Enquire Us

KSA PDPL

About KSA PDPL (Personal Data Protection Law)

The PDPL was implemented in Saudi Arabia by Royal Decree, and the SDAIA will oversee it for the first two years, followed by the NDMO. The PDPL aims to protect personal data privacy, regulate data sharing, and prevent misuse, in line with Saudi Arabia’s Vision 2030 for digital infrastructure and economy.

Main Features of PDPL

  • Data subject rights
  • Controller registration
  • Controller obligations
  • Consent
  • Non-consent-based processing
  • Privacy policy
  • Purpose limitation and data minimization
  • Impact assessments
  • Marketing
  • Breach notification

Although it shares similarities with other data protection laws worldwide, it has several unique features.

The PDPL has strict data sovereignty regulations, with controllers prohibiting transferring personal data outside Saudi Arabia without meeting specific requirements. Personal data disclosure is limited to avoid security risks or damage to Saudi Arabia’s reputation or relationships. The PDPL also applies to the data of deceased persons and has strict breach notification requirements. Controllers must destroy personal data in certain circumstances but may retain de-identified data or data required by law or legal proceedings.

Is it Required for Your Company?

The PDPL applies to all businesses and public entities processing personal data in Saudi Arabia, including those outside the country processing data of Saudi residents. It does not apply to personal and family use. The Data Office will impose administrative sanctions for violating the PDPL, but the specific violations and corresponding sanctions have not been released yet.

              KSA PDPL (Personal Data Protection Law)