Skip to content
GlanceDeskJurisdiction

Home › Law library › Saudi PDPL

SA

Saudi PDPL

Personal Data Protection Law (Royal Decree No. M/19 of 1443H, amended by Royal Decree No. M/148 of 1444H)

Sourced. Last verified 9 October 2026

Saudi Arabia Privacy

Status
In force 14 September 2023; full enforcement since 14 September 2024 (some entities may have extended deadlines).
Who it applies to
Any processing of personal data of individuals in Saudi Arabia, including by entities outside the Kingdom that process data of Saudi residents (extraterritorial). Covers all sectors with limited exceptions.
Size thresholds
No size threshold. DPO and registration duties depend on the type and scale of processing.
Regulator
Saudi Data & AI Authority (SDAIA). The Saudi Central Bank and CST keep powers within their sectors.
Breach or incident reporting
Notify SDAIA via the National Data Governance Platform within 72 hours of becoming aware; notify affected individuals without undue delay where the breach may harm them.
Deadline to answer personal data requests
30 days, extendable by a further 30 days for requests needing unusual effort or for multiple requests.
Data protection officer
Required for public entities processing at large scale, controllers whose core activity is regular, systematic monitoring of individuals, and controllers whose core activity is processing sensitive data. Can be internal or external.
Local representative
Being verified
Sending data abroad
Under the Transfer Regulation (amended 1 Sept 2024): allowed to adequate countries, or with SDAIA SCCs, binding common rules or accreditation certificates, or limited exemptions. Risk assessment needed for safeguard-based or large sensitive transfers.
Cookies and consent
Consent is the primary legal basis, with listed exceptions. No specific cookie legislation.
Maximum penalty
Fines up to SAR 5 million (doubled for repeat offences). Intentionally disclosing sensitive data to cause harm or gain benefit: up to 2 years' prison and/or SAR 3 million.

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

Full enforcement began 14 Sept 2024. 1 Sept 2024: amended Transfer Regulation and first SDAIA SCCs (4 modules). SDAIA guidelines issued on DPO appointment, privacy policies, destruction, anonymisation and breach notification.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].