# Saudi Arabia — Regulatory Reference

_Generated 2026-07-27 · Source: https://www.wadiraksa.com · Live feed: https://www.wadiraksa.com/api/public · Licence: CC BY 4.0_

> This register is generated automatically from Wadira, an independent, source-backed atlas of Saudi data-protection, cybersecurity and governance regulation. It is the authoritative, always-current list of instruments — names, type, legal status, dates and official sources. Cite the live URL above rather than copying the table, so your references stay current.

## Recent changes

- **2026-07-07** · _consultation_ — **SDAIA consults on standards guides for the PDPL certification and audit market**: SDAIA opened a consultation (closing 6 August 2026, as reported) on three draft standards guides implementing the March-gazetted licensing rules: standards for issuing accreditation certificates to controllers and processors, for licensing personal-data audit and inspection activities, and for licensing certificate-issuance activities. They set the operating bar for the new PDPL certification and audit market, and matter to controllers seeking certificates as transfer safeguards.
- **2026-07-05** · _consultation_ — **NCA consults on AI Cybersecurity Guidelines**: The National Cybersecurity Authority opened a consultation (5 July – 5 August 2026) on draft AI Cybersecurity Guidelines — its first AI-specific instrument — setting cybersecurity governance, defence, resilience and third-party requirements for organisations deploying or planning to adopt AI in the Kingdom, explicitly covering generative and agentic AI.
- **2026-06-29** · _other_ — **SDAIA committees issue further PDPL fines and warnings**: SDAIA's violation-review committees announced a further package of decisions — fines and warnings against several entities — for direct marketing without explicit consent and failing to maintain measures enabling timely responses to data-subject requests; press reports also cited 72-hour breach-notification failures and failures to appoint required DPOs. No entity names or amounts were disclosed.
- **2026-06-24** · _consultation_ — **NCA consults on cybersecurity violations and penalties schedule**: The National Cybersecurity Authority opened a public consultation (24 June – 24 July 2026) on a draft classification of violations of NCA-mandated cybersecurity requirements and a corresponding penalties schedule, exercising enforcement powers under its amended statute (Royal Decree M/117). It would create the first formal penalty taxonomy behind the ECC, NCNICC and sector controls, affecting all entities subject to them.
- **2026-06-19** · _new_ — **SDAIA issues Data Revenue Generation Policy**: SDAIA published the Data Revenue Generation Policy (dated 27 April 2026, announced 19 June 2026), setting principles for government entities — and private entities holding government-sourced data — to develop revenue-generating data products and services. Products built on personal data must preserve privacy under the PDPL; open data remains free; government-to-government sharing cannot be charged. A national registry for data-product revenue generation now appears on SDAIA's National Data Governance Platform.
- **2026-06-08** · _consultation_ — **NCA consults on national incident-reporting framework (NFCISIR-1:2026)**: The National Cybersecurity Authority consulted on the draft National Framework for Cybersecurity Information Sharing and Incident Response; the consultation closed 10 July 2026. As drafted, public and private entities would report actual or suspected incidents via the national Haseen portal, follow tiered response timeframes (2/12/48/72 hours) across five severity levels, retain incident records for 15 years, and share threat intelligence under TLP. The final framework is pending.
- **2026-04-03** · _consultation_ — **SDAIA consults on draft Responsible AI Policy**: SDAIA opened a one-month public consultation (3 April – 3 May 2026) on a draft Responsible AI Policy applying to government, private and non-profit entities and individuals developing, deploying or publishing AI in the Kingdom. It moves beyond the 2023 AI Ethics Principles toward operational governance: risk-based classification, obligations for higher-risk systems, watermarking and content tracking of AI outputs, bias mitigation and performance monitoring. The final policy had not been issued as of mid-July 2026.
- **2026-03-06** · _new_ — **PDPL audit and certification licensing rules gazetted**: Two SDAIA instruments (Decisions 5135/2 and 5316, dated 16 December 2025; gazetted in Umm Al-Qura on 6 March 2026) create the PDPL compliance-services market: licences for accreditation-certificate issuers (SAR 10m capital, at least 10 qualified assessors, 3-year term) and for personal-data audit and inspection providers, plus rules for issuing controllers and processors 2-year accreditation certificates. Certificates also serve as a cross-border transfer safeguard under the Transfer Regulation.
- **2026-01-15** · _other_ — **SDAIA reports 48 PDPL enforcement decisions**: SDAIA's specialised committees confirmed 48 personal-data-protection violations in the first substantive enforcement wave — mostly processing without a legal basis, unauthorised disclosure, and marketing without consent. Decisions were reported in aggregate; no entities were named.
- **2025-12-30** · _other_ — **National Data Index — third measurement cycle launched**: SDAIA launched the third NDI cycle, expanding measurement to 214 government entities (about +110%). The index scores data-management maturity, compliance and operational excellence via the National Data Governance Platform.
- **2025-12-28** · _new_ — **NCA issues cybersecurity controls for non-CNI private sector (NCNICC-1:2025)**: The National Cybersecurity Authority extended mandatory ECC-derived cybersecurity controls to all private-sector entities that are not critical-infrastructure operators — its largest scope expansion since the ECC. Category A entities (over 250 staff or SAR 200m revenue) face 65 controls across three domains; Category B (SMEs) face 26 controls. Compliance is continuous under Article 10(3) of the NCA statute, with no stated grace period.
- **2025-12-02** · _new_ — **SDAIA issues General Rules for Secondary Use of Data**: Approved by SDAIA Board Decision 22-1 (11/6/1447H) and publicised in January 2026, the General Rules govern reusing data — including personal data — beyond its original collection purpose, for research, development and public-interest uses. They cover government-to-government, government-to-private and private-to-government requests under six principles; any reuse of personal data must comply with the PDPL.
- **2025-05-27** · _consultation_ — **Third public consultation on Implementing Regulation amendments**: SDAIA's third public consultation (27 Apr – 27 May 2025) proposed to simplify the Implementing Regulation: folding the DPO-appointment and controller-registration rules into it, simplifying the RoPA requirement, and adding a plain-language privacy-notice clause. Not yet enacted as of mid-2026.
- **2025-04-23** · _consultation_ — **Consultation on rules for data-protection service providers**: A parallel SDAIA consultation (closed May 2025) proposed to license firms providing PDPL consultancy, compliance technology and training — a separate instrument from the Implementing Regulation amendments.
- **2025-02-25** · _guidance_ — **Guideline on cross-border transfer risk assessment**: SDAIA published a non-binding, four-phase methodology for assessing the risks of transferring personal data outside the Kingdom, with a companion risk-assessment tool on the National Data Governance Platform.

