Saudi PDPL: The Complete Compliance Guide for 2026
Saudi Arabia's Personal Data Protection Law (PDPL) is the kingdom's most significant privacy regulation, reshaping how every business handles personal data. Enacted by Royal Decree M/19, the law has been fully enforced since September 2024 with implementing regulations from SDAIA (the Saudi Data and Artificial Intelligence Authority) clarifying the detailed requirements. Whether you run a Riyadh-based e-commerce store, a multinational with Saudi customers, or a SaaS platform processing Saudi user data from abroad, PDPL compliance is mandatory — and penalties for non-compliance are severe.
What Is the PDPL?
The PDPL is Saudi Arabia's first comprehensive personal data protection law. It was designed to align with international best practices — drawing inspiration from the EU's GDPR — while reflecting the kingdom's unique legal and cultural context. The law is administered and enforced by SDAIA, which operates as the centralized supervisory authority, unlike the EU model where each member state has its own independent data protection authority.
The PDPL defines personal data broadly: any data that can identify an individual, directly or indirectly. This includes names, ID numbers, location data, online identifiers, IP addresses, and even cookie data. The law applies to both automated and manual data processing, meaning that spreadsheets and paper records fall under its scope alongside databases and analytics platforms.
PDPL: From Royal Decree to Full Enforcement
The Personal Data Protection Law has had one of the longest, most carefully managed rollouts of any major privacy regulation in the world. Royal Decree M/19 was issued in September 2021, formally enacting PDPL as Saudi law. Recognizing the significant operational changes required for businesses to comply, the Saudi government deliberately delayed full enforcement. The original effective date of March 17, 2022 was postponed first to March 2023, then to September 14, 2023 with a one-year transitional period for businesses to achieve compliance. Full enforcement officially began on September 14, 2024.
Throughout this transition period, SDAIA functioned primarily in an advisory capacity — publishing implementing regulations, issuing sector-specific guidance, and conducting voluntary compliance workshops. The Authority issued the binding Implementing Regulations in September 2023, with subsequent updates clarifying specific requirements around consent, cross-border transfers, and data subject rights. The Cross-Border Data Transfer Regulations and the Personal Data Breach Notification Regulations followed in 2025, completing the regulatory framework. As of 2026, SDAIA has formally transitioned from education-first to enforcement-first posture, with active monitoring, audit capabilities, and the operational authority to issue penalties at the full statutory limits.
Who Must Comply?
The PDPL has extraterritorial reach — it applies to any organization processing personal data of individuals located in Saudi Arabia, regardless of where the organization is headquartered. This means a European SaaS company with Saudi subscribers, a Dubai-based agency managing Saudi client campaigns, or a US e-commerce brand shipping to Riyadh all fall under the law.
- All Saudi-based businesses, public and private sector
- Foreign companies processing data of Saudi residents
- E-commerce platforms serving Saudi customers
- SaaS and cloud services storing Saudi user data
- Marketing and advertising platforms using Saudi audience data
- Special sensitivity categories: health, financial, genetic, biometric data
The only exemptions are personal data processed by individuals for purely personal or family purposes, and data processed for national security purposes by authorized government entities. Every other processing activity requires a lawful basis.
Sensitive Personal Data: Special Treatment
PDPL distinguishes between regular personal data and sensitive personal data, with significantly stricter protections for the latter. Sensitive data categories require explicit written consent (not just clear consent), a Data Protection Impact Assessment before processing begins, and heightened security measures including encryption at rest and in transit. Processing sensitive data without these safeguards is one of the most serious PDPL violations and carries the highest penalty exposure, including potential criminal liability.
- Health and medical data: Patient records, medical conditions, treatment history, prescriptions, genetic markers
- Biometric data: Fingerprints, facial recognition data, iris scans, voice prints, behavioral biometrics
- Genetic data: DNA sequences, hereditary disease markers, ancestry information
- Financial data: Bank account details, credit card numbers, transaction history, credit scores
- Religious and ideological beliefs: Religious affiliation, philosophical views, sect or denomination data
- Children's data: All personal data of individuals under 18 requires parental consent and additional protections
- Criminal and judicial data: Records of arrests, convictions, judicial proceedings — highly restricted
Key Requirements
The PDPL establishes several foundational requirements that organizations must implement. These are not suggestions — they are legal obligations with enforcement mechanisms behind them.
