Saudi Arabia went from no comprehensive privacy law to an enforced one on a fast clock: enacted 2021, rewritten 2023, enforceable September 2023, grace period over in September 2024. The law reads like a GDPR adaptation with two Saudi signatures: a consent-first design that the 2023 amendments only partially relaxed, and a criminal track, actual imprisonment exposure for disclosing sensitive data, that most privacy regimes lack. SDAIA is also the AI authority, so data governance and AI oversight arrive from the same regulator.
| Law | PDPL, Royal Decree M/19 (2021), amended M/148 (2023) |
|---|---|
| Regulator | SDAIA |
| Enforceable | Sept 14, 2023; grace ended Sept 14, 2024 |
| Breach clock | 72 hours to SDAIA |
| Max penalty | SAR 5M fines; criminal: 2 years / SAR 3M for sensitive-data disclosure |
Building the KSA program
Register and paper the basics. RoPA plus National Data Governance Platform registration where triggered, privacy notices to the regulations’ content list, and DPO analysis, these are what SDAIA’s compliance campaigns check first.
Consent architecture with the new bases layered in. Map each purpose to consent, contract, legal obligation, or (non-sensitive only) legitimate interest with a documented balance; the PDPL vs GDPR comparison shows where EU assumptions fail.
Transfers need Saudi instruments. SDAIA SCCs, risk assessments, and the sector localization rules covered in the Saudi localization guide; the compliance checklist sequences the full build.
Regional coherence. Gulf programs should reconcile KSA with the UAE’s federal PDPL and Bahrain’s PDPL rather than cloning one country’s setup.
Consent behavior and trackers on your Saudi-facing pages are externally checkable, by you or by SDAIA: run a free scan.