Saudi PDPL · The Foundation
Personal Data
Discovery & RoPA
You cannot protect — or evidence — data you have not mapped. TCSA’s discovery engagement builds the inventory, the flow maps, and the defensible RoPA that every other PDPL obligation stands on: breach response, data subject requests, transfers, and SDAIA scrutiny.
Accountability is a core PDPL principle: a controller must be able to produce its records of processing — not reconstruct them under deadline.
KSA PDPL (SDAIA) · Implementing & Transfer Regulations · Last reviewed June 2026
Direct Answer
What discovery actually produces
A discovery exercise produces three linked artefacts: a personal data inventory (what you hold and where), visual data-flow maps (how it moves through teams, systems, and third parties), and a legal-basis register tied to each activity. Together they roll up into the record of processing activities (RoPA) the PDPL requires controllers to maintain — covering purposes, data categories, recipients, cross-border transfers, and retention — and to produce to SDAIA on request.
Everything downstream depends on it. The 72-hour breach notification to SDAIA assumes you know which systems hold what; the 30-day data subject request window assumes you can find one person’s data across all of them; and with the PDPL fully enforced since 14 September 2024, administrative fines reach SAR 5 million per violation — doubled for repeat offences.
Legal specifics summarised here — RoPA scope, fine ceilings, notification windows — should be confirmed against SDAIA’s official publications before you rely on them.
The Self-Test
Five questions you should already be able to answer
If any of these makes you reach for “I’d have to check”, the processing landscape is not mapped — and neither the breach clock nor the DSR clock will pause while you map it mid-incident.
Which processing carries the greatest risk?
Sensitive categories, large volumes, profiling, public-facing products. Until every activity is inventoried, you are prioritising by instinct rather than evidence.
Where does data enter and exit?
Every collection point — forms, apps, recruitment, partner feeds — and every exit: vendors, group companies, regulators, and transfers out of the Kingdom.
How does it move once inside?
Across teams, systems, spreadsheets, and third parties. The undocumented copies and side-channels are exactly where breach response and DSR fulfilment fail.
Can you state purpose and basis per activity?
The PDPL expects each processing activity to have a stated purpose and a defensible legal basis. "It has always worked that way" is neither.
Could you demonstrate it to SDAIA?
Accountability under the PDPL means showing your records, not describing your intentions. A producible, current RoPA is the difference between the two.
How It Runs
Four phases, one living record
The same discipline Tranquility Cybersecurity brings to 500+ audits and assessments across 15+ countries, applied to discovery: structured, evidence-led, and built to hand over.
Stakeholder interviews
We sit with the people who actually own the data — marketing, HR, product, IT, finance, operations — and walk through what each function collects, why, where it sits, and who it is shared with. Undocumented and shadow processing surfaces here, by design.
Inventory & flow mapping
Findings become a structured inventory and visual data-flow maps across departments, systems, and vendors. Each flow is tagged with its purpose and legal basis — the exact fields that feed the RoPA: purposes, data categories, recipients, cross-border transfers, retention.
Validation against the PDPL
Every mapped activity is checked against the law and its Implementing Regulations: is the basis defensible, does a notice cover it, does the transfer have a lawful pathway, is retention defined? Mismatches are logged as flagged gaps for remediation — not buried in an appendix.
Keep-it-current cadence
Discovery is a snapshot; your organisation is not. We define refresh triggers — a new system, vendor, product, or market — plus periodic review cycles and named owners, so the inventory and RoPA stay producible instead of decaying into shelfware.
Deliverables
What you walk away with
Scoping and fees are confirmed on a short call — pricing depends on entity count, system landscape, and whether physical-records coverage is in scope. Gulf engagements are quoted in SAR, AED, or USD.
Data Discovery & RoPA — FAQs
What buyers ask before mapping anything.
What is a RoPA — and does the PDPL require one?
A RoPA (records of processing activities) is the controller’s structured register of what personal data it processes and how: purposes, data categories, recipients, cross-border transfers, and retention periods. Yes — maintaining it is a controller obligation under the PDPL’s accountability principle, and SDAIA can require you to produce it. Confirm the current formal requirements against SDAIA’s official publications, as guidance continues to evolve.
How is data discovery different from a PDPL gap assessment?
Discovery establishes the facts: what processing exists, where data lives, and how it flows — producing the inventory, flow maps, and RoPA. A gap assessment judges those facts against the law’s requirements and risk-ranks the shortfalls. They pair naturally: discovery gives the assessment something real to test. If you have neither, discovery — or a combined engagement — is the right starting point.
How do you handle shadow IT and systems nobody told you about?
By design. Interviews run across business functions, not just IT, and answers are triangulated — when marketing describes an export that IT has never heard of, that is a finding, not a failure. Where available we also review SSO logs, expense records, and vendor lists to surface unsanctioned SaaS. Unknown systems are precisely what the exercise exists to find.
How often should the inventory and RoPA be refreshed?
On triggers and on a cycle. Trigger events — a new system, vendor, product, or market — should update the affected entries immediately, and a periodic full review catches the drift in between. We set that cadence and name the owners in phase four, because an out-of-date RoPA is hard to defend as a record of anything.
Does discovery cover paper and physical records?
Yes. The PDPL applies to manual records processed systematically, not just databases — so HR filing cabinets, signed customer forms, and archived contracts are inventoried alongside systems, with location, access, and retention noted for each.
Continue your PDPL research
- The PDPL hub — the Saudi and UAE laws, obligations, and penalties in one place.
- PDPL gap assessment — test the mapped reality against every provision and get a risk-ranked register.
- PDPL implementation — turn the inventory and gap log into notices, workflows, and operating controls.
- DPO as a Service — ongoing ownership of the RoPA, DSRs, and SDAIA obligations once the foundation exists.
Written By Expert Auditors
Keep Exploring
Related Reading
PDPL Compliance (KSA & UAE)
Saudi Arabia's SDAIA-enforced privacy law and the UAE's federal PDPL.
Read morePDPL Gap Assessment
Identify gaps against PDPL requirements before a formal audit.
Read morePDPL Implementation
Phased roadmap for PDPL compliance across KSA and UAE operations.
Read moreWhat Is the PDPL?
Saudi and UAE Personal Data Protection Laws — scope, rights, penalties.
Read moreMiddle East — UAE & Saudi Arabia
How we serve Gulf banks, vendors and enterprises, remote + on-site.
Read moreDPDP Act Overview
India's Digital Personal Data Protection Act, explained.
Read moreGet in touch
Book a free consultation or send us your requirements. We respond within 24 hours.
Quick Call
Pick a time slot
Send Requirements
Get a custom quote in 24 hours