Wadira — Find your way through Saudi data & privacy law.
Home › Guide › PDPL vs GDPR — how Saudi Arabia's data law differs
Saudi Arabia's Personal Data Protection Law (Royal Decree M/19 of 2021, amended by M/148 of 2023; in force 14 September 2023, fully enforced since 14 September 2024) mirrors the GDPR's architecture but diverges on fundamentals: consent is the default legal basis, "legitimate interest" arrived only in 2023 and excludes sensitive data, there is no right to object, qualifying controllers must register with SDAIA, breach notification is a hard 72-hour rule, and sensitive-data disclosure carries criminal liability. This guide compares the two regimes article by article, against the official texts.
| Topic | Saudi PDPL | EU GDPR |
|---|---|---|
| Scope & extraterritoriality | Any processing in the Kingdom, plus processing of KSA residents' data by parties abroad; includes deceased persons' data (PDPL Art. 2). | EU establishments, plus offering goods/services to or monitoring people in the EU (Art. 3); deceased excluded (Recital 27). |
| Legal bases | Consent default (Art. 5); exceptions: actual interest, law/prior agreement, public-entity security/judicial needs, legitimate interest for non-sensitive data (Art. 6; IR Art. 16). | Six co-equal bases: consent, contract, legal obligation, vital interests, public task, legitimate interests (Art. 6(1)). |
| Data-subject rights | Information, access, copy, correction, destruction (Art. 4); withdrawal (Art. 5(2)); 30 + 30 days (IR Art. 3). No objection right. | Access, rectification, erasure, restriction, portability, objection, automated-decision rights (Arts. 15–22); one month + two (Art. 12(3)). |
| Cross-border transfers | Purpose test plus adequacy or safeguards — Saudi SCCs, Binding Common Rules, certification — with risk assessments (Art. 29; Transfer Reg. Arts. 3–7). No adequacy list published yet. | Adequacy decisions (Art. 45), appropriate safeguards incl. SCCs and BCRs (Arts. 46–47), derogations (Art. 49). |
| Breach notification | 72 hours to SDAIA where potential harm; data subjects "without undue delay" if damage possible; no carve-outs (PDPL Art. 20; IR Art. 24). | 72 hours to authority unless unlikely to result in risk (Art. 33); data subjects only on high risk, with exceptions (Art. 34). |
| DPO | Public entities with large-scale processing, regular/systematic monitoring, or sensitive-data core activities (IR Art. 32). | Public authorities, large-scale regular monitoring, or large-scale special-category/criminal data (Art. 37). |
| Records (RoPA) | Controllers keep records during processing plus 5 years after it ends (PDPL Art. 31; IR Art. 33). No SME carve-out. | Controllers and processors (Art. 30); no retention period; sub-250-employee carve-out (Art. 30(5)). |
| DPIA | Mandatory for sensitive data, dataset linking, constant monitoring, new technologies, automated decisions, vulnerable subjects (PDPL Art. 22; IR Art. 25). | Where likely high risk; profiling, large-scale special categories, public monitoring (Art. 35); prior consultation (Art. 36). |
| Registration | National Register of Controllers (PDPL Art. 30(4); IR Art. 34; 2024 Rules) — mandatory for qualifying controllers. | No general registration requirement; accountability via records instead. |
| Penalties | Sensitive-data disclosure crime: ≤2 years' prison and/or ≤SAR 3M (Art. 35); other violations ≤SAR 5M, doubled on repeat (Art. 36); SDAIA committees. | Administrative fines to €20M or 4% worldwide turnover (Art. 83); no imprisonment; independent DPAs. |
| Sensitive data | Racial/ethnic origin, beliefs, criminal/security data, biometric, genetic, health, unknown parentage (Art. 1(11)); explicit consent required (IR Art. 11(2)). | Art. 9(1) adds sex life/orientation and trade-union membership; conditions list in Art. 9(2). |
| PDPL-unique features | Deceased data, consent-conditionality ban (Art. 7), opt-in marketing (Arts. 25–26), official-document copying ban (Art. 28), 90-day complaint window (IR Art. 37). | Marketing handled via the objection right (Art. 21) and member-state e-privacy rules. |
PDPL Art. 2(1) applies the law to any processing of personal data "that takes place in the Kingdom," and expressly extends it to processing of data of individuals residing in the Kingdom by any party outside it — an extraterritorial hook based purely on residents' data, with no GDPR-style targeting test. It also covers deceased persons' data where the person or a family member is identifiable. GDPR Art. 3 instead uses establishment and, for foreign entities, offering goods/services or monitoring behaviour in the EU, and excludes deceased persons (Recital 27). Both exempt purely personal or family use (PDPL Art. 2(2), defined in IR Art. 2; GDPR Art. 2(2)(c)). Amended PDPL Art. 33(4) directs SDAIA to build mechanisms to monitor and enforce against controllers abroad.
