PDPL Compliance Guide: What Saudi Enterprises Need to Know in 2026

Saudi Arabia's data protection law is now fully enforced and regulators have already issued 48 formal decisions against organisations that fell short. Here is a clear, practical guide to what the law requires, what the penalties are, and exactly how your IT team can get compliant.

Saudi Arabia's data protection law is now fully enforced and regulators have already issued 48 formal decisions against organisations that fell short. Here is a clear, practical guide to what the law requires, what the penalties are, and exactly how your IT team can get compliant.

What Is the PDPL and Why Does It Matter Right Now?

Saudi Arabia's Personal Data Protection Law (PDPL) is the Kingdom's first comprehensive law governing how organisations collect, store, process, and share personal information about individuals. It was issued under Royal Decree No. M/19 in September 2021, updated by Royal Decree No. M/148 in March 2023, and came fully into force on 14 September 2023.

For the first year, organisations were given time to prepare. That grace period ended on 14 September 2024. Since then, the Saudi Data and Artificial Intelligence Authority (SDAIA) (the law's official regulator) has been issuing formal enforcement decisions, investigating complaints, and imposing penalties on organisations that are not compliant.

Key Enforcement Statistics

  • 48: SDAIA enforcement decisions issued as of early 2026.
  • SAR 5M: Maximum fine per violation (~USD 1.33M).
  • 72 hrs: Timeframe to report a data breach to SDAIA after discovery.
  • 5 days: Timeframe to respond once a violation notice is received.

If your organisation operates in Saudi Arabia or simply handles data about people living in the Kingdom, these numbers apply to you. The PDPL's reach extends beyond Saudi borders: any company anywhere in the world that processes the personal data of Saudi residents must comply, regardless of where that company is physically located.

Quick definition: "Processing" covers almost everything; collecting, storing, viewing, sharing, transferring, using, or deleting personal data. If your systems touch data about an individual, the PDPL applies.

PDPL: Key Dates and Regulatory Timeline

  • September 2021: PDPL enacted by Royal Decree No. M/19.
  • March 2023: PDPL updated by Royal Decree No. M/148 adds legitimate interests as a lawful basis and strengthens transfer rules.
  • September 7, 2023: SDAIA publishes the Implementing Regulations.
  • September 14, 2023: PDPL enters into force, one-year preparation period begins.
  • September 14, 2024: Full enforcement begins. Grace period over. All organisations must now comply.
  • February 2025: SDAIA publishes the Risk Assessment Guideline for transferring personal data outside the Kingdom.
  • November 2025: SDAIA publishes its AI Adoption Framework. Organisations using AI that processes personal data must now meet dual obligations.
  • Early 2026: SDAIA announces 48 cumulative enforcement decisions. Saudi Arabia officially declares 2026 the Year of AI.

Who Does the PDPL Apply To?

The PDPL applies to any organisation or individual that processes personal data of people located in Saudi Arabia, whether that organisation is based inside or outside the Kingdom.

In practical terms, this means:

  • Saudi-based companies of any size and sector.
  • Government entities and public sector organisations.
  • International companies with a website, app, or service used by Saudi residents.
  • Cloud providers, managed service providers, and SaaS platforms that host or process Saudi customer data.
  • HR platforms that manage employee data for Saudi-based staff.
  • Any company transferring Saudi residents' data to systems outside the Kingdom.

Important: The PDPL's reach is wider than Europe's GDPR in one key way. GDPR only applies to organisations that specifically target EU residents or monitor their behaviour. The PDPL applies to any processing of Saudi residents' data, regardless of the reason, meaning even a business with no deliberate Saudi strategy can fall within scope if Saudi residents happen to use its services.

What Data Does the PDPL Protect?

The PDPL distinguishes between two tiers of personal data. The tier determines what rules apply and how strict they are.

What Data Does the PDPL Protect? Standard vs Sensitive Data
Data Type Examples Classification
Name, national ID number Full name, Iqama number, passport number Standard
Contact information Email address, phone number, home address Standard
Photos and recordings Profile photos, voice notes Standard
Health and medical data Medical records, diagnoses, prescriptions Sensitive
Financial information Bank accounts, credit records, salary details Sensitive
Biometric data Fingerprints, facial recognition, retinal scans Sensitive
Genetic data DNA profiles, genetic test results Sensitive
Beliefs and affiliations Religious beliefs, political or intellectual views Sensitive
Criminal and security records Criminal history, security-related records Sensitive
Unknown parentage data Data revealing that one or both parents are unknown KSA-Specific Sensitive

Sensitive data requires stricter consent, stronger security controls, and carries higher criminal penalties for unauthorised disclosure. The "unknown parentage" category is unique to the PDPL, it does not exist in GDPR or most comparable frameworks.

