KSA PDPL Compliance Guide 2026: Requirements, Fines & Checklist
Saudi Arabia’s Personal Data Protection Law (PDPL) is no longer something organisations can prepare for “later.” The one-year grace period ended on September 14, 2024, and the Saudi Data and Artificial Intelligence Authority (SDAIA) has moved from awareness-building and guidance to regulatory action. In a single year, 48 enforcement decisions were issued confirming breaches and applying sanctions.
If your organisation collects or processes personal data of people in Saudi Arabia, this guide explains what the PDPL requires, what enforcement looks like today, and how to build a compliance programme that holds up under scrutiny.
What is the KSA PDPL?
The PDPL is Saudi Arabia’s first comprehensive data protection law. It sets rules for how organisations collect, use, store, share and transfer personal data, and gives individuals rights over their information. It is supported by Implementing Regulations and separate Regulations on the transfer of personal data outside the Kingdom.
The law defines personal data as any information, in any form, that could lead to the direct or indirect identification of a natural person. Names, ID numbers, phone numbers, email addresses, location data and online identifiers are all covered. Health, genetic, biometric, credit and similar categories are treated as sensitive data and carry stricter rules.
Who does the PDPL apply to?
The PDPL applies to any public or private organisation that processes personal data of individuals in Saudi Arabia, including organisations based outside the Kingdom. If you serve Saudi customers, employ staff in Saudi Arabia, or handle Saudi personal data on behalf of clients, you should assume the law applies to you.
Who enforces it?
SDAIA is the competent authority for PDPL enforcement. It holds power to issue implementing regulations and guidance, investigate potential violations through formal committee-led proceedings, impose administrative fines, and refer criminal matters to the courts.
PDPL penalties
The penalties are significant:
| Type of violation | Maximum penalty |
|---|---|
| General violations | Up to SAR 5 million (around USD 1.33 million), doubling to SAR 10 million for repeat violations |
| Intentional disclosure of sensitive data | Up to two years’ imprisonment and fines up to SAR 3 million |
| Operational sanctions | Warnings, mandatory corrective actions, and in severe cases suspension of data processing activities |
What are organisations being fined for?
The published enforcement decisions show that SDAIA is not only targeting large breaches. The decisions cover core compliance failures, including processing personal data without a valid legal basis, unauthorised disclosure, failure to implement technical and organisational safeguards, and sending marketing communications without consent. In other words, the basics matter most.
Key PDPL requirements
1. A valid legal basis for processing. Consent is the primary basis under the PDPL, with limited exceptions such as legal obligations, contracts, vital interests and legitimate interests (which cannot be used for sensitive data). Consent for marketing must be clear and specific.
2. Privacy notices. Individuals must be told, at or before collection, why their data is collected, how it will be used, who it will be shared with, and what rights they have.
3. Records of processing activities (ROPA). Controllers must keep records describing their processing activities, including purposes, categories of data, recipients, retention periods and transfers.
4. Data subject rights. Individuals have rights to be informed, to access, to obtain a copy, to correct, and to request destruction of their personal data. Requests generally need to be handled within 30 days.
5. Security measures. Organisations must apply appropriate technical and organisational safeguards to protect personal data.
6. Breach notification. Organisations have a maximum of 72 hours from breach detection to notify SDAIA. Affected individuals must also be notified where the breach could cause them harm.
7. Impact assessments. A risk or impact assessment is required for high-risk processing, such as processing sensitive data, large-scale processing, or new technologies.
8. Data Protection Officer. A DPO must be appointed in certain cases, including by public entities, organisations whose core activities involve large-scale regular monitoring, and those processing sensitive data at scale.
9. Cross-border transfers. Transfers outside the Kingdom are allowed only under specific conditions, such as to countries with an adequate level of protection or with appropriate safeguards like standard contractual clauses. Some transfers require a risk assessment first.
10. Registration. Where registration is required for your category, it must be completed through SDAIA’s National Data Governance Platform before starting the relevant processing activities.
PDPL vs GDPR: what’s different?
Organisations with a GDPR programme have a head start, but the PDPL is not a copy. Both require a lawful basis for processing, data subject rights, and security measures. Key differences include SDAIA’s approach to cross-border transfers and specific provisions aligned with the Saudi legal framework. The PDPL also leans more heavily on consent, has registration requirements, and includes criminal penalties. Reuse your GDPR work, but map it carefully against the PDPL rather than assuming full coverage.
KSA PDPL compliance checklist
- Confirm whether and how the PDPL applies to your organisation.
- Map all personal data you process and build your ROPA.
- Identify a legal basis for each processing activity and review consent flows, especially for marketing.
- Update privacy notices in Arabic and English.
- Set up a process to receive, verify and respond to data subject requests within the deadline.
- Assess high-risk processing with impact assessments.
- Review vendors and processors, and put data processing agreements in place.
- Identify all transfers outside Saudi Arabia and apply the right transfer mechanism.
- Build and test a breach response plan with the 72-hour SDAIA deadline built in.
- Appoint a DPO where required and register on the National Data Governance Platform if applicable.
- Train staff who handle personal data and keep records of completion.
- Review your compliance regularly, since the regulations and SDAIA guidance continue to evolve.
How Enactia helps with PDPL compliance
Managing all of this in spreadsheets quickly becomes unmanageable, especially if you also need to comply with GDPR, UAE laws or ISO 27001. Enactia brings every PDPL requirement into one platform:
- Compliance Assessments with ready-made KSA PDPL templates to measure your gaps.
- Compliance Universe to map PDPL controls against GDPR, ISO 27001 and other frameworks, so you reuse existing work instead of starting again.
- Record of Processing Activities (ROPA) to build and maintain your processing records.
- Data Subject Requests to track every request and never miss a deadline.
- Incident & Data Breach Management to assess breaches and meet the 72-hour notification window.
- DPIAs and Vendor & Third Party Management to manage high-risk processing and cross-border transfers.
Learn more on our KSA PDPL page, or start your 14-day free trial. No credit card required. Have questions about your PDPL obligations? Contact us and our data protection experts will be happy to help.
Frequently asked questions
Does the PDPL apply to companies outside Saudi Arabia?
Yes. It applies to organisations outside the Kingdom that process personal data of individuals in Saudi Arabia.
What is the maximum fine under the PDPL?
Up to SAR 5 million per violation, which can be doubled for repeat offences. Intentional disclosure of sensitive data can also lead to imprisonment.
How quickly must a data breach be reported?
Within 72 hours of becoming aware of it, to SDAIA.
Is GDPR compliance enough for the PDPL?
No. There is significant overlap, but the PDPL has its own rules on consent, transfers, registration and penalties. A mapping exercise will show exactly where your gaps are.
Do I need a Data Protection Officer?
Only in certain cases, such as public entities and organisations whose core activities involve large-scale monitoring or processing of sensitive data.
Still unsure where your organisation stands under the PDPL? Contact our team to talk through your requirements.
This article is for general information and does not constitute legal advice.
