WaqiSecWaqiSec

Saudi PDPL vs GDPR: Key Differences and What GDPR-Compliant Companies Still Need

WaqiSec Compliance Team · Last reviewed:

SHORT ANSWER

The Saudi PDPL follows the same broad model as the EU GDPR (legal bases, data subject rights, breach notification, records and transfer controls), so a GDPR programme is a strong starting point. It is not enough on its own. The PDPL has a different sensitive data list, fewer rights, a 30-day response clock, a lower breach-reporting threshold to SDAIA, its own transfer instruments, registration on SDAIA's National Data Governance Platform for some controllers, and criminal penalties for unlawfully disclosing sensitive data.

Saudi lawPersonal Data Protection Law (PDPL), Royal Decree M/19 (1443H), amended by M/148 (1444H)
Saudi regulatorSaudi Data & AI Authority (SDAIA)
EU lawRegulation (EU) 2016/679 (GDPR)
PDPL fully enforceable14 September 2024
Rights responsePDPL: 30 days + up to 30 · GDPR: 1 month + up to 2 months
Breach noticeBoth 72 hours to the regulator, with different triggers
Max finesPDPL: SAR 5 million, doubled for repeats · GDPR: €20 million or 4% of worldwide turnover, whichever is higher
Criminal sanctionPDPL: up to 2 years and/or SAR 3 million for disclosing sensitive data with intent to harm or for personal benefit

PDPL vs GDPR comparison table

TopicSaudi PDPLEU GDPR
RegulatorSDAIANational supervisory authorities, coordinated by the EDPB
Territorial scopeProcessing in the Kingdom, and processing abroad of data relating to individuals in the KingdomEU establishment, or offering goods/services to or monitoring people in the EU
Legitimate interestAvailable since the 2023 amendments; not for sensitive data; documented assessment requiredAvailable (Art. 6(1)(f)) with balancing test
Sensitive dataIncludes criminal and security data and data showing that one or both parents are unknownIncludes trade union membership and sex life or sexual orientation; criminal data handled separately (Art. 10)
RightsInformation, access, copy, correction, destruction, withdraw consentAdds restriction, portability, objection and automated decision rights
Response deadline30 days, +30 with advance notice1 month, +2 months
Breach to regulator72 hours, when the breach may harm the data or individuals or conflict with their rights72 hours, unless unlikely to result in a risk
Breach to individualsWithout undue delay when it could harm themWithout undue delay when high risk
Records of processingAll controllers; kept for processing period + 5 yearsExemption below 250 employees, with exceptions
RegistrationSDAIA National Data Governance Platform for certain controllersNone
TransfersSDAIA SCCs (unmodifiable), binding common rules, accreditation; risk assessmentAdequacy, EU SCCs, BCRs; transfer impact assessment
Complaints window90 days from the incident (Regulations Art. 37); SDAIA may accept later complaints with a reasonable excuseNo fixed window in the GDPR
FinesUp to SAR 5 million, doubled for repeats; criminal sanction for sensitive data disclosureUp to €20 million or 4% of worldwide annual turnover, whichever is higher

Scope: who does each law cover?

The PDPL applies to any processing in Saudi Arabia, and to processing outside the Kingdom of personal data relating to individuals in the Kingdom (Article 2). There is no GDPR-style "targeting" test to argue about. If you hold data about people in Saudi Arabia, assume you are covered. The GDPR applies to EU-established organizations and to non-EU organizations that offer goods or services to, or monitor, people in the EU.

A Dubai or US company with Saudi customers can therefore fall under both laws at once, and needs to meet the stricter rule on each point.

Legal bases and consent

Both laws recognize consent, contract, legal obligation, vital interests, public tasks and legitimate interest. The PDPL added legitimate interest in its 2023 amendments, with limits set by Article 16 of the Implementing Regulations: it cannot be used for sensitive data, the individual's rights must not be overridden, and the assessment must be documented. Under both laws, withdrawing consent must be as easy as giving it.

For marketing, Article 29 of the Regulations requires consent before direct marketing, a clear sender identity and an easy opt-out. Do not import GDPR habits such as relying on the ePrivacy "soft opt-in" without checking that it holds in Saudi Arabia.

How do the sensitive data definitions differ?

