Guide · Personal Data Protection Law
Data protection officer and registration under the Saudi PDPL
Two questions every controller should answer: must you appoint a data protection officer, and must you register with SDAIA?
Last verified against official sources: 26 September 2026
When you must appoint a data protection officer
Under Article 32 of the Implementing Regulation, a controller must appoint one or more people responsible for personal data protection in any of three cases:
- The controller is a public entity that provides services involving the processing of personal data on a large scale.
- The controller's primary activities consist of processing that requires regular and continuous monitoring of individuals on a large scale.
- The controller's core activities consist of processing sensitive personal data.
The role can be filled by an official, an employee or an external contractor.
SDAIA has since issued the Rules for Appointing Personal Data Protection Officer. They restate these three cases and explain the terms that decide them, including large scale, regular and systematic monitoring, and core activities. Under those rules, processing personal data for human resources purposes is not in itself a core activity.
When you must register
SDAIA's Rules Governing the National Register of Controllers make registration on the National Data Governance Platform mandatory in four cases:
- The controller is a public entity.
- The controller's main activity is based on processing personal data.
- The controller processes sensitive data.
- An individual processes personal data for purposes beyond personal or family use.
The sensitive data case is broader than the DPO test. It applies whenever a controller processes sensitive data, even if that is not a core activity. An HR department holding employee health records, for example, can trigger registration without triggering a DPO.
The legal basis is Article 30 of the law and Article 34 of the Implementing Regulation. A registration certificate is valid for up to 5 years. The rules cover controllers within the Kingdom; SDAIA has said rules for controllers outside the Kingdom will be issued separately.
| Situation | Appoint a DPO? | Register with SDAIA? |
|---|---|---|
| Public entity processing personal data on a large scale | Yes | Yes |
| Any other public entity | Not required by this case | Yes |
| Core activities involve sensitive personal data | Yes | Yes |
| Large-scale, regular and continuous monitoring of individuals is a primary activity | Yes | Yes (the main activity is based on processing personal data) |
| Main activity is processing personal data | Only if a DPO case also applies | Yes |
| Processes some sensitive data, not as a core activity | Not required by this case | Yes |
| None of the above (and not an individual processing beyond personal or family use) | Not required, but recommended | Not required |
If neither applies
You still carry every other obligation in the law. Most organizations name a privacy lead anyway, because someone has to own the privacy notice, the rights requests and the 72-hour breach clock.
How AccuSights helps
We check both questions against your actual processing activities, document the reasoning, and, where you need one, set up the data protection officer role with a clear scope and reporting line. See our services.
AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the NCA, SDAIA, SAMA, CST, DGA or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. Always confirm current requirements against the official source.
Sources
- SDAIA, Implementing Regulation of the Personal Data Protection Law (English translation for guidance) (opens in a new tab)
- SDAIA, Rules for Appointing Personal Data Protection Officer (opens in a new tab)
- SDAIA, Rules Governing the National Register of Controllers within the Kingdom (opens in a new tab)
- SDAIA, National Data Governance Platform (opens in a new tab)