Amendments pending — consultation closed 27 May 2025; not enacted as of Jun 2026
The Implementing Regulation (September 2023) gives the PDPL its operational detail across 38 articles. Amendments are pending: a third public consultation closed on 27 May 2025 and had not been enacted as of July 2026 — the provisions below reflect the Regulation as in force.
What it covers. Data-subject requests must be answered within 30 days, extendable by a further 30 (Art. 3). Consent must be freely given, purpose-specific, documented and separate per purpose — and explicit for sensitive data, credit data and solely automated decision-making (Art. 11); withdrawal must be as easy as consenting (Art. 12). Legitimate-interest processing requires a documented prior assessment and excludes public entities and sensitive data (Art. 16). Processor relationships need contracts covering purpose, data categories, breach notification and subcontracting (Art. 17). Security follows the National Cybersecurity Authority's controls, or recognised best practice where those are not mandatory (Art. 23). Personal-data breaches must be notified to SDAIA within 72 hours where harm is possible, and to affected individuals without undue delay (Art. 24). Impact assessments are mandatory for sensitive data, dataset linking, constant monitoring, new technologies and automated decisions (Art. 25). Sector rules cover health data (Art. 26) and credit data (Art. 27); advertising and direct marketing are opt-in with easy, free opt-out (Arts. 28–29). Controllers must appoint a data protection officer in the cases of Art. 32, keep records of processing for the duration of processing plus five years (Art. 33), and register on the national register per SDAIA's rules (Art. 34). Complaints go to SDAIA within 90 days (Art. 37).
Frequently asked questions
When must a data breach be notified in Saudi Arabia?
Article 24 requires the controller to notify SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the data subject, or conflict with their rights or interests. Affected data subjects must be notified without undue delay where the breach may cause them damage — there is no GDPR-style "unlikely risk" carve-out.
Who must appoint a data protection officer (DPO)?
Article 32 requires a DPO where the controller is a public entity providing large-scale processing services, where core activities involve regular and systematic monitoring of data subjects, or where core activities consist of processing sensitive data. The DPO may be an employee or an external provider.
What triggers a data protection impact assessment?
Article 25 lists the mandatory cases: processing sensitive data; collecting, comparing or linking two or more datasets; large-scale or repetitive processing of persons lacking capacity; operations requiring constant monitoring; newly adopted technologies; solely automated decision-making; and any product or service likely to cause serious privacy harm.
What is changing in the pending amendments?
The May 2025 consultation proposed consolidating the DPO and controller-registration rules into the Regulation, simplifying the records-of-processing format, easing some direct-marketing provisions and removing the 90-day complaint window. None of this had been enacted as of July 2026 — the September 2023 text remains in force.
Key provisions
Art. 4 — Right to be informed. The data subject's right to be informed — the transparency / privacy-notice obligation at or before collection (IR Arts. 3-8 set out the data-subject rights).
Art. 1 — Definitions. Adopts the definitions of Article 1 of the Personal Data Protection Law and defines additional terms used in the Regulation, including Direct Marketing, Personal Data Breach, Vital Interest, Actual Interest, Legitimate Interest, Pseudonymisation, Anonymization, and Explicit Consent.
Art. 24 — Personal Data Breach Notification. The Controller must notify SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the data subject; affected data subjects are notified without undue delay.
Art. 2 — Personal or Family Use. Excludes from the Law's scope an individual's Processing of Personal Data for purposes not exceeding personal or family use, defined as Processing within a family or limited social circle. Publishing data to the public, disclosure beyond that circle, or professional, commercial, or non-profit use is not covered.
Art. 25 — Data Protection Impact Assessment. Specifies the processing activities that require an impact assessment — including sensitive data, large-scale processing, vulnerable data subjects, new technologies and automated decision-making.
Art. 3 — General Provisions for Data Subject Rights. Requires the Controller to act on data subject rights requests within 30 days, extendable by a further 30 days with notice, verify the requester's identity, and document all requests. Repetitive, manifestly unfounded, or disproportionate requests may be refused with reasons; legal guardians exercise rights for those lacking capacity.
Art. 32 — Data Protection Officer. Lists the processing that requires appointing a DPO (public bodies processing at scale, regular and systematic monitoring, core processing of sensitive data); the appointment is documented and notified to SDAIA.
