Saudi Arabia · Privacy Guide

PDPL in practice:
data, systems and evidence

Privacy notice does not replace data inventory, grounds for processing, contracts with vendors, transfer file, security and verified incident plan.

Purposetarget before collection
Minimumrequired volume
Rightsoperating procedure
Transferseparate analysis

01

When does Saudi PDPL apply?

The regime covers the processing of personal data in the KSA, as well as certain processing of data of persons living in the Kingdom from abroad. The Controller defines the goals and methods, the processor acts on its instructions. Industry rules for banks, telecom, healthcare and cybersecurity apply additionally.

02

Start with a data map

Data
Categories, source and sensitivity
Subject
Customer, Employee, UBO, User or Contact
Purpose
Specific business and legal purpose
System
Where is it stored and who has access?
Recipient
Group company, vendor, authority and bank
Lifecycle
Storage period, archive and destruction

Without inventory, it is impossible to prove minimization, give a full notice, or evaluate international transfer.

03

Consent is not a universal button

For each purpose, an acceptable PDPL basis is determined. If consent is used, it must be free, specific, informed and demonstrable, and revocation must be accessible. For sensitive data, children, credit and health information, increased requirements apply.

Share goals

Execution of the contract, statutory KYC, analytics and advertising mailings are not combined into one consent.

04

Rights turn into ticket workflow

Information
Know the basis and purpose of the collection
Access
Access data
Copy
Get a clear copy in an acceptable format
Correction
Correct, supplement or update
Destruction
Demand destruction if there is no reason to store
Complaint
Contact the competent authority

05

Cloud and processor

Vendor due diligence checks data location, security, personnel access, subprocessors, incidents and exit. The agreement specifies instructions, confidentiality, technical controls, assistance with rights, breach escalation, audit evidence and return/deletion.

06

DPO, DPIA and records

A DPO is appointed in cases specified by the Implementing Regulations, including certain large-scale or sensitive processing. Impact assessment is prepared before high-risk processing and significant system changes. The decision as to why a DPO or DPIA is or is not required is documented.

07

Leak: the clock starts from the moment of knowledge

If an incident is capable of causing harm to data or a subject or affecting its rights and interests, the controller notifies the competent authority within a period not exceeding 72 hours from the moment it learned about the incident. The subject's notification is assessed separately against the applicable threshold.

  1. 01
    Contain

    Stop access and save evidence.

  2. 02
    Assess

    Data, faces, consequences and risk threshold.

  3. 03
    Notify

    SDAIA and subjects when required.

  4. 04
    Remediate

    Eliminate the cause and update controls.

08

Transfer of data outside the KSA

PDPL does not establish an absolute ban, but requires checking the purpose, national interests, level of protection, volume of data and the provided transfer mechanism. Depending on the country and situation, adequacy, appropriate safeguards, binding common rules, contractual protection, risk assessment or a narrow exception are used.

Remote access is also checked

Cloud hosting, group support, global HR and foreign contractor access are included in the data-flow map before launch.

09

Direct marketing and cookies

Advertising messages, profiling and tracking are separated from the main service. The company stores proof of consent, explains channels and goals, provides a simple opt-out and maintains a suppression list so that the review actually stops the mailing.

10

Minimum privacy program

  1. 01

    Data inventory, classification and retention schedule.

  2. 02

    Lawful-basis matrix, notices and consent records.

  3. 03

    Rights procedures, DPO/DPIA analysis and training.

  4. 04

    Vendor, cloud and cross-border transfer file.

  5. 05

    72-hour incident playbook and rehearsal.

Official base

SDAIA and PDPL

01

SDAIA — Personal Data Protection Law

Official text of the PDPL with amendments and rights of subjects.

Open source
02

SDAIA — Implementing Regulations and Transfer Regulations

Rules on a lawful basis, DPO, DPIA, incidents, processors and cross-border transfers.

Open source
03

SDAIA — Guide to the Saudi PDPL

Practical official handbook on building privacy compliance.

Open source
04

National Data Governance Platform — breach notification

Official notification procedure for a qualifying personal data breach.

Open source

Privacy setup

Let's collect PDPL compliance into one system

Inventory, notices, vendors, transfers and incident response.

Discuss data
WAWhatsAppTGTelegram