- Privacy policy: Publish a clear, Arabic-language privacy policy explaining what data you collect, why, and how long you keep it
- Data minimization: Only collect data necessary for the stated purpose
- Purpose limitation: Data collected for one purpose cannot be used for another without fresh consent
- Storage limitation: Personal data must be deleted when the processing purpose is fulfilled
- Data protection impact assessments: Required for high-risk processing activities
- Breach notification: Report data breaches to SDAIA within 72 hours of discovery
- Record keeping: Maintain detailed records of all data processing activities
Free real-browser scan of any e-commerce site. 30 seconds, no signup.
Scan my store freeAppointing a Data Protection Officer (DPO)
PDPL requires certain organizations to appoint a Data Protection Officer responsible for overseeing data protection compliance. The DPO appointment requirement applies to: government entities processing personal data, organizations whose core activities involve large-scale processing or monitoring of data subjects, and organizations processing sensitive personal data at scale. For most mid-market businesses, hiring a full-time DPO is impractical — the practical alternative is to appoint a designated employee who takes on DPO responsibilities alongside their primary role, or to engage a fractional or external DPO service that provides the role on a contracted basis.
- Monitor compliance with PDPL and internal data protection policies
- Provide advice on data protection impact assessments (DPIAs) and their conduct
- Cooperate with SDAIA and act as the primary contact for data subjects regarding their data rights
- Maintain records of all data processing activities under your organization's control
- Conduct annual compliance reviews and report findings to executive leadership
- Train employees on data protection obligations relevant to their roles
Data Protection Impact Assessments (DPIAs)
A DPIA is a structured risk assessment required before initiating any high-risk processing activity. PDPL specifically requires DPIAs for: large-scale processing of sensitive personal data, systematic monitoring of public areas, processing using new technologies (AI, biometrics, IoT), automated decision-making with legal effects on individuals, and cross-border data transfers to countries without adequacy. The DPIA documents the processing purpose, evaluates necessity and proportionality, identifies risks to data subjects, and specifies mitigation measures. SDAIA can request DPIAs during audits — having them ready demonstrates good-faith compliance and reduces enforcement risk significantly.
Consent Requirements
Consent under the PDPL must be explicit, informed, freely given, and specific to the stated purpose. Pre-checked boxes, bundled consent, and dark patterns are prohibited. The data subject must understand what they are consenting to, and withdrawal of consent must be as easy as giving it. This has direct implications for how websites implement cookie consent banners — a generic 'Accept All' button without clear information about data categories does not meet the legal standard.
For sensitive data categories — including health, genetic, biometric, and financial data — the PDPL requires explicit written consent with additional safeguards. Organizations processing sensitive data must also conduct a data protection impact assessment before beginning processing. Cookie consent specifically must identify each category of cookies (essential, analytics, marketing, preferences) and allow granular opt-in choices.
Free bilingual privacy policy generator. Covers the seven mandatory PDPL disclosures.
Generate my policyVendor and Processor Management
Under PDPL, you remain legally responsible for personal data even when it is processed by third parties (vendors, SaaS providers, cloud platforms). This means you need contractual safeguards with every processor that touches Saudi resident data. The Data Processing Agreement (DPA) is the key document — it must specify the processing purpose, data categories, retention periods, security measures, sub-processor management, and breach notification obligations. International cloud providers (AWS, Google Cloud, Microsoft Azure) all offer PDPL-compliant DPAs through their compliance portals, but you must execute them — they are not auto-applied.
- Maintain an inventory of every vendor processing Saudi personal data, including SaaS tools, payment processors, email services, analytics, and cloud infrastructure
- Execute a Data Processing Agreement (DPA) with each processor before they begin processing
- Verify the processor's security certifications: ISO 27001, SOC 2, or equivalent regional standards
- Document sub-processor chains — your processor's processors are your responsibility too
- Conduct annual vendor risk reviews, especially for processors handling sensitive data
- Include audit rights in DPAs — you should be able to verify compliance on demand
Data Subject Rights
Saudi residents have comprehensive rights under the PDPL. Organizations must respond to data subject access requests (DSARs) within 30 days. Building systems to handle these requests efficiently is critical — manual processes break down at scale.
