Wadira: Find your way through Saudi data & privacy law.
Home › Frameworks › Personal Data Protection (PDPL) › Guide to the PDPL for Controllers and Processors
| Type | Guideline |
|---|---|
| Issuing authority | Saudi Data & AI Authority / National Data Management Office (SDAIA / NDMO) |
| Framework | Personal Data Protection (PDPL) |
| Tier | Guidelines & circulars |
| Legal status | Guidance |
| Dates | December 2023 |
The Guide to the Saudi Personal Data Protection Law for Controllers and Processors (Version 1.0, December 2023) is SDAIA's plain-language companion to the PDPL (Royal Decree M/19, 9/2/1443H). It is explicitly non-binding: the Guidance contains no rules or obligations of its own and has no status as a legal instrument; its aim is to clarify the Law and direct organisations towards compliance.
The Guide works through the PDPL's building blocks with worked scenarios: the material scope (what personal data is, sensitive data, data of the deceased, and the treatment of opinions, inferences, pseudonymised and anonymised data); the territorial scope (what counts as processing in the Kingdom, who resides in the Kingdom, and who is a party outside it); the roles of controllers and processors; exclusions such as personal or family use; the grace period; SDAIA's role as Competent Authority; individuals' rights; and the data-protection principles. An appendix lists bad data-protection practices to avoid.
Within the atlas it sits beneath the PDPL, its Implementing Regulation and the Transfer Regulation as the primary interpretive aid for day-to-day compliance work.
Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-13