PDPL vs GDPR: The Key Differences

Many organisations operating in Saudi Arabia already have a GDPR compliance programme in place. While the two laws share the same basic goal of protecting people's personal data, there are important differences that mean a GDPR programme alone will not make you PDPL compliant.

Area Saudi PDPL EU GDPR
Who it covers Any processing of data of people in Saudi Arabia, regardless of purpose or the organisation's location Processing of EU residents' data where the organisation targets them or monitors their behaviour
Default lawful basis Consent — explicit, specific, documented, and revocable. Primary basis for most processing. Six lawful bases available (consent, legitimate interests, contract, legal obligation, vital interests, public task)
Legitimate interests Available since 2023 amendments, but cannot be used for sensitive data Widely used across many data types, with some restrictions for sensitive categories
Sensitive data categories Health, financial, biometric, genetic, beliefs, criminal, parentage data (parentage = KSA-unique) Health, biometric, genetic, beliefs, racial/ethnic origin, trade union membership, sexual orientation
Cross-border transfers Restricted by default. Requires adequacy assessment or SDAIA-approved SCCs/BCRs. EU SCCs alone are not sufficient. Restricted to countries without an EU adequacy decision, unless EU SCCs or BCRs are in place
Data subject response time 30 days (extendable by 30 days with notice to the individual) 30 days (extendable by 2 months for complex requests)
Breach notification deadline 72 hours to notify SDAIA — no materiality threshold 72 hours to notify the supervisory authority — only for breaches likely to cause risk to individuals
Maximum fine SAR 5 million (~USD 1.33M) per violation; doubled for repeat offences €20 million or 4% of global annual turnover, whichever is higher
Criminal penalties Up to 2 years imprisonment + SAR 3M fine for intentional disclosure of sensitive data Criminal penalties are set by individual EU member states — no EU-wide imprisonment provision
Regulator SDAIA (Saudi Data and Artificial Intelligence Authority) National supervisory authorities in each EU member state, coordinated by the EDPB

The single most important difference for GDPR-compliant organisations: If your current compliance programme relies heavily on "legitimate interests" as your lawful basis for processing, you will need to revisit every processing activity that involves Saudi residents' data and either obtain explicit consent or identify a different valid basis. This is the most common gap we see in organisations that assume their GDPR programme covers PDPL.

PDPL Penalties: What Non-Compliance Actually Costs

The consequences of failing to comply with the PDPL go beyond a fine. SDAIA can suspend your processing activities entirely which, for a business that depends on customer data or digital services, can bring operations to a halt.

Here is the full penalty picture, based on the published law:

  • Written warning: for first or minor violations.
  • Fine up to SAR 5 million (~USD 1.33M): for substantive violations.
  • Fine up to SAR 10 million (~USD 2.67M): for repeat violations (double the standard maximum).
  • Processing suspension: SDAIA can order you to stop processing data entirely.
  • Publication of the decision: judgment published publicly at the organisation's expense.
  • Up to 2 years imprisonment + SAR 3M fine: for intentional disclosure of sensitive personal data.
  • Up to 4 years imprisonment + SAR 6M fine: for repeat criminal offences.

The 5-day window you cannot miss: Once SDAIA notifies your organisation of an alleged violation, you have just five days to submit your response and supporting evidence. This is not enough time to begin building a compliance programme from scratch. Your documentation, records of processing, and authorised representatives must all be in place before a notification arrives.

The four most common violations in SDAIA's 48 enforcement decisions were:

  1. Processing personal data without a valid lawful basis.
  2. Unauthorised disclosure of personal data.
  3. Failure to implement adequate technical security controls.
  4. Sending marketing messages without prior explicit consent.

Three of these four are primarily IT infrastructure failures not legal ones.

