PDPL Scope and Regulatory Landscape

The Saudi Personal Data Protection Law (PDPL) and its implementing regulations establish binding obligations for any organisation that collects, processes, stores, or shares personal data of Saudi nationals or residents, regardless of where the organisation is physically located. This extraterritorial reach means GCC-based enterprises—including banks, telecoms, healthcare providers, and digital platforms—must comply with PDPL standards even if data processing occurs outside Saudi Arabia.

The PDPL applies alongside sector-specific frameworks. Financial institutions must align PDPL controls with the Saudi Central Bank's (SAMA) Cybersecurity Framework (CSF), which mandates governance, risk management, and incident reporting. Telecoms and digital service providers answer to the National Cybersecurity Authority (NCA) and its Essential Cybersecurity Controls (ECC) standard. This layered approach means compliance requires integration across multiple regulatory domains.

Core PDPL Obligations for Data Controllers

Organisations acting as data controllers (those determining the purpose and means of processing) must establish documented data protection policies and appoint a Data Protection Officer (DPO) or equivalent governance function. Key obligations include:

  • Lawful basis and consent: Processing must have a legal foundation. For most commercial use, explicit, informed consent is required. Consent must be freely given, specific, and documented.
  • Data minimisation: Collect and retain only data necessary for stated purposes. Retention periods must be defined and enforced.
  • Security and encryption: Implement technical and organisational measures proportionate to the sensitivity of data. Encryption of personal data in transit and at rest is expected for high-risk processing.
  • Breach notification: Report unauthorised access, loss, or disclosure to the PDPL supervisory authority within 30 days, and to affected individuals without undue delay if there is high risk of harm.
  • Data subject rights: Individuals have rights to access, correct, delete, and port their data. Organisations must respond to requests within 30 days.
  • Third-party processor agreements: If data is processed on behalf of the controller by a vendor or partner, a Data Processing Agreement (DPA) must be in place, defining liability and security obligations.

Alignment with SAMA CSF and NCA ECC

Financial institutions must map PDPL controls to SAMA CSF governance and risk domains. This includes defining roles and responsibilities, maintaining an asset inventory, and conducting regular risk assessments. The SAMA CSF emphasises board-level accountability for cybersecurity, which extends to data protection oversight.

NCA ECC requires organisations in critical sectors to implement essential controls covering access management, encryption, logging, and incident response. These controls directly support PDPL compliance: strong access controls prevent unauthorised data access; encryption meets data security requirements; and comprehensive logging enables breach investigation and notification.

Enforcement and Penalties

The PDPL supervisory authority has authority to investigate complaints, conduct audits, and impose administrative penalties. Violations can result in fines up to 5 million Saudi Riyals and public enforcement notices. Reputational damage from a publicised breach or enforcement action can harm customer trust and market position, particularly in regulated sectors.

Practical Roadmap for 2026

Governance: Establish a data protection committee with representation from legal, security, and business units. Document data flows and processing purposes. Appoint a DPO or designate a senior officer with clear accountability.

Technical controls: Conduct a data protection impact assessment (DPIA) for high-risk processing. Implement encryption for personal data at rest and in transit. Enable audit logging and monitor for unauthorised access.

Vendor management: Review all Data Processing Agreements with third parties. Ensure vendors meet PDPL and SAMA/NCA security standards. Include audit rights and breach notification clauses.

Incident response: Develop a breach response plan that includes notification timelines, evidence preservation, and communication with the supervisory authority. Test the plan annually.

Training and awareness: Ensure staff handling personal data understand PDPL obligations, consent requirements, and data subject rights. Conduct annual refresher training.

Compliance with the PDPL is not a one-time project but an ongoing governance discipline. Organisations that integrate data protection into their security architecture, align with SAMA CSF and NCA ECC, and maintain transparent communication with regulators are best positioned to manage risk and maintain stakeholder confidence.