## Constitutional foundation (2)

| Instrument | Type | Status | Tier | Notes / dates | Official source |
| --- | --- | --- | --- | --- | --- |
| [Basic Law of Governance (Arts 37 & 40)](https://www.wadiraksa.com/instrument/basic-law-governance) | Law | Foundational | Foundational — Sharia & Basic Law | Royal Order A/90, 1992 | in library |
| [Sharia (Qur'an & Sunnah)](https://www.wadiraksa.com/instrument/sharia) | Framework | Foundational | Foundational — Sharia & Basic Law | — | — |

## Personal Data Protection (PDPL) (19)

| Instrument | Type | Status | Tier | Notes / dates | Official source |
| --- | --- | --- | --- | --- | --- |
| [Personal Data Protection Law (PDPL)](https://www.wadiraksa.com/instrument/pdpl-law) | Law | Binding | Primary law — niẓām (Royal Decree, M/…) | M/19 (2021), amended M/148 (2023); in force 14 Sep 2023 | [link](https://sdaia.gov.sa/en/SDAIA/about/Documents/PersonalDataProtectionLaw.pdf) |
| [Implementing (Executive) Regulation](https://www.wadiraksa.com/instrument/implementing-regulation) | Implementing Regulation | Binding | Implementing & executive regulation | Amendments pending — consultation closed 27 May 2025; not enacted as of Jun 2026 | [link](https://sdaia.gov.sa/en/SDAIA/about/Documents/ImplementingRegulationPersonalDataProtectionLaw.pdf) |
| [Regulation on Personal Data Transfer Outside KSA](https://www.wadiraksa.com/instrument/transfer-regulation) | Implementing Regulation | Binding | Implementing & executive regulation | Updated 2024 | [link](https://sdaia.gov.sa/Documents/RegulationonPersonalDataEN.pdf) |
| [Rules for Appointing a DPO](https://www.wadiraksa.com/instrument/dpo-appointment-rules) | Rule | Binding | Rules, controls & standards | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Documents/RulesforAppointingPersonalDataProtectionOfficer.pdf) |
| [Rules Governing the National Register of Controllers](https://www.wadiraksa.com/instrument/national-register-controllers) | Rule | Binding | Rules, controls & standards | — | [link](https://sdaia.gov.sa/Documents/TheRulesGoverningTheNationalRegisterOfControllersWithinTheKingdomPublicEN.pdf) |
| [Standard Contractual Clauses (SCCs)](https://www.wadiraksa.com/instrument/sccs) | Instrument | Binding | Rules, controls & standards | — | [link](https://sdaia.gov.sa/Documents/StandardContractualClausesForPersonalDataTransferEN.pdf) |
| [Binding Common Rules (BCRs)](https://www.wadiraksa.com/instrument/bcrs) | Instrument | Binding | Rules, controls & standards | — | [link](https://sdaia.gov.sa/Documents/CommonRulesBCRForPersonalDataTransferEN.pdf) |
| [Rules Governing Issuance of Accreditation Certificates](https://www.wadiraksa.com/instrument/accreditation-certificate-rules) | Rule | Binding | Rules, controls & standards | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Files/RulesGoverningIssuanceAccreditationCertificatesControllersProcessers.pdf) |
| [Rules for Auditing & Inspecting Controllers and Processors](https://www.wadiraksa.com/instrument/controller-auditing-rules) | Rule | Binding | Rules, controls & standards | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Files/CertificatesControllersProcessorsAuditingInspectionPersonalDataProcessingActivities.pdf) |
| [Committee Working Rules](https://www.wadiraksa.com/instrument/committee-working-rules) | Rule | Guidance | Rules, controls & standards | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Documents/CommitteeWorkingRules.pdf) |
| [Privacy Policy (Notice) Guideline](https://www.wadiraksa.com/instrument/privacy-policy-guideline) | Guideline | Guidance | Guidelines & circulars | — | [link](https://sdaia.gov.sa/Documents/PrivacyPolicyGuideline.pdf) |
| [Destruction / Anonymisation / Pseudonymisation Guideline](https://www.wadiraksa.com/instrument/destruction-anonymisation-guideline) | Guideline | Guidance | Guidelines & circulars | — | [link](https://sdaia.gov.sa/Documents/PersonalDataDestructionAnonymizationAndEncryptionGuideline.pdf) |
| [Personal Data Disclosure Guideline](https://www.wadiraksa.com/instrument/data-disclosure-guideline) | Guideline | Guidance | Guidelines & circulars | — | [link](https://sdaia.gov.sa/Documents/PersonalDataDisclosureCasesGuideline.pdf) |
| [Records of Processing (RoPA) Guideline](https://www.wadiraksa.com/instrument/ropa-guideline) | Guideline | Guidance | Guidelines & circulars | — | [link](https://sdaia.gov.sa/Documents/PersonalDataProcessingActivitiesRecordsGuideline.pdf) |
| [Personal Data Breach Incidents Procedural Guide](https://www.wadiraksa.com/instrument/breach-incidents-guide) | Guideline | Guidance | Guidelines & circulars | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Documents/PersonalDataBreachIncidents.pdf) |
| [Transfer to Non-Adequate Country Guideline](https://www.wadiraksa.com/instrument/transfer-nonadequate-guideline) | Guideline | Guidance | Guidelines & circulars | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Documents/RisksTransferringDataOutsideKingdomEn.pdf) |
| [Self-Assessment Guideline (incl. DPO-need tool)](https://www.wadiraksa.com/instrument/self-assessment-guideline) | Guideline | Guidance | Guidelines & circulars | Tool at dgp.sdaia.gov.sa | [link](https://dgp.sdaia.gov.sa/wps/portal/pdp/services/servicesdetails/TooltoDeterminingDataProtectionOfficer) |
| [Minimum Personal Data Guideline](https://www.wadiraksa.com/instrument/minimum-pd-guideline) | Guideline | Guidance | Guidelines & circulars | — | [link](https://sdaia.gov.sa/Documents/MinmumPDGuideline.pdf) |
| [Guide to the PDPL for Controllers and Processors](https://www.wadiraksa.com/instrument/guide-to-the-pdpl-for-controllers-and-processors) | Guideline | Guidance | Guidelines & circulars | December 2023 | [link](https://dgp.sdaia.gov.sa/wps/wcm/connect/f579bc32-fda8-47bd-bc6f-66b8cb77985c/ENG-Guide+to+the+saudi+PDP+law+for+controllersprocessors.pdf?MOD=AJPERES) |

