Guide · Personal Data Protection Law

Data protection officer and registration under the Saudi PDPL

Two questions every controller should answer: must you appoint a data protection officer, and must you register with SDAIA?

Last verified against official sources: 26 September 2026

When you must appoint a data protection officer

Under Article 32 of the Implementing Regulation, a controller must appoint one or more people responsible for personal data protection in any of three cases:

  1. The controller is a public entity that provides services involving the processing of personal data on a large scale.
  2. The controller's primary activities consist of processing that requires regular and continuous monitoring of individuals on a large scale.
  3. The controller's core activities consist of processing sensitive personal data.

The role can be filled by an official, an employee or an external contractor.

SDAIA has since issued the Rules for Appointing Personal Data Protection Officer. They restate these three cases and explain the terms that decide them, including large scale, regular and systematic monitoring, and core activities. Under those rules, processing personal data for human resources purposes is not in itself a core activity.

When you must register

SDAIA's Rules Governing the National Register of Controllers make registration on the National Data Governance Platform mandatory in four cases:

  1. The controller is a public entity.
  2. The controller's main activity is based on processing personal data.
  3. The controller processes sensitive data.
  4. An individual processes personal data for purposes beyond personal or family use.

The sensitive data case is broader than the DPO test. It applies whenever a controller processes sensitive data, even if that is not a core activity. An HR department holding employee health records, for example, can trigger registration without triggering a DPO.

The legal basis is Article 30 of the law and Article 34 of the Implementing Regulation. A registration certificate is valid for up to 5 years. The rules cover controllers within the Kingdom; SDAIA has said rules for controllers outside the Kingdom will be issued separately.

Both questions side by side
SituationAppoint a DPO?Register with SDAIA?
Public entity processing personal data on a large scaleYesYes
Any other public entityNot required by this caseYes
Core activities involve sensitive personal dataYesYes
Large-scale, regular and continuous monitoring of individuals is a primary activityYesYes (the main activity is based on processing personal data)
Main activity is processing personal dataOnly if a DPO case also appliesYes
Processes some sensitive data, not as a core activityNot required by this caseYes
None of the above (and not an individual processing beyond personal or family use)Not required, but recommendedNot required

If neither applies

You still carry every other obligation in the law. Most organizations name a privacy lead anyway, because someone has to own the privacy notice, the rights requests and the 72-hour breach clock.

How AccuSights helps

We check both questions against your actual processing activities, document the reasoning, and, where you need one, set up the data protection officer role with a clear scope and reporting line. See our services.

AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the NCA, SDAIA, SAMA, CST, DGA or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. Always confirm current requirements against the official source.

Sources

  1. SDAIA, Implementing Regulation of the Personal Data Protection Law (English translation for guidance) (opens in a new tab)
  2. SDAIA, Rules for Appointing Personal Data Protection Officer (opens in a new tab)
  3. SDAIA, Rules Governing the National Register of Controllers within the Kingdom (opens in a new tab)
  4. SDAIA, National Data Governance Platform (opens in a new tab)

Ten minutes to know exactly where you stand

Tell us what you do and who regulates you. We will show you which Saudi rules apply, where the gaps usually are, and the shortest route to ready. No slides, no pitch.