Back to Frameworks
Frameworks

Saudi Protection of Personal Data (PDPL) (Saudi Arabia)

Framework Name

Saudi Arabia Personal Data Protection Law (PDPL)

Type

Mandatory

Region / Jurisdiction

Saudi Arabia (applies to any organization processing personal data of individuals located in the Kingdom, regardless of where the organization itself is based)

Enforcing Body / Certifying Party

Saudi Data and Artificial Intelligence Authority (SDAIA), designated as the law's competent authority for its first two years, with a possible future transfer to a new National Data Management Office depending on a government assessment of the data sector's maturity. As of today, that transfer hasn't happened, SDAIA remains the active regulator

Penalty / Consequence of Non-Compliance

Administrative fines up to SAR 5 million (roughly $1.33 million) per violation, doubling to SAR 10 million for repeat offenses. Unlawfully disclosing sensitive personal data carries separate criminal penalties, up to SAR 3 million and up to two years imprisonment, doubling for repeat violations. SDAIA can also suspend an organization's data processing activities entirely

What It Is & Why It Matters

Saudi Arabia's PDPL, enacted by Royal Decree in 2021 and fully in force since September 2023, is the Kingdom's comprehensive national data protection law, introduced as part of the broader Saudi Vision 2030 digital transformation strategy. It requires organizations to have a lawful basis for processing personal data, report breaches to SDAIA within 72 hours, and, for certain organizations, appoint a Data Protection Officer, mandatory for public entities, anyone processing sensitive personal data at scale, anyone handling cross-border data transfers, and anyone processing data belonging to children or vulnerable individuals. Cross-border transfers currently require SDAIA-approved standard contractual clauses, since a formal country-by-country adequacy list hasn't been published yet.

It matters because the compliance grace period that followed the law's launch has genuinely ended, and enforcement is no longer theoretical. SDAIA's specialized violation committees issued 48 confirmed enforcement decisions in the most recent review cycle, covering unlawful data collection, disclosure without legal justification, inadequate security measures, and unsolicited marketing without consent. Combined with real financial and criminal exposure, this is a law where "we'll get to it eventually" is no longer a defensible position for any organization handling Saudi residents' data.

Who Needs It

  • You process personal data of individuals located in Saudi Arabia, regardless of where your company is based
  • You need to transfer personal data out of Saudi Arabia and must put SDAIA-approved contractual safeguards in place
  • You process sensitive personal data, children's data, or data belonging to vulnerable individuals, all of which trigger a mandatory DPO requirement
  • You operate across the Gulf region and need to track Saudi PDPL alongside Bahrain's PDPL and Qatar's PIPL, each with its own specific requirements despite a broadly similar structure
Book A Demo