Wadira — اعثر على طريقك عبر أنظمة البيانات والخصوصية في المملكة العربية السعودية.

التحديثات التنظيمية

2026-07-07 — SDAIA consults on standards guides for the PDPL certification and audit market

SDAIA opened a consultation (closing 6 August 2026, as reported) on three draft standards guides implementing the March-gazetted licensing rules: standards for issuing accreditation certificates to controllers and processors, for licensing personal-data audit and inspection activities, and for licensing certificate-issuance activities. They set the operating bar for the new PDPL certification and audit market, and matter to controllers seeking certificates as transfer safeguards. نظام حماية البيانات الشخصية (PDPL)

2026-07-05 — NCA consults on AI Cybersecurity Guidelines

The National Cybersecurity Authority opened a consultation (5 July – 5 August 2026) on draft AI Cybersecurity Guidelines — its first AI-specific instrument — setting cybersecurity governance, defence, resilience and third-party requirements for organisations deploying or planning to adopt AI in the Kingdom, explicitly covering generative and agentic AI.

2026-06-29 — SDAIA committees issue further PDPL fines and warnings

SDAIA's violation-review committees announced a further package of decisions — fines and warnings against several entities — for direct marketing without explicit consent and failing to maintain measures enabling timely responses to data-subject requests; press reports also cited 72-hour breach-notification failures and failures to appoint required DPOs. No entity names or amounts were disclosed. نظام حماية البيانات الشخصية (PDPL)

2026-06-24 — NCA consults on cybersecurity violations and penalties schedule

The National Cybersecurity Authority opened a public consultation (24 June – 24 July 2026) on a draft classification of violations of NCA-mandated cybersecurity requirements and a corresponding penalties schedule, exercising enforcement powers under its amended statute (Royal Decree M/117). It would create the first formal penalty taxonomy behind the ECC, NCNICC and sector controls, affecting all entities subject to them.

2026-06-19 — SDAIA issues Data Revenue Generation Policy

SDAIA published the Data Revenue Generation Policy (dated 27 April 2026, announced 19 June 2026), setting principles for government entities — and private entities holding government-sourced data — to develop revenue-generating data products and services. Products built on personal data must preserve privacy under the PDPL; open data remains free; government-to-government sharing cannot be charged. A national registry for data-product revenue generation now appears on SDAIA's National Data Governance Platform.

2026-06-08 — NCA consults on national incident-reporting framework (NFCISIR-1:2026)

The National Cybersecurity Authority consulted on the draft National Framework for Cybersecurity Information Sharing and Incident Response; the consultation closed 10 July 2026. As drafted, public and private entities would report actual or suspected incidents via the national Haseen portal, follow tiered response timeframes (2/12/48/72 hours) across five severity levels, retain incident records for 15 years, and share threat intelligence under TLP. The final framework is pending.

2026-04-03 — SDAIA consults on draft Responsible AI Policy

SDAIA opened a one-month public consultation (3 April – 3 May 2026) on a draft Responsible AI Policy applying to government, private and non-profit entities and individuals developing, deploying or publishing AI in the Kingdom. It moves beyond the 2023 AI Ethics Principles toward operational governance: risk-based classification, obligations for higher-risk systems, watermarking and content tracking of AI outputs, bias mitigation and performance monitoring. The final policy had not been issued as of mid-July 2026.

2026-03-06 — PDPL audit and certification licensing rules gazetted

Two SDAIA instruments (Decisions 5135/2 and 5316, dated 16 December 2025; gazetted in Umm Al-Qura on 6 March 2026) create the PDPL compliance-services market: licences for accreditation-certificate issuers (SAR 10m capital, at least 10 qualified assessors, 3-year term) and for personal-data audit and inspection providers, plus rules for issuing controllers and processors 2-year accreditation certificates. Certificates also serve as a cross-border transfer safeguard under the Transfer Regulation. نظام حماية البيانات الشخصية (PDPL)

2026-01-15 — سدايا تُعلن عن 48 قراراً بإنفاذ نظام حماية البيانات

أكدت لجان سدايا المختصة 48 مخالفة لنظام حماية البيانات الشخصية في أول موجة إنفاذ جوهرية — معظمها معالجة دون أساس نظامي، وإفصاح غير مصرّح، وتسويق دون موافقة. ونُشرت القرارات بشكل إجمالي دون تسمية الجهات. نظام حماية البيانات الشخصية (PDPL)

2025-12-30 — المؤشر الوطني للبيانات — إطلاق الدورة الثالثة للقياس

أطلقت سدايا الدورة الثالثة للمؤشر الوطني للبيانات، موسِّعةً القياس إلى 214 جهة حكومية (بزيادة نحو 110%). ويقيس المؤشر نضج إدارة البيانات والالتزام والتميّز التشغيلي عبر منصة حوكمة البيانات الوطنية. المؤشر الوطني للبيانات (NDI)

2025-12-28 — NCA issues cybersecurity controls for non-CNI private sector (NCNICC-1:2025)

The National Cybersecurity Authority extended mandatory ECC-derived cybersecurity controls to all private-sector entities that are not critical-infrastructure operators — its largest scope expansion since the ECC. Category A entities (over 250 staff or SAR 200m revenue) face 65 controls across three domains; Category B (SMEs) face 26 controls. Compliance is continuous under Article 10(3) of the NCA statute, with no stated grace period. ضوابط الأمن السيبراني للبنى التحتية الوطنية غير الحساسة (NCNICC-1:2025)

2025-12-02 — SDAIA issues General Rules for Secondary Use of Data

Approved by SDAIA Board Decision 22-1 (11/6/1447H) and publicised in January 2026, the General Rules govern reusing data — including personal data — beyond its original collection purpose, for research, development and public-interest uses. They cover government-to-government, government-to-private and private-to-government requests under six principles; any reuse of personal data must comply with the PDPL.

2025-05-27 — الاستطلاع العام الثالث لتعديلات اللائحة التنفيذية

اقترح الاستطلاع العام الثالث لسدايا (27 أبريل – 27 مايو 2025) تبسيط اللائحة التنفيذية: بدمج قواعد تعيين مسؤول حماية البيانات وتسجيل جهات التحكم فيها، وتبسيط متطلب سجل المعالجة، وإضافة بند لإشعار الخصوصية بلغة واضحة. ولم تُعتمد بعدُ حتى منتصف 2026. اللائحة التنفيذية

2025-04-23 — استطلاع حول قواعد مزوّدي خدمات حماية البيانات

اقترح استطلاع موازٍ لسدايا (أُغلق في مايو 2025) ترخيص الشركات التي تقدّم الاستشارات وتقنيات الامتثال والتدريب في مجال حماية البيانات — وهو أداة منفصلة عن تعديلات اللائحة التنفيذية.

2025-02-25 — دليل تقييم مخاطر النقل عبر الحدود

أصدرت سدايا منهجية غير ملزمة من أربع مراحل لتقييم مخاطر نقل البيانات الشخصية خارج المملكة، مع أداة مصاحبة لتقييم المخاطر على منصة حوكمة البيانات الوطنية. لائحة نقل البيانات الشخصية خارج المملكة العربية السعودية


المحتوى وبيانات السجل مرخّصة CC BY 4.0 — يُستشهد بالرابط المباشر. سجل قابل للقراءة الآلية (JSON) · سجل بصيغة Markdown · آخر تحقق من المحتوى: 2026-07-27