Middle East & Africa Saudi Arabia

Saudi PDPL: Complete Guide to the Personal Data Protection Law

Saudi Arabia's PDPL: SDAIA enforcement, consent and lawful bases, data subject rights, the 72-hour breach rule, transfer regulations, and criminal penalties.

Regulation

Personal Data Protection Law (Royal Decree M/19 of 2021, amended by M/148 of 2023), Implementing Regulations (2023, amended 2024)

Max Penalty

Fines up to SAR 5 million per violation (doubling for repeats); disclosure of sensitive data can bring criminal penalties up to 2 years' imprisonment and SAR 3 million

Enforcing Authority

Saudi Data and Artificial Intelligence Authority (SDAIA)

Official Source

sdaia.gov.sa

Executive Summary

  • The PDPL (Royal Decree M/19 of 2021, substantially amended by M/148 in 2023) became enforceable on September 14, 2023, with a one-year grace period that ended September 14, 2024: full SDAIA enforcement is now live.
  • SDAIA, the Saudi Data and Artificial Intelligence Authority, is the competent authority, supported by Implementing Regulations and separate Personal Data Transfer Regulations (2023, amended 2024).
  • Consent is the default basis, with the 2023 amendments adding legitimate interest for non-sensitive data, plus contract, legal obligation, and vital/public interest grounds.
  • Controllers face a 72-hour breach notification duty to SDAIA, national RoPA registration duties, and DPO appointment triggers set by the regulations.
  • Penalties are unusual regionally for including criminal exposure: disclosing sensitive data in violation of the law can mean up to 2 years' imprisonment; administrative fines reach SAR 5 million and double for repeat violations.

Saudi Arabia went from no comprehensive privacy law to an enforced one on a fast clock: enacted 2021, rewritten 2023, enforceable September 2023, grace period over in September 2024. The law reads like a GDPR adaptation with two Saudi signatures: a consent-first design that the 2023 amendments only partially relaxed, and a criminal track, actual imprisonment exposure for disclosing sensitive data, that most privacy regimes lack. SDAIA is also the AI authority, so data governance and AI oversight arrive from the same regulator.

LawPDPL, Royal Decree M/19 (2021), amended M/148 (2023)
RegulatorSDAIA
EnforceableSept 14, 2023; grace ended Sept 14, 2024
Breach clock72 hours to SDAIA
Max penaltySAR 5M fines; criminal: 2 years / SAR 3M for sensitive-data disclosure

Building the KSA program

Register and paper the basics. RoPA plus National Data Governance Platform registration where triggered, privacy notices to the regulations’ content list, and DPO analysis, these are what SDAIA’s compliance campaigns check first.

Consent architecture with the new bases layered in. Map each purpose to consent, contract, legal obligation, or (non-sensitive only) legitimate interest with a documented balance; the PDPL vs GDPR comparison shows where EU assumptions fail.

Transfers need Saudi instruments. SDAIA SCCs, risk assessments, and the sector localization rules covered in the Saudi localization guide; the compliance checklist sequences the full build.

Regional coherence. Gulf programs should reconcile KSA with the UAE’s federal PDPL and Bahrain’s PDPL rather than cloning one country’s setup.

Consent behavior and trackers on your Saudi-facing pages are externally checkable, by you or by SDAIA: run a free scan.

Frequently Asked Questions

Who does the PDPL apply to?

Any processing of personal data of individuals residing in Saudi Arabia, by entities inside the Kingdom or, extraterritorially, by entities outside it processing residents' data. It covers companies, public entities, and deceased persons' data where it could identify them or their family. There is no small-business exemption. Foreign companies serving Saudi customers online, e-commerce, SaaS, apps, are in scope and were expected to comply when the grace period closed in September 2024.

What lawful bases exist after the 2023 amendments?

Consent remains the default, and it must be freely given, specific, and documented, with explicit consent needed for sensitive data. The M/148 amendments added the bases that made the law workable: actual or legitimate interest of the controller for non-sensitive data (with a balancing requirement and SDAIA guidance), performance of an agreement with the data subject, compliance with another law, and public or vital interest grounds. Marketing generally requires consent, and sensitive data can never rest on legitimate interest.

What operational duties bite hardest?

Five: (1) privacy notices meeting the regulations' content list before or at collection; (2) records of processing activities, with registration on SDAIA's National Data Governance Platform for controllers meeting the criteria; (3) breach notification to SDAIA within 72 hours of awareness where harm is possible, and to data subjects without undue delay where serious; (4) DPO appointment where the regulations' triggers are met (public bodies, core large-scale processing, sensitive data at scale); (5) DPIAs for high-risk processing. Data subject rights (access, correction, deletion, portability) run on 30-day clocks under the regulations.

How do international transfers work?

Under the amended Article 29 and the Transfer Regulations (2023, amended 2024), transfers are allowed to countries SDAIA deems to have adequate protection, or with safeguards: SDAIA-form standard contractual clauses, binding common rules for groups, or certification, plus narrow derogations (contract necessity, the data subject's vital interest). A transfer risk assessment is required in defined cases. The regime landed close to GDPR Chapter V, but the clauses and assessments are Saudi instruments, EU SCCs are not a substitute. See the dedicated Saudi transfers and localization guide for sector rules stacking on top.

What are the real penalties and who has been enforced against?

Administrative fines up to SAR 5 million (about USD 1.3 million) per violation, doubling for repeats, plus warnings and corrective orders; the public prosecution handles the criminal track, up to 2 years' imprisonment and SAR 3 million for unlawful disclosure of sensitive data, and confiscation is available. SDAIA's early posture has emphasized registration, guidance, and compliance campaigns over headline fines, consistent with a young regulator building its docket, but the criminal provisions and the closed grace period mean the downside is real, particularly for health and financial data.

Regulatory Crosswalk

GDPRUAE PDPLBahrain PDPL

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.