M/19 (2021), amended M/148 (2023); in force 14 Sep 2023
The Personal Data Protection Law (PDPL) is Saudi Arabia's first comprehensive data-protection statute — issued by Royal Decree M/19 (9/2/1443H, 16 September 2021), published in the Umm al-Qura Official Gazette on 24 September 2021, amended by Royal Decree M/148 (27 March 2023), and in force since 14 September 2023, with SDAIA's compliance grace period ending 14 September 2024. The Saudi Data & Artificial Intelligence Authority (SDAIA) supervises implementation as the competent authority (Art. 30).
Who it applies to. The Law covers any processing of personal data in the Kingdom and — notably — processing of Saudi residents' data by parties outside the Kingdom (Art. 2). It extends to data of the deceased where it could identify them or a family member; purely personal or family use is excluded.
How it regulates. Processing rests on consent by default (Art. 5), with exceptions including the data subject's actual interest, another law or prior agreement, public-entity security or judicial requirements, and the controller's legitimate interest for non-sensitive data (Arts. 6, 10, 15). Data subjects can be informed, access, obtain a copy, correct and destroy their data (Art. 4). Controllers must publish a privacy policy (Art. 12), verify accuracy (Art. 14), secure data (Art. 19), notify breaches (Art. 20 — 72 hours to SDAIA under the Implementing Regulation), conduct impact assessments (Art. 22) and keep records of processing (Art. 31). Cross-border transfers are permitted for defined purposes subject to safeguards (Art. 29, detailed in the Transfer Regulation).
Penalties. Disclosing sensitive data with intent to harm or for personal gain is a criminal offence — up to two years' imprisonment and/or a SAR 3,000,000 fine, prosecuted by the Public Prosecution (Art. 35). Any other violation draws a warning or a fine up to SAR 5,000,000, doubled for repeat violations, imposed by SDAIA violation committees with appeal to the competent court (Art. 36). Courts may order confiscation and publication of judgments (Art. 38), and injured individuals may claim compensation (Art. 40).
Frequently asked questions
Does the Saudi PDPL apply to companies outside Saudi Arabia?
Yes. Article 2 extends the Law to any processing of the personal data of individuals residing in the Kingdom by parties outside it, and Article 33 directs the competent authority to set mechanisms for monitoring and enforcing compliance by controllers and processors abroad.
Is consent always required to process personal data?
No. Consent is the default legal basis (Art. 5), but Articles 6, 10 and 15 permit processing without it — including for the data subject's actual interest where contact is impossible or difficult, under another law or a prior agreement with the data subject, for public-entity security or judicial purposes, and for the controller's legitimate interest provided no sensitive data is processed.
What are the penalties for violating the PDPL?
Unlawful disclosure of sensitive data with intent to harm or for personal benefit carries up to two years' imprisonment and/or SAR 3 million (Art. 35). Other violations carry a warning or a fine up to SAR 5 million, doubled for repeat violations (Art. 36), plus possible confiscation and publication of the judgment (Art. 38) and civil compensation (Art. 40).
When did the PDPL come into force?
The Law took effect on 14 September 2023 — 720 days after Official Gazette publication (Art. 43) — and SDAIA's transition period for full compliance ended on 14 September 2024. The Implementing Regulation accompanied it, and the Transfer Regulation was reissued as version 2.0 in September 2024.
Key provisions
Art. 1 — Definitions. Definitional article setting out nineteen terms used throughout the Law, including Personal Data, Processing, Collection, Disclosure, Transfer, Sensitive Data, Genetic Data, Health Data, Credit Data, Data Subject, Public Entity, Controller, Processor and the Competent Authority, whose meanings apply unless the context requires otherwise.
Art. 2 — Scope of Application. Defines the Law's scope: it applies to any Processing of Personal Data in the Kingdom, including Processing of residents' data by parties outside the Kingdom, and to deceased persons' data if it would identify them or a family member. Purely personal or family use is excluded unless published or disclosed; the Regulations define such use.
Art. 3 — Relationship With Other Laws. States that the Law's provisions and procedures do not prejudice any provision that grants a right to the Data Subject or confers better protection of Personal Data under any other law or an international agreement to which the Kingdom is a party.
Art. 5 — Consent and Withdrawal. Prohibits Processing Personal Data or changing the Processing purpose without the Data Subject's consent, except in cases stated in the Law. The Regulations set consent conditions, cases requiring explicit consent, and legal-guardian consent where capacity is lacking. Consent may be withdrawn at any time, subject to controls in the Regulations.
Art. 6 — Exceptions to Consent Requirement. Lists four cases where Processing does not require consent: it serves the Data Subject's actual interests and contacting them is impossible or difficult; it is pursuant to another law or a prior agreement with the Data Subject; a Public Entity requires it for security or judicial purposes; or the Controller's legitimate interest, excluding Sensitive Data.
Art. 7 — Consent Not a Service Condition. Provides that consent to Processing may not be made a condition for providing a service or benefit, unless the service or benefit is directly related to the Personal Data Processing for which the consent is given.
Art. 4 — Data Subject Rights. The data subject's rights: to be informed, to access their data, to obtain a copy in a readable format, to request correction/completion/update, and to request destruction.
Art. 8 — Processor Selection and Oversight. Requires the Controller to select only Processors that provide sufficient guarantees to implement the Law and Regulations, and to monitor their compliance. The Controller remains responsible towards the Data Subject and the Competent Authority. The Regulations govern related matters, including subsequent contracts concluded by the Processor.
Art. 20 — Breach Notification (duty). Imposes the duty to notify the Competent Authority and affected data subjects of a personal-data breach. The Law sets no fixed deadline — the 72-hour timeline is set by IR Art. 24.
Art. 9 — Restrictions on Access Right. Permits the Controller to set time frames for exercising the right of access and to limit that right where necessary to protect the Data Subject or others from harm, or where a Public Entity requires it for security, legal or judicial reasons. Access must be prevented in the situations listed in Article 16.
Art. 22 — Impact Assessment. The Controller shall conduct an impact assessment for any product or service involving personal-data processing, in accordance with the Regulations (detailed in IR Art. 25).
Art. 31 — Records of Processing (Law). Lists the information that a controller's records of processing activities must contain (elaborated by IR Art. 33).
Art. 10 — Collection Sources and Purpose Limits. Requires collecting Personal Data directly from the Data Subject and Processing it only for the Collection purpose, subject to seven exceptions: consent; publicly available data; Public Entity requirements; avoiding harm to the Data Subject or their vital interests; protecting public health, safety or lives; non-identifying storage; and the Controller's legitimate interests excluding Sensitive Data.
Art. 11 — Lawful Collection and Data Minimization. Sets Collection standards: the purpose must relate directly to the Controller's purposes and comply with law; methods must be lawful, appropriate, direct, clear, secure and free of deception, misleading or extortion; content must be limited to the minimum necessary; and Collection must cease and collected data be destroyed when no longer needed.
Art. 12 — Privacy Policy. Requires the Controller to adopt a privacy policy and make it available to Data Subjects before collecting their Personal Data. The policy must state the purpose of Collection, the data collected, the means of Collection, Processing, storage and Destruction, and the Data Subject's rights and how to exercise them.
Art. 13 — Notice Upon Direct Collection. Obliges the Controller, when collecting Personal Data directly, to inform the Data Subject of the legal basis, the purpose, which data is mandatory or optional, the collector's identity, recipient entities, any Transfer or Processing outside the Kingdom, consequences of not collecting, the Data Subject's rights, and other elements the Regulations specify.
Art. 14 — Accuracy of Personal Data. Prohibits the Controller from Processing Personal Data without first taking sufficient steps to verify the data's accuracy, completeness, timeliness and relevance to the purpose for which it was collected, in accordance with the provisions of the Law.
Art. 15 — Permitted Disclosure Cases. Restricts Disclosure of Personal Data to six situations: the Data Subject's consent; data from a publicly available source; a Public Entity's request for public interest, security, legal or judicial purposes; protection of public health, safety or specific lives; non-identifying subsequent Processing; or the Controller's legitimate interests excluding Sensitive Data.
