Riyadh | +966‑557400202 | hello@nazztec.com
Compliance & Regulation

PDPL Compliance Checklist for Saudi Organisations

The Personal Data Protection Law has been fully enforceable since September 2024. A practical checklist of what controllers must have in place — and evidence.

8 September 20269 min readNAZZTEC Editorial Team
PDPL Compliance Checklist for Saudi Organisations — cover illustration

Key takeaways

  • The PDPL came into force on 14 September 2023, with full enforcement from 14 September 2024.
  • SDAIA is the competent authority and supervises compliance.
  • Breaches must be notified to SDAIA within 72 hours in qualifying cases.
  • Serious violations can lead to fines of up to SAR 5 million, and certain offences to imprisonment.

The law in brief

Saudi Arabia's Personal Data Protection Law (PDPL) was issued by Royal Decree M/19 in 2021 and amended in 2023. It came into force on 14 September 2023, and after a one-year grace period became fully enforceable on 14 September 2024. The Saudi Data & AI Authority (SDAIA) is the competent authority, supported by Implementing Regulations and a separate regulation on transferring personal data outside the Kingdom.

The PDPL applies to any processing of personal data relating to individuals in the Kingdom, including by organisations based outside it. It is not a document-writing exercise: it requires working processes, and the evidence that they work.

The checklist

Use the following as a structured starting point. Each item should have an owner and evidence.

  • Data inventory — know what personal data you hold, where, why, for how long and who can access it.
  • Records of processing — maintain records of processing activities covering purposes, categories, recipients, transfers and retention.
  • Legal basis — identify a lawful basis for each processing activity. Consent is one basis; the law also recognises others, such as contractual necessity and legal obligation.
  • Consent management — where consent is relied on, make it explicit, recorded and as easy to withdraw as to give.
  • Privacy notice — publish a clear notice explaining purposes, legal basis, recipients, retention and rights before data is collected.
  • Data minimisation and retention — collect only what is necessary and destroy data when it is no longer needed.
  • Data subject rights — operate processes to handle requests to be informed, access, obtain a copy, correct and destroy data within the required timescales.
  • Security measures — apply organisational and technical controls proportionate to the sensitivity of the data.
  • Processor contracts — ensure service providers processing data on your behalf are bound by appropriate obligations and oversight.
  • Breach response — detect, assess and notify SDAIA within 72 hours where required, and notify affected individuals where the breach may cause them harm.
  • Cross-border transfers — assess every transfer outside the Kingdom against the transfer regulation, and document the basis and safeguards.
  • Data Protection Officer — appoint one where the regulations require it, and give the role real access and authority.
  • Registration — register on SDAIA's national data governance platform where the regulations require it for your organisation.
  • Training — make sure staff who handle personal data understand their obligations.

Sensitive data needs extra care

The PDPL treats certain categories — including health, genetic, credit, religious and biometric data, and data revealing ethnic origin — as sensitive. Processing them carries stricter conditions, and unauthorised disclosure of sensitive data can carry criminal penalties. Identify sensitive data in your inventory first, and apply the tightest controls there.

Penalties

ViolationPotential penalty
Disclosure or publication of sensitive data in breach of the law, with intent to harm or for personal benefitImprisonment of up to two years and/or a fine of up to SAR 3 million
Other violations of the law or its regulationsA warning or a fine of up to SAR 5 million, which may be doubled for repeat offences

Courts may also order confiscation of proceeds, and decisions may be published. Beyond the penalties, a public breach carries significant reputational cost with customers and regulators.

Where organisations commonly struggle

  • Data inventories that cover systems but not spreadsheets, email and shared folders.
  • Privacy notices written for the law rather than for the people reading them.
  • No working process for data subject requests — until the first request arrives.
  • Cloud and SaaS services that transfer data abroad without an assessment.
  • Breach response plans that do not include the 72-hour notification decision.
  • Marketing lists built without a recorded basis.

How PDPL fits with your other obligations

PDPL sits alongside sector requirements from regulators such as SAMA, and national frameworks such as the NCA Data Cybersecurity Controls and the National Data Management Office standards. A combined programme — one data inventory, one classification scheme, one set of controls mapped to every obligation — is far more sustainable than separate projects for each.

Frequently asked questions

Does PDPL apply to companies outside Saudi Arabia?
Yes. It applies to processing of personal data relating to individuals in the Kingdom, including by organisations located outside it.
When must a data breach be reported?
Where the regulations require notification, SDAIA must be informed within 72 hours of becoming aware of the incident, and affected individuals must be told where the breach may harm them.
Is consent always required under PDPL?
No. Consent is one lawful basis. The law and its regulations recognise others, such as performing a contract or meeting a legal obligation, subject to conditions.
Keep reading

More insights

Talk to the team behind this briefing

Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.

We respond to every enquiry within one business day.