- Right to be informed: Know what data is collected, why, and who it is shared with
- Right of access: Obtain a copy of all personal data held by the organization
- Right to correction: Request correction of inaccurate or incomplete data
- Right to deletion: Request erasure of personal data when no longer needed
- Right to portability: Receive data in a structured, machine-readable format
- Right to withdraw consent: Revoke previously granted consent at any time
- Right to object: Object to processing based on legitimate interests
Building DSAR Response Workflows
Receiving a Data Subject Access Request triggers a 30-day legal response clock. To meet this consistently at scale, you need a documented workflow before requests arrive. The workflow should specify: how DSARs are received (web form, email, phone), how identity verification is performed (preventing unauthorized data disclosure), which systems need to be searched (database, e-commerce platform, analytics, CRM, email service), how data is compiled and reviewed for legal exemptions, and how the response is securely delivered. Manual DSAR handling typically takes 4-8 hours per request — at any meaningful volume, automation becomes necessary.
Cross-Border Data Transfers
The PDPL imposes strict controls on transferring personal data outside Saudi Arabia. Transfers are only permitted when the receiving country provides an adequate level of protection as determined by SDAIA, or when specific safeguards are in place (binding corporate rules, standard contractual clauses, or explicit consent from the data subject). Certain categories of data — particularly government-related and sensitive data — face additional restrictions. For businesses using international cloud providers, this means understanding where your data is stored and ensuring appropriate transfer mechanisms are in place.
For Saudi businesses using international cloud providers, the practical implications are significant. AWS Middle East (Bahrain) region, Google Cloud's Saudi region (Dammam), and Microsoft Azure's UAE North region (Abu Dhabi) all provide local data residency options that simplify PDPL compliance. Using these regional cloud zones, with appropriate DPAs in place, satisfies the cross-border transfer requirements for most processing activities. For businesses using US or European cloud regions, the legal pathway requires Standard Contractual Clauses (SCCs) modeled on the SDAIA-approved framework, plus a Transfer Impact Assessment documenting the risk analysis.
- SDAIA adequacy determination: Country listed in SDAIA's approved adequacy roster
- Standard Contractual Clauses (SCCs): Pre-approved contractual safeguards between sender and receiver
- Binding Corporate Rules (BCRs): Intra-group rules for multinational organizations
- Explicit consent: Data subject explicitly consents to the specific transfer with full disclosure
- Sub-processor disclosure: Notify data subjects of all sub-processors receiving their data
Penalties and Enforcement
SDAIA has broad enforcement powers under the PDPL, and penalties are designed to be dissuasive. The enforcement framework includes both administrative and criminal penalties:
- Administrative fines up to SAR 5 million (approximately $1.3 million USD) per violation
- Criminal penalties including imprisonment of up to 2 years for unauthorized data disclosure
- Public naming of violating organizations
- Orders to cease processing activities
- Requirement to notify affected data subjects at the organization's expense
- Repeated violations may result in doubled penalties
What PDPL Enforcement Looks Like in Practice
SDAIA's enforcement process typically begins one of three ways: a complaint filed by a data subject through SDAIA's online portal, a notification of a data breach that triggers an audit, or a proactive inspection targeting a specific sector or company type. Once an investigation is opened, SDAIA can request documentation (DPIAs, DPAs, consent records, security policies), conduct on-site inspections, interview staff, and require detailed remediation plans. The Authority operates on a graduated response model — first violations typically result in compliance orders and remediation requirements; repeated violations or willful non-compliance trigger financial penalties at the higher end of the statutory range.
