Saudi Arabia's data, cybersecurity and governance regime is tiered. The tier numbers below are the same ranks used across Wadira's framework pages; the full model, with UK and US mappings, is in How the tiers work.
Tier 0 · Constitutional / Sharia sits at the base: the Basic Law of Governance (Arts 37 & 40) and Sharia principles.
Tier 1 · Primary law: the PDPL is the horizontal baseline for personal data, alongside parallel primary laws such as the Anti-Cyber Crime Law.
Tier 2 · Cabinet instruments: Council of Ministers resolutions, which constitute the regulators themselves (SDAIA's Organizational Arrangements are a Council resolution).
Tier 3 · Regulations implement the law (the Implementing Regulation; the Data Transfer Regulation).
Sector regulators (NCA, SAMA, CMA, CST, MOH) layer their own requirements on top, inheriting the PDPL as a baseline. NDMO Standards feed the NDI. AI is a separate SDAIA family (ethics, generative-AI and adoption guidance).