Skip to main contentChat with us

Saudi PDPL · Questions & Answers

The PDPL
FAQ

Twenty-four questions we actually get from boards, GCs, CISOs, and founders building for the Saudi market — answered plainly, against the law as amended and the regulations as they stand in June 2026.

Grouped by theme. For the law itself, start with What is the PDPL?

24questions answered
6themes covered
72hthe deadline to know

KSA PDPL (SDAIA) · Implementing & Transfer Regulations · Last reviewed June 2026

Applicability & scope

We never received a notice from SDAIA. Do we still have to comply?

Yes. The PDPL applies by operation of law, not by invitation — every entity processing the personal data of individuals in Saudi Arabia has been expected to comply since full enforcement began on 14 September 2024. SDAIA does not owe you a warning letter before a violation committee owes you a fine.

Who exactly must comply with the PDPL?

Any entity — public or private, of any size, in any sector, inside or outside the Kingdom — that processes personal data of individuals residing in Saudi Arabia. That includes companies, government bodies, non-profits, and professional firms. Foreign entities are covered extraterritorially and are expected to designate a representative in the Kingdom.

We are purely B2B. Does the PDPL really concern us?

Almost certainly. The law protects individuals, not consumer relationships: your employees, job candidates, business points of contact, directors named in contracts, and vendor staff are all data subjects. B2B narrows your processing inventory — it does not empty it.

We only process employee data. Are we in scope?

Fully. Names, salaries, national IDs, performance reviews, attendance logs, and medical certificates are personal data — some of it sensitive. HR processing needs the same legal-basis mapping, notices, security, and retention discipline as customer data.

Does the PDPL apply to paper records?

Yes, where physical records are organised and processed systematically — personnel files, signed contracts, visitor registers. Secure storage, retention limits, and destruction duties apply to the filing cabinet as much as the database.

Are IP addresses, device IDs, and cookies personal data under the PDPL?

Yes. Anything that can identify an individual directly or indirectly qualifies — online identifiers included. Analytics, advertising, and session data should be in your processing inventory with a documented legal basis like any other category.

Does the PDPL cover anonymised or pseudonymised data?

Truly anonymised data — not re-identifiable by any reasonably available means — is outside the law. Pseudonymised data is not: if a key or attribute combination links it back to a person, it remains personal data. In our reviews, most datasets described as anonymised turn out to be pseudonymised.

Controllers, processors & DPOs

We do not collect data directly. Does that mean we are not a controller?

Not necessarily. Controllership turns on who decides the purpose and means of processing, not on who runs the web form. If you receive personal data from group companies, partners, or data brokers and decide what happens to it, you are a controller with full obligations — including transparency to individuals you have never met.

What duties do processors carry under the PDPL?

Processors must process only on the controller’s documented instructions, secure the data, support data subject rights, and assist breach response. Both sides can be held accountable, which is why the controller-processor contract — the DPA — matters: it is where these duties become enforceable.

Do we need to appoint a Data Protection Officer?

Only on defined triggers: public entities processing at scale, controllers whose core activities involve large-scale regular and systematic monitoring of individuals, or core processing of sensitive data. If triggered, the appointment can be an internal employee or an external provider, and it is registered through SDAIA’s National Data Governance Platform. Our DPO as a Service guide covers the decision in depth.

Do small businesses have to register with SDAIA?

Registration is trigger-based, not size-based — it applies notably to public entities, controllers whose main activity is processing personal data, and controllers processing sensitive data. A small health-tech or background-screening firm can be squarely in the net while a larger trading business is not. Verify your position rather than assuming an SME exemption.

Data subject rights & consent

What rights can Saudi residents exercise against us?

Eight in practice: to be informed, to access their data, to obtain a copy, to correct it, to have it destroyed, to withdraw consent, to complain to SDAIA within 90 days, and to seek court-ordered compensation for harm. Each needs a workflow, not just a policy paragraph — see the rights section of our PDPL guide.

How fast must we answer a data subject request?

Plan for 30 days under the Implementing Regulations, with extension available only in defined cases. The clock covers verification, retrieval, and response — so intake routing and identity checks need to be designed for speed, not improvised per request.

A customer demands erasure, but tax law requires us to keep the records. Who wins?

The legal retention duty prevails — destruction rights yield to statutory obligations. The correct response is to document the retention basis, restrict the data to that purpose, and tell the requester plainly why full erasure is not available yet and when it will be.

