Skip to content

PDPL in Saudi Arabia: what a business holding customer data has to do

Saudi Arabia’s Personal Data Protection Law has been in force since 14 September 2023 and the one-year grace period ended on 14 September 2024. It covers any processing of personal data in the Kingdom, and processing of residents’ data by entities outside it. Fines reach SAR 5,000,000, doubled on repetition.

Muhammad Abu Baker8 min read

If your business holds personal data about people in Saudi Arabia (customers, staff, suppliers’ contacts, enquiry forms), the Personal Data Protection Law applies to you now. It came into force on 14 September 2023, and the one-year period the Royal Decree gave controllers to bring their position into line ended on 14 September 2024. There is no open transition left to plan around.

Entry into force and the one-year period: Personal Data Protection Law, Royal Decree M/19 of 9/2/1443H as amended by M/148 of 5/9/1444H — consolidated text, Bureau of Experts at the Council of Ministers. Dates as stated by the regulator: SDAIA, Guide to the Personal Data Protection Law for controllers and processors.

Does the PDPL apply to my business?

Article 2 of the Law is broad on purpose. It applies to any processing of personal data relating to individuals that takes place in the Kingdom, by any means, and to the processing of personal data relating to individuals residing in the Kingdom, by any means, by any entity outside the Kingdom. The only carve-out is an individual processing data for purposes not exceeding personal or family use, and only so long as they do not publish it or disclose it to others.

Personal Data Protection Law, Royal Decree M/19 of 9/2/1443H as amended by M/148 of 5/9/1444H — consolidated text, Bureau of Experts at the Council of Ministers.

So there is no revenue threshold and no headcount threshold. A small distributor with a customer list is in scope on the same terms as a bank, and so is a supplier abroad who processes the data of people living here.

What does the Law actually require?

  • A privacy policy, adopted and made available to data subjects before their data is collected, with the contents the Law prescribes.
  • Telling people, at collection, the legal or practical basis and the purpose, and whether their data will be transferred, disclosed or processed outside the Kingdom.
  • Honouring data subject rights — to be informed, to access, to obtain their data in a readable and clear format, to have it corrected or completed, and to request its destruction, within 30 days, extendable once by a further 30 days where the work is unexpectedly heavy or the requests are numerous, and only if you tell the person in advance and give your reasons.
  • A written record of processing activities, kept accurate and current, produced to the regulator on request, and retained for as long as the processing runs plus five years from the date that activity ends. Eight items are required in it as a minimum, including retention periods per category of data and a description of every transfer outside the Kingdom with its legal basis and recipients.
  • A written, documented impact assessment where you process sensitive data; where you combine, compare or link two or more datasets from different sources; where your activity involves, at scale or repeatedly, data of people lacking legal capacity, continuous monitoring, emerging technologies or automated decisions; or where a product or service is likely to cause serious harm to privacy.
  • Security measures aligned with the controls issued by the National Cybersecurity Authority, or with recognised cybersecurity practice if those controls do not bind you.
  • Destroying personal data without delay once the purpose it was collected for has ended, including copies in your backups, with the exceptions the Law sets out for legal retention periods and live judicial proceedings.

Rights and the 30-day window: Implementing Regulation of the Personal Data Protection Law, SDAIA President's Decision 1516 of 19/2/1445H — text in Umm Al-Qura. (Art. 3) and Personal Data Protection Law, Royal Decree M/19 of 9/2/1443H as amended by M/148 of 5/9/1444H — consolidated text, Bureau of Experts at the Council of Ministers. (Art. 4). Records: Implementing Regulation of the Personal Data Protection Law, SDAIA President's Decision 1516 of 19/2/1445H — text in Umm Al-Qura. (Art. 33). Impact assessment: Implementing Regulation of the Personal Data Protection Law, SDAIA President's Decision 1516 of 19/2/1445H — text in Umm Al-Qura. (Art. 25). Security: Implementing Regulation of the Personal Data Protection Law, SDAIA President's Decision 1516 of 19/2/1445H — text in Umm Al-Qura. (Art. 23). Destruction: Personal Data Protection Law, Royal Decree M/19 of 9/2/1443H as amended by M/148 of 5/9/1444H — consolidated text, Bureau of Experts at the Council of Ministers. (Art. 18) and Implementing Regulation of the Personal Data Protection Law, SDAIA President's Decision 1516 of 19/2/1445H — text in Umm Al-Qura. (Art. 8). Privacy policy and notice at collection: Personal Data Protection Law, Royal Decree M/19 of 9/2/1443H as amended by M/148 of 5/9/1444H — consolidated text, Bureau of Experts at the Council of Ministers. (Arts. 12, 13).

Do I need a data protection officer?

Only in three cases, and they are narrower than they are usually reported. You must appoint or designate one where you are a public entity providing services that involve large-scale processing of personal data; where your core activities consist of processing that by its nature requires regular and systematic monitoring of data subjects; or where your core activities consist of processing sensitive personal data. The officer may be one of your own people, or an external contractor.

Implementing Regulation of the Personal Data Protection Law, SDAIA President's Decision 1516 of 19/2/1445H — text in Umm Al-Qura. (Art. 32).

What do I have to do if data leaks?

Notify SDAIA within 72 hours of becoming aware of the incident, where the incident would harm the personal data or the data subject, or conflict with their rights or interests. The notification has five required contents: a description of the incident including when it happened, how, and when you learned of it; the categories and actual or approximate number of people affected and the type of data; a description of the risks, the measures already taken and those planned to stop it recurring; whether the individuals have been or will be told; and contact details for you or your data protection officer.

