← All guides
Saudi Arabia PDPL14 min read22 July 2026

Saudi Arabia PDPL: Lawful Basis, Consent Architecture, Breach Notification & Cross-Border Transfers (2026)

Complete guide to Saudi Arabia's Personal Data Protection Law (PDPL) — Royal Decree M/19 as amended 2023 — covering lawful basis, consent requirements, sensitive data rules, data subject rights, 72-hour NDMO breach notification, cross-border transfer safeguards, and DPO obligations for the SDAIA/NDMO enforcement era.

What is the Saudi Arabia Personal Data Protection Law (PDPL)?

Saudi Arabia's Personal Data Protection Law (PDPL), enacted by Royal Decree No. M/19 in September 2021, is the Kingdom's first comprehensive data protection statute. It came into effect in September 2022, with full enforcement by the National Data Management Office (NDMO) — the supervisory authority operating under the Saudi Data & AI Authority (SDAIA) — beginning in March 2023. A significant amending decree, Royal Decree No. M/148, was issued in September 2023, strengthening data subject rights, tightening consent requirements, and substantially increasing penalties.

The PDPL applies to any entity that processes personal data of individuals inside Saudi Arabia, regardless of where the processing organisation is located. This extraterritorial scope means that any company with Saudi customers, employees, or data subjects — whether based in Riyadh, London, or Singapore — is within the PDPL's reach. The law forms a core pillar of Saudi Vision 2030's digital economy strategy, signalling that the Kingdom intends to be a serious player in global data governance.

Who does the PDPL apply to?

The PDPL distinguishes between Personal Data Controllers (entities that determine the purposes and means of processing) and Personal Data Processors (entities that process data on behalf of controllers). Controllers bear primary compliance obligations; processors are bound through contractual requirements. Joint controllers — two or more entities that jointly determine processing purposes and means — must have written agreements allocating compliance responsibilities.

The PDPL applies to: Saudi-incorporated companies; multinational companies with Saudi Arabia operations; foreign companies that process personal data of Saudi nationals or residents, whether or not those individuals are currently in the Kingdom; and e-commerce, SaaS, and platform companies serving Saudi users from abroad. Government bodies and public authorities are also subject to the law, though some public sector carve-outs apply for national security and law enforcement purposes.

Key definitions under the Saudi PDPL

Personal data is broadly defined as any data — regardless of source or form — that leads to identifying an individual specifically, or makes it possible to do so directly or indirectly. This includes names, identification numbers, voice and image recordings, and any combination of data that allows identification.

Sensitive personal data receives enhanced protection and requires explicit consent before processing. The PDPL categories of sensitive data include: racial or ethnic origin; political opinions; religious or philosophical beliefs; criminal records; health and medical data; biometric data used for unique identification purposes; genetic data; and credit and financial data. Sensitive data may only be processed with explicit, specific consent or where a narrowly defined exception applies (vital interests, legal obligation, protection of public interest).

Lawful basis for processing

The PDPL sets out a hierarchy of lawful bases for processing personal data. Unlike the GDPR's six-basis framework, the Saudi PDPL places explicit consent as the primary basis, with alternatives that must be genuinely applicable:

  • Consent: The data subject has given explicit, specific, informed, and freely given consent to processing for a stated purpose. Consent must not be bundled with acceptance of terms and conditions. Withdrawal of consent must not disadvantage the data subject.
  • Contractual necessity: Processing is necessary for the performance of a contract to which the data subject is a party, or to take pre-contractual steps at the data subject's request.
  • Legal obligation: Processing is necessary to comply with a legal obligation applicable to the controller.
  • Vital interests: Processing is necessary to protect the vital interests of the data subject or another person where the data subject is unable to give consent.
  • Public task: Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
  • Legitimate interests: Processing is necessary for the legitimate interests pursued by the controller or a third party, provided those interests are not overridden by the fundamental rights and interests of the data subject. A three-part test (purpose, necessity, balancing) must be documented.

Consent under the Saudi PDPL

Where consent is the lawful basis, it must be:

  • Explicit: Unambiguous affirmative action — no pre-ticked boxes, no inferred consent from inaction.
  • Specific: Each distinct processing purpose requires separate consent; blanket consent is invalid.
  • Informed: The data subject must be told, in clear and plain language, what data is collected, why, who it is shared with, how long it is retained, and their rights.
  • Freely given: Consent must not be conditioned on access to a service unless the processing is genuinely necessary for that service. No detriment or penalty for withdrawing consent.

For sensitive personal data, explicit consent is the default lawful basis. The consent record must document: who consented, the precise scope, the version of the consent notice, and the date. Controllers must be able to produce consent records on NDMO request.

Minors' data: For data subjects under 18 years of age, consent must be obtained from a parent or legal guardian. Age verification proportionate to the risk of the processing is required.

Data subject rights

The PDPL grants Saudi data subjects a comprehensive set of rights that controllers must be operationally ready to fulfil within 30 days of a request:

  • Right to access: Confirmation of whether personal data is processed; categories of data; sources; purposes; recipients; retention period.
  • Right to correction: Inaccurate, incomplete, or out-of-date data corrected or updated; third-party recipients notified where feasible.
  • Right to erasure: Data erased when the processing purpose no longer applies, consent is withdrawn, or processing is unlawful. Exception where legal retention obligation applies.
  • Right to restrict processing: Processing suspended while an objection or correction request is pending.
  • Right to data portability: Personal data provided in a structured, machine-readable format on request.
  • Right to object: Data subjects may object to processing based on legitimate interests. Processing suspended pending review unless compelling grounds override.