Art. 33 — Records of Processing Activities (RoPA). The Controller maintains a written record of processing activities during processing and for five years afterwards, kept accurate and produced to SDAIA on request. (Being simplified under the pending IR amendments.)
Art. 34 — National Register of Controllers. Sets the requirements for registering controllers in the national register — distinct from the RoPA in Art. 33.
Art. 5 — Right of Access. Grants the data subject the right to access their Personal Data held by the Controller, either on request or through a direct-access channel, provided access does not adversely affect others' rights such as intellectual property or trade secrets, and no Personal Data identifying another individual is disclosed.
Art. 6 — Right to Request Data Copy. Entitles the data subject to request a copy of their Personal Data in a readable and clear format, provided in a commonly used electronic format or, if feasible, a printed hard copy, without adversely affecting others' rights or disclosing Personal Data that identifies another individual.
Art. 36 — Auditing and Controlling. Audits and checks of personal-data processing to ensure the entity properly protects personal data. (This — not Art. 24/25/33 — is the audit obligation.)
Art. 7 — Right to Request Correction. Allows the data subject to obtain restriction of Processing while the accuracy of contested Personal Data is verified. The Controller may request supporting documents, which must be destroyed once verification is complete, and must notify parties to whom the data was previously disclosed after correction, without undue delay.
Art. 8 — Right to Request Destruction. Obliges the Controller to destroy Personal Data upon the data subject's request, when no longer necessary for the collection purpose, on withdrawal of consent where consent is the sole legal basis, or if processed unlawfully. All copies including backups must be destroyed and recipients notified, subject to Article 18 of the Law.
Art. 9 — Anonymisation. Sets conditions for anonymising Personal Data: the Controller must ensure re-identification is impossible, assess the impact and re-identification risk, apply and update organisational, administrative, and technical measures in light of technological developments, and evaluate the effectiveness of the techniques used. Anonymised data is no longer considered Personal Data.
Art. 10 — Means of Communication. Requires the Controller to provide appropriate means for handling data subject rights requests. The data subject may choose among the options made available, including e-mail, text messages, the national address, electronic applications, or any other lawful communication means provided by the Controller for this purpose.
Art. 11 — Consent Conditions. Sets conditions for valid consent: freely given without misleading methods, for clear and specific purposes explained in advance, given by a person with full legal capacity, documented verifiably, and obtained separately for each Processing purpose. Explicit consent is required for Sensitive Data, Credit Data, and solely automated decision-making.
Art. 12 — Consent Withdrawal. Confirms the data subject may withdraw consent at any time. Withdrawal must be as easy as giving consent, with procedures established in advance. The Controller must then cease Processing without undue delay and notify recipients to destroy the data; prior Processing and Processing on other legal bases remain unaffected.
Art. 13 — Legal Guardian. Regulates how the legal guardian of a data subject lacking full or partial legal capacity exercises rights and consents to Processing in the subject's best interests. The Controller must verify guardianship validity, ensure the guardian's consent causes no harm, and let the data subject exercise rights upon reaching legal capacity.
Art. 14 — Processing for Actual Interest. When Processing Personal Data to serve the data subject's Actual Interest, the Controller must retain evidence demonstrating both that the actual interest exists and that it is not possible to contact or communicate with the data subject.
Art. 15 — Collecting Data from Third Parties. Governs Processing of Personal Data collected from sources other than the data subject: Processing must be necessary, proportionate to the purpose, and must not affect the data subject's rights and interests. Collection from publicly available sources must be lawful, and the Regulation's anonymisation provisions apply where relevant.
Art. 16 — Processing for Legitimate Interest. Permits Controllers other than Public Entities to process Personal Data for a Legitimate Interest, provided the purpose is lawful, interests are balanced against the data subject's rights, no Sensitive Data is involved, and Processing is within reasonable expectations. A documented prior assessment is required, with modification if harm is indicated.
Art. 17 — Processor Selection. Requires the Controller to select Processors offering sufficient guarantees and to conclude agreements covering purpose, data categories, duration, breach notification, and subcontractors. The Controller must issue instructions and periodically assess compliance; a Processor breaching instructions is treated as a Controller, and subcontracting requires guarantees and the Controller's prior acceptance.
Art. 18 — Processing Beyond Original Purpose. Applies when Personal Data is processed for a purpose other than the one for which it was collected: the Controller must clearly define the new purposes, record them in Processing activity records, document data-scoping procedures such as data maps, and limit Processing to the minimum data necessary.
