Enforcement Timeline
SDAIA has commenced active enforcement of the Personal Data Protection Law (PDPL). Organizations that have not yet implemented PDPL compliance programs should treat this as an immediate priority.
Core Obligations
- Appoint a Data Protection Officer (DPO) for high-risk processing
- Implement privacy notices and consent mechanisms
- Establish data subject rights processes (access, correction, deletion)
- 72-hour breach notification to SDAIA
- Data Processing Impact Assessments for high-risk activities
Penalty Structure
Fines range from SAR 1 million for minor violations to SAR 5 million for intentional violations.
💬 Comments (0)
🔒 Please log in to comment
Be the first to comment