SDAIA's specialised committees issued 48 enforcement decisions against organisations found in violation of the PDPL during 2025 — announced on 25 February 2026, and representing the first substantive wave of adjudications since the law became fully enforceable in September 2024. The decisions covered three violation categories that map directly to the most common findings in compliance scans: processing personal data without a lawful basis, insufficient technical and organisational security controls, and — most often — sending marketing or promotional messages without obtaining prior consent. SDAIA explicitly named retail, telecommunications, and financial services as the sectors most affected. The most common triggers for SDAIA enforcement action observed so far include: e-commerce sites operating without proper consent banners (the highest-frequency violation in the regulator's published decisions), Saudi entities transferring personal data to international processors without documented adequacy or safeguards, organisations processing sensitive personal data without explicit opt-in, and controllers ignoring data subject access requests beyond the 30-day statutory response window.
Step-by-Step Compliance Checklist
Achieving PDPL compliance requires a systematic approach. Here is the practical checklist that businesses operating in Saudi Arabia should follow:
- Appoint a Data Protection Officer (DPO) — required for organizations processing data at scale
- Conduct a data mapping exercise to identify all personal data flows
- Implement a Consent Management Platform with explicit opt-in for cookies and trackers
- Publish an Arabic-language privacy policy covering all PDPL-required disclosures
- Set up data breach notification procedures with a 72-hour reporting workflow
- Conduct Data Protection Impact Assessments (DPIAs) for high-risk processing
- Implement data minimization — stop collecting data you do not need
- Build DSAR handling workflows with 30-day response SLA tracking
- Review cross-border data transfers and implement appropriate safeguards
- Train employees on data protection obligations and incident response
Public report on PDPL compliance across 27 Saudi e-commerce stores. Median: 49/100.
Read the IndexSector-Specific Guidance
While PDPL applies uniformly across all sectors, certain industries face additional layered requirements from sector-specific regulators. Understanding both the PDPL baseline and the sector-specific overlays is essential for full compliance.
E-commerce Compliance
E-commerce businesses face the most public-facing PDPL scrutiny because their consent practices are visible to every visitor. Critical requirements: an Arabic consent banner that loads before any tracking scripts, granular category-level consent (essential, analytics, marketing, preferences), Google Consent Mode v2 implementation to maintain Google Ads functionality, automated DSAR handling for the inevitable access requests, and clear privacy policies in Arabic that disclose every third-party processor — including Salla/Shopify platform data flows, payment processors, shipping providers, and marketing analytics.
Fintech and Financial Services
Financial services operate under both PDPL and SAMA (Saudi Central Bank) regulations, which add data localization requirements for customer financial data. SAMA's Cyber Security Framework imposes additional security baseline requirements, and the Open Banking Framework introduces specific consent and data sharing rules. Fintechs handling payment data must also comply with PCI-DSS, with documented procedures for cardholder data handling. The intersection of PDPL + SAMA + PCI-DSS makes financial services one of the highest-complexity sectors for compliance.
Healthcare and Health-Tech
Healthcare data is sensitive data under PDPL, requiring explicit written consent and mandatory DPIAs. The Ministry of Health (MoH) issues additional requirements under the e-Health Strategy, including specific provisions for telemedicine, electronic health records (EHRs), and genomic data. Healthcare providers must maintain detailed audit logs of every data access, implement role-based access controls, and provide data subjects with detailed information about how their health data is used in research or analytics. Cross-border transfers of health data are particularly restricted.
SaaS Platforms Serving Saudi Users
International SaaS platforms processing Saudi user data fall under PDPL's extraterritorial reach. This means a US-based SaaS company with Saudi customers needs: a PDPL-compliant Arabic privacy policy, consent mechanisms that satisfy PDPL standards (often stricter than the company's home jurisdiction), a designated PDPL contact point for SDAIA and data subject inquiries, and appropriate cross-border data transfer mechanisms. Many international SaaS platforms are now establishing local processing nodes in Saudi Arabia to simplify compliance — this is becoming a competitive advantage in the regional market.
