01
When does Saudi PDPL apply?
The regime covers the processing of personal data in the KSA, as well as certain processing of data of persons living in the Kingdom from abroad. The Controller defines the goals and methods, the processor acts on its instructions. Industry rules for banks, telecom, healthcare and cybersecurity apply additionally.
02
Start with a data map
- Data
- Categories, source and sensitivity
- Subject
- Customer, Employee, UBO, User or Contact
- Purpose
- Specific business and legal purpose
- System
- Where is it stored and who has access?
- Recipient
- Group company, vendor, authority and bank
- Lifecycle
- Storage period, archive and destruction
Without inventory, it is impossible to prove minimization, give a full notice, or evaluate international transfer.
03
Consent is not a universal button
For each purpose, an acceptable PDPL basis is determined. If consent is used, it must be free, specific, informed and demonstrable, and revocation must be accessible. For sensitive data, children, credit and health information, increased requirements apply.
Execution of the contract, statutory KYC, analytics and advertising mailings are not combined into one consent.
04
Rights turn into ticket workflow
- Information
- Know the basis and purpose of the collection
- Access
- Access data
- Copy
- Get a clear copy in an acceptable format
- Correction
- Correct, supplement or update
- Destruction
- Demand destruction if there is no reason to store
- Complaint
- Contact the competent authority
05
Cloud and processor
Vendor due diligence checks data location, security, personnel access, subprocessors, incidents and exit. The agreement specifies instructions, confidentiality, technical controls, assistance with rights, breach escalation, audit evidence and return/deletion.
06
DPO, DPIA and records
A DPO is appointed in cases specified by the Implementing Regulations, including certain large-scale or sensitive processing. Impact assessment is prepared before high-risk processing and significant system changes. The decision as to why a DPO or DPIA is or is not required is documented.
07
Leak: the clock starts from the moment of knowledge
If an incident is capable of causing harm to data or a subject or affecting its rights and interests, the controller notifies the competent authority within a period not exceeding 72 hours from the moment it learned about the incident. The subject's notification is assessed separately against the applicable threshold.
- 01Contain
Stop access and save evidence.
- 02Assess
Data, faces, consequences and risk threshold.
- 03Notify
SDAIA and subjects when required.
- 04Remediate
Eliminate the cause and update controls.
08
Transfer of data outside the KSA
PDPL does not establish an absolute ban, but requires checking the purpose, national interests, level of protection, volume of data and the provided transfer mechanism. Depending on the country and situation, adequacy, appropriate safeguards, binding common rules, contractual protection, risk assessment or a narrow exception are used.
Cloud hosting, group support, global HR and foreign contractor access are included in the data-flow map before launch.
09
Direct marketing and cookies
Advertising messages, profiling and tracking are separated from the main service. The company stores proof of consent, explains channels and goals, provides a simple opt-out and maintains a suppression list so that the review actually stops the mailing.
10
Minimum privacy program
- 01
Data inventory, classification and retention schedule.
- 02
Lawful-basis matrix, notices and consent records.
- 03
Rights procedures, DPO/DPIA analysis and training.
- 04
Vendor, cloud and cross-border transfer file.
- 05
72-hour incident playbook and rehearsal.
+7 (495) 221 31 46