GDPR Art. 6(1) offers six co-equal bases. The PDPL inverts this: Art. 5(1) prohibits processing without consent "except for the cases stated in this Law," making the other grounds exceptions. Art. 6 permits non-consensual processing where: it serves the actual interest of the data subject and contacting them is impossible or difficult (evidence must be retained, IR Art. 14); it is pursuant to another law or a prior agreement to which the data subject is party; a public entity requires it for security or judicial purposes; or — added by M/148 in 2023 — it is necessary for the controller's legitimate interest, provided no sensitive data is processed. IR Art. 16 excludes public entities from relying on legitimate interest, requires a documented assessment (a GDPR-style balancing test), and demands the processing stay within data subjects' reasonable expectations. Unlike GDPR Art. 7(4)'s "utmost account" test, PDPL Art. 7 flatly bars making consent a condition of service unless directly related to the processing.
PDPL Art. 4 grants five rights: to be informed, to access, to obtain a copy "in a readable and clear format" (IR Art. 6 specifies a commonly used electronic format), to correct, and to request destruction — the PDPL's term for erasure, defined as making data unreadable and irretrievable (Art. 1(7)). Consent may be withdrawn at any time (Art. 5(2); IR Art. 12). Missing versus GDPR: no right to object (GDPR Art. 21), no full portability — the copy right lacks GDPR Art. 20's controller-to-controller transmission — and no standalone automated-decision right (GDPR Art. 22), though solely automated decisions require explicit consent (IR Art. 11(2)). A narrow restriction right exists only while contested accuracy is verified (IR Art. 7(1)). Deadlines: 30 days, extendable by 30 (IR Art. 3(1)), versus GDPR's one month plus two (Art. 12(3)).
PDPL Art. 29(1) permits transfers only for defined purposes — Kingdom treaty obligations, the Kingdom's interests, performance of an obligation to which the data subject is party, or purposes in the Regulations, expanded by Transfer Regulation Art. 2 to central processing operations, services or benefits to the data subject, and scientific research. Art. 29(2) adds conditions: no prejudice to national security, an adequate level of protection abroad, and minimum-necessary data. The Transfer Regulation (version 2.0, August 2024) operationalises this: SDAIA is to publish an adequacy list reviewed every four years (Art. 3) — none published as of mid-2026 — and exempted transfers require appropriate safeguards: Saudi Standard Contractual Clauses (published September 2024), Binding Common Rules (a BCR analogue), or certification (Art. 4), plus a documented risk assessment when relying on safeguards or continuously transferring sensitive data (Art. 7). GDPR Chapter V is structurally similar but adequacy-decision-driven, with unrestricted intra-EEA flows. EU SCCs are not a recognised Saudi safeguard.
PDPL Art. 20 sets the duty; IR Art. 24 the mechanics. Controllers must notify SDAIA within 72 hours of becoming aware of an incident that potentially harms the personal data or the data subject or conflicts with their rights or interests — with no minimum-scale threshold and no GDPR-style "unlikely to result in a risk" carve-out (contrast GDPR Art. 33(1)). Phased notification with justification is allowed. Data subjects must be told "without undue delay" where the breach may cause them damage — a lower bar than GDPR Art. 34(1)'s "high risk," and without Art. 34(3)'s encryption/mitigation exceptions. Processor-to-controller notification is contractual under IR Art. 17, versus a statutory duty in GDPR Art. 33(2).