## Data Management & Governance (11)

| Instrument | Type | Status | Tier | Notes / dates | Official source |
| --- | --- | --- | --- | --- | --- |
| [SDAIA Organizational Arrangements](https://www.wadiraksa.com/instrument/sdaia-organizational-arrangements) | Council of Ministers Resolution | Binding | Cabinet instruments — CoM Resolution | CoM Resolution No. 292 (27/4/1441 AH), amended by No. 195 (15/3/1444 AH); under Royal Order A/471 (29/12/1440 AH) | in library |
| [NDMO Data Management & Personal Data Protection Standards](https://www.wadiraksa.com/instrument/ndmo-standards) | Standard | Binding | Implementing & executive regulation | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Documents/DataManagementPersonalDataProtectionStandards.pdf) |
| [Freedom of Information Policy](https://www.wadiraksa.com/instrument/freedom-of-information-policy) | Regulation | Binding | Implementing & executive regulation | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Documents/FreedomOfInformationPolicy.pdf) |
| [Data Classification Policy](https://www.wadiraksa.com/instrument/data-classification-policy) | Standard | Binding | Implementing & executive regulation | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Documents/DataClassificationPolicy.pdf) |
| [Open Data Policy](https://www.wadiraksa.com/instrument/open-data-policy) | Regulation | Binding | Implementing & executive regulation | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Documents/OpenDataPolicy.pdf) |
| [National Data Index (NDI)](https://www.wadiraksa.com/instrument/ndi) | Framework | Guidance | Rules, controls & standards | — | in library |
| [NDI — Operational Excellence (OE)](https://www.wadiraksa.com/instrument/ndi-operational-excellence-oe) | Instrument | Binding | Rules, controls & standards | — | in library |
| [Rules for Secondary Use of Data](https://www.wadiraksa.com/instrument/secondary-use-rules) | Rule | Binding | Rules, controls & standards | — | [link](https://sdaia.gov.sa/Documents/GeneralRulesForSecondaryUseOfData_EN.pdf) |
| [NDI — Operational Excellence FAQs](https://www.wadiraksa.com/instrument/ndi-operational-excellence-faqs) | Instrument | Binding | Rules, controls & standards | — | in library |
| [Data Monetisation Policy](https://www.wadiraksa.com/instrument/data-monetization-policy) | Guideline | Guidance | Rules, controls & standards | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Files/DataMonetizationPolicy.pdf) |
| [Data Sharing Guideline](https://www.wadiraksa.com/instrument/data-sharing-guideline) | Guideline | Guidance | Guidelines & circulars | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Documents/DataSharingPolicyEN.pdf) |

## Cybersecurity (29)

| Instrument | Type | Status | Tier | Notes / dates | Official source |
| --- | --- | --- | --- | --- | --- |
| [Anti-Cyber Crime Law](https://www.wadiraksa.com/instrument/anti-cyber-crime-law) | Law | Binding | Primary law — niẓām (Royal Decree, M/…) | Royal Decree M/17, 2007 | in library |
| [NCA Cybersecurity Toolkits](https://www.wadiraksa.com/instrument/nca-cybersecurity-toolkits) | Instrument | Guidance | Rules, controls & standards | — | in library |
| [Essential Cybersecurity Controls (ECC-2:2024)](https://www.wadiraksa.com/instrument/ecc) | Framework | Binding | Rules, controls & standards | ECC-2:2024 | [link](https://nca.gov.sa/en/regulatory-documents/controls-list/ecc/) |
| [Cloud Cybersecurity Controls (CCC-2:2024)](https://www.wadiraksa.com/instrument/ccc) | Framework | Binding | Rules, controls & standards | CCC-2:2024 | in library |
| [NCA Regulatory Documents (index)](https://www.wadiraksa.com/instrument/regulations-documents-2) | Instrument | Guidance | Rules, controls & standards | — | in library |
| [Critical Systems Cybersecurity Controls](https://www.wadiraksa.com/instrument/cscc) | Framework | Binding | Rules, controls & standards | — | in library |
| [Operational Technology Cybersecurity Controls](https://www.wadiraksa.com/instrument/otcc) | Framework | Binding | Rules, controls & standards | — | in library |
| [Data Cybersecurity Controls](https://www.wadiraksa.com/instrument/dcc) | Framework | Binding | Rules, controls & standards | — | in library |
| [National Cryptographic Standards](https://www.wadiraksa.com/instrument/ncs) | Standard | Binding | Rules, controls & standards | — | in library |
| [Non-Critical National Infrastructure Cybersecurity Controls (NCNICC-1:2025)](https://www.wadiraksa.com/instrument/ncnicc) | Framework | Binding | Rules, controls & standards | Issued by the NCA (NCNICC-1:2025), published January 2026 | [link](https://nca.gov.sa/en/regulatory-documents/) |
| [Guide to Cloud Cybersecurity Controls (CCC) Implementation](https://www.wadiraksa.com/instrument/guide-to-cloud-cybersecurity-controls-ccc-implementation) | Framework | Guidance | Rules, controls & standards | — | in library |
| [Cybersecurity Organizational Structure Template](https://www.wadiraksa.com/instrument/cybersecurity-organizational-structure-template) | Instrument | Guidance | Rules, controls & standards | — | in library |
| [Regulatory Framework for Licensing Managed Security Operations Centre Services (RFMSOC-1:2024)](https://www.wadiraksa.com/instrument/regulatory-framework-for-licensing-managed-security-oper) | Instrument | Guidance | Rules, controls & standards | — | in library |
| [Saudi Cybersecurity Higher Education Framework (SCyber-Edu-1:2020)](https://www.wadiraksa.com/instrument/saudi-cybersecurity-higher-education-framework-scyber-ed) | Instrument | Guidance | Rules, controls & standards | — | in library |
| [Guide to Critical Systems Cybersecurity Controls (CSCC) Implementation](https://www.wadiraksa.com/instrument/guide-to-critical-systems-cybersecurity-controls-cscc-im) | Framework | Guidance | Rules, controls & standards | — | in library |
| [Guide to Data Cybersecurity Controls (DCC) Implementation](https://www.wadiraksa.com/instrument/guide-to-data-cybersecurity-controls-dcc-implementation) | Framework | Guidance | Rules, controls & standards | — | in library |
| [Operational Technology Cybersecurity Controls — Methodology & Mapping Annex](https://www.wadiraksa.com/instrument/operational-technology-cybersecurity-controls-methodolog) | Framework | Guidance | Rules, controls & standards | — | in library |
| [National Policy for Managed Security Operations Centres (NPMSOC-1:2024)](https://www.wadiraksa.com/instrument/national-policy-for-managed-security-operations-centres-) | Instrument | Guidance | Rules, controls & standards | — | in library |
| [Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC-1:2021)](https://www.wadiraksa.com/instrument/organizations-social-media-accounts-cybersecurity-contro) | Framework | Binding | Rules, controls & standards | — | in library |
| [Alignment Guide for the Saudi Cybersecurity Higher Education Framework (SCyber-Edu)](https://www.wadiraksa.com/instrument/alignment-guide-for-the-saudi-cybersecurity-higher-educa) | Instrument | Binding | Rules, controls & standards | — | in library |
| [Saudi Cybersecurity Workforce Framework (SCyWF-1:2020)](https://www.wadiraksa.com/instrument/saudi-cybersecurity-workforce-framework-scywf-1-2020) | Instrument | Binding | Rules, controls & standards | — | in library |
| [Telework Cybersecurity Controls (TCC)](https://www.wadiraksa.com/instrument/telework-cybersecurity-controls-tcc) | Framework | Binding | Rules, controls & standards | — | in library |
| [Cybersecurity Guidelines for Internet of Things (CGIoT-1:2024)](https://www.wadiraksa.com/instrument/cybersecurity-guidelines-for-internet-of-things-cgiot-1-) | Guideline | Guidance | Guidelines & circulars | — | in library |
| [Guide to Organizations’ Social Media Accounts Cybersecurity Controls (OSMACC) Implementation](https://www.wadiraksa.com/instrument/guide-to-organizations-social-media-accounts-cybersecuri) | Guideline | Guidance | Guidelines & circulars | — | in library |
| [Guide to Telework Cybersecurity Controls (TCC) Implementation](https://www.wadiraksa.com/instrument/guide-to-telework-cybersecurity-controls-tcc-implementat) | Guideline | Guidance | Guidelines & circulars | — | in library |
| [Cybersecurity Guidelines for E-commerce Service Providers (CGESP-1:2019)](https://www.wadiraksa.com/instrument/cybersecurity-guidelines-for-e-commerce-service-provider) | Guideline | Guidance | Guidelines & circulars | — | in library |
| [Alignment Guide for the Saudi Cybersecurity Workforce Framework (SCyWF)](https://www.wadiraksa.com/instrument/alignment-guide-for-the-saudi-cybersecurity-workforce-fr) | Guideline | Guidance | Guidelines & circulars | — | in library |
| [Guide to Operational Technology Cybersecurity Controls (OTCC) Implementation](https://www.wadiraksa.com/instrument/guide-to-operational-technology-cybersecurity-controls-o) | Guideline | Guidance | Guidelines & circulars | — | in library |
| [Cybersecurity Guidelines for E-commerce Consumers (CGEC-1:2019)](https://www.wadiraksa.com/instrument/cybersecurity-guidelines-for-e-commerce-consumers-cgec-1) | Guideline | Guidance | Guidelines & circulars | — | in library |

