Law · Privacy · Saudi Arabia
Saudi PDPL compliance means meeting Saudi Arabia's Personal Data Protection Law, enforced by SDAIA. It has applied since 14 September 2023 and became fully enforceable after the grace period ended on 14 September 2024, with breach notification within 72 hours and fines of up to SAR 5 million per violation.
Organisations processing personal data in Saudi Arabia, or about people residing there.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
The Saudi PDPL requires a lawful basis, clear privacy notices, security measures, records of processing, 72-hour breach notification to SDAIA, impact assessments, controlled transfers abroad and respect for data subject rights.
Consent or listed cases.
In QULDEX: Basis per purposeInform at collection.
In QULDEX: Notice versions72-hour notice to SDAIA.
In QULDEX: Breach timersFor products and services.
In QULDEX: Assessment workflowTransfer Regulation conditions.
In QULDEX: Transfer registerAccess, copy, correct, destroy.
In QULDEX: Request logThese 14 provisions carry the obligations most organisations work on. Select any one to see what it requires, typical evidence and the matching GDPR article.
Showing up to 6 per group. Search, filter, or open a group to see all 14.
Art. 2ScopeApplies to processing of personal data in the Kingdom, and to processing outside it of personal data of people residing in the Kingdom.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Art. 1Sensitive dataDiffers from GDPRSensitive data includes racial or ethnic origin, religious belief, criminal records, biometric, genetic, health, credit and location data.
In QULDEXSensitive data is tagged in the record of processing.
Art. 5–6Consent and other basesProcess with consent, or under listed cases such as legitimate interest (except sensitive data), legal obligation or vital interest.
In QULDEXEach purpose records its basis.
Art. 11Purpose and minimisationCollect only what is needed for a specified, legitimate purpose.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Art. 12–13Privacy policy and noticePublish a privacy policy and inform data subjects when collecting their data.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Art. 8ProcessorsChoose processors that give sufficient guarantees and check their compliance.
In QULDEXEach processor is linked to its contract and checks.
Art. 19Security measuresApply organisational, administrative and technical measures to protect personal data.
In QULDEXSecurity controls are reused from ISO 27001 and NCA ECC.
Art. 20Breach notificationNotify SDAIA of a breach that may harm data subjects, within 72 hours under the Implementing Regulations, and inform data subjects where required.
In QULDEXBreaches start a 72-hour timer.
Art. 22Impact assessmentAssess the impact of processing on data subjects for products and services.
In QULDEXImpact assessments run with sign-off.
Art. 30Data protection officerAppoint a DPO in the cases set by the Implementing Regulations, such as public bodies, large-scale sensitive data or systematic monitoring.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Art. 31Records of processingKeep records of processing activities for the retention period.
In QULDEXThe record of processing is kept per activity.
Art. 4Data subject rightsRights to be informed, to access, to obtain a copy, to correct, and to destroy personal data.
In QULDEXRequests are logged with deadlines.
Art. 29Transfers outside the KingdomTransfer only under the conditions in the law and the Personal Data Transfer Regulation, such as adequate protection or appropriate safeguards.
In QULDEXTransfers record destination and basis.
Art. 35–36PenaltiesAdministrative fines up to SAR 5 million per violation, doubled for repeat violations; disclosing sensitive data unlawfully can bring up to 2 years in prison or a SAR 3 million fine.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Nothing matches that search.
Article numbers follow the PDPL as amended; details sit in the Implementing Regulations and the Transfer Regulation. Summaries are QULDEX paraphrases, not legal advice.
Map processing, fix notices and bases, set up breach and rights processes, and document every transfer abroad. Most organisations need 3 to 6 months, less with a GDPR programme.
Record purposes, data, bases, processors and transfers.
Publish the privacy policy, capture consent, record other bases.
72-hour notice to SDAIA and request handling.
Assess each transfer under the Transfer Regulation.
Appoint a DPO where required and assess high-impact processing.
