitive data. Check the current criteria on the platform.
Penalties: which is stricter?
GDPR fines are larger: up to €20 million or 4% of worldwide annual turnover, whichever is higher. Under Article 36 the PDPL allows a warning or a fine of up to SAR 5 million, which can be doubled for repeat violations. The PDPL adds a criminal route the GDPR does not have: disclosing or publishing sensitive data with intent to harm the data subject or for personal benefit is punishable by up to two years in prison and/or a fine of up to SAR 3 million. Enforcement is active: on 16 January 2026 the Saudi Press Agency reported that SDAIA's committees had issued 48 decisions confirming violations over the previous year.
GDPR to PDPL gap checklist
If you already comply with the GDPR, these are the items most often missing:
- Arabic version of the privacy notice, reflecting Saudi rights and SDAIA as the complaint authority
- Sensitive data inventory re-mapped to the PDPL list
- Rights procedure switched to the 30 + 30 day clock
- Breach assessment criteria lowered to the PDPL "may cause harm" trigger, with SDAIA filing access arranged
- SDAIA SCCs signed for every transfer out of the Kingdom, with risk assessments filed
- Registration status checked on the National Data Governance Platform
- DPO need re-assessed under SDAIA's rules
- RoPA retention of 5 years after processing ends
- Marketing consent and opt-out reviewed against Article 29 of the Regulations
Frequently Asked Questions
Is GDPR compliance enough for the Saudi PDPL?
No. A GDPR programme covers much of the ground, but the PDPL has its own sensitive data list, a 30-day rights clock, a lower breach-reporting threshold, SDAIA-specific transfer clauses, platform registration for some controllers and criminal penalties, so gaps remain.
Does the Saudi PDPL apply to companies outside Saudi Arabia?
Yes. Article 2 extends the PDPL to processing outside the Kingdom of personal data relating to individuals in the Kingdom.
Does the PDPL allow legitimate interest like the GDPR?
Yes, since the 2023 amendments, but it cannot be used for sensitive data, the individual's rights must not be overridden, and the assessment must be documented.
Is the breach notification deadline the same under the PDPL and GDPR?
Both use 72 hours from awareness, but the PDPL requires notice to SDAIA when a breach may cause harm or conflict with individuals' rights, which captures more incidents than the GDPR's risk-based test.
Can I use EU standard contractual clauses for transfers from Saudi Arabia?
No. Transfers out of the Kingdom need SDAIA's own standard contractual clauses, binding common rules or a certificate of accreditation, and SDAIA's clauses cannot be modified.
Which has higher fines, the PDPL or the GDPR?
GDPR fines are higher, up to €20 million or 4% of global turnover, whichever is higher. The PDPL allows fines up to SAR 5 million, doubled for repeats, and adds criminal penalties of up to two years in prison and/or SAR 3 million for disclosing sensitive data with intent to harm or for personal benefit.
Related guides
Sources
- SDAIA National Data Governance Platform — Personal Data Protection Law
- SDAIA National Data Governance Platform — Implementing Regulations
- EUR-Lex — Regulation (EU) 2016/679 (GDPR)
- Akin — Saudi Arabia approves amendments to the PDPL (2023)
- Addleshaw Goddard — Impact of the Regulations on the Saudi PDPL
- DLA Piper — Data Protection Laws: Saudi Arabia
- Mayer Brown — Updates to Saudi PDPL regulations, SCCs and guidelines (2024)
- Saudi Press Agency — SDAIA enforcement decisions (Jan 2026)
This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.