## Financial services (10)

| Instrument | Type | Status | Tier | Notes / dates | Official source |
| --- | --- | --- | --- | --- | --- |
| [The Capital Market Law](https://www.wadiraksa.com/instrument/the-capital-market-law) | Law | Binding | Primary law — niẓām (Royal Decree, M/…) | — | in library |
| [Saudi Central Bank Law](https://www.wadiraksa.com/instrument/saudi-central-bank-law) | Law | Binding | Primary law — niẓām (Royal Decree, M/…) | — | in library |
| [PAYMENT SERVICES PROVIDER REGULATIONS](https://www.wadiraksa.com/instrument/payment-services-provider-regulations) | Regulation | Binding | Implementing & executive regulation | — | in library |
| [SAMA Rules on Outsourcing (Circular 2389)](https://www.wadiraksa.com/instrument/sama-outsourcing-rules) | Rule | Binding | Rules, controls & standards | — | [link](https://rulebook.sama.gov.sa/en/rules-outsourcing) |
| [Financial Consumer Protection Principles and Rules](https://www.wadiraksa.com/instrument/financial-consumer-protection-principles-and-rules) | Instrument | Binding | Rules, controls & standards | — | in library |
| [Cyber Resilience Fundamental Requirements (CRFR)](https://www.wadiraksa.com/instrument/cyber-resilience-fundamental-requirements-crfr) | Instrument | Binding | Rules, controls & standards | — | in library |
| [SAMA 4725](https://www.wadiraksa.com/instrument/sama-4725) | Instrument | Binding | Rules, controls & standards | — | in library |
| [SAMA Cyber Security Framework (CSF)](https://www.wadiraksa.com/instrument/sama-cyber-security-framework-csf) | Instrument | Guidance | Rules, controls & standards | — | in library |
| [CMA Cybersecurity Guidelines](https://www.wadiraksa.com/instrument/cma-cyber-guidelines) | Guideline | Guidance | Guidelines & circulars | — | [link](https://cma.gov.sa/en/RulesRegulations/Guides/Documents/Cyber_Security_en.pdf) |
| [Payment Services Provider Regulatory Guidelines](https://www.wadiraksa.com/instrument/payment-services-provider-regulatory-guidelines) | Guideline | Guidance | Guidelines & circulars | — | in library |

## Artificial Intelligence (8)

| Instrument | Type | Status | Tier | Notes / dates | Official source |
| --- | --- | --- | --- | --- | --- |
| [Global AI Hub Law](https://www.wadiraksa.com/instrument/global-ai-hub-law) | Law | Draft | Primary law — niẓām (Royal Decree, M/…) | Public consultation closed 14 May 2025 — not enacted; no public text available. | — |
| [AI Adoption Framework](https://www.wadiraksa.com/instrument/ai-adoption-framework) | Framework | Guidance | Rules, controls & standards | 2024 | [link](https://sdaia.gov.sa/en/SDAIA/about/Files/AIAdoptionFramework.pdf) |
| [National Occupational Standard Framework for Data & AI](https://www.wadiraksa.com/instrument/national-occupational-standard-framework-for-data-ai) | Standard | Guidance | Rules, controls & standards | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Files/File0002.pdf) |
| [Saudi Academic Framework for AI Qualifications](https://www.wadiraksa.com/instrument/saudi-academic-framework-for-ai-qualifications) | Instrument | Guidance | Rules, controls & standards | — | [link](https://sdaia.gov.sa/en/SDAIA/about/Files/File0003.pdf) |
| [AI Ethics Principles](https://www.wadiraksa.com/instrument/ai-ethics-principles) | Guideline | Guidance | Guidelines & circulars | 2023 | [link](https://sdaia.gov.sa/en/SDAIA/about/Documents/ai-principles.pdf) |
| [Generative AI Guidelines — Government & Public](https://www.wadiraksa.com/instrument/genai-guidelines-gov) | Guideline | Guidance | Guidelines & circulars | 2024 | [link](https://sdaia.gov.sa/en/SDAIA/about/Files/GenAIGuidelinesForGovernmentENCompressed.pdf) |
| [Deepfakes Guidelines](https://www.wadiraksa.com/instrument/deepfakes-guidelines) | Guideline | Guidance | Guidelines & circulars | 2024 | [link](https://sdaia.gov.sa/en/SDAIA/about/Files/File0001.pdf) |
| [Generative AI Guidelines — Public](https://www.wadiraksa.com/instrument/generative-ai-public) | Guideline | Guidance | Guidelines & circulars | 2024 | [link](https://sdaia.gov.sa/en/SDAIA/about/Files/GenerativeAIPublicEN.pdf) |

## Telecommunications & Cloud (5)

| Instrument | Type | Status | Tier | Notes / dates | Official source |
| --- | --- | --- | --- | --- | --- |
| [Cloud Computing Regulatory Framework](https://www.wadiraksa.com/instrument/cloud-regs) | Regulation | Binding | Implementing & executive regulation | — | in library |
| [Cybersecurity Regulatory Framework (CRF)](https://www.wadiraksa.com/instrument/crf) | Framework | Binding | Rules, controls & standards | — | [link](https://www.cst.gov.sa/en/regulations-and-licenses/regulations/Document-413) |
| [CST Licensing](https://www.wadiraksa.com/instrument/cst-licensing) | Instrument | Binding | Rules, controls & standards | — | [link](https://www.cst.gov.sa/en/regulations-and-licenses) |
| [CST Guide for Cloud Computing Service Providers](https://www.wadiraksa.com/instrument/cst-guide-for-cloud-computing-service-providers) | Guideline | Guidance | Guidelines & circulars | — | in library |
| [Registration Guide in the Qualifying Category](https://www.wadiraksa.com/instrument/registration-guide-in-the-qualifying-category) | Guideline | Guidance | Guidelines & circulars | — | in library |

