Law · Privacy · Saudi Arabia

Saudi PDPL compliance: obligations, transfers and penalties

Saudi PDPL compliance means meeting Saudi Arabia's Personal Data Protection Law, enforced by SDAIA. It has applied since 14 September 2023 and became fully enforceable after the grace period ended on 14 September 2024, with breach notification within 72 hours and fines of up to SAR 5 million per violation.

Key takeaways

What you need to know about Saudi PDPL

Fully enforceableThe grace period ended in September 2024; SDAIA committees now issue decisions.
72-hour breach noticeNotify SDAIA of breaches that may harm people.
ExtraterritorialCovers processing abroad of data about people living in the Kingdom.
Sensitive dataIncludes credit and location data, unlike GDPR.
Transfers regulatedA separate regulation governs transfers outside the Kingdom.

Who must comply with the Saudi PDPL?

Organisations processing personal data in Saudi Arabia, or about people residing there.

Saudi organisationsPublic and private entities processing personal data.
Foreign companiesProcessing personal data of people residing in the Kingdom.
Processors and SaaS providersActing for Saudi controllers.
Financial and health organisationsWith sensitive data such as credit and health data.
Public bodiesWith DPO requirements.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the law requires

What does the Saudi PDPL require?

The Saudi PDPL requires a lawful basis, clear privacy notices, security measures, records of processing, 72-hour breach notification to SDAIA, impact assessments, controlled transfers abroad and respect for data subject rights.

Art. 5–6 Basis

Lawful processing

Consent or listed cases.

In QULDEX: Basis per purpose
Art. 12–13 Notice

Privacy policy

Inform at collection.

In QULDEX: Notice versions
Art. 19–20 Secure

Security and breaches

72-hour notice to SDAIA.

In QULDEX: Breach timers
Art. 22 Assess

Impact assessments

For products and services.

In QULDEX: Assessment workflow
Art. 29 Transfer

Transfers abroad

Transfer Regulation conditions.

In QULDEX: Transfer register
Art. 4 Rights

Data subject rights

Access, copy, correct, destroy.

In QULDEX: Request log
Article explorer

Which Saudi PDPL articles matter most?

These 14 provisions carry the obligations most organisations work on. Select any one to see what it requires, typical evidence and the matching GDPR article.

2021law issued
Sep 2023in force
Sep 2024grace ends
2026active enforcement

Showing up to 6 per group. Search, filter, or open a group to see all 14.

Scope 2

  1. Art. 2Scope

    Applies to processing of personal data in the Kingdom, and to processing outside it of personal data of people residing in the Kingdom.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Maps to
    GDPR Art. 3

  2. Art. 1Sensitive dataDiffers from GDPR

    Sensitive data includes racial or ethnic origin, religious belief, criminal records, biometric, genetic, health, credit and location data.

    In QULDEXSensitive data is tagged in the record of processing.

Lawful processing 3

  1. Art. 5–6Consent and other bases

    Process with consent, or under listed cases such as legitimate interest (except sensitive data), legal obligation or vital interest.

    In QULDEXEach purpose records its basis.

    Typical evidence
    Purpose register
    Maps to
    GDPR Art. 6

  2. Art. 11Purpose and minimisation

    Collect only what is needed for a specified, legitimate purpose.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Maps to
    GDPR Art. 5

  3. Art. 12–13Privacy policy and notice

    Publish a privacy policy and inform data subjects when collecting their data.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Typical evidence
    Privacy policy
    Maps to
    GDPR Art. 13

Obligations 6

  1. Art. 8Processors

    Choose processors that give sufficient guarantees and check their compliance.

    In QULDEXEach processor is linked to its contract and checks.

    Typical evidence
    Processor contracts
    Maps to
    GDPR Art. 28

  2. Art. 19Security measures

    Apply organisational, administrative and technical measures to protect personal data.

    In QULDEXSecurity controls are reused from ISO 27001 and NCA ECC.

    Typical evidence
    Security evidence
    Maps to
    GDPR Art. 32NCA ECC

  3. Art. 20Breach notification

    Notify SDAIA of a breach that may harm data subjects, within 72 hours under the Implementing Regulations, and inform data subjects where required.

    In QULDEXBreaches start a 72-hour timer.