Do we need separate consent for marketing?

Direct marketing generally needs its own informed, specific consent — bundled or implied consent does not meet the standard, and withdrawal must be as easy as the opt-in. The 2023 amendment’s legitimate-interest basis is narrow and does not behave like GDPR’s marketing workhorse, so EU-style soft-opt-in programmes usually need re-engineering for the Kingdom.

Transfers & localisation

Does the PDPL force us to store data inside Saudi Arabia?

Not as a blanket rule. The law regulates transfers rather than mandating localisation: data can leave the Kingdom through a lawful pathway under the Transfer Regulations — adequacy once SDAIA’s list lands, Saudi-form Standard Contractual Clauses, Binding Common Rules, or certification — with minimisation and, in defined cases, a transfer risk assessment. Sector regulators can be stricter, so check those too.

What counts as a cross-border transfer?

Any movement of personal data outside the Kingdom — including remote access from abroad, regional support teams, group shared services, and cloud regions outside KSA. Most organisations transfer far more than they realise; the transfer map is usually the most eye-opening artefact of a gap assessment.

We use EU Standard Contractual Clauses. Do they work for Saudi transfers?

No. Outbound transfers from the Kingdom must use the mechanisms in SDAIA’s Transfer Regulations — Saudi-form SCCs, Binding Common Rules, adequacy, or certification. EU SCCs remain useful precedent and may govern the EU-side leg of the same flow, but they do not create a lawful PDPL pathway.

Breaches, penalties & sector rules

What are the penalties for breaking the PDPL?

Administrative fines up to SAR 5 million per violation, doubled for repeat violations, issued by violation committees within SDAIA. Separately, unlawful disclosure of sensitive data — with intent to harm or for personal benefit — is a criminal offence carrying up to two years’ imprisonment and/or a SAR 3 million fine. Add the quieter costs: processing suspensions, failed enterprise deals, and compensation claims from harmed individuals.

When and how do we report a data breach?

Notify SDAIA within 72 hours of becoming aware of a breach that may harm personal data or data subjects, and notify affected individuals without undue delay where their rights or interests are at risk. The deadline is awareness-based — which makes detection capability and a drilled escalation path part of legal compliance, not just good security.

What happens if PDPL conflicts with another Saudi regulation?

The PDPL is the baseline for personal data; sector regimes — SAMA’s frameworks for financial entities, health-sector rules, NCA cybersecurity controls — can layer stricter or additional duties on top. In practice you comply with both: the stricter requirement usually wins on any given point, and your control set should be designed once to satisfy the union.

Building & evidencing the programme

We are GDPR compliant. How much PDPL work is actually left?

The operational machinery carries over — inventory, DSR workflow, breach process, vendor management. What remains is the legal localisation: consent-first basis mapping, Saudi-form notices, SDAIA registration and DPO filings where triggered, Transfer-Regulations pathways instead of EU paperwork, and the 72-hour clock pointed at SDAIA. Our PDPL vs GDPR comparison breaks down exactly what transplants and what must be rebuilt.

How do we demonstrate compliance if SDAIA — or a big customer — asks?

With artefacts, not assurances: a current RoPA, legal-basis register, published notices, DSR and breach logs with timestamps, DPIAs for high-risk processing, signed DPAs, transfer assessments, and training records. If those exist and are current, an enquiry is an exercise in retrieval; if not, it is an investigation.

Where do we find official PDPL guidance?

SDAIA publishes the law, the Implementing and Transfer Regulations, rules (such as DPO appointment), and evolving guidance via sdaia.gov.sa and the National Data Governance Platform — including, eventually, the cross-border adequacy list. Treat secondary commentary, this page included, as a map: the territory is SDAIA’s official text.

What is the fastest sensible path to PDPL compliance?

Sequence beats speed: a gap assessment to establish where you stand, remediation in risk order — notices, legal bases, RoPA, DSR and breach workflows, transfer safeguards, registrations — then an operating rhythm to keep it alive, whether in-house or through a virtual DPO. For most mid-size organisations that arc runs 6–12 weeks; what stretches it is entity count and cross-border complexity, not paperwork volume.

Continue your PDPL research

  • What is the PDPL? — the complete guide: timeline, definitions, principles, rights, and penalties.
  • PDPL gap assessment — when the questions turn into “where do we actually stand?”
  • PDPL vs GDPR — for teams arriving with an EU programme already built.
  • The PDPL hub — every guide and service in one place.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: June 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations