The Personal Data Protection Law (PDPL) is the Kingdom’s first comprehensive data protection law. Issued by Royal Decree in 2021 and amended in 2023, it came into force in September 2023 with a one-year grace period. That period has ended: since 14 September 2024 the PDPL is fully enforceable, overseen by the Saudi Data & Artificial Intelligence Authority (SDAIA), with the Implementing Regulations filling in the detail.
Who it applies to
Almost anyone. It covers any entity — public or private, inside the Kingdom or abroad — that processes the personal data of individuals in Saudi Arabia. If you hold data about Saudi residents, you are in scope.
What it asks of you
- A valid lawful basis for every processing activity, and clear, documented, withdrawable consent where consent is the basis.
- Data minimisation — collect only what you need, keep it only as long as you need it.
- Data subject rights — access, correction and deletion, answered within set timeframes.
- A Data Protection Officer where required, and registration on the SDAIA National Data Governance Platform for certain controllers.
- Breach notification to SDAIA within 72 hours of becoming aware of a qualifying breach.
- Strict rules on transferring data outside the Kingdom, backed by a risk assessment.
Why it is urgent now
This is no longer theoretical. SDAIA committees issued dozens of enforcement decisions through 2025 and into 2026, and organisations can have as little as a few days to respond once notified of a violation. The readiness has to exist before the notice arrives.
Compliance is now an active defence, not a document you file and forget.
Run a gap analysis against this framework.
The compliance builder walks each requirement, tracks your evidence, and produces a gap report — part of GRC Forge Pro. Join now to be first in when it launches.
Get started