The Saudi Personal Data Protection Law (PDPL) came into force on 14 September 2023 and has been fully enforceable since 14 September 2024, overseen by the Saudi Data and Artificial Intelligence Authority (SDAIA). A data controller must notify SDAIA of a personal data breach within 72 hours of becoming aware of it. Penalties reach SAR 5 million. IT owns the technical half: access, encryption, logging, retention and a rehearsed breach process.
The PDPL entered into force on 14 September 2023, with a one-year transition, and has been fully enforceable since 14 September 2024. SDAIA oversees enforcement through specialised committees that review violations. Law firm Clyde & Co reported that by mid-January 2026 the committees had issued 48 enforcement decisions across multiple sectors.
The PDPL is supported by Implementing Regulations. This guide summarises the law as reported by the sources listed below. The official texts and your legal adviser are the authority.
According to DLA Piper’s summary, the data controller must notify SDAIA through the National Data Governance Platform within 72 hours of becoming aware of a breach, and must notify affected individuals without undue delay. The same summary notes that other regulators may need to be told in specific sectors, for example a cloud service provider may need to report to the CST.
Decide these things before an incident:
DLA Piper summarises two tiers: for most violations, a warning or a fine of up to SAR 5 million; and for intentional disclosure of sensitive data that causes harm, imprisonment of up to two years and/or a fine of up to SAR 3 million. Repeat offenders can face doubled fines, and harmed individuals can claim compensation for material or moral damage.
The PDPL defines sensitive data to include, among other categories, criminal and security data, biometric data, genetic data, credit data, health data, location data and data indicating that one or both parents are unknown. Hospitals, insurers, lenders and any business that tracks location or uses biometric access control should treat these categories as higher risk.
| IT builds and evidences | Legal or the data protection lead decides |
|---|---|
| Least-privilege access and regular access reviews | What personal data you hold and why |
| Encryption on devices, in storage and in transit | Lawful basis and consent |
| Logging that lets you reconstruct what happened | Privacy notices and individuals’ requests |
| Retention and deletion settings | How long each category may be kept |
| Backup, recovery and a tested breach process | Whether an event must be notified and to whom |
Last reviewed 20 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
