Personal Data Protection Law
Saudi Arabia
In force since 14 September 2023
Royal Decree No. M/19, as amended by Royal Decree No. M/148, supplemented by the Implementing Regulations and the Regulation on Personal Data Transfer Outside the Kingdom.
Asia & Africa
Personal Data Protection Law
Kingdom of Saudi Arabia
Saudi Data & AI Authority (SDAIA)
Royal Decree No. M/19, as amended by Royal Decree No. M/148
14 September 2023
In force
Subject to dedicated transfer regulation
Required in specified circumstances, but not universally
Subject to additional restrictions
Required in specified circumstances
Required for applicable controllers
Subject to regulatory notification requirements
SAR 5 million, with repeat violations potentially doubled
Up to 2 years' imprisonment and/or SAR 3 million fine
The PDPL applies to processing of personal data relating to individuals that takes place in Saudi Arabia. It can also apply when a party outside Saudi Arabia processes personal data relating to individuals residing in the Kingdom. Organizations potentially within scope include Saudi companies, international companies operating in Saudi Arabia, government entities, e-commerce businesses, financial organizations, healthcare organizations, educational institutions, employers, technology companies, advertising and marketing companies, SaaS providers, mobile applications, websites collecting personal information, organizations using third-party processors, and businesses transferring Saudi personal data internationally. The PDPL excludes an individual's personal-data processing for purposes that do not go beyond personal or family use, provided the data subject has not published or disclosed the data to others.
The PDPL provides for different penalties depending on the violation. An individual who unlawfully discloses or publishes sensitive data with the intention of harming the data subject or obtaining a personal benefit may face imprisonment of up to two years, a fine of up to SAR 3 million, or both, and the fine may be doubled in cases of repeat violations, subject to the statutory limits. For violations not covered by that specific criminal offence, the PDPL provides for a warning or a fine of up to SAR 5 million, which may also be doubled for a repeat violation, subject to the statutory framework. Individuals suffering qualifying material or moral damage may also seek compensation through the competent court.
For organizations operating websites, applications, digital services, advertising platforms, and international technology stacks, compliance involves more than deploying a cookie banner. SDAIA's current knowledge center publishes the PDPL, Implementing Regulations, international-transfer regulation, and supporting compliance guidance.
The Saudi Personal Data Protection Law, commonly referred to as the Saudi PDPL, establishes rules for protecting personal data and regulating its processing.
The law defines personal data broadly. It covers information that can identify an individual directly or indirectly, including names, identification numbers, addresses, contact numbers, license numbers, personal assets, bank and credit-card numbers, photographs, videos, and other information of a personal nature.
Processing is also defined broadly and includes activities such as:
This means that organizations should consider PDPL compliance throughout the complete personal-data lifecycle.
The Saudi PDPL came into force on 14 September 2023.
The framework was subsequently supplemented by its Implementing Regulations and related regulatory instruments. SDAIA's current compliance materials treat the PDPL and Implementing Regulations as the core framework governing personal-data protection in Saudi Arabia.
Organizations should therefore assess compliance against the current law and implementing requirements rather than treating the PDPL as an upcoming regulation.
Yes, in certain circumstances.
Article 2 applies the law to processing personal data relating to individuals residing in Saudi Arabia when that processing is carried out by a party outside the Kingdom.
This can be particularly relevant to international businesses using:
Organizations outside Saudi Arabia should therefore assess whether their processing activities fall within the territorial scope of the PDPL.
Personal data includes information that can identify an individual specifically or make identification possible directly or indirectly.
Examples include:
The law is technology-neutral, meaning organizations should not assume that only traditional databases or paper records fall within scope.
Sensitive personal data receives additional protection under the Saudi PDPL framework.
Sensitive information can include data relating to matters such as:
The regulatory framework imposes additional restrictions on processing sensitive personal data. For example, the legitimate-interest basis cannot be used for processing sensitive personal data.
The Saudi PDPL does not require consent for every processing activity.
Article 5 establishes consent as the general rule, while Article 6 identifies circumstances where processing is not subject to that consent requirement. These include situations where:
The Implementing Regulations provide additional controls and conditions.
Organizations should therefore document the legal basis for each processing activity instead of assuming that all processing must be based on consent.
Where consent is the applicable legal basis, organizations must obtain consent in accordance with the PDPL and Implementing Regulations.
Article 5 provides that personal data generally cannot be processed, or its purpose changed, without the data subject's consent except in circumstances provided by the law. It also establishes the data subject's ability to withdraw consent.
A compliant consent process should be designed to demonstrate:
Consent should be specific to the relevant processing and should not be used as a blanket authorization for unrelated purposes.
Not always.
Article 7 provides that consent may not be made a condition for providing a service or benefit unless the service or benefit is directly related to the processing for which consent is being obtained.