How to Achieve PDPL Compliance: 8 Practical Steps for IT Teams

PDPL compliance is not a one-time project, it is a continuous programme. But it starts with these eight concrete actions that IT Directors, CISOs, and compliance teams can begin immediately:

How to Achieve PDPL Compliance: 8 Practical Steps for IT Teams

1. Appoint a Data Protection Officer (DPO)

A DPO is mandatory if your organisation is a public entity, processes sensitive data at scale, or regularly transfers data outside Saudi Arabia. Even if it is not strictly required in your case, appointing one even as a part-time role or an outsourced function gives you a dedicated person responsible for tracking PDPL obligations and responding to SDAIA enquiries.

2. Map All Your Data Flows

Before you can comply, you need to know what personal data your organisation holds, where it came from, where it is stored, who can access it, and where it goes. This data inventory which SDAIA can request at any time is the foundation of everything else. Include data in HR systems, CRM tools, cloud platforms, marketing databases, supplier portals, and any third-party processors.

3. Classify Your Data by Sensitivity

Once mapped, label every data category as standard personal data or sensitive personal data. Sensitive data requires stronger security controls, explicit consent for all processing, and cannot be relied upon via legitimate interests under any circumstances. This classification step tells you exactly where your highest-risk exposure lies.

4. Build Explicit Consent Mechanisms

For any processing activity that relies on consent which under the PDPL is most of them, you need a consent system that records explicit, specific, and revocable agreement from each individual. This means updating website forms, mobile app sign-ups, employee onboarding workflows, and marketing subscription processes. Pre-ticked boxes, implied consent, and bundled consent statements are all non-compliant. Your privacy policy must be available in Arabic and clearly explain what data is collected, why, and how long it is kept.

5. Implement the Right Technical Security Controls

Failure to implement adequate security controls is one of the top four violation categories in SDAIA's enforcement decisions. At minimum, your infrastructure must include: encryption for data at rest and in transit; role-based access controls limiting who can see what; audit logging for all access to sensitive data; network segmentation keeping sensitive systems isolated; endpoint protection on all devices accessing personal data; and regular vulnerability assessments.

GBG Tip: GBG's MSSP solution and Zero Trust Security Service provide the technical controls layer that PDPL compliance requires.

6. Review Every Cross-Border Data Transfer

If any of your cloud platforms, HR systems, analytics tools, or managed services store or process Saudi residents' data outside the Kingdom, you need to assess and document each transfer. As of mid-2026, SDAIA has not published an adequacy list, so you cannot simply rely on a destination country being "safe". You need SDAIA-approved Standard Contractual Clauses or Binding Corporate Rules in place for each transfer. Note that EU SCCs alone are not sufficient. For sensitive data, a formal risk assessment following SDAIA's February 2025 guideline is mandatory before the transfer begins.

GBG Tip: GBG's cloud architecture team can help you design a data residency strategy that keeps sensitive workloads inside the Kingdom where required. See our Cloud Solutions.

7. Build a 72-Hour Breach Response Plan

You have 72 hours from the moment you discover a breach to notify SDAIA with no minimum size threshold. This means every breach that may harm personal data must be reported, not just major ones. Your response plan must assign clear responsibilities: who detects incidents, who assesses them, who prepares the SDAIA notification, and who notifies affected individuals. Test this plan at least once per year. All notifications go through SDAIA's National Data Governance Platform (NDGP). You need to be registered there before a breach happens, not after.

8. Register with SDAIA and Run an Annual Audit

Most organisations processing personal data in Saudi Arabia are required to register their data activities on SDAIA's NDGP. Registration is free and completed online. Once registered, schedule a formal PDPL compliance audit each year. It is not just a legal review, but a hands-on technical audit of your actual controls, access logs, data flows, and breach procedures. Compliance is not a certification you earn once; it is a programme you run continuously.

PDPL and AI in 2026: A New Layer of Obligations

Saudi Arabia declared 2026 its official Year of AI. SDAIA, which regulates both data protection and artificial intelligence in the Kingdom, published its AI Adoption Framework in November 2025. This framework creates mandatory governance requirements for any AI system that processes personal data.

If your organisation uses AI tools, customer service chatbots, automated decision systems, data analytics platforms, Microsoft Copilot, or any other AI-powered product and those tools touch personal data of Saudi residents, you now face two sets of obligations simultaneously: PDPL compliance and AI Adoption Framework compliance.

The practical questions to ask for each AI system in your environment are:

  • Does this AI system process personal data of Saudi residents?
  • Has explicit consent been obtained for AI-driven processing where required?
  • Has a Data Protection Impact Assessment been completed for this system?
  • Is there documented human oversight of AI-generated decisions?
  • Is the data used to train or run this system being transferred outside the Kingdom?

