Saudi PDPL Compliance Guide for Companies (2026) with a Practical Checklist
Saudi Arabia's Personal Data Protection Law (PDPL) applies to any organization that processes personal data of individuals in the Kingdom, including foreign companies. It has been in force since 14 September 2023 and fully enforceable since 14 September 2024. Core obligations include a privacy notice at collection, a legal basis for every processing activity, records of processing, answering data subject requests within 30 days, and notifying SDAIA of harmful breaches within 72 hours. Fines reach SAR 5 million and can be doubled for repeat violations.
| Official name | Personal Data Protection Law (نظام حماية البيانات الشخصية) |
|---|---|
| Legal basis | Royal Decree M/19 (1443H), amended by Royal Decree M/148 (1444H) |
| In force | 14 September 2023 |
| Fully enforceable | 14 September 2024 (after a one-year compliance period) |
| Regulator | Saudi Data & AI Authority (SDAIA) |
| Applies to | Processing in Saudi Arabia, and processing abroad of data about individuals in Saudi Arabia |
| Breach notice | To SDAIA within 72 hours when the breach may cause harm |
| Maximum fine | SAR 5 million per violation, doubled for repeat violations |
Who does the PDPL apply to?
The PDPL covers any processing of personal data that takes place in Saudi Arabia. It also covers processing outside the Kingdom when the data relates to individuals in Saudi Arabia. A company in Dubai, London or the US that collects data from Saudi customers is therefore in scope. Purely personal or family use is excluded.
"Personal data" means any information that identifies a person directly or indirectly: names, ID numbers, phone numbers, email addresses, location data, account details, photos and similar. Sector rules from regulators such as SAMA continue to apply alongside the PDPL.
Legal bases for processing
Every processing activity needs a legal basis. The PDPL and its Implementing Regulations recognize:
- Consent, which can be withdrawn at any time; processing must then stop without undue delay.
- Contract, where processing is needed to perform an agreement with the individual.
- Legal obligation, where a law requires the processing.
- Vital interests, to protect someone's life or health.
- Legitimate interest, which requires a documented assessment and cannot be used for sensitive data.
- Public tasks, for public entities.
Sensitive data needs explicit consent and extra care. It includes health data, genetic and biometric data used for identification, racial or ethnic origin, religious, intellectual or political beliefs, and criminal and security data.
Privacy notice requirements
You must tell individuals, at the time you collect their data, what you are doing with it. At a minimum your privacy notice should state:
- who you are and how to contact you;
- the purpose of the processing and its legal basis;
- what data you collect, and its source if you did not collect it directly;
- who you share it with, and whether it goes outside Saudi Arabia;
- how long you keep it;
- the individual's rights and how to exercise them, including the right to complain to SDAIA.
SDAIA has published guidance on privacy notices (see our privacy notice requirements guide). A notice copied from another country's law, or one dated before September 2024, is a common gap and one of the first things partners and regulators check.
Records of processing activities (RoPA)
Controllers must keep a record of their processing activities: what data, for what purpose, on which legal basis, who receives it, retention periods, transfers and security measures. The record must be kept for as long as the processing continues plus five years after it ends, and made available to SDAIA on request.
Data subject rights
Individuals have the right to:
- be informed about how their data is used;
- access their data and obtain a copy in a readable format;
- request correction, completion or updating;
- request destruction of data that is no longer needed;
- withdraw consent.
You must respond within 30 days, and the period can be extended by up to 30 more days in specific circumstances. A written procedure with owners and templates is the simplest way to meet these deadlines.
Breach notification
If a personal data breach may cause harm to the data or to individuals, you must notify SDAIA within 72 hours of becoming aware of it. If you can't meet the 72 hours, you must explain the delay. You must also inform affected individuals without undue delay, in clear and simple language, when the breach could harm them.
In practice this requires a breach response procedure prepared in advance (see our step-by-step breach notification guide). It should cover who assesses the breach, how severity is judged, who contacts SDAIA and what gets recorded.