Organizations should therefore review whether consent requests are genuinely optional or whether they are being improperly tied to unrelated services.
Data subjects can withdraw consent at any time where processing is based on consent, subject to the applicable regulatory controls.
Organizations should therefore provide a practical mechanism for users to:
Consent withdrawal should also be reflected in downstream systems where continued processing depends on that consent.
Controllers must provide a privacy policy and make it available to data subjects before collecting their personal data.
The privacy policy must address matters including:
Article 13 also requires organizations collecting data directly from data subjects to provide additional information, including the legal basis, purpose, mandatory and optional data, relevant recipients, international transfers, potential consequences of not providing the data, and applicable rights.
A Saudi PDPL privacy notice should therefore be specific to the organization's actual processing operations rather than being a generic privacy statement.
The PDPL requires personal-data collection to be connected to the controller's purposes.
The law requires the amount of personal data collected to be appropriate and limited to the minimum necessary to achieve the collection purpose. When personal data is no longer necessary for its original purpose, collection should cease and previously collected data should be destroyed, subject to applicable requirements.
Organizations should regularly review:
Controllers must take sufficient steps to verify that personal data is:
The PDPL also requires controllers to communicate corrections, completions, or updates to other entities to which the personal data has been transferred, subject to applicable requirements.
The Saudi PDPL provides individuals with several rights concerning their personal data.
Right to be informed. Individuals have the right to information concerning the legal basis and purpose of collecting their personal data.
Right of access. Data subjects can request access to personal data held by the controller, subject to applicable limitations.
Right to obtain data. Individuals can request their personal data in a readable and clear format, subject to applicable controls.
Right to correction. Individuals can request correction, completion, or updating of their personal data.
Right to destruction. Individuals may request destruction of personal data when it is no longer needed, subject to the exceptions and retention requirements established by the law.
Right to withdraw consent. Where processing is based on consent, the data subject can withdraw that consent.
Right to complain. A data subject may submit a complaint to the competent authority concerning implementation of the PDPL and its regulations.
Right to compensation. Individuals who suffer damage resulting from qualifying violations may seek proportionate compensation for material or moral damage through the competent court.
Controllers generally cannot disclose personal data except in circumstances permitted by the PDPL.
Permitted circumstances can include:
Additional restrictions apply to disclosure where it could affect national security, international relations, criminal investigations, individual safety, another person's privacy, professional obligations, or other protected interests.
The Saudi PDPL contains specific requirements for advertising and awareness materials sent through personal communication channels.
Except for specified public-entity awareness materials, controllers generally cannot use personal communication channels such as email or post to send advertising or awareness materials without prior consent.
The sender must also provide a clear mechanism through which the recipient can request that such communications stop.
The PDPL separately provides that personal data may be processed for marketing purposes where it was collected directly from the data subject and consent was obtained, subject to the law and regulations. Sensitive data is excluded from this marketing provision.
The Saudi PDPL should be considered when websites and applications use cookies, pixels, SDKs, advertising technologies, analytics tools, and other tracking technologies that process personal data.
Organizations should assess:
A cookie banner alone does not establish complete PDPL compliance. Organizations should combine consent management with privacy notices, data governance, vendor management, security controls, and data-subject rights processes.
The Saudi PDPL and Implementing Regulations provide for appointment of a Personal Data Protection Officer (DPO) in specified circumstances.
SDAIA has issued dedicated rules concerning the appointment of personal-data protection officers. DPO requirements should be assessed based on the organization's activities and the circumstances specified by the Implementing Regulations.
Where required, the DPO can support activities such as:
Organizations should not assume that every controller has the same DPO requirement.
The Saudi PDPL requires controllers to conduct an impact assessment of personal-data processing in relation to products or services, based on the nature of the controller's activity and the applicable regulatory requirements.
An assessment should consider factors such as:
Organizations should integrate privacy impact assessments into product and service development rather than treating them as a purely retrospective compliance exercise.
Controllers must implement organizational, administrative, and technical measures to protect personal data, including during transfers.
SDAIA's current guidance identifies principles including integrity and confidentiality, requiring appropriate security controls to protect personal data against loss, destruction, or damage.
Security measures may include:
The appropriate controls should reflect the nature and risks of the processing.
Controllers must notify the competent authority when they become aware of a breach, damage, or illegal access to personal data, in accordance with the applicable regulatory requirements.
Controllers must also notify affected data subjects where the incident could cause damage to their data or prejudice their rights and interests.
Organizations should maintain a documented breach-response process covering:
The applicable notification deadlines and thresholds should be assessed against the current Implementing Regulations and SDAIA procedures.
Controllers must maintain records of personal-data processing activities in accordance with the law and Implementing Regulations.
SDAIA's current guidance states that processing-activity records should be maintained for five years after cessation of each processing activity.
Records should contain information including:
These records should be available to the competent authority when requested.