The PDPL's list covers racial or ethnic origin, religious, intellectual or political belief, security and criminal data, biometric or genetic data used for identification, health data, and data indicating that one or both parents are unknown. The GDPR's special categories include trade union membership and data on sex life or sexual orientation, which the PDPL list does not name, and the GDPR handles criminal data under a separate article. Re-run your sensitive data mapping against the Saudi list instead of reusing the GDPR one.

Data subject rights and response deadlines

The PDPL gives fewer rights: no standalone right to object and no GDPR-style portability right. The clock is shorter at the long end: 30 days plus one 30-day extension, against the GDPR's one month plus two. Requests can be refused when they are unjustifiably repetitive or need extraordinary effort. Our guide to PDPL data subject requests has the full procedure.

Breach notification: same 72 hours, different trigger

Both laws use 72 hours from awareness. The difference is the threshold. The GDPR lets you skip notification if the breach is unlikely to result in a risk. The PDPL requires notice to SDAIA when a breach may harm the data or individuals or conflict with their rights or interests, and requires telling individuals whenever it could harm them, not only when the risk is high. Expect to notify more often in Saudi Arabia. See the PDPL 72-hour breach guide.

International transfers

EU SCCs do not work for data leaving Saudi Arabia. SDAIA has its own standard contractual clauses in four modules, and they cannot be edited except to fill in the blanks. The alternatives are binding common rules or a certificate of accreditation. A documented transfer risk assessment is required for transfers that rely on these tools and for continuous or large-scale transfers of sensitive data. Details are in our guide to PDPL cross-border transfers.

DPO, records, DPIA and registration

Penalties: which is stricter?

GDPR fines are larger: up to €20 million or 4% of worldwide annual turnover, whichever is higher. Under Article 36 the PDPL allows a warning or a fine of up to SAR 5 million, which can be doubled for repeat violations. The PDPL adds a criminal route the GDPR does not have: disclosing or publishing sensitive data with intent to harm the data subject or for personal benefit is punishable by up to two years in prison and/or a fine of up to SAR 3 million. Enforcement is active: on 16 January 2026 the Saudi Press Agency reported that SDAIA's committees had issued 48 decisions confirming violations over the previous year.

GDPR to PDPL gap checklist

If you already comply with the GDPR, these are the items most often missing:

Frequently Asked Questions

Is GDPR compliance enough for the Saudi PDPL?

No. A GDPR programme covers much of the ground, but the PDPL has its own sensitive data list, a 30-day rights clock, a lower breach-reporting threshold, SDAIA-specific transfer clauses, platform registration for some controllers and criminal penalties, so gaps remain.

Does the Saudi PDPL apply to companies outside Saudi Arabia?

Yes. Article 2 extends the PDPL to processing outside the Kingdom of personal data relating to individuals in the Kingdom.

Does the PDPL allow legitimate interest like the GDPR?

Yes, since the 2023 amendments, but it cannot be used for sensitive data, the individual's rights must not be overridden, and the assessment must be documented.

Is the breach notification deadline the same under the PDPL and GDPR?

Both use 72 hours from awareness, but the PDPL requires notice to SDAIA when a breach may cause harm or conflict with individuals' rights, which captures more incidents than the GDPR's risk-based test.

Can I use EU standard contractual clauses for transfers from Saudi Arabia?

No. Transfers out of the Kingdom need SDAIA's own standard contractual clauses, binding common rules or a certificate of accreditation, and SDAIA's clauses cannot be modified.

Which has higher fines, the PDPL or the GDPR?

GDPR fines are higher, up to €20 million or 4% of global turnover, whichever is higher. The PDPL allows fines up to SAR 5 million, doubled for repeats, and adds criminal penalties of up to two years in prison and/or SAR 3 million for disclosing sensitive data with intent to harm or for personal benefit.

Related guides

Sources

  1. SDAIA National Data Governance Platform — Personal Data Protection Law
  2. SDAIA National Data Governance Platform — Implementing Regulations
  3. EUR-Lex — Regulation (EU) 2016/679 (GDPR)
  4. Akin — Saudi Arabia approves amendments to the PDPL (2023)
  5. Addleshaw Goddard — Impact of the Regulations on the Saudi PDPL
  6. DLA Piper — Data Protection Laws: Saudi Arabia
  7. Mayer Brown — Updates to Saudi PDPL regulations, SCCs and guidelines (2024)
  8. Saudi Press Agency — SDAIA enforcement decisions (Jan 2026)

This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.

💬