Durations are QULDEX planning ranges.
SDAIA expects these records.
| Record | Article | Where it lives in QULDEX |
|---|---|---|
| Record of processing | Art. 31 | Risk register |
| Privacy policy and notices | Art. 12–13 | Policy library |
| Consent logs | Art. 5–6 | Evidence vault |
| Processor contracts and checks | Art. 8 | Vendor register |
| Breach register and notifications | Art. 20 | CAPA automation |
| Impact assessments | Art. 22 | Audit workspace |
| DPO appointment | Art. 30 | Policy library |
| Transfer assessments | Art. 29 | Vendor register |
| Rights request log | Art. 4 | Evidence vault |
Record names are QULDEX recommendations based on the PDPL and its regulations.
Most organisations need 3 to 6 months. Sensitive data, transfers abroad and processor numbers drive the effort.
Bars show the upper end of each range on one scale (6 months = full width).
Check these eight things first. Nothing you enter leaves this page.
The Saudi PDPL shares GDPR's building blocks but treats more data as sensitive and regulates transfers through its own regulation. NCA ECC evidence covers the security measures.
| Saudi PDPL | GDPR | |
|---|---|---|
| Regulator | SDAIA | National supervisory authorities |
| Breach notice | 72 hours to SDAIA | 72 hours to the authority |
| Sensitive data | Includes credit and location data | Special categories, no credit data |
| Transfers | Transfer Regulation conditions | Adequacy, SCCs, BCRs |
| Penalties | Up to SAR 5 million, doubled for repeats; prison for sensitive data disclosure | Up to €20m or 4% of turnover |
| In QULDEX | QULDEX maps each process to both laws, so one privacy programme serves Saudi Arabia and the EU. | |
| Saudi PDPL | GDPR | UAE PDPL | NCA ECC-2:2024 | Shared evidence |
|---|---|---|---|---|
| Art. 5–6 Basis | Art. 6 | Art. 4 | — | Purpose register |
| Art. 8 Processors | Art. 28 | Art. 8 | 4-1 | Contracts |
| Art. 19 Security | Art. 32 | Art. 20 | Domain 2 | Security evidence |
| Art. 20 Breach | Art. 33–34 | Art. 9 | 2-13 | Breach register |
| Art. 22 Impact | Art. 35 | Art. 21 | 1-5 | Assessments |
| Art. 29 Transfers | Art. 44–49 | Art. 22–23 | 4-2 | Transfer register |
| Art. 31 Records | Art. 30 | Art. 7 | — | Record of processing |
Indicative mapping for planning, not legal advice.
QULDEX is Saudi PDPL compliance and audit management software built from EGV Group's audit delivery, used by controllers, their DPOs and privacy auditors. Pick your role to see who does what.
For organisations processing personal data in Saudi Arabia.
For DPOs and privacy consultants.
For independent privacy auditors.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →It came into force on 14 September 2023, with a one-year grace period that ended on 14 September 2024. Since then it has been fully enforceable.
The Saudi Data and Artificial Intelligence Authority (SDAIA). Its violation review committees issued 48 decisions confirming violations by January 2026.
Administrative fines of up to SAR 5 million per violation, which can be doubled for repeat violations. Unlawfully disclosing sensitive data can bring up to 2 years in prison or a fine of up to SAR 3 million.
Within 72 hours of becoming aware of a breach that may harm data subjects, under the Implementing Regulations, with data subjects informed where required.
Yes, under the conditions in the PDPL and the Personal Data Transfer Regulation, such as adequate protection in the destination or appropriate safeguards.
NCA ECC, SAMA CSF, UAE IAS and Gulf data protection laws.
blog.quldex.comGDPR, ISO 27701 and privacy-law comparisons.
blog.quldex.comA file-naming scheme auditors can follow.
blog.quldex.comHow many samples auditors look at.
Reviewed by
Answer a short readiness check and get a gap summary by article. No sales call needed to see the result.