Data Protection Matters
← All privacy laws

Saudi Arabia

PDPL

Personal Data Protection Law (Royal Decree No. M/19 of 9/2/1443H, as amended by Royal Decree No. M/148 of 5/9/1444H)

Keywords

Saudi Arabia PDPLPersonal Data Protection LawSDAIARoyal Decree M/19M/148controllerdata subjectconsentlegitimate interestcross-border transferdata breachDPOnational register of controllersfines
Plain-English overview, not the law. This is a general summary we wrote to help you get oriented. It is not legal advice, it is not binding, and it may simplify, omit, or get things wrong. We also cannot guarantee that the source we link to is the correct, current, or official text; we may have linked or labelled it wrong. For anything that matters, find and read the law itself and seek advice for your situation.

What it is

The Personal Data Protection Law (PDPL) is Saudi Arabia's comprehensive data protection statute. It was issued by Royal Decree M/19 in 2021 and amended by Royal Decree M/148 in 2023. It entered into force in September 2023, with a one-year grace period before full enforcement began. It is supported by Implementing Regulations and by separate regulations on transfers of personal data outside the Kingdom.

Who it applies to

The PDPL applies to any processing of personal data related to individuals that takes place in the Kingdom, by any means, including processing of data about residents by entities located outside the Kingdom. It covers "controllers", the parties that decide the purpose and means of processing, and "processors" acting on their behalf. Processing for purely personal or family use is excluded.

Core principles

Controllers must process data lawfully and for a clearly defined purpose, collect only what is necessary, keep data accurate, and retain it no longer than needed. They must give data subjects clear information about processing at the time of collection, and apply security measures proportionate to the risk. Processing must also follow the law's rules on purpose limitation and on the handling of sensitive data.

Consent is the main basis for processing. The 2023 amendment changed the consent standard from "written" to "explicit" and added a legitimate-interests basis, subject to conditions set in the Implementing Regulations. Other grounds include a legal requirement, performance of a contract, and the protection of the public interest, in each case under the conditions the law lays down.

Individual rights

Data subjects have the right to be informed about the collection and use of their data, to access their data, to request a copy in a readable format, to ask for correction of inaccurate data, and to request its destruction when it is no longer needed. Individuals can withdraw consent, and the law sets out the procedure and time limits that controllers must follow when handling these requests.

Key obligations

Controllers must adopt privacy policies, apply security and organizational safeguards, keep records of processing, and use processors only under suitable contractual terms. Rules set under the law also require certain controllers to appoint a data protection officer and to register with the national register of controllers run by the regulator. Risk assessments are expected where processing may harm data subjects.

Data breaches

A controller that becomes aware of a leak, damage, or unauthorized access to personal data must notify the competent authority within the period set in the Implementing Regulations, and must notify the data subjects as well if the incident is likely to cause them serious harm. The Implementing Regulations contain the detailed timing and content requirements.

Cross-border transfers

Personal data may be transferred or disclosed outside the Kingdom only where the conditions in the law and the transfer regulations are met. These include appropriate safeguards, such as standard contractual clauses or binding common rules, and an adequate level of protection in the destination, or another route approved by the regulator.

Enforcement and penalties

The Saudi Data and Artificial Intelligence Authority (SDAIA) is the competent authority and regulator, with the Saudi Central Bank retaining powers over financial-sector data. Penalties include fines, which can reach several million riyals for serious violations, and imprisonment for specific offences, such as disclosing sensitive data with intent to harm or for personal benefit. Affected individuals may also claim compensation for damage.

The official text

The authoritative version is the Arabic text of the Personal Data Protection Law as issued by Royal Decree M/19 and amended by Royal Decree M/148, published by the Bureau of Experts at the Council of Ministers. SDAIA publishes an English translation, but the Arabic text prevails. Use that text, not this summary, for anything that matters.

Below is the source we understand to be the official text (Arabic, official; English translation available from SDAIA). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:

Go to the source →