Implementing Regulation of the Personal Data Protection Law, SDAIA President's Decision 1516 of 19/2/1445H — text in Umm Al-Qura. (Art. 24).

If you cannot supply one of those items inside 72 hours, supply it as soon as you can with your reasons for the delay. You must keep a copy of what you reported and document the remedial measures. Separately, the individuals themselves must be told without undue delay where the incident would harm their data or conflict with their rights or interests.

Implementing Regulation of the Personal Data Protection Law, SDAIA President's Decision 1516 of 19/2/1445H — text in Umm Al-Qura. (Art. 24).

Do I have to register with SDAIA?

Probably not, and this is where a lot of published advice is out of date. The Law originally required every controller to register on an electronic portal and allowed an annual fee of up to SAR 100,000. That was Article 32, and it was repealed outright by Royal Decree M/148. It is no longer the law, and the fee no longer exists.

Personal Data Protection Law, Royal Decree M/19 of 9/2/1443H as amended by M/148 of 5/9/1444H — consolidated text, Bureau of Experts at the Council of Ministers. — Article 32, "this article was repealed by Royal Decree M/148 of 5/9/1444H".

What replaced it is narrower. The Implementing Regulation leaves it to SDAIA to issue registration rules and to determine which controllers must register, and the rules for controllers inside the Kingdom make registration on the National Data Governance Platform mandatory in four cases only: the controller is a public entity; the controller’s main activity is based on personal data processing; the controller processes sensitive data; or an individual processes personal data for purposes exceeding personal or family use.

Implementing Regulation of the Personal Data Protection Law, SDAIA President's Decision 1516 of 19/2/1445H — text in Umm Al-Qura. (Art. 34); SDAIA, Rules Governing the National Register of Controllers Within the Kingdom (Art. 2).

What about data held outside the Kingdom?

Transferring personal data abroad, or disclosing it to a party abroad, is permitted for the purposes Article 29 sets out, subject to three conditions: no prejudice to national security or the Kingdom’s vital interests; a level of protection outside the Kingdom not less than the Law provides, assessed by SDAIA; and limiting the transfer to the minimum data needed. The Regulation now in force is the one issued by Decision 1840 and published on 1 September 2024. It replaced the 2023 version, so guidance written against the earlier text is stale.

Personal Data Protection Law, Royal Decree M/19 of 9/2/1443H as amended by M/148 of 5/9/1444H — consolidated text, Bureau of Experts at the Council of Ministers. (Art. 29); Regulation on Personal Data Transfer Outside the Kingdom, SDAIA President's Decision 1840 of 27/2/1446H, published 1 September 2024 — text in Umm Al-Qura.

Where you rely on an exemption from the adequacy or minimisation conditions, the transfer has to rest on appropriate safeguards (standard contractual clauses, binding common rules, or a certificate from a body licensed by SDAIA), and a transfer risk assessment must be carried out before the transfer, and before any continuous or large-scale transfer of sensitive data. Onward transfers by the foreign recipient stay subject to the Law.

Regulation on Personal Data Transfer Outside the Kingdom, SDAIA President's Decision 1840 of 27/2/1446H, published 1 September 2024 — text in Umm Al-Qura. (Arts. 4, 5, 7).

In practice this is a question about your software estate rather than about your contracts. Every SaaS tool that holds a customer name is a transfer, and it belongs in the record of processing activities with its legal basis named.

What are the penalties?

Two regimes. Disclosing or publishing sensitive personal data in violation of the Law, with intent to harm the data subject or to obtain a personal benefit, is a criminal offence: imprisonment for up to two years and a fine of up to SAR 3,000,000, or either one, prosecuted by the Public Prosecution before the competent court.

Personal Data Protection Law, Royal Decree M/19 of 9/2/1443H as amended by M/148 of 5/9/1444H — consolidated text, Bureau of Experts at the Council of Ministers. (Art. 35, as amended).

Everything else is administrative. Any other violation of the Law or its Regulations by a private natural or legal person is punishable by a warning, or a fine of up to SAR 5,000,000, decided by a committee of at least three members appointed by SDAIA’s President and graded by the type of violation, its gravity and its impact. In both regimes the fine may be doubled on repetition, even past the ceiling, but not beyond twice it. Decisions can be appealed to the competent court.

Personal Data Protection Law, Royal Decree M/19 of 9/2/1443H as amended by M/148 of 5/9/1444H — consolidated text, Bureau of Experts at the Council of Ministers. (Arts. 35, 36).

Most of this is a systems problem, not a document problem

A policy can be written in an afternoon. The obligations that actually bite are properties of the systems you run: deleting data when its purpose ends means something has to know when that is; answering an access request in 30 days means someone can find every copy of one person’s data; a record of processing activities is only accurate if it is maintained where the processing changes. If your customer data lives in four systems and a spreadsheet, none of those is answerable, and no amount of policy fixes it.

Our own privacy policy is written the same way, and is a fair illustration of the standard: it describes what the code actually does, verified against the code, rather than what a template says. If you are trying to work out what your systems would have to change, tell us what you run, or start with how we handle integration, which is usually where the copies of the same customer come from.

Written by

Muhammad Abu Baker

Founder & CEO

Builds and runs the systems behind the work here: integration, data and the infrastructure underneath both.

Muhammad Abu Baker8 min read

Have a system that should be doing more?

Start with an assessment. We look at what you actually run, and tell you what we would change.