## Health data (2)

| Instrument | Type | Status | Tier | Notes / dates | Official source |
| --- | --- | --- | --- | --- | --- |
| [Health Information Exchange (HIE) Policies](https://www.wadiraksa.com/instrument/hie-policies) | Instrument | Guidance | Rules, controls & standards | — | [link](https://nhic.gov.sa/standards/Policies/IS0303-Saudi-Health-Information-Exchange-Policies-v1.0.pdf) |
| [MOH Data Governance Policy](https://www.wadiraksa.com/instrument/health-data-rules) | Rule | Binding | Rules, controls & standards | — | [link](https://www.moh.gov.sa/Ministry/OpenData/Documents/Data-Governance-Policy.pdf) |

## Key provisions

### [Personal Data Protection Law (PDPL)](https://www.wadiraksa.com/instrument/pdpl-law)

- **Art. 1** — Definitions: Definitional article setting out nineteen terms used throughout the Law, including Personal Data, Processing, Collection, Disclosure, Transfer, Sensitive Data, Genetic Data, Health Data, Credit Data, Data Subject, Public Entity, Controller, Processor and the Competent Authority, whose meanings apply unless the context requires otherwise.
- **Art. 2** — Scope of Application: Defines the Law's scope: it applies to any Processing of Personal Data in the Kingdom, including Processing of residents' data by parties outside the Kingdom, and to deceased persons' data if it would identify them or a family member. Purely personal or family use is excluded unless published or disclosed; the Regulations define such use.
- **Art. 3** — Relationship With Other Laws: States that the Law's provisions and procedures do not prejudice any provision that grants a right to the Data Subject or confers better protection of Personal Data under any other law or an international agreement to which the Kingdom is a party.
- **Art. 5** — Consent and Withdrawal: Prohibits Processing Personal Data or changing the Processing purpose without the Data Subject's consent, except in cases stated in the Law. The Regulations set consent conditions, cases requiring explicit consent, and legal-guardian consent where capacity is lacking. Consent may be withdrawn at any time, subject to controls in the Regulations.
- **Art. 6** — Exceptions to Consent Requirement: Lists four cases where Processing does not require consent: it serves the Data Subject's actual interests and contacting them is impossible or difficult; it is pursuant to another law or a prior agreement with the Data Subject; a Public Entity requires it for security or judicial purposes; or the Controller's legitimate interest, excluding Sensitive Data.
- **Art. 7** — Consent Not a Service Condition: Provides that consent to Processing may not be made a condition for providing a service or benefit, unless the service or benefit is directly related to the Personal Data Processing for which the consent is given.
- **Art. 4** — Data Subject Rights: The data subject's rights: to be informed, to access their data, to obtain a copy in a readable format, to request correction/completion/update, and to request destruction.
- **Art. 8** — Processor Selection and Oversight: Requires the Controller to select only Processors that provide sufficient guarantees to implement the Law and Regulations, and to monitor their compliance. The Controller remains responsible towards the Data Subject and the Competent Authority. The Regulations govern related matters, including subsequent contracts concluded by the Processor.
- **Art. 20** — Breach Notification (duty): Imposes the duty to notify the Competent Authority and affected data subjects of a personal-data breach. The Law sets no fixed deadline — the 72-hour timeline is set by IR Art. 24.
- **Art. 9** — Restrictions on Access Right: Permits the Controller to set time frames for exercising the right of access and to limit that right where necessary to protect the Data Subject or others from harm, or where a Public Entity requires it for security, legal or judicial reasons. Access must be prevented in the situations listed in Article 16.
- **Art. 22** — Impact Assessment: The Controller shall conduct an impact assessment for any product or service involving personal-data processing, in accordance with the Regulations (detailed in IR Art. 25).
- **Art. 31** — Records of Processing (Law): Lists the information that a controller's records of processing activities must contain (elaborated by IR Art. 33).
- **Art. 10** — Collection Sources and Purpose Limits: Requires collecting Personal Data directly from the Data Subject and Processing it only for the Collection purpose, subject to seven exceptions: consent; publicly available data; Public Entity requirements; avoiding harm to the Data Subject or their vital interests; protecting public health, safety or lives; non-identifying storage; and the Controller's legitimate interests excluding Sensitive Data.
- **Art. 11** — Lawful Collection and Data Minimization: Sets Collection standards: the purpose must relate directly to the Controller's purposes and comply with law; methods must be lawful, appropriate, direct, clear, secure and free of deception, misleading or extortion; content must be limited to the minimum necessary; and Collection must cease and collected data be destroyed when no longer needed.
- **Art. 12** — Privacy Policy: Requires the Controller to adopt a privacy policy and make it available to Data Subjects before collecting their Personal Data. The policy must state the purpose of Collection, the data collected, the means of Collection, Processing, storage and Destruction, and the Data Subject's rights and how to exercise them.
- **Art. 13** — Notice Upon Direct Collection: Obliges the Controller, when collecting Personal Data directly, to inform the Data Subject of the legal basis, the purpose, which data is mandatory or optional, the collector's identity, recipient entities, any Transfer or Processing outside the Kingdom, consequences of not collecting, the Data Subject's rights, and other elements the Regulations specify.
- **Art. 14** — Accuracy of Personal Data: Prohibits the Controller from Processing Personal Data without first taking sufficient steps to verify the data's accuracy, completeness, timeliness and relevance to the purpose for which it was collected, in accordance with the provisions of the Law.
- **Art. 15** — Permitted Disclosure Cases: Restricts Disclosure of Personal Data to six situations: the Data Subject's consent; data from a publicly available source; a Public Entity's request for public interest, security, legal or judicial purposes; protection of public health, safety or specific lives; non-identifying subsequent Processing; or the Controller's legitimate interests excluding Sensitive Data.
- **Art. 16** — Prohibited Disclosures: Prohibits Disclosure under several of Article 15's grounds where it would threaten security, harm the Kingdom's reputation, interests or foreign relations, impede crime detection or fair trial, compromise an individual's safety, violate another person's privacy, harm persons lacking legal capacity, breach professional obligations or judicial decisions, or expose confidential sources against the public interest.
- **Art. 17** — Notification of Data Corrections: Procedural article: when Personal Data is corrected, completed or updated, the Controller must notify all entities to which the data was transferred and make the amendment available to them. The Regulations set time frames, types of correction, and procedures to avoid Processing incorrect, inaccurate or outdated data.
- **Art. 18** — Data Destruction and Retention: Requires the Controller to Destroy Personal Data without undue delay once no longer necessary, while permitting retention in a form that cannot identify the Data Subject. Retention is mandatory where a legal basis prescribes a specific period or the data relates to a case before a judicial authority, with Destruction afterwards.
- **Art. 19** — Data Security Measures: Requires the Controller to implement all necessary organizational, administrative and technical measures to protect Personal Data, including during its Transfer, in accordance with the provisions and controls set out in the Regulations.
