Updated: Sep 28, 2026
PDPL is Saudi Arabia's data protection law. It applies to any business, local or foreign, that handles personal data of people in the Kingdom. Full enforcement began on 14 September 2024, and compliance now touches where you host data and how your software stores it.
Contents
PDPL stands for the Personal Data Protection Law. Saudi Arabia enacted PDPL by Royal Decree M/19 on 16 September 2021, and amended it by Royal Decree M/148 on 27 March 2023. The law came into force on 14 September 2023, after a one-year grace period. Full enforcement began on 14 September 2024. The Saudi Data and Artificial Intelligence Authority, known as SDAIA, writes the rules and enforces them.
PDPL controls how a business collects, stores, uses, and shares personal data. Personal data means any information tied to an identified or identifiable person. Names, national ID numbers, phone numbers, email addresses, and even device or location data all count.
PDPL applies to every business, government body, and nonprofit that processes personal data of people in Saudi Arabia. Location matters more than nationality here. A company based outside the Kingdom still falls under PDPL if it handles data belonging to people inside Saudi Arabia. A Saudi retailer with customers only in Riyadh and Jeddah is covered. A software vendor in another country that serves Saudi users is covered too.
The law also protects data after a person dies, and it covers data about family members if that data can identify them. Coverage is broad by design. Very few data-handling activities sit outside it.
A business under PDPL carries a specific set of duties. Registering as a data controller on SDAIA's National Data Governance Platform comes first. From there, the business needs a lawful basis for every use of personal data, most often consent or a genuine business need spelled out in the law.
Two principles run through the whole law. Purpose limitation means a business can only use data for the reason it collected it. Data minimization means a business collects only the data it actually needs, not everything it could possibly gather.
People whose data gets collected keep several rights under PDPL. They can ask to see their data, correct it, or have it deleted. They can also object to certain uses, such as marketing they never agreed to.
Where the data physically sits matters under PDPL. Saudi Arabia allows personal data to leave the Kingdom only under specific conditions. SDAIA published a Risk Assessment Guideline in February 2025. It spells out how a business should judge that risk before any cross-border transfer. A business planning to move customer data to a foreign cloud provider needs to work through this guideline first, not after the transfer already happened.
Hosting data inside Saudi Arabia removes a whole layer of that risk assessment. A business does not need to justify a transfer that never happens. Server location becomes a compliance decision, not just a technical one. GO-Globe offers web hosting inside Saudi Arabia. This keeps customer and employee records on servers located in the Kingdom. It also removes the extra approval step that a transfer abroad would trigger.
PDPL enforcement is active, not theoretical. Committees for Reviewing Violations of the Provisions of the Personal Data Protection Law handle the cases. By early 2026, these committees had issued 48 decisions confirming violations and imposing penalties on the businesses involved.
The penalties scale with the violation. Administrative fines apply to most breaches, such as processing data without a lawful basis or skipping required security measures. The most serious cases, like unlawfully disclosing sensitive data, carry fines up to SAR 5 million and can bring criminal charges, including prison time. Once a business receives formal notice of a violation, it often has as little as five days to respond.
Common violations follow a pattern. Processing data without a valid legal basis leads the list. Unauthorized disclosure of personal data, weak technical safeguards, and marketing messages sent without consent round out the rest.
The table below lays out the key PDPL milestones in order.
| Date | Milestone |
| 16 September 2021 | PDPL enacted by Royal Decree M/19 |
| 27 March 2023 | PDPL amended by Royal Decree M/148 |
| 14 September 2023 | PDPL enters into force; grace period begins |
| September 2024 | Grace period ends; full enforcement begins |
| February 2025 | SDAIA publishes Risk Assessment Guideline for cross-border transfers |
| November 2025 | SDAIA publishes AI Adoption Framework |
| Early 2026 | SDAIA reports 48 cumulative enforcement decisions |
Each milestone builds on the one before it. Registration and lawful-basis rules came first. Enforcement power followed once the grace period ended. Cross-border and AI-specific guidance came after that, once regulators had seen how businesses were actually handling data in practice.
PDPL compliance is not just a legal document sitting in a drawer. It is a property of the software a business runs every day. Every system that stores a name, a phone number, or a customer record falls inside PDPL's reach.
A CRM system holds some of the most sensitive personal data a business keeps: customer names, contact details, purchase history, and support records. A CRM platform built for the Saudi market needs the access controls and data-handling rules that PDPL requires built in from the start, not added on later.
Employee data falls under PDPL too. Payroll details, national ID numbers, and performance records all count as personal data. An employee portal that centralizes this information needs the same lawful-basis and access-control standards as any customer-facing system.
AI systems raise a newer set of questions. SDAIA published an AI Adoption Framework in November 2025 that sets governance rules for AI tools that process personal data. A business running AI technology on customer or employee data needs to account for both PDPL and this newer AI-specific guidance. That includes a customer-facing AI portal just as much as an internal AI tool.
Even a website's own lead forms and analytics tools collect personal data the moment a visitor submits a name or email address. A business running SEO campaigns for Saudi Arabian websites still needs to handle that captured data under the same PDPL rules that apply to any other system.
Building for PDPL from the start costs less than retrofitting an existing system later. Consent tracking, access controls, and data retention limits belong at the architecture level, not bolted on after launch. Combined with hosting inside the Kingdom, this approach removes most of the cross-border transfer questions before they come up.
Your CRM, employee portal, or website may currently sit on infrastructure outside Saudi Arabia, or it may have been built before PDPL existed at all. GO-Globe reviews where that data lives and how each system handles it, then builds or adjusts the system to fit. Visit the GO-Globe homepage to see the full range of services, or go straight to custom software built for Saudi Arabia, hosted inside the Kingdom from day one.
Yes. PDPL applies to every business that processes personal data of people in Saudi Arabia, including foreign companies with no physical office in the Kingdom. Location of the data subject decides coverage, not the location of the company.
No. A small business with a handful of customer records carries the same registration and lawful-basis duties as a large enterprise. Enforcement priority in practice tends to follow the volume and sensitivity of the data involved, but the legal obligation itself does not change with company size.
Only after passing a risk assessment under SDAIA's guidelines, and in some cases only with added regulatory approval. Hosting data inside the Kingdom avoids this requirement entirely, since the data never crosses a border in the first place.
Fines for PDPL violations vary by severity. Most breaches draw administrative fines. Unlawfully disclosing sensitive personal data sits at the serious end, and it can bring fines up to SAR 5 million along with possible criminal charges.
Yes. PDPL requires every data controller to register on SDAIA's National Data Governance Platform before processing personal data of people in Saudi Arabia. Company size and sector do not exempt a business from this step.