Middle East & Africa Saudi Arabia

Saudi PDPL Compliance Checklist: SDAIA-Ready in Nine Steps

An implementation sequence for Saudi Arabia's PDPL: registration, notices, consent records, DSR clocks, DPO triggers, DPIAs, 72-hour breach response, and transfers.

Regulation

PDPL Implementing Regulations and Personal Data Transfer Regulations (2023, amended 2024)

Max Penalty

Fines up to SAR 5 million per violation, doubled for repeats; criminal exposure for sensitive-data disclosure

Enforcing Authority

Saudi Data and Artificial Intelligence Authority (SDAIA)

Official Source

sdaia.gov.sa

Executive Summary

  • With the grace period closed since September 14, 2024, PDPL compliance is a current-state obligation; SDAIA's Implementing Regulations and Transfer Regulations define the concrete tasks.
  • The build is nine steps: applicability scoping, data inventory/RoPA, platform registration, privacy notices, consent and basis records, DSR pipeline, DPO and DPIA machinery, 72-hour breach response, and transfer instruments.
  • SDAIA's National Data Governance Platform is the administrative spine: controller registration, DPO details, and breach notifications all flow through it.
  • Data subject requests run on 30-day clocks (extendable once) and must be free; consent must be provable, which makes consent-record engineering a first-order task.
  • Sector overlays stack on top: SAMA rules for financial institutions, CST for telecom, NCA controls for critical infrastructure, and health-sector rules, PDPL compliance alone is not full Saudi compliance.

Saudi compliance work changed character in September 2024: the question stopped being “when do we need to be ready” and became “what does SDAIA see if it looks today.” What it sees first is the externally visible layer, platform registration, the Arabic privacy notice, consent behavior on your Saudi-facing properties, and what it asks for in an inquiry is the producible layer: RoPA, consent records, DPIAs, breach log, transfer instruments. The checklist below builds both layers in the order enforcement actually tests them.

StepDeliverable
1. ScopeApplicability memo (residents’ data, extraterritorial reach)
2. InventoryRoPA with basis per purpose
3. RegisterNational Data Governance Platform filing
4. NoticesArabic-first notice to the regulations’ content list
5. ConsentProvable consent + withdrawal mechanics
6. Rights30-day DSR pipeline
7. GovernanceDPO trigger analysis; DPIA templates
8. Incidents72-hour SDAIA breach runbook
9. TransfersSDAIA SCCs, risk assessments, localization check

Running the checklist

Steps 3, 4, and 8 are the urgency tier. Registration gaps and non-compliant notices are visible without an investigation, and the 72-hour breach duty fails catastrophically if built mid-incident.

Consent is an engineering problem. Provable, specific, withdrawable consent means consent-management tooling wired to your Saudi-facing web properties, the same machinery GDPR programs use, tuned to PDPL’s stricter marketing stance; the PDPL vs GDPR guide lists the deltas.

Close transfers last but audit them first. Most Saudi programs discover unlawful transfers already running; inventory them in step 2, then paper them with SDAIA instruments and localization checks in step 9.

Gulf-wide reuse. The RoPA, DSR pipeline, and breach runbook extend to the UAE and Bahrain with jurisdiction switches rather than rebuilds.

Steps 4 and 5 are testable from outside right now: check your Saudi-facing pages with a free scan.

Frequently Asked Questions

What should be done first if we are behind?

Triage by visibility and harm: (1) register on the National Data Governance Platform if you meet the criteria, absence is trivially detectable by SDAIA; (2) publish a compliant privacy notice in Arabic (and English where relevant); (3) stand up the 72-hour breach process, the one obligation you cannot retrofit after the incident; (4) fix sensitive-data flows, because that is where criminal exposure lives; then build the inventory, DSR pipeline, and transfer paper in parallel. Document the remediation plan; SDAIA has responded better to documented programs than to silence.

Who must register on the National Data Governance Platform?

SDAIA's registration rules capture controllers meeting the criteria published on the platform, public entities, controllers whose core activities involve large-scale or sensitive processing, and those SDAIA directs, with the platform also hosting DPO registration and breach filings. Registration involves describing processing activities in RoPA-like detail. Even where registration is not strictly triggered, the underlying RoPA duty applies to all controllers, so build the inventory once and reuse it for the filing.

What must consent records prove?

That consent was freely given, specific to declared purposes, informed by a compliant notice, and given before processing, plus explicit form for sensitive data and parental consent mechanics for minors. Records need who consented, when, to what text, and through which mechanism, and must reflect withdrawals, which have to be as easy as giving consent. Bundled consent (one checkbox for service plus marketing) fails the specificity requirement. For flows moved to legitimate interest after the 2023 amendments, keep the balancing assessment on file instead.

When do we need a DPO and DPIAs?

DPO: where the regulations' triggers are met, public entities, controllers whose core activity is processing that requires regular and systematic monitoring at large scale, or large-scale sensitive-data processing; the DPO can be an employee or contractor and is registered with SDAIA. DPIA: before processing likely to cause high risk, profiling, large-scale sensitive data, new technologies, covering purposes, necessity, risks, and mitigations. Both artifacts are producibility items: SDAIA asks for them in inquiries, and their absence converts a technical violation into a governance one.

How do the sector regulators interact with SDAIA?

PDPL is the general law; sector rules add or tighten. SAMA (central bank) imposes outsourcing and data rules on banks and insurers, including localization expectations for certain systems. CST regulates telecom and cloud providers, with its Cloud Computing Regulatory Framework tiering data by sensitivity. NCA cybersecurity controls (ECC and cloud controls) apply localization to critical infrastructure and government data. Health data carries its own rules. A Saudi compliance file therefore has a PDPL core plus sector annexes; conflicts resolve toward the stricter rule in practice.

Regulatory Crosswalk

GDPRISO 27701NIST Privacy Framework

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.