Guide · Personal Data Protection Law
Personal data breach notification in Saudi Arabia: the 72-hour rule
What the Implementing Regulation requires when personal data is breached, and a response process that fits inside the deadline.
Last verified against official sources: 26 September 2026
The rule at a glance
- Who notifies
- The controller
- Notify whom
- SDAIA, the competent authority
- Deadline
- Within 72 hours of becoming aware of the incident
- When it applies
- The incident may cause harm to the personal data or to the data subject, or conflict with their rights or interests
- If facts are missing
- Provide the information not available within 72 hours as soon as possible, with the reasons for the delay
- Individuals
- Notify without undue delay where the breach may damage their data or conflict with their rights or interests, in simple and clear language
- Legal basis
- Article 24 of the Implementing Regulation
Why the clock starts earlier than you think
The 72 hours run from when you become aware of the incident, not from when your investigation ends. You will rarely have every fact in time, and the regulation allows for that: information that is not available within the deadline can follow as soon as possible, with the reason it is late.
What does not work is waiting for certainty. Decide early, notify on time, and update.
A response process that fits
- Record the moment of awareness. Log the date and time you learned of the incident. That is when the 72 hours begin.
- Contain and preserve. Stop the exposure, and keep the logs and evidence you will need to understand what happened.
- Assemble the team. Your data protection lead, legal, IT and the business owner of the affected data.
- Apply the harm test. Decide whether the incident may harm the personal data or the people it belongs to, or conflict with their rights or interests. Write down the reasoning.
- Notify SDAIA within 72 hours with what you know, and follow up with the rest as soon as you can.
- Notify affected individuals without undue delay where the breach may harm them, in simple and clear language they can act on.
- Close the loop. Record the incident, the decisions and the fixes, and feed the lessons back into your controls.
Rehearse it before you need it
A 72-hour deadline is short when people are finding out what happened. Run a tabletop exercise at least once a year: a realistic scenario, the real team, and a clock. Most gaps show up in the first hour, when nobody is sure who decides.
How AccuSights helps
We write the runbook with you, name the owners, rehearse it, and map the process to the Personal Data Protection Law and to the incident requirements of any other framework you follow, so one process serves all of them. See our services.
AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the NCA, SDAIA, SAMA, CST, DGA or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. Always confirm current requirements against the official source.