Controllers must maintain a request log, provide responses within 30 days, and have accessible intake mechanisms — a web portal, email address, or physical address — without imposing unreasonable barriers.

Controller obligations: privacy notice and data minimisation

The PDPL requires controllers to provide a comprehensive privacy notice at or before the point of data collection. The notice must cover: controller identity and contact details; purposes of processing; legal basis for each purpose; data categories collected; recipients (including any overseas recipients); retention periods; data subject rights and how to exercise them; and the complaint pathway to NDMO. For Saudi users, the privacy notice must be available in Arabic.

Controllers must also observe the principles of data minimisation (collect only what is adequate, relevant, and limited to the stated purpose); purpose limitation (no processing for incompatible secondary purposes); data accuracy (reasonable steps to keep data accurate and up to date); and storage limitation (documented retention schedules per data category, with automated deletion or anonymisation on expiry).

Personal data breach notification

One of the PDPL's most operationally demanding requirements is the 72-hour breach notification obligation. Where a breach affects sensitive personal data or is likely to cause serious harm to data subjects, the controller must notify NDMO within 72 hours of becoming aware of the breach. The notification must include:

  • Nature and description of the breach
  • Categories and approximate number of data subjects affected
  • Categories and approximate volume of personal data records affected
  • Likely consequences of the breach
  • Measures taken or proposed to mitigate adverse effects
  • Contact details of the DPO or other point of contact

Where the breach is likely to result in serious harm to individuals, affected data subjects must also be notified directly as soon as reasonably practicable. Controllers must maintain a breach register documenting all incidents — including those that do not meet the NDMO notification threshold — for regulatory inspection purposes.

Cross-border data transfers

The PDPL restricts cross-border transfers of personal data. Before transferring personal data outside Saudi Arabia, controllers must:

  1. Assess whether the destination country has an adequate level of personal data protection (as determined by NDMO).
  2. Where the country is not on NDMO's adequate protection list, implement appropriate safeguards — typically contractual protections equivalent to the PDPL's requirements, binding corporate rules, or an NDMO-approved derogation.
  3. For cloud computing and SaaS vendors located outside Saudi Arabia: conduct a vendor PDPL compliance assessment; enter into a compliant Data Processing Agreement; assess whether sector-specific data residency rules apply.

Certain sectors have additional data localisation requirements beyond the baseline PDPL rules:

  • Financial sector: Saudi Central Bank (SAMA) Cybersecurity Framework requires specific data localisation for customer financial data.
  • Telecoms: CITC (Communications and Information Technology Commission) has data localisation obligations for subscriber data.
  • Healthcare: Ministry of Health (MOH) requirements for health record localisation.
  • Critical national infrastructure: NCA Essential Cybersecurity Controls (ECC) impose additional requirements for critical sector entities.

DPO appointment and NDMO registration

The PDPL Executive Regulations require Data Protection Officers (DPOs) for controllers that process sensitive personal data at scale, conduct systematic monitoring of data subjects, or perform core activities involving sensitive data categories. The DPO must have sufficient expertise, authority, and resources to fulfil the role. DPO contact details must be registered with NDMO and made accessible to data subjects.

Controllers are also required to register with NDMO and to maintain Records of Processing Activities — detailed documentation covering: controller identity, processing purposes, legal basis, data categories, recipients, retention periods, cross-border transfers, and security measures.

Penalties under the Saudi PDPL

The amended PDPL (Royal Decree M/148, 2023) significantly strengthened the penalty framework:

  • Administrative penalties: Up to SAR 5 million per violation.
  • Criminal penalties (intentional violations involving sensitive data): Up to SAR 3 million fine plus two years' imprisonment.
  • Repeat violations: Penalties may be doubled, up to SAR 10 million.
  • Reputational enforcement: NDMO can publish enforcement decisions, creating significant reputational risk for companies operating in the Kingdom.

Assess your Saudi Arabia PDPL compliance

The Saudi Arabia PDPL Compliance Checker covers 42 key obligations across six categories: lawful basis and consent (explicit consent, sensitive data rules, minors' data, withdrawal mechanisms, legitimate interests documentation), data subject rights (access, correction, erasure, restriction, portability, objection — 30-day response), controller obligations and privacy notice (required notice contents, data minimisation, purpose limitation, accuracy, storage limitation, processor and sub-processor agreements), personal data breach notification (72-hour NDMO notification, data subject notification, breach log, annual simulation), cross-border transfers (adequacy assessment, contractual safeguards, cloud vendor DPAs, sector-specific localisation — SAMA/CITC/MOH/NCA), and governance and NDMO compliance (DPO appointment, privacy management programme, DPIAs, records of processing activities, NDMO registration, penalty risk management, staff training).

Related tools

See also: Singapore PDPA Compliance Checker, India DPDP Act Compliance Checklist, GDPR Compliance Audit, Privacy Policy Generator, DPIA Generator.