GBG insight: At the IDC CIO Summit Egypt 2026, GBG showcased how Agentic AI solutions can be deployed in enterprise environments in a way that maintains data governance and audit trails, both key requirements for PDPL-compliant AI use. Our team can assess whether your existing AI deployments meet SDAIA's expectations.

Frequently Asked Questions About PDPL Compliance

1. What is the PDPL in Saudi Arabia?

The PDPL (Personal Data Protection Law) is Saudi Arabia's national data protection law, issued under Royal Decree No. M/19 in September 2021 and updated in March 2023. It sets out how organisations must collect, store, process, and share the personal data of individuals in Saudi Arabia. It is enforced by SDAIA (the Saudi Data and Artificial Intelligence Authority) and has been fully in force since September 14, 2024.

2. Who does the PDPL apply to?

The PDPL applies to any organisation—Saudi-based or international—that processes personal data of individuals located in Saudi Arabia. This includes companies that process Saudi residents' data from outside the Kingdom, such as cloud providers, SaaS platforms, e-commerce businesses, and managed service providers, even if they have no physical presence in Saudi Arabia.

3. What are the PDPL penalties for non-compliance?

Fines reach up to SAR 5 million (approximately USD 1.33 million) per violation, with that amount doubling for repeat violations. SDAIA can also suspend your data processing activities. Intentionally disclosing sensitive personal data is a criminal offence, carrying up to two years imprisonment and a fine of up to SAR 3 million. For repeat criminal offences, both penalties can double.

4. How is PDPL different from GDPR?

Both laws protect personal data, but they differ in several important ways. The PDPL relies more heavily on explicit consent as the lawful basis for processing; legitimate interests cannot be used at all for sensitive personal data. The PDPL's cross-border transfer rules are stricter, and EU Standard Contractual Clauses alone are not sufficient. The PDPL also includes criminal imprisonment as a penalty, which has no direct equivalent in GDPR.

5. Do I need to appoint a Data Protection Officer under the PDPL?

A DPO is mandatory for public entities that provide large-scale services involving personal data, organisations whose core activities involve processing sensitive personal data at scale, and those that regularly transfer data outside Saudi Arabia. Even where it is not strictly required, appointing a DPO (including through an outsourced service provider) is strongly recommended.

6. What is the breach notification deadline under the PDPL?

You must notify SDAIA within 72 hours of discovering a data breach that may harm personal data or individuals' rights. There is no minimum size threshold; any qualifying breach must be reported. Notifications are submitted through SDAIA's National Data Governance Platform (NDGP).

7. Can I transfer data outside Saudi Arabia under the PDPL?

Yes, but only if specific conditions are met. The transfer must not harm national security or public interest, the receiving country must offer adequate data protection, and SDAIA-approved safeguards (like Standard Contractual Clauses) must be in place. For sensitive data, a formal risk assessment is required.

8. Does PDPL apply to AI systems?

Yes. If an AI system processes personal data of Saudi residents, PDPL obligations apply (consent, Data Protection Impact Assessments, data minimisation). On top of this, SDAIA's AI Adoption Framework (published November 2025) adds governance requirements covering data governance, model accountability, transparency, and human oversight.

9. Is PDPL being actively enforced in 2026?

Yes. The grace period ended on September 14, 2024. As of early 2026, SDAIA's enforcement committees had issued 48 formal decisions against organisations found in violation. Once an investigation is opened, organisations have just five days to respond.


Ready to Assess Your PDPL Stand?

Our security team offers a PDPL Readiness Assessment that identifies your compliance gaps, maps your current data flows against SDAIA's requirements, and delivers a prioritised action plan in plain language, not legal jargon.

No commitment required · 30-minute session with a GBG security engineer · Available for KSA and Egypt-based teams.

Legal disclaimer: This article provides general information about the PDPL for educational purposes. It does not constitute legal advice. For guidance on your organisation's specific compliance obligations, consult a qualified legal adviser with expertise in Saudi data protection law.

...

Need a bespoke IT solution for your business?

Start a complimentary and obligation-free 30-minute consultation with our business development engineers. Together, we’ll design an IT solution that suits your business operations and scale.

Global Brands Group has been inaugurated with an inventive spirit, and this spirit continues to guide us through our journey. Ever- listening and -answering to industry shifts and demands, GBG grows, transforms and caters to an ever-expanding customer base.

preloader