Art. 16 — Prohibited Disclosures. Prohibits Disclosure under several of Article 15's grounds where it would threaten security, harm the Kingdom's reputation, interests or foreign relations, impede crime detection or fair trial, compromise an individual's safety, violate another person's privacy, harm persons lacking legal capacity, breach professional obligations or judicial decisions, or expose confidential sources against the public interest.
Art. 17 — Notification of Data Corrections. Procedural article: when Personal Data is corrected, completed or updated, the Controller must notify all entities to which the data was transferred and make the amendment available to them. The Regulations set time frames, types of correction, and procedures to avoid Processing incorrect, inaccurate or outdated data.
Art. 18 — Data Destruction and Retention. Requires the Controller to Destroy Personal Data without undue delay once no longer necessary, while permitting retention in a form that cannot identify the Data Subject. Retention is mandatory where a legal basis prescribes a specific period or the data relates to a case before a judicial authority, with Destruction afterwards.
Art. 19 — Data Security Measures. Requires the Controller to implement all necessary organizational, administrative and technical measures to protect Personal Data, including during its Transfer, in accordance with the provisions and controls set out in the Regulations.
Art. 21 — Responding to Data Subject Requests. Procedural provision requiring the Controller to respond to Data Subjects' requests concerning their rights under the Law within the period and in the manner set out in the Regulations.
Art. 23 — Health Data Processing Controls. Mandates additional controls in the Regulations for Processing Health Data, protecting Data Subjects' privacy and rights. These include restricting access to Health Data, including medical files, to the minimum number of employees necessary to provide Health Services, and limiting Processing operations to what health services or insurance programs require.
Art. 24 — Credit Data Processing Controls. Requires the Regulations to set additional controls for Processing Credit Data consistent with this Law and the Credit Information Law, including verifying the Data Subject's explicit consent to Collection, purpose changes, Disclosure or Publishing, and notifying the Data Subject whenever a request to disclose their Credit Data is received.
Art. 25 — Advertising and Awareness Communications. Prohibits using a Data Subject's personal means of communication, including post and email, to send advertising or awareness-raising materials, except Public Entities' awareness materials, unless the recipient gave prior consent and the sender provides a clear mechanism to stop receiving them; the Regulations govern such materials and recipient consent.
Art. 26 — Processing for Marketing Purposes. Permits Processing Personal Data, other than Sensitive Data, for marketing purposes only where the data was collected directly from the Data Subject and their consent was given in accordance with the Law. The Regulations set out the applicable controls.
Art. 27 — Scientific, Research and Statistical Purposes. Allows Collection or Processing of Personal Data without consent for scientific, research or statistical purposes where the data does not specifically identify the Data Subject, identity evidence is destroyed before Disclosure and the data is not Sensitive, or another law or a prior agreement so requires. The Regulations set the required controls.
Art. 28 — Copying Official Documents. Prohibits copying official documents that identify Data Subjects, except where copying is required by law or a competent public authority requests such copies in accordance with the Regulations.
Art. 29 — Cross-Border Data Transfers. Permits Transfer or Disclosure of Personal Data outside the Kingdom for agreements the Kingdom is party to, the Kingdom's interests, obligations the Data Subject is party to, or other purposes per the Regulations, subject to national security, an adequate protection level assessed by the Competent Authority, and data minimization, waived in extreme necessity involving life or health.
Art. 30 — Supervisory Role of Competent Authority. Designates the Competent Authority, without prejudice to the Saudi Central Bank's powers, as overseer of the Law's implementation. The Regulations identify when Controllers must appoint personal data protection officers. Controllers must cooperate with the Authority, which may request documents, seek other parties' assistance, maintain a national register of Controllers, charge service fees, and delegate supervisory duties.
Art. 32 — Repealed Provision. The text of this article states only that it has been repealed. It contains no operative provisions in the amended version of the Law, reflecting the removal of its former content while the article numbering of the Law is preserved.
Art. 33 — Licensing, Accreditation and Audits. Empowers the Competent Authority to set requirements for commercial, professional or non-profit personal data protection activities, license entities issuing accreditation certificates to Controllers and Processors, license entities auditing Processing activities, and establish tools and procedures for monitoring and enforcing compliance of Controllers and Processors outside the Kingdom processing residents' data.
Art. 34 — Complaints to Competent Authority. Procedural article entitling Data Subjects to submit to the Competent Authority any complaint arising from the implementation of the Law and the Regulations, and directing the Regulations to set out the rules for processing such complaints.
Art. 35 — Criminal Penalties for Sensitive Data. Penal provision: disclosing or publishing Sensitive Data in violation of the Law, with intent to harm the Data Subject or gain personal benefit, is punishable by imprisonment up to two years and/or a fine up to three million riyals. The Public Prosecution prosecutes; the competent court adjudicates and may double fines for recidivism.
Art. 36 — Administrative Penalties. For violations not covered by Article 35, provides a warning or fine up to five million riyals, doublable for repeat violations. A committee of at least three members formed by the Competent Authority's president examines violations and imposes penalties, subject to the president's approval; decisions are appealable before the competent court.
Art. 37 — Inspection and Seizure Powers. Grants employees appointed by the Competent Authority's president powers to control and inspect violations of the Law and Regulations, under rules the president issues. Such employees may seek assistance from criminal investigation and other competent authorities, and the Competent Authority may seize the means or tools used in committing a violation.
Art. 38 — Confiscation and Judgment Publication. Empowers the competent court to order confiscation of funds obtained from violations, without prejudice to bona fide third parties. The court or the violations committee may also order publication of a summary of the penalty decision at the violator's expense once final, according to the violation's type, seriousness and impact.
Art. 39 — Disciplining Public Entity Employees. Requires Public Entities, without prejudice to the penalties in Article 35 and Paragraph 1 of Article 36, to discipline any of their employees who violate the Law or the Regulations, in accordance with the disciplinary provisions and procedures prescribed by law.
Art. 40 — Compensation for Damage. Entitles any individual who suffers damage as a result of a violation of the Law or the Regulations to apply to the competent court for compensation proportionate to the material or moral damage sustained, without prejudice to the penalties prescribed by the Law.
Art. 41 — Ongoing Confidentiality Obligation. Imposes a duty of confidentiality on any person who engages in the Processing of Personal Data, requiring them to protect the confidentiality of that data even after the end of their occupational or contractual relationship.
Art. 42 — Issuance of Implementing Regulations. Directs the president of the Competent Authority to issue the Regulations within seven hundred twenty days of the Law's publication, after coordination with seven named bodies, including the communications and foreign affairs ministries, the cybersecurity and digital government authorities, the Saudi Health Council and the Saudi Central Bank, each within its jurisdiction.
Art. 43 — Entry Into Force. Final provision stating that the Law shall come into force after seven hundred and twenty days commencing on the date of its publication in the Official Gazette.
2026-07-07 — SDAIA consults on standards guides for the PDPL certification and audit market: SDAIA opened a consultation (closing 6 August 2026, as reported) on three draft standards guides implementing the March-gazetted licensing rules: standards for issuing accreditation certificates to controllers and proces
2026-06-29 — SDAIA committees issue further PDPL fines and warnings: SDAIA's violation-review committees announced a further package of decisions — fines and warnings against several entities — for direct marketing without explicit consent and failing to maintain measures enabling timely
2026-03-06 — PDPL audit and certification licensing rules gazetted: Two SDAIA instruments (Decisions 5135/2 and 5316, dated 16 December 2025; gazetted in Umm Al-Qura on 6 March 2026) create the PDPL compliance-services market: licences for accreditation-certificate issuers (SAR 10m capit
2026-01-15 — SDAIA reports 48 PDPL enforcement decisions: SDAIA's specialised committees confirmed 48 personal-data-protection violations in the first substantive enforcement wave — mostly processing without a legal basis, unauthorised disclosure, and marketing without consent.