Wadira — Find your way through Saudi data & privacy law.

HomeFrameworksPersonal Data Protection (PDPL) › Implementing (Executive) Regulation

Implementing (Executive) Regulation

TypeImplementing Regulation
CodeRegulations
Issuing authoritySaudi Data & AI Authority / National Data Management Office (SDAIA / NDMO)
FrameworkPersonal Data Protection (PDPL)
TierImplementing & executive regulation
Legal statusBinding
DatesAmendments pending — consultation closed 27 May 2025; not enacted as of Jun 2026

The Implementing Regulation (September 2023) gives the PDPL its operational detail across 38 articles. Amendments are pending: a third public consultation closed on 27 May 2025 and had not been enacted as of July 2026 — the provisions below reflect the Regulation as in force.

What it covers. Data-subject requests must be answered within 30 days, extendable by a further 30 (Art. 3). Consent must be freely given, purpose-specific, documented and separate per purpose — and explicit for sensitive data, credit data and solely automated decision-making (Art. 11); withdrawal must be as easy as consenting (Art. 12). Legitimate-interest processing requires a documented prior assessment and excludes public entities and sensitive data (Art. 16). Processor relationships need contracts covering purpose, data categories, breach notification and subcontracting (Art. 17). Security follows the National Cybersecurity Authority's controls, or recognised best practice where those are not mandatory (Art. 23). Personal-data breaches must be notified to SDAIA within 72 hours where harm is possible, and to affected individuals without undue delay (Art. 24). Impact assessments are mandatory for sensitive data, dataset linking, constant monitoring, new technologies and automated decisions (Art. 25). Sector rules cover health data (Art. 26) and credit data (Art. 27); advertising and direct marketing are opt-in with easy, free opt-out (Arts. 28–29). Controllers must appoint a data protection officer in the cases of Art. 32, keep records of processing for the duration of processing plus five years (Art. 33), and register on the national register per SDAIA's rules (Art. 34). Complaints go to SDAIA within 90 days (Art. 37).

Frequently asked questions

When must a data breach be notified in Saudi Arabia?

Article 24 requires the controller to notify SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the data subject, or conflict with their rights or interests. Affected data subjects must be notified without undue delay where the breach may cause them damage — there is no GDPR-style "unlikely risk" carve-out.

Who must appoint a data protection officer (DPO)?

Article 32 requires a DPO where the controller is a public entity providing large-scale processing services, where core activities involve regular and systematic monitoring of data subjects, or where core activities consist of processing sensitive data. The DPO may be an employee or an external provider.

What triggers a data protection impact assessment?

Article 25 lists the mandatory cases: processing sensitive data; collecting, comparing or linking two or more datasets; large-scale or repetitive processing of persons lacking capacity; operations requiring constant monitoring; newly adopted technologies; solely automated decision-making; and any product or service likely to cause serious privacy harm.

What is changing in the pending amendments?

The May 2025 consultation proposed consolidating the DPO and controller-registration rules into the Regulation, simplifying the records-of-processing format, easing some direct-marketing provisions and removing the 90-day complaint window. None of this had been enacted as of July 2026 — the September 2023 text remains in force.

Key provisions

Documents

Updates for this instrument

In this framework


Content and register data licensed CC BY 4.0 — cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-07-27