← All guides
Compliance Tools5 min read22 July 2026

ComplyKit Now Has 120 Free Compliance Generators: Saudi Arabia PDPL + Australia Privacy Act 2024

ComplyKit adds Saudi Arabia PDPL Compliance Checker (119th) and Australia Privacy Act 2024 Amendments Checker (120th) — 42-item assessments covering Saudi PDPL lawful basis, 72-hour NDMO breach notification, SAR 5M penalties, and the 2024 Australian Privacy Act reforms including statutory tort (AUD $50M), NDB scheme updates, and children's online privacy.

ComplyKit now offers 120 free compliance generators — no account, no login required. Today we're adding two new tools covering a major Middle Eastern privacy law and significant 2024 amendments to Australia's privacy framework.

Saudi Arabia PDPL Compliance Checker (119th generator)

Saudi Arabia's Personal Data Protection Law (PDPL) — Royal Decree No. M/19 (2021), as amended by Royal Decree No. M/148 (2023) — is the Kingdom's first comprehensive data protection statute. With full enforcement by the NDMO/SDAIA since March 2023, and penalties up to SAR 5 million (administrative) and SAR 3 million + 2 years imprisonment (criminal), PDPL compliance is a serious operational requirement for Saudi companies and multinationals with Saudi data subjects. The Saudi Arabia PDPL Compliance Checker covers 42 key obligations across six categories:

  • Lawful Basis & Consent (PDPL Art. 5–12): Lawful basis identified and documented for each processing activity; valid consent (explicit, specific, informed, freely given, no bundling, withdrawal without detriment); sensitive personal data explicit consent (health, genetic, biometric, financial, criminal, religious beliefs, personal opinions); consent records maintained with proof; legitimate interests three-part test documented; consent withdrawal mechanism as easy as granting; minors' data guardian consent
  • Data Subject Rights (PDPL Art. 13–18): Right to access (30-day response, data categories, sources, recipients, retention); right to correction with third-party notification; right to erasure when purpose no longer applies; right to restrict processing pending review; right to data portability in structured machine-readable format; accessible request intake mechanism; right to object with documented response process
  • Controller Obligations & Privacy Notice: Comprehensive privacy notice (controller identity, purposes, legal basis, categories, recipients, retention, rights, NDMO complaint pathway); data minimisation; purpose limitation; data accuracy; storage limitation with automated deletion; processor DPAs (instruction binding, security, sub-processor controls, audit rights, deletion on termination); sub-processor authorisation and equivalent obligations
  • Personal Data Breach Notification (PDPL Art. 19): Breach detection monitoring and logging; 72-hour NDMO notification for sensitive data or serious harm breaches; data subject notification for serious harm; breach log maintained; breach notifiability assessment criteria; notification content template (nature, categories, subjects affected, consequences, measures taken); annual breach simulation
  • Cross-Border Transfers (PDPL Art. 29–31): Adequacy assessment against NDMO country list; contractual safeguards (PDPL-equivalent) for non-adequate countries; transfer records maintained; cloud and SaaS vendor PDPL assessment and DPAs; sector-specific localisation (SAMA financial, CITC telecom, MOH health, NCA critical infrastructure); government and national security data restrictions; transfer impact assessments for high-risk destinations
  • Governance & NDMO/SDAIA Compliance: DPO appointment (mandatory where processing sensitive data at scale; NDMO registration; sufficient authority and resources); privacy management programme; DPIAs for high-risk processing; records of processing activities (comprehensive documentation); NDMO registration; penalty risk management (SAR 5M administrative, SAR 3M + 2 years criminal, SAR 10M repeat violations); annual staff privacy training

Who it's for: Saudi-incorporated companies; MNCs with Saudi Arabia operations; foreign companies processing Saudi nationals' data; e-commerce and SaaS platforms serving Saudi users; fintech and financial services companies subject to both PDPL and SAMA Cybersecurity Framework; healthcare platforms; legal and compliance teams preparing for NDMO scrutiny.

Australia Privacy Act 2024 Amendments Checker (120th generator)

The Privacy and Other Legislation Amendment Act 2024 (passed November 2024) implements the most significant reforms to Australia's Privacy Act 1988 in a generation — including a new statutory tort for serious invasions of privacy, AUD $50 million civil penalties, and enhanced OAIC enforcement. The Australia Privacy Act 2024 Amendments Checker covers 42 key obligations across six categories:

  • APP Governance & Collection (APPs 1–3, 5): Privacy policy updated for 2024 reforms; Privacy Management Framework documented (APP 1.2); anonymity and pseudonymity options; reasonable necessity for collection; sensitive information consent; collection notice at time of collection; use and disclosure for primary purpose
  • Data Quality, Security & Retention (APPs 10–11): APP 10 data quality steps; APP 11.1 security safeguards (technical and organisational controls); APP 11.2 destruction and de-identification when no longer needed; retention schedule by data category; employee records exemption scope check; small business exemption assessment; security testing programme
  • Individual Rights (APPs 12–13) & Complaints: APP 12 access right (30-day response); access refusal on permitted grounds only; no excessive fee for making a request; APP 13 correction within 30 days; refused correction notation; internal complaints mechanism (5-day acknowledgement, 30-day resolution); OAIC complaint referral process
  • Cross-Border Disclosure (APP 8) & 2024 Reforms: APP 8.1 reasonable steps before overseas disclosure; APP 8.2 exception assessment; statutory tort for serious invasions of privacy (intrusion upon seclusion; misuse of private information); Children's Online Privacy Code readiness (age-appropriate design, no dark patterns, no behavioural profiling of children); doxxing offences review; NDB scheme procedure aligned with 2024 enhancements; AUD $50M civil penalty risk compliance programme
  • Notifiable Data Breach (NDB) Scheme: Eligible data breach definition and detection; 30-day assessment obligation; OAIC SEDB notification as soon as practicable after assessment; direct individual notification (or substitution notice); breach response procedure documented and tested; breach register maintained for 7 years; annual breach simulation
  • Governance & OAIC Enforcement (2024 Reforms): Privacy Management Framework with annual review; Privacy Officer with authority and published contact; PIAs for high-risk activities (OAIC PIA Guide methodology); 2024 Act enforcement readiness (civil penalties, infringement notices, compliance notices); health information obligations (state/territory Acts, My Health Records Act); staff training updated for 2024 reforms; privacy code applicability (health, credit, children's)

Who it's for: Australian companies and startups; MNCs with Australian operations; government agencies; health service providers; credit reporting bodies; organisations assessing their 2024 Privacy Act reform exposure; legal and compliance teams preparing for enhanced OAIC enforcement.

Browse all 120 generators

All 120 free compliance generators are at /generate. No account required. Covers GDPR, CCPA, SOC 2, HIPAA, ISO 27001/27701, EU AI Act (GPAI + High-Risk), NIS2, DORA, PSD2/PSD3, FCA Consumer Duty, CSRD, CRA, NIST CSF 2.0, NIST AI RMF, NIST SP 800-53 Rev 5, CMMC 2.0, Digital Markets Act, EU Data Governance Act, EU Data Act, ePrivacy, AI Fairness, SOC 2 Trust Services Criteria, US State Privacy Laws, APRA CPS 230, APRA CPS 234, Singapore PDPA, India DPDP Act, Saudi Arabia PDPL, Australia Privacy Act 2024, and more.