Skip to main contentChat with us

Saudi PDPL · The Foundation

Personal Data
Discovery & RoPA

You cannot protect — or evidence — data you have not mapped. TCSA’s discovery engagement builds the inventory, the flow maps, and the defensible RoPA that every other PDPL obligation stands on: breach response, data subject requests, transfers, and SDAIA scrutiny.

Accountability is a core PDPL principle: a controller must be able to produce its records of processing — not reconstruct them under deadline.

4discovery phases
72hbreach notice to SDAIA
30dDSR response window

KSA PDPL (SDAIA) · Implementing & Transfer Regulations · Last reviewed June 2026

Direct Answer

What discovery actually produces

A discovery exercise produces three linked artefacts: a personal data inventory (what you hold and where), visual data-flow maps (how it moves through teams, systems, and third parties), and a legal-basis register tied to each activity. Together they roll up into the record of processing activities (RoPA) the PDPL requires controllers to maintain — covering purposes, data categories, recipients, cross-border transfers, and retention — and to produce to SDAIA on request.

Everything downstream depends on it. The 72-hour breach notification to SDAIA assumes you know which systems hold what; the 30-day data subject request window assumes you can find one person’s data across all of them; and with the PDPL fully enforced since 14 September 2024, administrative fines reach SAR 5 million per violation — doubled for repeat offences.

Legal specifics summarised here — RoPA scope, fine ceilings, notification windows — should be confirmed against SDAIA’s official publications before you rely on them.

The Self-Test

Five questions you should already be able to answer

If any of these makes you reach for “I’d have to check”, the processing landscape is not mapped — and neither the breach clock nor the DSR clock will pause while you map it mid-incident.

Which processing carries the greatest risk?

Sensitive categories, large volumes, profiling, public-facing products. Until every activity is inventoried, you are prioritising by instinct rather than evidence.

Where does data enter and exit?

Every collection point — forms, apps, recruitment, partner feeds — and every exit: vendors, group companies, regulators, and transfers out of the Kingdom.

How does it move once inside?

Across teams, systems, spreadsheets, and third parties. The undocumented copies and side-channels are exactly where breach response and DSR fulfilment fail.

Can you state purpose and basis per activity?

The PDPL expects each processing activity to have a stated purpose and a defensible legal basis. "It has always worked that way" is neither.

Could you demonstrate it to SDAIA?

Accountability under the PDPL means showing your records, not describing your intentions. A producible, current RoPA is the difference between the two.

How It Runs

Four phases, one living record

The same discipline Tranquility Cybersecurity brings to 500+ audits and assessments across 15+ countries, applied to discovery: structured, evidence-led, and built to hand over.

01

Stakeholder interviews

We sit with the people who actually own the data — marketing, HR, product, IT, finance, operations — and walk through what each function collects, why, where it sits, and who it is shared with. Undocumented and shadow processing surfaces here, by design.

02

Inventory & flow mapping

Findings become a structured inventory and visual data-flow maps across departments, systems, and vendors. Each flow is tagged with its purpose and legal basis — the exact fields that feed the RoPA: purposes, data categories, recipients, cross-border transfers, retention.

03

Validation against the PDPL

Every mapped activity is checked against the law and its Implementing Regulations: is the basis defensible, does a notice cover it, does the transfer have a lawful pathway, is retention defined? Mismatches are logged as flagged gaps for remediation — not buried in an appendix.

04

Keep-it-current cadence

Discovery is a snapshot; your organisation is not. We define refresh triggers — a new system, vendor, product, or market — plus periodic review cycles and named owners, so the inventory and RoPA stay producible instead of decaying into shelfware.

Deliverables

What you walk away with

Personal data inventory across systems, departments, and third parties
Visual data-flow maps showing where data enters, moves, and leaves the organisation
RoPA in SDAIA-ready form — purposes, data categories, recipients, cross-border transfers, and retention per activity
Legal-basis register mapping every processing activity to its lawful basis
Retention schedule inputs per data category, ready for policy work
Gap log of activities flagged for remediation — missing bases, undocumented transfers, orphaned data

Scoping and fees are confirmed on a short call — pricing depends on entity count, system landscape, and whether physical-records coverage is in scope. Gulf engagements are quoted in SAR, AED, or USD.

Data Discovery & RoPA — FAQs

What buyers ask before mapping anything.

What is a RoPA — and does the PDPL require one?

A RoPA (records of processing activities) is the controller’s structured register of what personal data it processes and how: purposes, data categories, recipients, cross-border transfers, and retention periods. Yes — maintaining it is a controller obligation under the PDPL’s accountability principle, and SDAIA can require you to produce it. Confirm the current formal requirements against SDAIA’s official publications, as guidance continues to evolve.

How is data discovery different from a PDPL gap assessment?

Discovery establishes the facts: what processing exists, where data lives, and how it flows — producing the inventory, flow maps, and RoPA. A gap assessment judges those facts against the law’s requirements and risk-ranks the shortfalls. They pair naturally: discovery gives the assessment something real to test. If you have neither, discovery — or a combined engagement — is the right starting point.

How do you handle shadow IT and systems nobody told you about?

By design. Interviews run across business functions, not just IT, and answers are triangulated — when marketing describes an export that IT has never heard of, that is a finding, not a failure. Where available we also review SSO logs, expense records, and vendor lists to surface unsanctioned SaaS. Unknown systems are precisely what the exercise exists to find.

How often should the inventory and RoPA be refreshed?

On triggers and on a cycle. Trigger events — a new system, vendor, product, or market — should update the affected entries immediately, and a periodic full review catches the drift in between. We set that cadence and name the owners in phase four, because an out-of-date RoPA is hard to defend as a record of anything.

Does discovery cover paper and physical records?

Yes. The PDPL applies to manual records processed systematically, not just databases — so HR filing cabinets, signed customer forms, and archived contracts are inventoried alongside systems, with location, access, and retention noted for each.

Continue your PDPL research

  • The PDPL hub — the Saudi and UAE laws, obligations, and penalties in one place.
  • PDPL gap assessment — test the mapped reality against every provision and get a risk-ranked register.
  • PDPL implementation — turn the inventory and gap log into notices, workflows, and operating controls.
  • DPO as a Service — ongoing ownership of the RoPA, DSRs, and SDAIA obligations once the foundation exists.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: June 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations