Wadira: Find your way through Saudi data & privacy law.
Guide to Saudi data & cybersecurity law
SAMA vs CMA: | | SAMA | CMA | |---|---|---| | Entities | Licensed banks, insurance, finance & payments | Capital Market Institutions (~188) | |
The PDPL Instrument Family: The complete PDPL set spans the Law, two Regulations, several Rules & instruments, and a family of Guidelines. See the interactive
Privacy, Recording & Surveillance: A four-layer stack governs privacy, recording and surveillance: 1. Basic Law of Governance: Arts 37 (sanctity of the home) & 40 (p
CMA Scope: The CMA binds Capital Market Institutions (~188), not Tadawul-listed issuers. Its cybersecurity guidelines are non-binding but exa
Regulatory Currency & Consultation: The third consultation on amendments to the Implementing Regulation closed on 27 May 2025 and is not enacted as of August 2026; th
NDI: Two Levels: The National Data Index operates at two levels: - Level 1: NDMO Standards: the requirements (mandatory for government). - Level 2:
Applicability Matrix: Which entity types fall under which frameworks? See the interactive grid at /matrix: rows are entity types, columns are frameworks
About & Methodology: This atlas is a living, database-driven reference to Saudi Arabia's data-protection, cybersecurity and governance regime. Methodol
Data Localisation: Localisation depends on data type: - Government data: mandatory (CST / NDMO) - Banking data: conditional (SAMA) - CMI data: mandat
How the Framework Fits Together: Saudi Arabia's data, cybersecurity and governance regime is tiered. The tier numbers below are the same ranks used across Wadira's