Saudi PDPL vs GDPR
Saudi Arabia’s Personal Data Protection Law and the European Union’s General Data Protection Regulation cover the same subject but sit under different authorities. The Saudi PDPL was issued by Royal Decree M/19 of 2021, amended in March 2023, and is administered by the Saudi Data and Artificial Intelligence Authority (SDAIA). It came into force on 14 September 2023 with a one year transition period that ended on 14 September 2024, from which point it is fully enforceable. The GDPR is Regulation (EU) 2016/679, adopted on 27 April 2016 and applicable from 25 May 2018. It is enforced by the national supervisory authority of each EU and EEA member state, with the European Data Protection Board working to keep application consistent across them.
What is the Saudi PDPL?
The Personal Data Protection Law is the Kingdom of Saudi Arabia’s general data protection law. SDAIA is the competent authority: it issued the Implementing Regulations and the separate Regulation on Personal Data Transfer Outside the Kingdom, and it operates the National Data Governance Platform.
- Registration. Controllers in scope register on the National Data Governance Platform, including public entities, controllers whose main activity is processing personal data, and controllers processing sensitive data.
- Data protection officer. A DPO must be appointed in defined cases, including public entities carrying out large scale processing, controllers whose core activities involve regular and systematic monitoring, and controllers whose core activity is processing sensitive data. DPO details are submitted through the platform.
- Breach notification. Controllers notify SDAIA of a personal data breach within 72 hours of becoming aware of it, and notify affected individuals without undue delay.
- Transfers abroad. Transfers outside the Kingdom are handled under the transfer regulation, using instruments such as standard contractual clauses, binding common rules or certificates of accreditation.
- Legal basis. Consent has a more central role than under the GDPR, with defined exceptions rather than a broad set of alternative bases.
What is the GDPR?
The General Data Protection Regulation, Regulation (EU) 2016/679, applies directly in every EU member state and, through the EEA Agreement, in Iceland, Liechtenstein and Norway. It has extraterritorial reach: it can apply to a controller or processor outside the EU that offers goods or services to people in the EU or monitors their behaviour there.
- Enforcement. Each member state has an independent supervisory authority. Cross border cases run through a lead supervisory authority under the one stop shop mechanism, and the European Data Protection Board issues guidelines and binding decisions to keep interpretation consistent.
- Legal bases. Six lawful bases are available, including consent, contract, legal obligation, vital interests, public task and legitimate interests.
- Breach notification. Controllers notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to individuals, and notify individuals where the risk is high.
- Transfers. Transfers outside the EEA rely on an adequacy decision, or on safeguards such as standard contractual clauses or binding corporate rules.
- Data protection officers and impact assessments. A DPO is required in defined cases, and a data protection impact assessment is required where processing is likely to result in high risk.
Saudi PDPL vs GDPR compared
| Attribute | Saudi PDPL | GDPR |
|---|---|---|
| Instrument | Personal Data Protection Law, Royal Decree M/19 of 2021, amended 2023 | Regulation (EU) 2016/679 |
| Regulator | Saudi Data and Artificial Intelligence Authority (SDAIA) | National supervisory authority in each EU and EEA state, coordinated by the European Data Protection Board |
| Key dates | In force 14 September 2023, fully enforceable after the transition ended 14 September 2024 | Adopted 27 April 2016, applicable from 25 May 2018 |
| Territory | The Kingdom of Saudi Arabia, including processing carried out abroad relating to residents of the Kingdom | The EU and EEA, plus controllers and processors outside who target or monitor people there |
| Registration duty | Controllers in scope register on the National Data Governance Platform | No general registration duty, replaced by an internal record of processing activities |
| Legal bases | Consent is central, with defined exceptions | Six lawful bases including consent, contract, legal obligation, vital interests, public task and legitimate interests |
| Data protection officer | Required in defined cases, registered through the platform | Required in defined cases under Article 37 |
| Breach notification to the regulator | Within 72 hours of becoming aware | Within 72 hours where the breach is likely to result in a risk to individuals |
| Transfers abroad | Governed by the Regulation on Personal Data Transfer Outside the Kingdom, using instruments such as standard contractual clauses and binding common rules | Adequacy decision, or safeguards such as standard contractual clauses or binding corporate rules |
| One stop shop | Not applicable, a single national authority supervises | Yes, a lead supervisory authority handles cross border cases |
Where they overlap
The two regimes are close enough that a single privacy programme can serve both, provided the differences are handled deliberately. Both require a lawful basis, a record of processing, transparency to individuals, security of processing, controller and processor contracts, breach response, and rights handling. Both use a 72 hour regulator notification clock. Both restrict transfers abroad and both use contractual instruments as a route.
The differences that most often catch organisations out are the registration duty on the Saudi side, which has no GDPR equivalent, the heavier reliance on consent as a legal basis under the PDPL, and the fact that supervision sits with a single national authority in Saudi Arabia rather than with a network of supervisory authorities coordinated by the EDPB.
Which law applies to you?
- The Saudi PDPL applies if you process the personal data of individuals residing in the Kingdom, including where the processing is carried out from outside Saudi Arabia. Entities operating in the Kingdom should confirm their registration position with SDAIA.
- The GDPR applies if you are established in the EU or EEA, or if you offer goods or services to people there or monitor their behaviour from outside.
- Both can apply at once. A Saudi headquartered company with EU customers, or a European company with a Riyadh branch, is inside both regimes and needs one programme that satisfies the stricter requirement in each area.
- Do not assume adequacy. Saudi Arabia is not covered by an EU adequacy decision, so EU to Saudi transfers still need an appropriate safeguard.
Frequently Asked Questions
When did the Saudi PDPL become enforceable?
The law came into force on 14 September 2023 and a one year transition period ran until 14 September 2024. From that date the Personal Data Protection Law is fully enforceable by SDAIA.
Who enforces each law?
The Saudi Data and Artificial Intelligence Authority (SDAIA) is the competent authority for the Saudi PDPL. The GDPR is enforced by the independent supervisory authority of each EU and EEA member state, with the European Data Protection Board coordinating consistent application and issuing binding decisions in cross border cases.
Does the Saudi PDPL require registration in a way the GDPR does not?
Yes. Controllers in scope register on SDAIA’s National Data Governance Platform, and data protection officer details are submitted through the same platform. The GDPR abolished the general notification and registration duty that existed under the old Directive, replacing it with an internal record of processing activities.
How do the breach notification rules compare?
Both use a 72 hour clock to the regulator. Under the Saudi PDPL, controllers notify SDAIA within 72 hours of becoming aware of a breach and notify affected individuals without undue delay. Under the GDPR, controllers notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk, and notify individuals where the risk is high.
Can transfers move freely between Saudi Arabia and the EU?
No. Saudi Arabia is not the subject of an EU adequacy decision, so transfers from the EEA need a safeguard such as standard contractual clauses or binding corporate rules. Transfers out of the Kingdom are governed by SDAIA’s Regulation on Personal Data Transfer Outside the Kingdom, which recognises instruments including standard contractual clauses and binding common rules.
If we already comply with the GDPR, are we compliant with the Saudi PDPL?
Not automatically. A mature GDPR programme covers most of the ground, but the Saudi law adds obligations that have no direct GDPR equivalent, notably registration on the National Data Governance Platform and a narrower set of legal bases with consent at the centre. A gap assessment against the PDPL and its Implementing Regulations is the practical starting point.
Univate advises on both sides of this comparison across its international markets. Book a free consultation for a scoped view of what applies to your organisation.
Related Services & Resources
Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.