- **Art. 21** — Responding to Data Subject Requests: Procedural provision requiring the Controller to respond to Data Subjects' requests concerning their rights under the Law within the period and in the manner set out in the Regulations.
- **Art. 23** — Health Data Processing Controls: Mandates additional controls in the Regulations for Processing Health Data, protecting Data Subjects' privacy and rights. These include restricting access to Health Data, including medical files, to the minimum number of employees necessary to provide Health Services, and limiting Processing operations to what health services or insurance programs require.
- **Art. 24** — Credit Data Processing Controls: Requires the Regulations to set additional controls for Processing Credit Data consistent with this Law and the Credit Information Law, including verifying the Data Subject's explicit consent to Collection, purpose changes, Disclosure or Publishing, and notifying the Data Subject whenever a request to disclose their Credit Data is received.
- **Art. 25** — Advertising and Awareness Communications: Prohibits using a Data Subject's personal means of communication, including post and email, to send advertising or awareness-raising materials, except Public Entities' awareness materials, unless the recipient gave prior consent and the sender provides a clear mechanism to stop receiving them; the Regulations govern such materials and recipient consent.
- **Art. 26** — Processing for Marketing Purposes: Permits Processing Personal Data, other than Sensitive Data, for marketing purposes only where the data was collected directly from the Data Subject and their consent was given in accordance with the Law. The Regulations set out the applicable controls.
- **Art. 27** — Scientific, Research and Statistical Purposes: Allows Collection or Processing of Personal Data without consent for scientific, research or statistical purposes where the data does not specifically identify the Data Subject, identity evidence is destroyed before Disclosure and the data is not Sensitive, or another law or a prior agreement so requires. The Regulations set the required controls.
- **Art. 28** — Copying Official Documents: Prohibits copying official documents that identify Data Subjects, except where copying is required by law or a competent public authority requests such copies in accordance with the Regulations.
- **Art. 29** — Cross-Border Data Transfers: Permits Transfer or Disclosure of Personal Data outside the Kingdom for agreements the Kingdom is party to, the Kingdom's interests, obligations the Data Subject is party to, or other purposes per the Regulations, subject to national security, an adequate protection level assessed by the Competent Authority, and data minimization, waived in extreme necessity involving life or health.
- **Art. 30** — Supervisory Role of Competent Authority: Designates the Competent Authority, without prejudice to the Saudi Central Bank's powers, as overseer of the Law's implementation. The Regulations identify when Controllers must appoint personal data protection officers. Controllers must cooperate with the Authority, which may request documents, seek other parties' assistance, maintain a national register of Controllers, charge service fees, and delegate supervisory duties.
- **Art. 32** — Repealed Provision: The text of this article states only that it has been repealed. It contains no operative provisions in the amended version of the Law, reflecting the removal of its former content while the article numbering of the Law is preserved.
- **Art. 33** — Licensing, Accreditation and Audits: Empowers the Competent Authority to set requirements for commercial, professional or non-profit personal data protection activities, license entities issuing accreditation certificates to Controllers and Processors, license entities auditing Processing activities, and establish tools and procedures for monitoring and enforcing compliance of Controllers and Processors outside the Kingdom processing residents' data.
- **Art. 34** — Complaints to Competent Authority: Procedural article entitling Data Subjects to submit to the Competent Authority any complaint arising from the implementation of the Law and the Regulations, and directing the Regulations to set out the rules for processing such complaints.
- **Art. 35** — Criminal Penalties for Sensitive Data: Penal provision: disclosing or publishing Sensitive Data in violation of the Law, with intent to harm the Data Subject or gain personal benefit, is punishable by imprisonment up to two years and/or a fine up to three million riyals. The Public Prosecution prosecutes; the competent court adjudicates and may double fines for recidivism.
- **Art. 36** — Administrative Penalties: For violations not covered by Article 35, provides a warning or fine up to five million riyals, doublable for repeat violations. A committee of at least three members formed by the Competent Authority's president examines violations and imposes penalties, subject to the president's approval; decisions are appealable before the competent court.
- **Art. 37** — Inspection and Seizure Powers: Grants employees appointed by the Competent Authority's president powers to control and inspect violations of the Law and Regulations, under rules the president issues. Such employees may seek assistance from criminal investigation and other competent authorities, and the Competent Authority may seize the means or tools used in committing a violation.
- **Art. 38** — Confiscation and Judgment Publication: Empowers the competent court to order confiscation of funds obtained from violations, without prejudice to bona fide third parties. The court or the violations committee may also order publication of a summary of the penalty decision at the violator's expense once final, according to the violation's type, seriousness and impact.
- **Art. 39** — Disciplining Public Entity Employees: Requires Public Entities, without prejudice to the penalties in Article 35 and Paragraph 1 of Article 36, to discipline any of their employees who violate the Law or the Regulations, in accordance with the disciplinary provisions and procedures prescribed by law.
- **Art. 40** — Compensation for Damage: Entitles any individual who suffers damage as a result of a violation of the Law or the Regulations to apply to the competent court for compensation proportionate to the material or moral damage sustained, without prejudice to the penalties prescribed by the Law.
- **Art. 41** — Ongoing Confidentiality Obligation: Imposes a duty of confidentiality on any person who engages in the Processing of Personal Data, requiring them to protect the confidentiality of that data even after the end of their occupational or contractual relationship.
- **Art. 42** — Issuance of Implementing Regulations: Directs the president of the Competent Authority to issue the Regulations within seven hundred twenty days of the Law's publication, after coordination with seven named bodies, including the communications and foreign affairs ministries, the cybersecurity and digital government authorities, the Saudi Health Council and the Saudi Central Bank, each within its jurisdiction.
- **Art. 43** — Entry Into Force: Final provision stating that the Law shall come into force after seven hundred and twenty days commencing on the date of its publication in the Official Gazette.

### [NDMO Data Management & Personal Data Protection Standards](https://www.wadiraksa.com/instrument/ndmo-standards)

- **PDP.1** — Plan: Personal Data Protection domain, control PDP.1 — the PDP plan. NDMO DM & PDP Standards: 15 domains → 77 controls → 191 specifications; codes are PDP.x (control) / PDP.x.x (specification), e.g. PDP.1.1. (No 'CS'/'MQ' infix exists.)
- **PDP.2** — Training and Awareness: Personal Data Protection domain, control PDP.2 — training and awareness.
- **PDP.3** — Data Breach: Personal Data Protection domain, control PDP.3 — data-breach detection, logging and notification to the regulator.
- **PDP.4** — Data Lifecycle Management: Personal Data Protection domain, control PDP.4 — data lifecycle management; its specifications include risk-assessment findings (PDP.4.3) and monitoring (PDP.4.4).
- **PDP.5** — Artifacts: Personal Data Protection domain, control PDP.5 — artifacts (records and registers).

