Updated: Sep 28, 2026
PDPL Saudi Arabia rules cover any business that handles personal data in the Kingdom. SDAIA enforces the law. Fines reach SAR 5 million. Six duties follow: consent, data residency, access control, breach handling, rights requests, and records. Each shows how a system meets the rule.
Many businesses treat the PDPL as a legal problem. In practice, it's a systems problem. Consent boxes, server locations, user permissions, and alert workflows all live in software. Fix the software, and most of this checklist gets easier. Here's where to start.
Contents
The Personal Data Protection Law (PDPL) is Saudi Arabia's first general data protection law. Royal Decree issued it in September 2021. It took effect on 14 September 2023. The compliance deadline passed on 14 September 2024. SDAIA, the Saudi Data and AI Authority, regulates it.
The law reaches beyond borders. Companies in Dubai, London, or Karachi must comply. This applies when they process data of people in Saudi Arabia. Controllers decide why data is used. Processors handle data for them. Both carry duties, and controllers stay accountable for processors.
Each item below has two parts. The first states the rule. The second describes how a well-built system handles it. Treat the second part as a requirement list. Hand it to your developers, your hosting provider, or your own IT team.
The PDPL requires explicit, specific consent when consent is the legal basis. Pre-ticked boxes and vague terms of service are not valid. Users must be able to withdraw consent. Sensitive data, such as health or financial data, needs explicit consent and extra care.
A well-built system stores each consent with a timestamp, a purpose, and the notice version. Withdrawal takes one click and updates every connected tool. CRM software in Riyadh can hold these records beside each profile. Marketing never emails someone who opted out.
The PDPL restricts sending personal data outside Saudi Arabia. Transfers need a lawful ground and safeguards, such as SDAIA's standard contractual clauses. SDAIA published four versions of these clauses in September 2024. Many transfers need a documented risk assessment. Record every transfer decision.
A well-built system maps every data flow before launch. It stores Saudi resident data on chosen servers and logs each outside transfer. Web hosting in Saudi Arabia keeps storage inside the Kingdom. That removes the transfer question for that data.
The PDPL demands organizational, administrative, and technical measures to protect personal data. Enforcement has targeted businesses that lacked basic controls: access management, encryption, and audit logging. Every access to personal data needs a business reason. Anything else is a gap a regulator can find.
A well-built system uses role-based access. A finance clerk sees invoices, not medical files. Every view and export leaves a log entry. An employee portal applies these rules to staff. Permissions change the day someone switches roles or leaves the company.
Article 24 of the Implementing Regulations sets a 72-hour deadline. Controllers must notify SDAIA within 72 hours of learning about a harmful breach. The notice covers the incident, the affected group, likely impact, and containment steps. Serious risks also go to affected individuals.
A well-built system spots unusual activity in real time and alerts a named owner. Logs show what was touched, which speeds up the SDAIA report. A written playbook assigns every step. Cybersecurity consulting helps teams design and rehearse that playbook.
People in Saudi Arabia can ask to access, correct, delete, or move their data. They can also withdraw consent and object to processing. Businesses must answer within 30 days. Ignoring these requests is a frequent enforcement finding, according to one 2026 compliance guide.
A well-built system offers a self-service request form. Each request gets a ticket, an owner, and a due date. One search finds every record about one person across connected tools. A customer relationship management system with central records makes that search fast.
Businesses must keep records of processing activities. Some processing, such as customer profiling or AI tools, calls for an impact assessment. Some controllers must register on SDAIA's National Data Governance Platform. That covers public entities, sensitive data processors, and businesses focused on data processing.
A well-built system produces these records automatically. It lists what data is collected, why, where it is stored, and who receives it. An AI portal that touches customer data logs inputs and outputs. The impact assessment then rests on facts.
Administrative penalties reach up to SAR 5 million. Intentionally disclosing sensitive data can bring up to two years in prison, according to KPMG. SDAIA can also suspend data processing. For a digital business, a suspension halts daily operations and revenue.
Enforcement is active. A 2026 legal guide from Recording Law counts 48 SDAIA enforcement decisions by early 2026. Response windows after an investigation opens are short. One guide reports 5 days. This article is general information, not legal advice. Confirm current rules with counsel.
Policies alone don't protect data. Software does the daily work: it asks for consent, limits access, logs activity, and raises alarms. Built-in compliance is easier to prove to SDAIA than compliance kept in a binder. That's the gap most audits expose.
GO-Globe, founded in 2005, builds custom software and hosting for businesses in Saudi Arabia. Its solutions support Arabic and English, and account for data residency requirements. The team can review your data flows. Then it builds consent, access, logging, and request handling into your systems.
Start with one system: your CRM, portal, or website. List the checklist items it fails today. Then talk to GO-Globe about custom software and AI solutions in Saudi Arabia. Ask for hosting that matches your PDPL duties too, so both layers work together.
Yes. The PDPL covers any organization that processes personal data of people in Saudi Arabia. Location doesn't matter. A foreign online store with Saudi customers is covered. Covered businesses follow the same rules as local ones: consent, security, transfers, and breaches.
No. The PDPL does not ban all transfers. It restricts them and sets conditions: a lawful ground, safeguards, and a documented risk assessment where required. Sector rules, such as health regulations, can add localization duties. Check the rules for your own industry before choosing servers.
The deadline is 72 hours. The clock starts when the business becomes aware of the breach. The notice goes to SDAIA under Article 24 of the Implementing Regulations. The notice lists the incident, affected people, likely impact, and containment steps.
It depends on the business. The regulations set thresholds for appointing a Data Protection Officer. Check whether the business meets them. If it does, appoint the officer and register the appointment on SDAIA's platform. Affected people receive the officer's contact details after a breach.