Wadira: Find your way through Saudi data & privacy law.

HomeFrameworksPersonal Data Protection (PDPL) › Guide to the PDPL for Controllers and Processors

Guide to the PDPL for Controllers and Processors

TypeGuideline
Issuing authoritySaudi Data & AI Authority / National Data Management Office (SDAIA / NDMO)
FrameworkPersonal Data Protection (PDPL)
TierGuidelines & circulars
Legal statusGuidance
DatesDecember 2023

The Guide to the Saudi Personal Data Protection Law for Controllers and Processors (Version 1.0, December 2023) is SDAIA's plain-language companion to the PDPL (Royal Decree M/19, 9/2/1443H). It is explicitly non-binding: the Guidance contains no rules or obligations of its own and has no status as a legal instrument; its aim is to clarify the Law and direct organisations towards compliance.

The Guide works through the PDPL's building blocks with worked scenarios: the material scope (what personal data is, sensitive data, data of the deceased, and the treatment of opinions, inferences, pseudonymised and anonymised data); the territorial scope (what counts as processing in the Kingdom, who resides in the Kingdom, and who is a party outside it); the roles of controllers and processors; exclusions such as personal or family use; the grace period; SDAIA's role as Competent Authority; individuals' rights; and the data-protection principles. An appendix lists bad data-protection practices to avoid.

Within the atlas it sits beneath the PDPL, its Implementing Regulation and the Transfer Regulation as the primary interpretive aid for day-to-day compliance work.

Documents

In this framework


Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13