Most Common PDPL Compliance Mistakes
After supporting dozens of Saudi businesses through PDPL compliance, these are the mistakes we see most frequently — each one represents a significant enforcement risk:
- Using a generic European privacy policy template that references GDPR, EU regulators, and EU adequacy decisions instead of PDPL and SDAIA
- Operating without a consent banner because "we don't really track users" — even basic analytics and embedded social widgets trigger PDPL consent requirements
- Treating cookie consent as a one-time checkbox rather than category-level granular consent with withdrawal mechanisms
- No Arabic version of the privacy policy — English-only does not satisfy PDPL for Saudi consumer-facing businesses
- Cross-border data transfers happening invisibly through cloud providers without DPAs or documented safeguards
- Missing 72-hour breach notification procedures — most businesses have no documented process for what happens if a breach occurs
- DSAR requests handled ad-hoc by random employees — no documented workflow, no identity verification, no audit trail
Frequently Asked Questions
These are the questions Saudi businesses most commonly ask about PDPL compliance:
Yes, if you process personal data of individuals located in Saudi Arabia. PDPL has extraterritorial reach — a US e-commerce platform shipping to Saudi customers, a European SaaS with Saudi subscribers, or a Dubai agency managing Saudi marketing campaigns all fall under PDPL regardless of where the company is headquartered.
SDAIA transitioned from education-first to enforcement-first posture in September 2024. As of 2026, active monitoring and audits are underway. The Authority typically follows a graduated approach: first-time violations result in compliance orders and remediation requirements, while repeated or willful violations trigger financial penalties at the statutory range (up to SAR 5,000,000 per violation).
Required for: government entities processing personal data, organizations whose core activities involve large-scale processing or monitoring of data subjects, and organizations processing sensitive personal data at scale. For most mid-market businesses, a designated employee taking on DPO responsibilities or a fractional/external DPO service satisfies the requirement.
Yes, but only with proper PDPL-compliant consent. You need: a consent banner that loads before GA fires, Google Consent Mode v2 implementation that signals consent state to Google's tag, granular category-level consent (analytics is one category), and consent records stored as audit evidence. Without these, you are processing personal data without legal basis.
Yes, with consent. Email addresses are personal data, and using them for marketing requires explicit opt-in consent at the point of collection. Pre-checked boxes do not count. You also need an easy unsubscribe mechanism in every marketing email, and you must honor unsubscribe requests within a reasonable period (typically 7 days).
Automate the routine 80%. A DSAR automation platform connects to your data sources (e-commerce platform, CRM, analytics, consent database), searches automatically when a request is received, and compiles the response in minutes instead of days. Your team then reviews for legal exemptions and approves delivery. Manual DSAR handling becomes unsustainable past 10+ requests per month.
Yes, when configured correctly. Both AWS (Middle East/Bahrain region) and Google Cloud (Saudi region in Dammam) offer local data residency options that simplify PDPL compliance. You need to: select Saudi or regional data residency, execute the PDPL-compliant DPA from the provider's compliance portal, and document this in your processor inventory.
If you process personal data of individuals located in Saudi Arabia (Saudi residents using your platform), PDPL applies extraterritorially. You need: a PDPL-compliant Arabic privacy policy, consent mechanisms meeting PDPL standards, a designated PDPL contact for SDAIA and data subjects, and appropriate cross-border transfer mechanisms. Many SaaS companies are establishing local processing nodes in Saudi to simplify compliance and gain competitive advantage in the regional market.
Official Sources and Further Reading
SDAIA Official Website Personal Data Protection Law (Royal Decree M/19) PDPL Implementing Regulations Google Consent Mode v2 DocumentationHow Arqam360 Helps You Comply
Arqam360 is purpose-built for Saudi PDPL compliance. Unlike European CMPs that bolt on Arabic translations as an afterthought, Arqam360 was designed from the ground up for the MENA region. The consent banner supports native Arabic RTL layout, displays the correct legal language required by PDPL, and stores granular consent records with timestamps that serve as your compliance evidence.
Beyond consent management, Arqam360 provides automated cookie scanning to identify every tracker on your site, a policy generator that creates PDPL-compliant privacy policies in Arabic and English, automated DSAR handling with 30-day SLA tracking, and Google Consent Mode v2 integration so your advertising data remains compliant. For Salla store owners, installation is zero-click — the app auto-provisions everything on install. Start with a free cookie scan to see your current compliance status.
Ready for MENA compliance?
Arqam360 handles GDPR, Saudi PDPL, and UAE PDPA from a single platform — with Arabic RTL support built in.
Start Free TrialRelated Articles
Stay updated
Get privacy compliance tips and Arqam360 updates delivered to your inbox.