IR Art. 32 requires a data protection officer in three cases that track GDPR Art. 37 closely: public entities providing services involving large-scale processing; core activities based on regular and systematic monitoring; or core activities consisting of sensitive-data processing. Records of processing must be kept throughout processing plus five years after the end of any processing activity (IR Art. 33) — GDPR sets no post-processing retention period and exempts most sub-250-employee organisations; the PDPL has no SME carve-out. Impact assessments are trigger-listed (IR Art. 25: sensitive data, dataset linking, constant monitoring, new technologies, solely automated decisions, vulnerable subjects) rather than GDPR's risk-threshold approach, and there is no prior-consultation mechanism like GDPR Art. 36.
GDPR abolished general notification regimes in favour of internal accountability. Under the PDPL, SDAIA maintains a National Register of Controllers (Art. 30(4); IR Art. 34), and the 2024 Rules make registration on SDAIA's National Data Governance Platform mandatory for qualifying controllers — notably private entities whose main activity is personal-data processing and those processing sensitive data. The original 2021 law's blanket registration duty with an annual fee up to SAR 100,000 (former Art. 32) was repealed by M/148; registration is currently free.
PDPL Art. 35 makes disclosing or publishing sensitive data in violation of the law, with intent to harm or for personal benefit, a crime: up to two years' imprisonment and/or a fine up to SAR 3 million, prosecuted by the Public Prosecution. The original 2021 text also criminalised unlawful cross-border transfers — M/148 removed that offence. Other violations draw a warning or a fine up to SAR 5 million, doubled for repeat violations (Art. 36), imposed by SDAIA-appointed committees with court appeal; courts may order confiscation and publication of judgments (Art. 38), and individuals may claim compensation (Art. 40). Enforcement is live — SDAIA's committees reported 48 violation decisions in their first wave (announced January 2026). GDPR relies on independent authorities with turnover-linked administrative fines up to €20M or 4% (Art. 83) — no imprisonment.
PDPL Art. 1(11), as amended, covers racial or ethnic origin; religious, intellectual or political belief; security and criminal data; biometric and genetic data; health data; and data indicating unknown parentage — the last a PDPL peculiarity. M/148 removed credit data, location data and NGO membership from the original definition (many older summaries still cite the old list). Versus GDPR Art. 9(1): the PDPL omits sex life/sexual orientation and trade-union membership, but folds criminal data (GDPR Art. 10) into the sensitive category. Credit data, though no longer "sensitive," keeps its own regime (PDPL Art. 24; IR Art. 27; explicit consent under IR Art. 11(2)).
Does the PDPL apply to companies with no presence in Saudi Arabia?
Yes. PDPL Art. 2(1) covers any processing of personal data of individuals residing in the Kingdom by parties outside it — with no GDPR-style "offering goods or services" or "monitoring" qualifier. Amended Art. 33(4) tasks SDAIA with mechanisms to monitor and enforce against foreign controllers.
Is there a Saudi equivalent of GDPR's legitimate-interests basis?
Since the 2023 amendments, yes — but narrower. PDPL Art. 6(4) permits processing necessary for the controller's legitimate interest only where no sensitive data is involved. IR Art. 16 adds that public entities cannot use it, processing must sit within reasonable expectations, and a documented balancing assessment is mandatory before processing begins.
Can we transfer personal data out of Saudi Arabia today?
Yes, without per-transfer SDAIA approval, if a permitted purpose applies and the conditions are met. Because no adequacy list had been published as of mid-2026, transfers in practice rely on the Article 4 safeguards — SDAIA's Standard Contractual Clauses, Binding Common Rules, or certification — plus an Article 7 risk assessment for continuous sensitive-data transfers.
If we comply with GDPR, are we PDPL-compliant?
No. GDPR compliance is a strong foundation — principles, DPIAs, DPOs, breach processes and records broadly transfer — but PDPL-specific gaps remain: consent-first legal bases, opt-in marketing, controller registration, Saudi SCCs for transfers, five-year RoPA retention, a stricter breach regime, a 90-day complaint window, and criminal exposure for sensitive-data disclosure.
The May 2025 public consultation on amendments to the Implementing Regulation (closed 27 May 2025) proposed consolidating the registration and DPO rules into the IR, simplifying RoPA format requirements, easing some direct-marketing provisions and dropping the 90-day complaint window. No enactment had been announced as of July 2026 — this guide reflects the texts in force. *Content last verified: 14 July 2026. Factual comparison of legal texts — not legal advice.*
Content and register data licensed CC BY 4.0 — cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-07-27