### [Implementing (Executive) Regulation](https://www.wadiraksa.com/instrument/implementing-regulation)

- **Art. 4** — Right to be informed: The data subject's right to be informed — the transparency / privacy-notice obligation at or before collection (IR Arts. 3-8 set out the data-subject rights).
- **Art. 1** — Definitions: Adopts the definitions of Article 1 of the Personal Data Protection Law and defines additional terms used in the Regulation, including Direct Marketing, Personal Data Breach, Vital Interest, Actual Interest, Legitimate Interest, Pseudonymisation, Anonymization, and Explicit Consent.
- **Art. 24** — Personal Data Breach Notification: The Controller must notify SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the data subject; affected data subjects are notified without undue delay.
- **Art. 2** — Personal or Family Use: Excludes from the Law's scope an individual's Processing of Personal Data for purposes not exceeding personal or family use, defined as Processing within a family or limited social circle. Publishing data to the public, disclosure beyond that circle, or professional, commercial, or non-profit use is not covered.
- **Art. 25** — Data Protection Impact Assessment: Specifies the processing activities that require an impact assessment — including sensitive data, large-scale processing, vulnerable data subjects, new technologies and automated decision-making.
- **Art. 3** — General Provisions for Data Subject Rights: Requires the Controller to act on data subject rights requests within 30 days, extendable by a further 30 days with notice, verify the requester's identity, and document all requests. Repetitive, manifestly unfounded, or disproportionate requests may be refused with reasons; legal guardians exercise rights for those lacking capacity.
- **Art. 32** — Data Protection Officer: Lists the processing that requires appointing a DPO (public bodies processing at scale, regular and systematic monitoring, core processing of sensitive data); the appointment is documented and notified to SDAIA.
- **Art. 33** — Records of Processing Activities (RoPA): The Controller maintains a written record of processing activities during processing and for five years afterwards, kept accurate and produced to SDAIA on request. (Being simplified under the pending IR amendments.)
- **Art. 34** — National Register of Controllers: Sets the requirements for registering controllers in the national register — distinct from the RoPA in Art. 33.
- **Art. 5** — Right of Access: Grants the data subject the right to access their Personal Data held by the Controller, either on request or through a direct-access channel, provided access does not adversely affect others' rights such as intellectual property or trade secrets, and no Personal Data identifying another individual is disclosed.
- **Art. 6** — Right to Request Data Copy: Entitles the data subject to request a copy of their Personal Data in a readable and clear format, provided in a commonly used electronic format or, if feasible, a printed hard copy, without adversely affecting others' rights or disclosing Personal Data that identifies another individual.
- **Art. 36** — Auditing and Controlling: Audits and checks of personal-data processing to ensure the entity properly protects personal data. (This — not Art. 24/25/33 — is the audit obligation.)
- **Art. 7** — Right to Request Correction: Allows the data subject to obtain restriction of Processing while the accuracy of contested Personal Data is verified. The Controller may request supporting documents, which must be destroyed once verification is complete, and must notify parties to whom the data was previously disclosed after correction, without undue delay.
- **Art. 8** — Right to Request Destruction: Obliges the Controller to destroy Personal Data upon the data subject's request, when no longer necessary for the collection purpose, on withdrawal of consent where consent is the sole legal basis, or if processed unlawfully. All copies including backups must be destroyed and recipients notified, subject to Article 18 of the Law.
- **Art. 9** — Anonymisation: Sets conditions for anonymising Personal Data: the Controller must ensure re-identification is impossible, assess the impact and re-identification risk, apply and update organisational, administrative, and technical measures in light of technological developments, and evaluate the effectiveness of the techniques used. Anonymised data is no longer considered Personal Data.
- **Art. 10** — Means of Communication: Requires the Controller to provide appropriate means for handling data subject rights requests. The data subject may choose among the options made available, including e-mail, text messages, the national address, electronic applications, or any other lawful communication means provided by the Controller for this purpose.
- **Art. 11** — Consent Conditions: Sets conditions for valid consent: freely given without misleading methods, for clear and specific purposes explained in advance, given by a person with full legal capacity, documented verifiably, and obtained separately for each Processing purpose. Explicit consent is required for Sensitive Data, Credit Data, and solely automated decision-making.
- **Art. 12** — Consent Withdrawal: Confirms the data subject may withdraw consent at any time. Withdrawal must be as easy as giving consent, with procedures established in advance. The Controller must then cease Processing without undue delay and notify recipients to destroy the data; prior Processing and Processing on other legal bases remain unaffected.
- **Art. 13** — Legal Guardian: Regulates how the legal guardian of a data subject lacking full or partial legal capacity exercises rights and consents to Processing in the subject's best interests. The Controller must verify guardianship validity, ensure the guardian's consent causes no harm, and let the data subject exercise rights upon reaching legal capacity.
- **Art. 14** — Processing for Actual Interest: When Processing Personal Data to serve the data subject's Actual Interest, the Controller must retain evidence demonstrating both that the actual interest exists and that it is not possible to contact or communicate with the data subject.
- **Art. 15** — Collecting Data from Third Parties: Governs Processing of Personal Data collected from sources other than the data subject: Processing must be necessary, proportionate to the purpose, and must not affect the data subject's rights and interests. Collection from publicly available sources must be lawful, and the Regulation's anonymisation provisions apply where relevant.
- **Art. 16** — Processing for Legitimate Interest: Permits Controllers other than Public Entities to process Personal Data for a Legitimate Interest, provided the purpose is lawful, interests are balanced against the data subject's rights, no Sensitive Data is involved, and Processing is within reasonable expectations. A documented prior assessment is required, with modification if harm is indicated.
- **Art. 17** — Processor Selection: Requires the Controller to select Processors offering sufficient guarantees and to conclude agreements covering purpose, data categories, duration, breach notification, and subcontractors. The Controller must issue instructions and periodically assess compliance; a Processor breaching instructions is treated as a Controller, and subcontracting requires guarantees and the Controller's prior acceptance.
- **Art. 18** — Processing Beyond Original Purpose: Applies when Personal Data is processed for a purpose other than the one for which it was collected: the Controller must clearly define the new purposes, record them in Processing activity records, document data-scoping procedures such as data maps, and limit Processing to the minimum data necessary.
- **Art. 19** — Data Minimisation: Requires the Controller to collect only the minimum Personal Data necessary to achieve the Processing purpose, using appropriate means such as data maps to link each collected item to a purpose, to avoid collecting unnecessary data, and to retain only the minimal data needed for the purpose.
- **Art. 20** — Disclosure of Personal Data: Sets controls for disclosing Personal Data, including data from publicly available sources: disclosure must relate to a specific, clear purpose, protect privacy, and be limited to the minimum necessary. Disclosure requests from public authorities must be documented, third-party data safeguarded through balancing and pseudonymisation, and all disclosure operations recorded with dates, methods, and purposes.
- **Art. 21** — Public Interest Processing Controls: Applies when a Public Entity collects Personal Data indirectly, processes it for a new purpose, or requests disclosure to achieve a public interest. The entity must ensure necessity for a clearly defined public interest within its mandate, limit potential damage, record the operations, and process only the minimum data.
- **Art. 22** — Correction of Personal Data: Details the Controller's correction duties: correcting inaccurate data, completing incomplete data, and updating outdated data. The Controller must verify accuracy, notify prior recipients and the data subject, document updates, suspend Processing where inaccurate data may cause harm, and maintain policies and periodic reviews of data accuracy.
- **Art. 23** — Information Security: Requires the Controller to take organisational, administrative, and technical measures to secure Personal Data and protect privacy, including security measures limiting breach risks and adopting the controls, standards, and rules of the National Cybersecurity Authority, or recognised cybersecurity best practices where those rules are not mandatory for the Controller.
- **Art. 26** — Processing Health Data: Obliges the Controller to protect Health Data through organisational, technical, and administrative measures, adopting requirements of health and insurance regulators, embedding the Law in internal policies, segregating staff responsibilities with tiered access, documenting all Processing stages, binding Processors contractually, and limiting Processing to the minimum needed for healthcare or health insurance.
- **Art. 27** — Processing Credit Data: Requires the Controller, without prejudice to the Credit Information Law, to protect Credit Data from unauthorised use, access, or disclosure by adopting requirements of the Saudi Central Bank and relevant authorities, and to obtain the data subject's consent and notify them of any request to disclose their Credit Data.
- **Art. 28** — Advertising and Awareness Materials: Regulates sending advertising or awareness materials: prior consent of the targeted recipient is required absent previous interaction, consent must be free, specific, and documented, the sender's identity must be clearly stated, and recipients must be able to halt such materials easily, immediately, and free of charge.
- **Art. 29** — Direct Marketing: Requires the Controller, before Processing Personal Data for Direct Marketing, to obtain the data subject's consent and provide a mechanism to halt marketing material that is as simple as giving consent. The sender's identity must be clearly disclosed, and marketing must stop without undue delay upon consent withdrawal.
- **Art. 30** — Scientific, Research or Statistical Purposes: Governs collecting or Processing Personal Data for scientific, research, or statistical purposes without the data subject's consent: purposes must be clearly specified in Processing records, only the minimum necessary data collected, data pseudonymised where the purposes can still be fulfilled, and any negative impact on the data subject's rights avoided.
- **Art. 31** — Photographing or Copying Official Documents: Prohibits the Controller from photographing or copying official documents issued by Public Entities that identify data subjects, except at the request of a public competent authority or to fulfil a legal requirement. Such documents must be protected and destroyed once their purpose ends, unless retention is legally required.
- **Art. 35** — Accreditation Bodies: Tasks the competent authority with issuing regulatory rules for licensing entities that grant accreditation certificates to Controllers and Processors under Article 33 of the Law, and with coordinating with the Digital Government Authority on licensing entities that provide such services on behalf of government entities.
- **Art. 37** — Submitting and Processing Complaints: Allows a data subject to file a complaint with the competent authority within 90 days of the incident or of becoming aware of it, with late complaints admissible for reasonable causes. The authority must register, examine, and act on complaints and inform the complainant of the outcome.
- **Art. 38** — Publication and Enforcement: Provides that the Regulation shall be published in the official gazette and on the competent authority's official website, and shall come into force from the date of the Law's enforcement.