SDAIA maintains a National Register of Controllers through the National Data Governance Platform.
Current registration rules identify categories of controllers that must register, including:
SDAIA states that the National Register is intended to support monitoring and follow-up of controllers and their compliance with the PDPL and Implementing Regulations. SDAIA also provides registration processes for external organizations.
The Saudi PDPL distinguishes responsibilities between organizations determining how and why personal data is processed and organizations processing data on their behalf.
Controllers must select processors that provide necessary guarantees for implementing the PDPL and Implementing Regulations and must monitor processor compliance.
Organizations should therefore conduct appropriate processor due diligence and ensure contracts address:
The Saudi PDPL contains specific provisions governing transfers and disclosures of personal data outside Saudi Arabia.
Article 29 permits transfers or disclosures outside the Kingdom in specified circumstances and imposes conditions concerning:
The law also provides an exception for extreme necessity involving the life or vital interests of a data subject or preventing, examining, or treating disease.
The separate Regulation on Personal Data Transfer Outside the Kingdom provides additional requirements and mechanisms for international transfers. SDAIA identifies this regulation as part of the current Saudi data-protection framework. Organizations using international cloud providers, analytics platforms, CRM systems, advertising services, or global SaaS infrastructure should therefore map their international data flows.
Organizations should not retain personal data indefinitely.
The PDPL requires controllers to stop collecting personal data and destroy previously collected data when it is no longer necessary for the purpose for which it was collected, subject to applicable requirements and exceptions.
Organizations should establish retention schedules covering:
SDAIA also publishes guidance concerning personal-data destruction, anonymization, and pseudonymization.
Certain categories of personal data receive additional regulatory treatment.
The PDPL provides for additional controls concerning health data, including restrictions on access and processing by employees and workers to the minimum extent necessary for providing health services or health-insurance programs.
The law also contains additional requirements for credit data, including requirements concerning explicit consent and notification in specified circumstances.
Organizations operating in healthcare, financial services, insurance, credit, and related sectors should therefore consider the PDPL together with sector-specific Saudi requirements.
The Saudi Data & AI Authority (SDAIA) is responsible for overseeing implementation of the PDPL and its amendments and operates the National Data Governance Platform.
SDAIA provides organizations with:
The current SDAIA knowledge center identifies the PDPL, Implementing Regulations, and international-transfer regulation as core elements of the Saudi data-protection framework.
Organizations operating in Saudi Arabia should consider the following.
Deploy consent interfaces that allow visitors to make informed choices about applicable tracking and processing purposes.
Prevent applicable non-essential cookies, pixels, tags, and third-party scripts from running before the required consent decision.
Configure Saudi-specific privacy and consent rules for visitors covered by the Saudi PDPL.
Maintain evidence of consent status, consent timestamp, selected purposes, consent version, user preferences, and the relevant consent configuration.
Give users a mechanism to revisit and change their applicable privacy preferences.
Support workflows associated with access, correction, deletion, and other privacy requests.
Identify cookies, pixels, scripts, and third-party technologies operating across digital properties.
Maintain structured records that can support internal privacy governance and compliance reviews.
Saudi PDPL compliance requires organizations to manage personal data across the entire processing lifecycle. ConsentX helps organizations manage the digital layer of privacy compliance through cookie consent management, prior-script blocking, consent records, region-based privacy rules, tracker discovery, consent withdrawal, DSAR workflows, audit evidence, and multi-jurisdiction privacy controls. Make privacy compliance easier to manage with ConsentX.
This page provides a general, plain-English overview of the Saudi Arabia Personal Data Protection Law and its supporting regulations. It is not legal advice and does not cover every exemption, sector-specific requirement, SDAIA rule, regulatory interpretation, or individual compliance circumstance. A cookie banner alone does not establish complete PDPL compliance: broader compliance also requires legal assessment, governance, security, processing records, vendor management, transfer controls, and breach response. Organizations should review the current Saudi legislation and SDAIA guidance and obtain qualified Saudi legal advice where necessary.
Identify cookies, pixels, analytics scripts, advertising technologies, SDKs, tags, and other third-party technologies.
Determine which technologies collect or process personal data and document their purposes.
Do not automatically classify every processing activity as consent-based. Determine whether the processing relies on consent or another lawful basis under the PDPL.
Apply the appropriate Saudi PDPL configuration to visitors and processing activities within scope.
Prevent applicable non-essential technologies from activating before the required user choice.
Record consent choices with sufficient evidence to demonstrate what the user selected and when.
Allow users to change or withdraw applicable consent choices.
Keep historical consent evidence to support audits, privacy requests, and internal governance.
Use ConsentX workflows to manage applicable data-subject requests and consent-related actions.
Websites change frequently. Continue scanning for newly introduced cookies, trackers, vendors, and processing activities.