    Typical evidence
    Breach register
    Maps to
    GDPR Art. 33–34

  4. Art. 22Impact assessment

    Assess the impact of processing on data subjects for products and services.

    In QULDEXImpact assessments run with sign-off.

    Typical evidence
    Impact assessments
    Maps to
    GDPR Art. 35

  5. Art. 30Data protection officer

    Appoint a DPO in the cases set by the Implementing Regulations, such as public bodies, large-scale sensitive data or systematic monitoring.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Typical evidence
    DPO appointment
    Maps to
    GDPR Art. 37

  6. Art. 31Records of processing

    Keep records of processing activities for the retention period.

    In QULDEXThe record of processing is kept per activity.

    Typical evidence
    Record of processing
    Maps to
    GDPR Art. 30

Rights 1

  1. Art. 4Data subject rights

    Rights to be informed, to access, to obtain a copy, to correct, and to destroy personal data.

    In QULDEXRequests are logged with deadlines.

    Typical evidence
    Request log
    Maps to
    GDPR Art. 15–17

Transfers 1

  1. Art. 29Transfers outside the Kingdom

    Transfer only under the conditions in the law and the Personal Data Transfer Regulation, such as adequate protection or appropriate safeguards.

    In QULDEXTransfers record destination and basis.

    Typical evidence
    Transfer register
    Maps to
    GDPR Art. 44–49

Enforcement 1

  1. Art. 35–36Penalties

    Administrative fines up to SAR 5 million per violation, doubled for repeat violations; disclosing sensitive data unlawfully can bring up to 2 years in prison or a SAR 3 million fine.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

Article numbers follow the PDPL as amended; details sit in the Implementing Regulations and the Transfer Regulation. Summaries are QULDEX paraphrases, not legal advice.

Compliance path

How do you comply with the Saudi PDPL?

Map processing, fix notices and bases, set up breach and rights processes, and document every transfer abroad. Most organisations need 3 to 6 months, less with a GDPR programme.

  1. Map processing and sensitive data

    Record purposes, data, bases, processors and transfers.

  2. Notices and bases

    Publish the privacy policy, capture consent, record other bases.

  3. Breach and rights processes

    72-hour notice to SDAIA and request handling.

  4. Transfers abroad

    Assess each transfer under the Transfer Regulation.

    1–2 monthsRisk register →
  5. DPO and impact assessments

    Appoint a DPO where required and assess high-impact processing.

  6. Keep it current

    Every breachNotify within 72 hours
    On changeRe-assess impact
    YearlyReview the programme

Durations are QULDEX planning ranges.

Records to keep

Which records does the Saudi PDPL need?

SDAIA expects these records.

RecordArticleWhere it lives in QULDEX
Record of processingArt. 31Risk register
Privacy policy and noticesArt. 12–13Policy library
Consent logsArt. 5–6Evidence vault
Processor contracts and checksArt. 8Vendor register
Breach register and notificationsArt. 20CAPA automation
Impact assessmentsArt. 22Audit workspace
DPO appointmentArt. 30Policy library
Transfer assessmentsArt. 29Vendor register
Rights request logArt. 4Evidence vault

Record names are QULDEX recommendations based on the PDPL and its regulations.

Time and cost

How long does Saudi PDPL compliance take and what drives the effort?

Most organisations need 3 to 6 months. Sensitive data, transfers abroad and processor numbers drive the effort.

Where the time goes

Processing map3–6 wk
Notices and bases1–2 mo
Breach and rights3–6 wk
Transfers1–2 mo
DPO and assessments1–2 mo

Bars show the upper end of each range on one scale (6 months = full width).

What changes the effort

  • Sensitive data: credit, health and location data need extra care
  • Transfers abroad: cloud and group transfers need assessment
  • Processors: every processor needs checks
  • Existing GDPR programme: much carries over
  • NCA ECC in place: covers security measures
Readiness check · 2 minutes

How ready are you for the Saudi PDPL?

Check these eight things first. Nothing you enter leaves this page.

Art. 31Do you keep a record of processing?
Art. 5Is there a basis for every purpose?
Art. 12Is your privacy policy published and current?
Art. 20Can you notify SDAIA of a breach within 72 hours?
Art. 4Can you answer access, copy, correction and destruction requests?
Art. 29Is every transfer abroad assessed?
Art. 22Do you assess high-impact processing?
Art. 8Do processors act under contract with checks?
Crosswalk

How the Saudi PDPL maps to GDPR, the UAE PDPL and NCA ECC

The Saudi PDPL shares GDPR's building blocks but treats more data as sensitive and regulates transfers through its own regulation. NCA ECC evidence covers the security measures.

