Saudi Arabia flag

Saudi Arabia

Saudi Arabia Data Privacy Laws: PDPL Compliance Guide (2026)

By Recording Law Editorial TeamReviewed July 23, 202621 min read
Saudi Arabia Data Privacy Laws: PDPL Compliance Guide (2026)

Frequently Asked Questions

Who does the Saudi PDPL apply to?

The PDPL applies to all entities and individuals located within Saudi Arabia that process personal data by any means. It also applies extraterritorially to organizations outside the Kingdom that process personal data of individuals located in Saudi Arabia. International companies offering goods or services to Saudi residents, or monitoring their behavior, must comply even without a physical presence in the country.

When did full PDPL enforcement begin?

The PDPL entered into force on September 14, 2023. SDAIA granted a one-year compliance grace period, which expired on September 14, 2024. Full enforcement commenced on that date. As of early 2026, SDAIA had issued 48 cumulative enforcement decisions against organizations found in violation.

Who is the PDPL regulator: SDAIA or the NDMO?

SDAIA is the current and active regulator. The PDPL provides that SDAIA serves as the competent authority for the first two years after the law enters into force, with a possible transfer of enforcement responsibility to the National Data Management Office (NDMO) thereafter, subject to a government assessment of the data sector's maturity. As of May 2026, no formal transfer has been announced and SDAIA continues to lead enforcement.

What are the penalties for non-compliance with the PDPL?

Administrative fines reach up to SAR 5 million (approximately USD 1.33 million) for general violations, doubling to SAR 10 million for repeat violations. Criminal penalties for intentional disclosure of sensitive personal data include up to two years imprisonment and fines up to SAR 3 million, doubling to SAR 6 million and extended imprisonment for repeat criminal offenses. Courts may also order publication of judgments and confiscation of proceeds.

What is the breach notification deadline under the PDPL?

Controllers must notify SDAIA within 72 hours of becoming aware of a data breach that may harm personal data or data subjects' rights. There is no materiality threshold; all breaches meeting this description must be reported. Notifications are submitted through the National Data Governance Platform at dgp.sdaia.gov.sa.

How does the PDPL handle cross-border data transfers?

Transferring personal data outside Saudi Arabia requires meeting several conditions: the transfer must not prejudice national security or public order; the recipient country must provide adequate data protection as assessed by SDAIA; appropriate safeguards such as SDAIA-approved Standard Contractual Clauses must be in place; and the data transferred must be limited to the minimum necessary. For sensitive or large-scale transfers, a documented risk assessment following SDAIA's February 2025 Risk Assessment Guideline is mandatory.

Is PDPL consent different from GDPR consent?

There are significant differences. The PDPL places greater emphasis on consent as the default lawful basis. Legitimate interests cannot be used for sensitive personal data under the PDPL, which is stricter than the GDPR. The PDPL also includes a unique sensitive data category covering individuals whose parents are unknown. Criminal imprisonment is available under the PDPL for intentional sensitive data disclosure, which has no direct GDPR equivalent.

Do organizations need to appoint a Data Protection Officer?

DPO appointment is mandatory for public entities providing large-scale services involving personal data, organizations whose core activities involve regular and systematic monitoring of data subjects on a large scale, and organizations whose core activities involve large-scale processing of sensitive personal data. The DPO must be registered on SDAIA's National Data Governance Platform. Proposed 2025 amendments would consolidate DPO requirements into the Implementing Regulations.

What are the proposed 2025 amendments to the PDPL Implementing Regulations?

SDAIA opened a third public consultation on proposed amendments in April 2025, which closed May 27, 2025. The proposals would consolidate controller registration rules and DPO appointment rules into the Implementing Regulations (repealing the standalone instruments), simplify records of processing activity requirements, clarify direct marketing consent obligations, and revise breach notification definitions. The final amendments had not been published as of May 2026.

How does the Year of AI 2026 affect PDPL compliance?

Saudi Arabia declared 2026 its Year of AI. SDAIA's November 2025 AI Adoption Framework creates mandatory governance obligations for AI systems covering data governance, model accountability, transparency, human oversight, and risk management. AI systems that process personal data of Saudi residents must comply with both the PDPL and the AI Adoption Framework simultaneously. Organizations should assess whether AI tools they deploy trigger PDPL consent, DPIA, and data minimization requirements.