Art. 19 — Data Minimisation. Requires the Controller to collect only the minimum Personal Data necessary to achieve the Processing purpose, using appropriate means such as data maps to link each collected item to a purpose, to avoid collecting unnecessary data, and to retain only the minimal data needed for the purpose.
Art. 20 — Disclosure of Personal Data. Sets controls for disclosing Personal Data, including data from publicly available sources: disclosure must relate to a specific, clear purpose, protect privacy, and be limited to the minimum necessary. Disclosure requests from public authorities must be documented, third-party data safeguarded through balancing and pseudonymisation, and all disclosure operations recorded with dates, methods, and purposes.
Art. 21 — Public Interest Processing Controls. Applies when a Public Entity collects Personal Data indirectly, processes it for a new purpose, or requests disclosure to achieve a public interest. The entity must ensure necessity for a clearly defined public interest within its mandate, limit potential damage, record the operations, and process only the minimum data.
Art. 22 — Correction of Personal Data. Details the Controller's correction duties: correcting inaccurate data, completing incomplete data, and updating outdated data. The Controller must verify accuracy, notify prior recipients and the data subject, document updates, suspend Processing where inaccurate data may cause harm, and maintain policies and periodic reviews of data accuracy.
Art. 23 — Information Security. Requires the Controller to take organisational, administrative, and technical measures to secure Personal Data and protect privacy, including security measures limiting breach risks and adopting the controls, standards, and rules of the National Cybersecurity Authority, or recognised cybersecurity best practices where those rules are not mandatory for the Controller.
Art. 26 — Processing Health Data. Obliges the Controller to protect Health Data through organisational, technical, and administrative measures, adopting requirements of health and insurance regulators, embedding the Law in internal policies, segregating staff responsibilities with tiered access, documenting all Processing stages, binding Processors contractually, and limiting Processing to the minimum needed for healthcare or health insurance.
Art. 27 — Processing Credit Data. Requires the Controller, without prejudice to the Credit Information Law, to protect Credit Data from unauthorised use, access, or disclosure by adopting requirements of the Saudi Central Bank and relevant authorities, and to obtain the data subject's consent and notify them of any request to disclose their Credit Data.
Art. 28 — Advertising and Awareness Materials. Regulates sending advertising or awareness materials: prior consent of the targeted recipient is required absent previous interaction, consent must be free, specific, and documented, the sender's identity must be clearly stated, and recipients must be able to halt such materials easily, immediately, and free of charge.
Art. 29 — Direct Marketing. Requires the Controller, before Processing Personal Data for Direct Marketing, to obtain the data subject's consent and provide a mechanism to halt marketing material that is as simple as giving consent. The sender's identity must be clearly disclosed, and marketing must stop without undue delay upon consent withdrawal.
Art. 30 — Scientific, Research or Statistical Purposes. Governs collecting or Processing Personal Data for scientific, research, or statistical purposes without the data subject's consent: purposes must be clearly specified in Processing records, only the minimum necessary data collected, data pseudonymised where the purposes can still be fulfilled, and any negative impact on the data subject's rights avoided.
Art. 31 — Photographing or Copying Official Documents. Prohibits the Controller from photographing or copying official documents issued by Public Entities that identify data subjects, except at the request of a public competent authority or to fulfil a legal requirement. Such documents must be protected and destroyed once their purpose ends, unless retention is legally required.
Art. 35 — Accreditation Bodies. Tasks the competent authority with issuing regulatory rules for licensing entities that grant accreditation certificates to Controllers and Processors under Article 33 of the Law, and with coordinating with the Digital Government Authority on licensing entities that provide such services on behalf of government entities.
Art. 37 — Submitting and Processing Complaints. Allows a data subject to file a complaint with the competent authority within 90 days of the incident or of becoming aware of it, with late complaints admissible for reasonable causes. The authority must register, examine, and act on complaints and inform the complainant of the outcome.
Art. 38 — Publication and Enforcement. Provides that the Regulation shall be published in the official gazette and on the competent authority's official website, and shall come into force from the date of the Law's enforcement.
2025-05-27 — Third public consultation on Implementing Regulation amendments: SDAIA's third public consultation (27 Apr – 27 May 2025) proposed to simplify the Implementing Regulation: folding the DPO-appointment and controller-registration rules into it, simplifying the RoPA requirement, and addi