Saudi PDPL vs GDPR at a glance

Saudi PDPLGDPR
RegulatorSDAIANational supervisory authorities
Breach notice72 hours to SDAIA72 hours to the authority
Sensitive dataIncludes credit and location dataSpecial categories, no credit data
TransfersTransfer Regulation conditionsAdequacy, SCCs, BCRs
PenaltiesUp to SAR 5 million, doubled for repeats; prison for sensitive data disclosureUp to €20m or 4% of turnover
In QULDEXQULDEX maps each process to both laws, so one privacy programme serves Saudi Arabia and the EU.

Privacy crosswalk

Saudi PDPLGDPRUAE PDPLNCA ECC-2:2024Shared evidence
Art. 5–6 BasisArt. 6Art. 4—Purpose register
Art. 8 ProcessorsArt. 28Art. 84-1Contracts
Art. 19 SecurityArt. 32Art. 20Domain 2Security evidence
Art. 20 BreachArt. 33–34Art. 92-13Breach register
Art. 22 ImpactArt. 35Art. 211-5Assessments
Art. 29 TransfersArt. 44–49Art. 22–234-2Transfer register
Art. 31 RecordsArt. 30Art. 7—Record of processing

Indicative mapping for planning, not legal advice.

Where QULDEX fits

How QULDEX runs Saudi PDPL compliance from data map to SDAIA review

QULDEX is Saudi PDPL compliance and audit management software built from EGV Group's audit delivery, used by controllers, their DPOs and privacy auditors. Pick your role to see who does what.

For organisations processing personal data in Saudi Arabia.

  1. MapRecord processingRecord of processing
  2. NoticeFix noticesPolicy versions and consent logs
  3. BreachesNotify SDAIA in 72 hoursBreach timers
  4. TransfersAssess transfersTransfer register
  5. AssessRun impact assessmentsAssessment workflow
  6. AuditProve complianceControlled evidence sharing
Without one systemWith QULDEX
Transfers to cloud regions unassessedEvery transfer assessed
Breach deadlines tracked by hand72-hour timers
GDPR and PDPL run separatelyOne programme mapped to both
Sensitive data not taggedSensitive data flagged in records
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

Saudi PDPL questions people ask

When did the Saudi PDPL come into force?

It came into force on 14 September 2023, with a one-year grace period that ended on 14 September 2024. Since then it has been fully enforceable.

Who enforces the Saudi PDPL?

The Saudi Data and Artificial Intelligence Authority (SDAIA). Its violation review committees issued 48 decisions confirming violations by January 2026.

What are the Saudi PDPL penalties?

Administrative fines of up to SAR 5 million per violation, which can be doubled for repeat violations. Unlawfully disclosing sensitive data can bring up to 2 years in prison or a fine of up to SAR 3 million.

How fast must breaches be reported?

Within 72 hours of becoming aware of a breach that may harm data subjects, under the Implementing Regulations, with data subjects informed where required.

Can personal data be transferred outside Saudi Arabia?

Yes, under the conditions in the PDPL and the Personal Data Transfer Regulation, such as adequate protection in the destination or appropriate safeguards.

Sources

References

  1. Personal Data Protection Law, Royal Decree M/19 (2021), as amended by Royal Decree M/148 (2023). sdaia.gov.sa
  2. PDPL Implementing Regulations and Personal Data Transfer Regulation, SDAIA. sdaia.gov.sa
  3. Saudi Press Agency on SDAIA violation decisions, Jan 2026. spa.gov.sa
  4. EU GDPR, Regulation (EU) 2016/679. eur-lex.europa.eu

Reviewed by

Ankit Tiwari

Framework reviewer · QULDEX

Reviewed this page against the Saudi PDPL, its Implementing Regulations and the Transfer Regulation.

Page history
  • : Page first built: article explorer, transfers, penalties, readiness check and GDPR comparison

Be ready for an SDAIA review

Answer a short readiness check and get a gap summary by article. No sales call needed to see the result.

Schedule
Book a Demo