Enquire Us

KSA PDPL Compliance

The Saudi Personal Data Protection Law is legislation issued by Royal Decree and regulated by SDAIA. It is a law rather than a certifiable standard, and this page sets out what it requires and what evidence of compliance actually looks like.

The Law and the Regulator

The Personal Data Protection Law was issued by Royal Decree M/19 and subsequently amended by Royal Decree M/148, dated 27 March 2023. Two subordinate instruments give it operational detail: the Implementing Regulation of the Personal Data Protection Law and the Regulation on Personal Data Transfer outside the Kingdom, both published in September 2023.

The regulator is the Saudi Data and Artificial Intelligence Authority, known as SDAIA. Following a transitional period the law became enforceable on 14 September 2024, so obligations are live and not prospective.

Penalties are set out in the law itself:

  • Disclosure or publication of sensitive data in breach of the law can attract imprisonment for up to two years, a fine of up to three million Saudi riyals, or both.
  • Other violations can attract a warning or a fine of up to five million Saudi riyals.
  • Fines may be doubled for repeat violations.
  • Individuals who suffer damage retain the right to claim compensation through the competent courts.

There Is No PDPL Certification, but There Is Now an Accreditation Certificate Scheme

The PDPL is legislation. It is not a management system standard, so there is no ISO style certification against it, no accredited certification body scheme and no Stage 1 and Stage 2 audit cycle. Compliance is a legal state that a regulator assesses, not a certificate a body awards.

One qualification is worth stating precisely, because it is recent. SDAIA has published Rules Governing the Issuance of Accreditation Certificates for Controllers and Processors, issue 1.0, in 2026. The scheme is voluntary, and the important structural point is that the certificate is issued by a licensee authorised by the competent authority rather than directly by SDAIA. It is presented as a way of evidencing the maturity of privacy governance, not as a substitute for compliance with the law. Availability depends on licensing being in place, so check the current position with SDAIA before building a programme around it.

In the meantime, organisations demonstrate their position through a documented gap assessment against the law and the implementing regulations, records of processing, and an independent review. ISO/IEC 27001 certification is frequently used alongside this as evidence of the security measures the law requires, but it is not a finding of PDPL compliance.

What the Law Requires

  • Lawful basis and consent. Processing requires a lawful basis. Where consent is relied on it must be freely given and specific, and the data subject may withdraw it.
  • Privacy notice. Data subjects must be told the purpose of collection, the identity of the controller where collection is not from them directly, and the other particulars the law specifies before collection.
  • Records of processing activities. Controllers must maintain records covering purposes, categories of data and recipients, transfers outside the Kingdom and retention periods.
  • Data subject rights. The right to be informed, to access, to obtain a copy, to request correction and to request destruction, exercised through defined procedures and timeframes.
  • Data protection officer. Required in defined circumstances, including public entities providing services involving large scale personal data processing, and controllers whose core activities involve regular monitoring or processing of sensitive data.
  • Impact assessment. Required for processing likely to present a high risk, and for products and services directed at personal data.
  • Breach notification. SDAIA must be notified on becoming aware of an incident that harms the data or the data subject, and data subjects must be told where the breach could cause them damage.
  • Transfers outside the Kingdom. Permitted only on the grounds and subject to the safeguards set out in the transfer regulation, which include an assessment of the risk to the data subject.
  • Registration. Controllers are required to register on the national platform operated by SDAIA.

How Univate Runs a PDPL Engagement

  1. Applicability and scoping. Establish which entities process personal data of individuals in the Kingdom, and which are acting as controller or processor.
  2. Data mapping. Build the record of processing activities, including transfers outside the Kingdom and the hosting arrangements behind them.
  3. Gap assessment. Test each obligation in the law and the two regulations against evidence, and produce a finding register with owners and severity.
  4. Remediation. Notices, consent capture, retention and destruction, rights handling, vendor terms, transfer assessments, security measures and breach response.
  5. Sustainment. Registration, data protection officer support, impact assessment triggers, staff training and periodic review.

Points Worth Being Careful About

  • The PDPL is not a copy of the GDPR. Consent, legitimate interests, breach timelines and transfer rules differ, and a GDPR programme lifted wholesale will leave gaps.
  • Data localisation is not an absolute rule, but transfers outside the Kingdom must satisfy the transfer regulation, which requires an assessment rather than a contractual clause alone.
  • An ISO/IEC 27001 certificate does not evidence PDPL compliance. It evidences an information security management system, which is one part of the obligation.
  • The law reaches organisations outside the Kingdom that process personal data of individuals inside it, so foreign providers are not automatically out of scope.
  • Treat the new accreditation certificate scheme as a supplementary assurance option, not as a compliance shortcut. SDAIA has been explicit that it does not replace compliance with the law.

KSA PDPL Questions We Are Asked Most Often

Can we obtain a PDPL certification?

Not in the ISO sense. The PDPL is a law, so there is no accredited certification body scheme against it. SDAIA has published rules for a voluntary accreditation certificate for controllers and processors, issued by a licensee authorised by the competent authority rather than by SDAIA directly. It evidences privacy governance maturity and does not substitute for compliance with the law.

When did the PDPL become enforceable?

14 September 2024, at the end of the transitional period. The law itself was issued by Royal Decree M/19 and amended by Royal Decree M/148 dated 27 March 2023, with the implementing regulation and the transfer regulation published in September 2023.

Who regulates the PDPL?

The Saudi Data and Artificial Intelligence Authority, SDAIA. It supervises compliance, operates the national registration platform and handles breach notifications, with the competent courts handling criminal matters and compensation claims.

What are the penalties for breaching the PDPL?

Disclosure or publication of sensitive data in breach of the law can attract imprisonment for up to two years, a fine of up to three million Saudi riyals, or both. Other violations can attract a warning or a fine of up to five million Saudi riyals, and fines may be doubled for repeat violations.

Does the PDPL apply to companies outside Saudi Arabia?

Yes, where they process personal data of individuals residing in the Kingdom. Foreign controllers and processors are expected to meet the same obligations, including the requirements governing transfers of personal data outside the Kingdom.

Tell us what personal data you process in the Kingdom, where it is hosted and who you transfer it to. We will scope a PDPL gap assessment against the law and its implementing regulations and give you a prioritised remediation plan.

Univate supports certification, assessment and compliance programmes for organisations operating across international markets. Talk to our team about scope, effort and the route that genuinely applies to your organisation.