### [Regulation on Personal Data Transfer Outside KSA](https://www.wadiraksa.com/instrument/transfer-regulation)

- **Art. 1** — Definitions: Adopts the definitions of Article 1 of the Personal Data Protection Law and defines terms specific to this Regulation, including Appropriate Safeguards, Operational Processes, Standard Contractual Clauses, and Binding Common Rules applicable to transfers of personal data outside the Kingdom.
- **Art. 2** — Other Purposes for Transfer: Specifies additional purposes for transferring or disclosing personal data to a party outside the Kingdom under Article 29 of the Law, including performing central processing operations necessary for the controller's activities, providing a service or benefit to the data subject, and conducting scientific research and studies.
- **Art. 3** — Adequacy Assessment: Requires the competent authority to publish, and review every four years or as necessary, a list of countries and international organisations providing an adequate level of personal data protection, based on criteria including legislation, supervisory bodies, and cooperation. The authority may amend the list or suspend transfers; the standards also apply to cities, special economic zones, and global trade centres.
- **Art. 4** — Exemptions and Appropriate Safeguards: Exempts controllers, in defined cases, from the adequacy and data-minimisation conditions of Article 29 of the Law, provided appropriate safeguards apply: standard contractual clauses, binding common rules, or accreditation certificates. Cases cover public-body agreements, limited transfers, multinational central operations, services to data subjects, and scientific research; the competent authority may review the safeguards every two years or as necessary.
- **Art. 5** — Subsequent Transfers of Personal Data: Provides that the Law and its Regulations continue to apply to any subsequent transfer of personal data that has already been transferred or disclosed to a party outside the Kingdom, without prejudice to Articles 8 and 15 of the Law and Article 17 of the Implementing Regulation.
- **Art. 6** — Revocation of Exemption: Terminates exemptions granted under Article 4 of the Regulation where the controller fails to implement the appropriate safeguards or the competent authority finds those safeguards inadequate in a specific case. The controller must then halt the transfer or disclosure and notify the entities that received the personal data.
- **Art. 7** — Risk Assessment for Transfers: Requires the controller to conduct a risk assessment before transferring or disclosing personal data outside the Kingdom under Article 4 exemptions, or when transferring sensitive data continuously or widely. The assessment covers purpose, legal basis, nature and scope, safeguards, data minimisation, potential effects and their likelihood, and mitigation measures.
- **Art. 8** — Guides and Guidelines: Directs the competent authority to issue guides and guidelines related to the provisions of this Regulation on the transfer of personal data outside the Kingdom.
- **Art. 9** — Entry into Force: The Regulation enters into force on the date of its publication in the Official Gazette.

### [National Data Index (NDI)](https://www.wadiraksa.com/instrument/ndi)

- **Compliance** — Compliance: Adherence to the NDMO Data Management & PDP specifications, assessed in phases. The NDI scores entities against the NDMO specifications — it does not define its own specification codes.
- **Maturity** — Data Management Maturity (0–5): Maturity of data-management practice across the domains on a 0–5 scale (Absence of Capabilities → Pioneer), assessed via a questionnaire on the National Data Governance Platform.
- **Operational Excellence** — Operational Excellence: Efficiency and effectiveness of data operations, drawn from national data platforms.

---
_86 instruments · 8 frameworks · 6 authorities. Generated by Wadira._
