Wadira — Find your way through Saudi data & privacy law.

Regulatory updates — Saudi data & cyber law

2026-07-07 — SDAIA consults on standards guides for the PDPL certification and audit market

SDAIA opened a consultation (closing 6 August 2026, as reported) on three draft standards guides implementing the March-gazetted licensing rules: standards for issuing accreditation certificates to controllers and processors, for licensing personal-data audit and inspection activities, and for licensing certificate-issuance activities. They set the operating bar for the new PDPL certification and audit market, and matter to controllers seeking certificates as transfer safeguards. Personal Data Protection Law (PDPL)

2026-07-05 — NCA consults on AI Cybersecurity Guidelines

The National Cybersecurity Authority opened a consultation (5 July – 5 August 2026) on draft AI Cybersecurity Guidelines — its first AI-specific instrument — setting cybersecurity governance, defence, resilience and third-party requirements for organisations deploying or planning to adopt AI in the Kingdom, explicitly covering generative and agentic AI.

2026-06-29 — SDAIA committees issue further PDPL fines and warnings

SDAIA's violation-review committees announced a further package of decisions — fines and warnings against several entities — for direct marketing without explicit consent and failing to maintain measures enabling timely responses to data-subject requests; press reports also cited 72-hour breach-notification failures and failures to appoint required DPOs. No entity names or amounts were disclosed. Personal Data Protection Law (PDPL)

2026-06-24 — NCA consults on cybersecurity violations and penalties schedule

The National Cybersecurity Authority opened a public consultation (24 June – 24 July 2026) on a draft classification of violations of NCA-mandated cybersecurity requirements and a corresponding penalties schedule, exercising enforcement powers under its amended statute (Royal Decree M/117). It would create the first formal penalty taxonomy behind the ECC, NCNICC and sector controls, affecting all entities subject to them.

2026-06-19 — SDAIA issues Data Revenue Generation Policy

SDAIA published the Data Revenue Generation Policy (dated 27 April 2026, announced 19 June 2026), setting principles for government entities — and private entities holding government-sourced data — to develop revenue-generating data products and services. Products built on personal data must preserve privacy under the PDPL; open data remains free; government-to-government sharing cannot be charged. A national registry for data-product revenue generation now appears on SDAIA's National Data Governance Platform.

2026-06-08 — NCA consults on national incident-reporting framework (NFCISIR-1:2026)

The National Cybersecurity Authority consulted on the draft National Framework for Cybersecurity Information Sharing and Incident Response; the consultation closed 10 July 2026. As drafted, public and private entities would report actual or suspected incidents via the national Haseen portal, follow tiered response timeframes (2/12/48/72 hours) across five severity levels, retain incident records for 15 years, and share threat intelligence under TLP. The final framework is pending.

2026-04-03 — SDAIA consults on draft Responsible AI Policy

SDAIA opened a one-month public consultation (3 April – 3 May 2026) on a draft Responsible AI Policy applying to government, private and non-profit entities and individuals developing, deploying or publishing AI in the Kingdom. It moves beyond the 2023 AI Ethics Principles toward operational governance: risk-based classification, obligations for higher-risk systems, watermarking and content tracking of AI outputs, bias mitigation and performance monitoring. The final policy had not been issued as of mid-July 2026.

2026-03-06 — PDPL audit and certification licensing rules gazetted

Two SDAIA instruments (Decisions 5135/2 and 5316, dated 16 December 2025; gazetted in Umm Al-Qura on 6 March 2026) create the PDPL compliance-services market: licences for accreditation-certificate issuers (SAR 10m capital, at least 10 qualified assessors, 3-year term) and for personal-data audit and inspection providers, plus rules for issuing controllers and processors 2-year accreditation certificates. Certificates also serve as a cross-border transfer safeguard under the Transfer Regulation. Personal Data Protection Law (PDPL)

2026-01-15 — SDAIA reports 48 PDPL enforcement decisions

SDAIA's specialised committees confirmed 48 personal-data-protection violations in the first substantive enforcement wave — mostly processing without a legal basis, unauthorised disclosure, and marketing without consent. Decisions were reported in aggregate; no entities were named. Personal Data Protection Law (PDPL)

2025-12-30 — National Data Index — third measurement cycle launched

SDAIA launched the third NDI cycle, expanding measurement to 214 government entities (about +110%). The index scores data-management maturity, compliance and operational excellence via the National Data Governance Platform. National Data Index (NDI)

2025-12-28 — NCA issues cybersecurity controls for non-CNI private sector (NCNICC-1:2025)

The National Cybersecurity Authority extended mandatory ECC-derived cybersecurity controls to all private-sector entities that are not critical-infrastructure operators — its largest scope expansion since the ECC. Category A entities (over 250 staff or SAR 200m revenue) face 65 controls across three domains; Category B (SMEs) face 26 controls. Compliance is continuous under Article 10(3) of the NCA statute, with no stated grace period. Non-Critical National Infrastructure Cybersecurity Controls (NCNICC-1:2025)

2025-12-02 — SDAIA issues General Rules for Secondary Use of Data

Approved by SDAIA Board Decision 22-1 (11/6/1447H) and publicised in January 2026, the General Rules govern reusing data — including personal data — beyond its original collection purpose, for research, development and public-interest uses. They cover government-to-government, government-to-private and private-to-government requests under six principles; any reuse of personal data must comply with the PDPL.

2025-05-27 — Third public consultation on Implementing Regulation amendments

SDAIA's third public consultation (27 Apr – 27 May 2025) proposed to simplify the Implementing Regulation: folding the DPO-appointment and controller-registration rules into it, simplifying the RoPA requirement, and adding a plain-language privacy-notice clause. Not yet enacted as of mid-2026. Implementing (Executive) Regulation

2025-04-23 — Consultation on rules for data-protection service providers

A parallel SDAIA consultation (closed May 2025) proposed to license firms providing PDPL consultancy, compliance technology and training — a separate instrument from the Implementing Regulation amendments.

2025-02-25 — Guideline on cross-border transfer risk assessment

SDAIA published a non-binding, four-phase methodology for assessing the risks of transferring personal data outside the Kingdom, with a companion risk-assessment tool on the National Data Governance Platform. Regulation on Personal Data Transfer Outside KSA


Content and register data licensed CC BY 4.0 — cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-07-27