WaqiSecWaqiSec

Saudi PDPL Compliance Guide for Companies (2026) with a Practical Checklist

WaqiSec Compliance Team · Last reviewed:

SHORT ANSWER

Saudi Arabia's Personal Data Protection Law (PDPL) applies to any organization that processes personal data of individuals in the Kingdom, including foreign companies. It has been in force since 14 September 2023 and fully enforceable since 14 September 2024. Core obligations include a privacy notice at collection, a legal basis for every processing activity, records of processing, answering data subject requests within 30 days, and notifying SDAIA of harmful breaches within 72 hours. Fines reach SAR 5 million and can be doubled for repeat violations.

Official namePersonal Data Protection Law (نظام حماية البيانات الشخصية)
Legal basisRoyal Decree M/19 (1443H), amended by Royal Decree M/148 (1444H)
In force14 September 2023
Fully enforceable14 September 2024 (after a one-year compliance period)
RegulatorSaudi Data & AI Authority (SDAIA)
Applies toProcessing in Saudi Arabia, and processing abroad of data about individuals in Saudi Arabia
Breach noticeTo SDAIA within 72 hours when the breach may cause harm
Maximum fineSAR 5 million per violation, doubled for repeat violations

Who does the PDPL apply to?

The PDPL covers any processing of personal data that takes place in Saudi Arabia. It also covers processing outside the Kingdom when the data relates to individuals in Saudi Arabia. A company in Dubai, London or the US that collects data from Saudi customers is therefore in scope. Purely personal or family use is excluded.

"Personal data" means any information that identifies a person directly or indirectly: names, ID numbers, phone numbers, email addresses, location data, account details, photos and similar. Sector rules from regulators such as SAMA continue to apply alongside the PDPL.

Legal bases for processing

Every processing activity needs a legal basis. The PDPL and its Implementing Regulations recognize:

Sensitive data needs explicit consent and extra care. It includes health data, genetic and biometric data used for identification, racial or ethnic origin, religious, intellectual or political beliefs, and criminal and security data.

Privacy notice requirements

You must tell individuals, at the time you collect their data, what you are doing with it. At a minimum your privacy notice should state:

SDAIA has published guidance on privacy notices (see our privacy notice requirements guide). A notice copied from another country's law, or one dated before September 2024, is a common gap and one of the first things partners and regulators check.

Records of processing activities (RoPA)

Controllers must keep a record of their processing activities: what data, for what purpose, on which legal basis, who receives it, retention periods, transfers and security measures. The record must be kept for as long as the processing continues plus five years after it ends, and made available to SDAIA on request.

Data subject rights

Individuals have the right to:

You must respond within 30 days, and the period can be extended by up to 30 more days in specific circumstances. A written procedure with owners and templates is the simplest way to meet these deadlines.

Breach notification

If a personal data breach may cause harm to the data or to individuals, you must notify SDAIA within 72 hours of becoming aware of it. If you can't meet the 72 hours, you must explain the delay. You must also inform affected individuals without undue delay, in clear and simple language, when the breach could harm them.

In practice this requires a breach response procedure prepared in advance (see our step-by-step breach notification guide). It should cover who assesses the breach, how severity is judged, who contacts SDAIA and what gets recorded.

DPO, impact assessments and registration

Transfers outside Saudi Arabia

Data may be transferred to countries with an adequate level of protection. At the time of writing, however, SDAIA has not published an adequacy list. Most companies therefore rely on appropriate safeguards:

A transfer risk assessment is required when relying on safeguards, and for continuous or large-scale transfers of sensitive data. SDAIA issued risk assessment guidelines in February 2025. Cloud tools, overseas support teams and group-level systems all count as transfers.

Direct marketing

Marketing messages to individuals need their prior consent and an easy way to opt out. Unsolicited marketing without consent is one of the violation types SDAIA has already acted on.

Penalties and enforcement

Enforcement is active. In January 2026 the Saudi Press Agency reported that SDAIA's committees had issued 48 decisions confirming violations. They involved processing or disclosure without a legal basis, inadequate security measures, and marketing messages sent without consent.

PDPL compliance checklist

Frequently Asked Questions

When did the Saudi PDPL come into force?

The PDPL came into force on 14 September 2023 and became fully enforceable on 14 September 2024, after a one-year compliance period.

Does the PDPL apply to foreign companies?

Yes. It applies to processing outside Saudi Arabia when the personal data relates to individuals in the Kingdom.

How quickly must a data breach be reported?

Breaches that may cause harm must be reported to SDAIA within 72 hours of becoming aware of them, and affected individuals must be informed without undue delay.

What is the maximum PDPL fine?

Administrative fines reach SAR 5 million and can be doubled for repeat violations. Disclosing sensitive data with intent to harm can lead to up to 2 years in prison and/or a SAR 3 million fine.

Do all companies need a Data Protection Officer?

No. A DPO is mandatory for public entities processing data at large scale and for controllers whose core activities involve large-scale monitoring or sensitive data. Others should still assign an internal owner.

What documents do I need for PDPL compliance?

At minimum: a privacy notice, records of processing activities, a data subject rights procedure, a breach response procedure, and transfer safeguards where data leaves Saudi Arabia.

Related guides

Sources

  1. SDAIA — Saudi Data & AI Authority
  2. SDAIA — National Data Governance Platform
  3. DLA Piper — Data Protection Laws: Saudi Arabia
  4. CMS — One year of the Saudi PDPL
  5. Akin — PDPL and Implementing Regulations: key obligations
  6. Mayer Brown — Updates to Saudi PDPL regulations, SCCs and guidelines
  7. Clyde & Co — Saudi transfer risk assessment guidelines (2025)
  8. Clyde & Co — Enforcement of the Saudi PDPL (2026)
  9. Saudi Press Agency — SDAIA enforcement decisions (Jan 2026)

This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.

💬