Wadira: Find your way through Saudi data & privacy law.
Home › Guide › How the tiers work: ranking legal instruments
Every framework in Wadira arranges its instruments on the same six-rung ladder. The ladder is a hierarchy of norms: each tier records *who issued an instrument and by what authority*, not how important it is in daily compliance work. A tier-4 control set can be the document your auditors care about most; it still sits below the law that empowered the regulator to write it.
The six tiers, in Saudi terms
| Tier | Rank | Saudi form | Example |
|---|---|---|---|
| 0 | Foundational | Sharia & the Basic Law of Governance | Basic Law (Royal Order A/90) |
| 1 | Primary law | Niẓām, enacted by Royal Decree (M/…) | PDPL (M/19, amended M/148) |
| 2 | Cabinet instruments | Council of Ministers Resolution | SDAIA's Organizational Arrangements (Resolution 292) |
| 3 | Implementing regulation | Issued by a regulator under delegated power | PDPL Implementing Regulation |
| 4 | Rules, controls & standards | Binding technical instruments | NCA's Essential Cybersecurity Controls (ECC) |
| 5 | Guidelines & circulars | Non-binding interpretive guidance | SDAIA's breach-notification guideline |
Two points answer the questions readers most often ask. First, why do Cabinet resolutions outrank a regulator's own regulations? Because the Council of Ministers is the executive's supreme organ: it *creates* the regulators. SDAIA's constitutive charter is a Council resolution; no instrument SDAIA itself issues can outrank the act that established it, and only a Royal Decree stands higher. Second, rank is not bindingness. A tier-4 control set is hard-binding on the entities in its scope, while a tier-2 charter imposes no compliance duty on anyone outside government. The *Binding / Guidance* status on each instrument answers "must I comply?"; the tier answers "where does this sit in the legal order?".
Where is case law? Deliberately absent. Saudi Arabia does not operate a system of binding precedent: judgments bind the parties to a dispute, not future courts, and court decisions are not a source of law. PDPL penalties are imposed by SDAIA's violation-review committees (established under Article 36 of the law), with appeal to the competent court; those decisions *apply* the norms on this ladder; they do not create new ones. Placing them on a tier would misstate Saudi legal theory. Enforcement practice is tracked in Updates instead.
The same ladder in the United Kingdom
The model transfers to Westminster systems almost rung for rung, with two differences worth noticing.
| Tier | UK form | Example |
|---|---|---|
| 0 | The uncodified constitution: constitutional statutes and conventions | Human Rights Act 1998 |
| 1 | Acts of Parliament (primary legislation) | Data Protection Act 2018; the UK GDPR (assimilated law) |
| 2 | Orders in Council | Rarely used in this domain; the rung is mostly empty |
| 3 | Statutory instruments (secondary legislation) | DPPEC Regulations 2019, which shaped the UK GDPR |
| 4 | Regulator rules and statutory codes | FCA Handbook rules; the ICO's statutory codes of practice (e.g. the Age Appropriate Design Code), which tribunals must take into account |
| 5 | Regulator guidance | ICO guidance; NCSC advice |
The differences: the UK's tier 2 is nearly empty: ministers make secondary legislation directly under powers delegated by an Act, so there is no standing cabinet-instrument layer; and, above all, judicial precedent is itself a source of law. A Court of Appeal ruling on the UK GDPR binds lower courts. In a common-law jurisdiction, case law is a parallel column standing next to the ladder, not a missing rung within it.
The same ladder in the United States
| Tier | US form | Example |
|---|---|---|
| 0 | The Constitution (and state constitutions) | Fourth Amendment |
| 1 | Statutes (federal and state) | HIPAA, GLBA, COPPA; California's CCPA/CPRA |
| 2 | Executive instruments | Executive Order 14028 on cybersecurity; OMB memoranda |
| 3 | Agency regulations (notice-and-comment rulemaking, codified in the CFR) | HIPAA Privacy & Security Rules; FTC Safeguards Rule |
| 4 | Binding technical standards | NIST FIPS, mandatory for federal agencies under FISMA |
| 5 | Voluntary frameworks & guidance | NIST Cybersecurity & Privacy Frameworks; FTC business guidance |
Three US particulars: there is no omnibus federal privacy statute, so tier 1 is a patchwork of sectoral and state laws; executive instruments (tier 2) bind only the executive branch, unlike Saudi Cabinet resolutions; and enforcement does much of the law-making: FTC consent decrees and state-attorney-general settlements function as a de-facto common law of privacy. Like UK precedent, that body of decisions belongs beside the ladder, not on it. A US mapping also needs a second dimension the ladder itself does not carry: jurisdiction, because federal and state stacks run in parallel.
Reading Wadira with the ladder in mind
The tier tells you where an instrument sits in the legal order and who had the power to make it. The legal status tells you whether it binds. The applicability matrix tells you whether it binds *you*. And because the tier labels are configurable rather than hard-coded, the same model extends to any jurisdiction whose norms descend from a constitutional foundation through legislation to regulation and guidance, which is nearly all of them.
Why are Council of Ministers resolutions tier 2 rather than tier 1? Because in the Saudi hierarchy of norms they sit below Royal Decrees, the Kingdom's legislative acts, but above anything an individual regulator can issue. The Council empowers the regulators; a Royal Decree empowers the Council.
Does a higher tier mean an instrument matters more? No. Tier records rank in the legal order, not operational weight. The ECC (tier 4) drives more day-to-day compliance work than any tier-2 instrument; check each instrument's Binding / Guidance status for whether it imposes duties.
Why doesn't Wadira put court decisions in a tier? Saudi Arabia has no binding precedent: judgments bind the parties, not future courts, so decisions apply the law rather than create it. In common-law systems such as the UK and US, precedent is a genuine source of law, but even there it forms a parallel body of decisions alongside the legislative ladder, which is exactly how practitioner tools model it.
Content and register data licensed CC BY 4.0. Cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-08-12