Updates

Light verification pass: confirmed PDPL full enforcement since September 14, 2024, SDAIA's continued status as active regulator, the continued absence of a published SDAIA adequacy list, and the November 2025 AI Adoption Framework remain current. The proposed third-consultation Implementing Regulation amendments remain unadopted and are described as pending. No factual changes required. Added internal links to the Standard Contractual Clauses, data localization, and Data Protection Officer requirement guides.

Full refresh: added 2026 enforcement track record (48 decisions), NDMO transition status, Year of AI context and SDAIA AI Adoption Framework, April 2025 third public consultation on Implementing Regulations amendments, February 2025 Risk Assessment Guideline detail, enforcement process (five-day response window), expanded cross-border transfer, sensitive data, and compliance checklist sections. Word count expanded from approximately 2,847 to approximately 5,800 words.

Initial publication: PDPL framework, SDAIA enforcement, data subject rights, breach notification, cross-border transfer rules, and penalties.

Sources and References

  1. SDAIA Laws and Regulations Portal(sdaia.gov.sa).gov
  2. National Data Governance Platform(dgp.sdaia.gov.sa).gov
  3. SDAIA Personal Data Breach Incidents Procedural Guide(sdaia.gov.sa).gov
  4. SDAIA Rules for Appointing Data Protection Officer(sdaia.gov.sa).gov
  5. SDAIA Regulation on Personal Data Transfer Outside the Kingdom(dgp.sdaia.gov.sa).gov
  6. SDAIA Risk Assessment Guideline for Transferring Personal Data Outside the Kingdom(dgp.sdaia.gov.sa).gov
  7. Saudi National Portal — Data Regulation and Cybersecurity(my.gov.sa).gov
  8. Istitlaa Platform — Proposed Amendments to PDPL Implementing Regulations(istitlaa.ncc.gov.sa).gov
  9. IAPP — Saudi PDPL First Anniversary: Amendments, Enforcement and Ongoing Developments(iapp.org)
  10. IAPP — Saudi Arabia Data Protection Authority Steps Up Enforcement(iapp.org)
  11. ICLG Data Protection Laws and Regulations Report 2025-2026: Saudi Arabia(iclg.com)
  12. Chambers Data Protection and Privacy 2026: Saudi Arabia(practiceguides.chambers.com)
  13. Clyde and Co — Enforcement of the Saudi PDPL is Live (March 2026)(clydeco.com)
  14. Clyde and Co — Saudi Arabia PDPL Third Public Consultation (May 2025)(clydeco.com)
  15. Clyde and Co — Update on Saudi Arabia Risk Assessment Guidelines for Cross-Border Transfers(clydeco.com)
  16. Dentons — Proposed Amendments to KSA PDPL Implementing Regulations (May 2025)(dentons.com)
  17. Dentons — Saudi Arabia Framework for Cross-Border Data Transfers(dentons.com)
  18. A and O Shearman — Enforcement of the Saudi Personal Data Protection Law(aoshearman.com)
  19. Global Privacy Blog — Active Enforcement of Saudi Arabia Privacy Regime (May 2026)(globalprivacyblog.com)
  20. Global Privacy Blog — KSA Issues New Data Transfer Risk Assessment Guidelines(globalprivacyblog.com)
  21. CMS Law — One Year Anniversary Saudi PDPL (September 2025)(cms-lawnow.com)
  22. Morgan Lewis — Guide to Registering as a Data Controller under Saudi PDPL(morganlewis.com)
  23. King and Spalding — International Personal Data Transfers under Saudi PDPL(kslaw.com)
  24. Akin Gump — KSA PDPL and Implementing Regulations: Key Obligations(akingump.com)
  25. U.S. Commercial Service — Saudi Arabia ICT Cross-Border Data Transfer Rules Under Enforcement(trade.gov).gov
  26. Bird and Bird — Saudi Arabia Public Consultation on Draft Changes to Data Protection Regulations(twobirds.com)
  27. DLA Piper Data Protection Laws of the World: Saudi Arabia(dlapiperdataprotection.com)
Share: