Home › Law library › Saudi PDPL
SA
Saudi PDPL
Personal Data Protection Law (Royal Decree No. M/19 of 1443H, amended by Royal Decree No. M/148 of 1444H)
Sourced. Last verified 9 October 2026
Saudi Arabia Privacy
- Status
- In force 14 September 2023; full enforcement since 14 September 2024 (some entities may have extended deadlines).
- Who it applies to
- Any processing of personal data of individuals in Saudi Arabia, including by entities outside the Kingdom that process data of Saudi residents (extraterritorial). Covers all sectors with limited exceptions.
- Size thresholds
- No size threshold. DPO and registration duties depend on the type and scale of processing.
- Regulator
- Saudi Data & AI Authority (SDAIA). The Saudi Central Bank and CST keep powers within their sectors.
- Breach or incident reporting
- Notify SDAIA via the National Data Governance Platform within 72 hours of becoming aware; notify affected individuals without undue delay where the breach may harm them.
- Deadline to answer personal data requests
- 30 days, extendable by a further 30 days for requests needing unusual effort or for multiple requests.
- Data protection officer
- Required for public entities processing at large scale, controllers whose core activity is regular, systematic monitoring of individuals, and controllers whose core activity is processing sensitive data. Can be internal or external.
- Local representative
- Being verified
- Sending data abroad
- Under the Transfer Regulation (amended 1 Sept 2024): allowed to adequate countries, or with SDAIA SCCs, binding common rules or accreditation certificates, or limited exemptions. Risk assessment needed for safeguard-based or large sensitive transfers.
- Cookies and consent
- Consent is the primary legal basis, with listed exceptions. No specific cookie legislation.
- Maximum penalty
- Fines up to SAR 5 million (doubled for repeat offences). Intentionally disclosing sensitive data to cause harm or gain benefit: up to 2 years' prison and/or SAR 3 million.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Register on SDAIA's National Data Governance Platform where required, including foreign entities.
- Use SDAIA's tool to check if a DPO is mandatory, and appoint one if so.
- Report breaches to SDAIA within 72 hours; notify harmed individuals without undue delay.
- Answer data subject requests within 30 days (one 30-day extension allowed).
- Use SDAIA SCCs or another approved safeguard for transfers abroad, and document a risk assessment.
- Keep records of processing during processing and for five years after it ends.
- Collect consent unless another statutory basis applies.
Recent changes
Full enforcement began 14 Sept 2024. 1 Sept 2024: amended Transfer Regulation and first SDAIA SCCs (4 modules). SDAIA guidelines issued on DPO appointment, privacy policies, destruction, anonymisation and breach notification.
Sources
- Primary source: https://dgp.sdaia.gov.sa/wps/portal/pdp/home
- Second source: https://www.dlapiperdataprotection.com/index.html?t=law&c=SA
- Regulator: Saudi Data & AI Authority (SDAIA). The Saudi Central Bank and CST keep powers within their sectors.
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].