
NCA ECC Compliance in Saudi Arabia: A Practical Guide for 2026
Who the Essential Cybersecurity Controls apply to, how they are structured, the governance requirements that trip organisations up, and a phased route to demonstrable compliance.
The Personal Data Protection Law has been fully enforceable since September 2024. A practical checklist of what controllers must have in place — and evidence.

Saudi Arabia's Personal Data Protection Law (PDPL) was issued by Royal Decree M/19 in 2021 and amended in 2023. It came into force on 14 September 2023, and after a one-year grace period became fully enforceable on 14 September 2024. The Saudi Data & AI Authority (SDAIA) is the competent authority, supported by Implementing Regulations and a separate regulation on transferring personal data outside the Kingdom.
The PDPL applies to any processing of personal data relating to individuals in the Kingdom, including by organisations based outside it. It is not a document-writing exercise: it requires working processes, and the evidence that they work.
Use the following as a structured starting point. Each item should have an owner and evidence.
The PDPL treats certain categories — including health, genetic, credit, religious and biometric data, and data revealing ethnic origin — as sensitive. Processing them carries stricter conditions, and unauthorised disclosure of sensitive data can carry criminal penalties. Identify sensitive data in your inventory first, and apply the tightest controls there.
| Violation | Potential penalty |
|---|---|
| Disclosure or publication of sensitive data in breach of the law, with intent to harm or for personal benefit | Imprisonment of up to two years and/or a fine of up to SAR 3 million |
| Other violations of the law or its regulations | A warning or a fine of up to SAR 5 million, which may be doubled for repeat offences |
Courts may also order confiscation of proceeds, and decisions may be published. Beyond the penalties, a public breach carries significant reputational cost with customers and regulators.
PDPL sits alongside sector requirements from regulators such as SAMA, and national frameworks such as the NCA Data Cybersecurity Controls and the National Data Management Office standards. A combined programme — one data inventory, one classification scheme, one set of controls mapped to every obligation — is far more sustainable than separate projects for each.

Who the Essential Cybersecurity Controls apply to, how they are structured, the governance requirements that trip organisations up, and a phased route to demonstrable compliance.

The four domains, the six-level maturity model and why “level 3” is about formalisation, not technology — with a practical view of the evidence reviewers expect.

A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.
Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.
We respond to every enquiry within one business day.