Insights · PDPL

Saudi PDPL: an IT checklist for the Personal Data Protection Law

What the Saudi PDPL means for IT: enforced since September 2024, the 72-hour breach notice to SDAIA, the penalties and the technical measures needed.
The short answer

The Saudi Personal Data Protection Law (PDPL) came into force on 14 September 2023 and has been fully enforceable since 14 September 2024, overseen by the Saudi Data and Artificial Intelligence Authority (SDAIA). A data controller must notify SDAIA of a personal data breach within 72 hours of becoming aware of it. Penalties reach SAR 5 million. IT owns the technical half: access, encryption, logging, retention and a rehearsed breach process.

Key points
  • The PDPL entered into force on 14 September 2023 and became fully enforceable on 14 September 2024. SDAIA is the competent authority.
  • A controller must notify SDAIA within 72 hours of becoming aware of a breach, through the National Data Governance Platform, and tell affected individuals without undue delay.
  • Fines for violations reach SAR 5 million and can be doubled for repeat offences. Intentional disclosure of sensitive data can carry up to two years in prison and/or a SAR 3 million fine.
  • Sensitive data includes health, genetic, credit, biometric and location data.
  • IT builds the controls and the evidence. Lawful basis, notices and materiality decisions belong to your data protection lead or legal adviser.

Where the PDPL stands

The PDPL entered into force on 14 September 2023, with a one-year transition, and has been fully enforceable since 14 September 2024. SDAIA oversees enforcement through specialised committees that review violations. Law firm Clyde & Co reported that by mid-January 2026 the committees had issued 48 enforcement decisions across multiple sectors.

The PDPL is supported by Implementing Regulations. This guide summarises the law as reported by the sources listed below. The official texts and your legal adviser are the authority.

Breach notification: the 72-hour clock

According to DLA Piper’s summary, the data controller must notify SDAIA through the National Data Governance Platform within 72 hours of becoming aware of a breach, and must notify affected individuals without undue delay. The same summary notes that other regulators may need to be told in specific sectors, for example a cloud service provider may need to report to the CST.

Decide these things before an incident:

  • Who decides whether an event is a personal data breach, and how fast they can be reached.
  • Who can submit to the National Data Governance Platform, and whether they have practised it.
  • Which logs, system details and contacts you need in the first 24 hours.
  • How your IT provider must notify you, in writing in the contract, so that their delay does not use up your 72 hours.

Penalties

DLA Piper summarises two tiers: for most violations, a warning or a fine of up to SAR 5 million; and for intentional disclosure of sensitive data that causes harm, imprisonment of up to two years and/or a fine of up to SAR 3 million. Repeat offenders can face doubled fines, and harmed individuals can claim compensation for material or moral damage.

Sensitive data: health, credit, biometric and location

The PDPL defines sensitive data to include, among other categories, criminal and security data, biometric data, genetic data, credit data, health data, location data and data indicating that one or both parents are unknown. Hospitals, insurers, lenders and any business that tracks location or uses biometric access control should treat these categories as higher risk.

IT builds and evidencesLegal or the data protection lead decides
Least-privilege access and regular access reviewsWhat personal data you hold and why
Encryption on devices, in storage and in transitLawful basis and consent
Logging that lets you reconstruct what happenedPrivacy notices and individuals’ requests
Retention and deletion settingsHow long each category may be kept
Backup, recovery and a tested breach processWhether an event must be notified and to whom

A practical IT checklist

  1. Map where personal data lives: Microsoft 365, file servers, line-of-business systems, laptops and phones.
  2. Turn on multi-factor authentication and remove standing admin access.
  3. Encrypt devices and restrict removable media and sharing.
  4. Set retention so data is not kept longer than the legal team decides.
  5. Confirm logs are on, retained and searchable.
  6. Write the breach process down, name the people, and rehearse it once.
  7. Put breach notification and data return terms in every IT provider contract.

Sources and further reading

Last reviewed 20 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

When did the Saudi PDPL become enforceable?

It entered into force on 14 September 2023 and has been fully enforceable since 14 September 2024, after a one-year transition.

How quickly must a breach be reported?

According to DLA Piper’s summary, to SDAIA within 72 hours of becoming aware, through the National Data Governance Platform, and to affected individuals without undue delay.

What are the penalties?

Warnings or fines of up to SAR 5 million for most violations, doubled for repeat offences, and up to two years’ imprisonment and/or SAR 3 million for intentional disclosure of sensitive data that causes harm.

Does using Cre8 IT make us PDPL compliant?

No provider can. We implement and evidence the technical measures. Your legal adviser or data protection lead owns the legal decisions.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
Cloud and Microsoft 365

Microsoft 365 and cloud governance for Saudi organisations

What the NCA’s cloud controls say, where data localisation now sits, what Microsoft has announced for Saudi Arabia and the Microsoft 365 settings to keep.
3 min read · Reviewed 20 September 2026
Audit readiness

Audit readiness for NCA and SAMA reviews: the IT evidence checklist

How the NCA assesses ECC compliance, what control 1-8 requires, the evidence pack to build and how ISO 27001:2022 fits alongside.
3 min read · Reviewed 20 September 2026
NCA ECC

NCA Essential Cybersecurity Controls (ECC-2:2024): what Saudi organisations need to evidence

A plain-English guide to the NCA’s ECC-2:2024: who it applies to, its four domains, what changed from ECC-1:2018 and the IT evidence to keep.
6 min read · Reviewed 20 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.