The PDPL is best read as the GDPR translated into a consent-first, state-supervised idiom: the machinery is recognizably European, but the defaults shift, consent where Brussels allows legitimate interest, registration where Brussels abolished it, prison where Brussels only fines. GDPR-mature companies clear most of the Saudi bar with configuration, then stumble on exactly three things: marketing basis, transfer paperwork, and sector localization. Those three account for most real-world Saudi exposure.
| Dimension | GDPR | PDPL |
|---|---|---|
| Default basis | Any of six | Consent (LI non-sensitive only) |
| Registration | Abolished 2018 | SDAIA platform where triggered |
| Breach clock | 72 hours | 72 hours |
| DSR clock | 1 month | 30 days |
| Transfers | EU SCCs, adequacy, BCRs | SDAIA SCCs, adequacy, binding common rules |
| Max sanction | 4% worldwide turnover | SAR 5M + criminal (2 yrs) for sensitive disclosure |
Converting a GDPR program for the Kingdom
Diff the bases, not the architecture. Re-map every purpose against the PDPL’s grounds, escalating EU legitimate-interest flows to consent where sensitive data or marketing is involved; the full PDPL guide details the grounds.
Swap the transfer paper. SDAIA SCCs and risk assessments replace EU instruments wholesale, and the localization stack adds gates no GDPR program contains.
Add the Saudi-only artifacts. Platform registration, Arabic notices, and a sensitive-data incident path that accounts for criminal exposure; sequence via the nine-step checklist.
Regional note. The UAE’s PDPL made different choices on several of these axes; do not clone the Saudi module across the Gulf.
Marketing consent behavior is the most common PDPL/GDPR divergence visible on a website: test your Saudi-facing pages with a free scan.