SDAIA · Personal Data Protection Law
The Saudi Personal Data Protection Law, in plain language
What the law requires, when it took effect, and the obligations that matter most in day-to-day practice.
Last verified against official sources: 26 September 2026
Key facts
- Issued by
- Royal Decree No. M/19, 16 September 2021; amended March 2023
- Competent authority
- Saudi Data and Artificial Intelligence Authority (SDAIA)
- In force
- 14 September 2023, together with its Implementing Regulation
- Fully enforceable
- 14 September 2024, after a one-year grace period
- Companion rules
- The Implementing Regulation; the Regulation on Personal Data Transfer outside the Kingdom; the Rules Governing the National Register of Controllers; the Rules for Appointing Personal Data Protection Officer
Who it applies to
Under Article 2 of the law, it applies to any processing of personal data in the Kingdom, and to processing by any party outside the Kingdom of personal data relating to individuals residing in the Kingdom. A foreign company that handles personal data of people living in the Kingdom can therefore be in scope. The law does not apply to an individual processing personal data purely for personal or family use, as long as the data is not published or disclosed to others.
The law works with two roles: the controller, which decides why and how personal data is processed, and the processor, which processes it on the controller's behalf.
SDAIA's registration rules cover controllers within the Kingdom and state that rules for controllers outside the Kingdom will be issued separately.
What the law expects in practice
- A lawful basis for each processing activity, and processing kept to what that purpose needs.
- A clear privacy notice that tells people what you collect, why, and what rights they have.
- Respect for data subject rights, including access, correction and deletion.
- Security safeguards appropriate to the data you hold.
- Breach notification to SDAIA within 72 hours where a breach may cause harm, under Article 24 of the Implementing Regulation.
- A data protection officer in three defined cases, under Article 32 of the Implementing Regulation.
- Registration on SDAIA's National Data Governance Platform in four defined cases.
- Conditions on transfers of personal data outside the Kingdom, set by the Regulation on Personal Data Transfer outside the Kingdom.
Transfers outside the Kingdom
Personal data may leave the Kingdom only where the conditions in the Regulation on Personal Data Transfer outside the Kingdom, issued by SDAIA, are met. Before you rely on an overseas cloud region, support desk or parent company, map where personal data flows and record the basis for each transfer.
Enforcement
The grace period ended on 14 September 2024, and the law has been enforced since. Treat compliance as current, not upcoming, and follow SDAIA's own announcements for the latest position.
Where to start
- Map the personal data you hold, where it lives and who can reach it.
- Check whether you must appoint a data protection officer and whether you must register. The DPO and registration guide walks through both questions.
- Write or update your privacy notice and your process for handling rights requests.
- Build and rehearse a 72-hour breach process. The breach notification guide has the steps.
- List every transfer of personal data outside the Kingdom and the basis for it.
Questions about the PDPL
Is the PDPL enforceable now?
Yes. It came into force on 14 September 2023 and became fully enforceable on 14 September 2024, when the one-year grace period ended.
Who do we notify about a breach?
SDAIA, within 72 hours of becoming aware of a breach that may harm the personal data or the people it belongs to. Affected individuals must be told without undue delay where the breach may harm them.
Does every company need a data protection officer?
No. Under Article 32 of the Implementing Regulation, the requirement applies in three cases: public entities processing personal data on a large scale, controllers whose primary activities involve regular and continuous monitoring of individuals on a large scale, and controllers whose core activities involve processing sensitive personal data.
AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the NCA, SDAIA, SAMA, CST, DGA or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. Always confirm current requirements against the official source.
Sources
- SDAIA, Implementing Regulation of the Personal Data Protection Law (English translation for guidance) (opens in a new tab)
- SDAIA, Rules Governing the National Register of Controllers within the Kingdom (opens in a new tab)
- SDAIA, National Data Governance Platform (opens in a new tab)
- IAPP, Saudi PDPL first anniversary: enforcement and developments (opens in a new tab)