Wadira — Find your way through Saudi data & privacy law.
Guide to Saudi data & cybersecurity law
The PDPL Instrument Family — The complete PDPL set spans the Law, two Regulations, several Rules & instruments, and a family of Guidelines — see the interactiv
NDI — Two Levels — The National Data Index operates at two levels: - Level 1 — NDMO Standards: the requirements (mandatory for government). - Level 2
SAMA vs CMA — | | SAMA | CMA | |---|---|---| | Entities | Licensed banks, insurance, finance & payments | Capital Market Institutions (~188) | |
Privacy, Recording & Surveillance — A four-layer stack governs privacy, recording and surveillance: 1. Basic Law of Governance — Arts 37 (sanctity of the home) & 40 (
Applicability Matrix — Which entity types fall under which frameworks? See the interactive grid at /matrix — rows are entity types, columns are framework
About & Methodology — This atlas is a living, database-driven reference to Saudi Arabia's data-protection, cybersecurity and governance regime. Methodol
How the Framework Fits Together — Saudi Arabia's data, cybersecurity and governance regime is tiered. - Constitutional / Sharia sits at the base — the Basic Law of
Regulatory Currency & Consultation — The third consultation on amendments to the Implementing Regulation closed on 27 May 2025 and is not enacted as of June 2026 — the
CMA Scope — The CMA binds Capital Market Institutions (~188) — not Tadawul-listed issuers. Its cybersecurity guidelines are non-binding but ex
Data Localisation — Localisation depends on data type: - Government data — mandatory (CST / NDMO) - Banking data — conditional (SAMA) - CMI data — man