DPO, impact assessments and registration
- Data Protection Officer: required when a public entity processes data on a large scale, or when your core activities involve regular, large-scale monitoring or processing of sensitive data. Other companies should still name an internal owner.
- Data protection impact assessment (DPIA): required for sensitive data processing and for processing likely to cause serious harm, such as new technologies or large-scale profiling.
- Registration on SDAIA's National Data Governance Platform: required for public entities, controllers whose main activity is data processing, and controllers processing sensitive data.
Transfers outside Saudi Arabia
Data may be transferred to countries with an adequate level of protection. At the time of writing, however, SDAIA has not published an adequacy list. Most companies therefore rely on appropriate safeguards:
- SDAIA's standard contractual clauses (used without modification);
- binding common rules for groups of companies; or
- an accreditation certificate.
A transfer risk assessment is required when relying on safeguards, and for continuous or large-scale transfers of sensitive data. SDAIA issued risk assessment guidelines in February 2025. Cloud tools, overseas support teams and group-level systems all count as transfers.
Direct marketing
Marketing messages to individuals need their prior consent and an easy way to opt out. Unsolicited marketing without consent is one of the violation types SDAIA has already acted on.
Penalties and enforcement
- Administrative: warnings or fines of up to SAR 5 million, which can be doubled for repeat violations.
- Criminal: disclosing or publishing sensitive data with intent to harm is punishable by up to 2 years in prison and/or a fine of up to SAR 3 million.
- Other: courts can order confiscation of proceeds and publication of the judgment, and individuals can claim compensation.
Enforcement is active. In January 2026 the Saudi Press Agency reported that SDAIA's committees had issued 48 decisions confirming violations. They involved processing or disclosure without a legal basis, inadequate security measures, and marketing messages sent without consent.
PDPL compliance checklist
- Map what personal data you collect, where it is stored and who can access it
- Identify a legal basis for each processing activity
- Publish a PDPL-compliant privacy notice (Arabic and English)
- Build and maintain records of processing activities (RoPA)
- Write a data subject rights procedure with a 30-day response workflow
- Write a breach response procedure covering SDAIA notice within 72 hours
- Check whether you need a DPO, a DPIA or platform registration
- List all transfers outside Saudi Arabia and put safeguards in place
- Collect and record marketing consent, with an easy opt-out
- Apply security controls: access control, MFA, encryption and backups
- Set retention periods and a destruction process
- Train staff who handle personal data
Frequently Asked Questions
When did the Saudi PDPL come into force?
The PDPL came into force on 14 September 2023 and became fully enforceable on 14 September 2024, after a one-year compliance period.
Does the PDPL apply to foreign companies?
Yes. It applies to processing outside Saudi Arabia when the personal data relates to individuals in the Kingdom.
How quickly must a data breach be reported?
Breaches that may cause harm must be reported to SDAIA within 72 hours of becoming aware of them, and affected individuals must be informed without undue delay.
What is the maximum PDPL fine?
Administrative fines reach SAR 5 million and can be doubled for repeat violations. Disclosing sensitive data with intent to harm can lead to up to 2 years in prison and/or a SAR 3 million fine.
Do all companies need a Data Protection Officer?
No. A DPO is mandatory for public entities processing data at large scale and for controllers whose core activities involve large-scale monitoring or sensitive data. Others should still assign an internal owner.
What documents do I need for PDPL compliance?
At minimum: a privacy notice, records of processing activities, a data subject rights procedure, a breach response procedure, and transfer safeguards where data leaves Saudi Arabia.
Related guides
Sources
- SDAIA — Saudi Data & AI Authority
- SDAIA — National Data Governance Platform
- DLA Piper — Data Protection Laws: Saudi Arabia
- CMS — One year of the Saudi PDPL
- Akin — PDPL and Implementing Regulations: key obligations
- Mayer Brown — Updates to Saudi PDPL regulations, SCCs and guidelines
- Clyde & Co — Saudi transfer risk assessment guidelines (2025)
- Clyde & Co — Enforcement of the Saudi PDPL (2026)
- Saudi Press Agency — SDAIA enforcement decisions (Jan 2026)
This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.