BlackTree Security · Infrastructure · Automation · AI

Saudi Arabia’s Personal Data Protection Law After the Grace Period

Saudi Arabia’s Personal Data Protection Law took effect in September 2023. Its general one-year grace period ended on 14 September 2024, moving compliance from preparation to operation.

Saudi Arabia’s PDPL establishes rules for processing personal data and is supported by implementing regulations and rules for transfers outside the Kingdom. The Saudi Data and AI Authority acts as the competent authority during the current regulatory arrangement.

The framework has familiar privacy themes—purpose, transparency, rights, security and accountability—but it operates inside Saudi law and alongside National Cybersecurity Authority controls and sector requirements.

Start with purpose and data flow

Controllers need to understand why personal data is processed, the legal basis, the information provided to the individual and the period for which the data remains necessary.

That sounds like policy work, but the evidence lives in systems. A service may collect an identifier for account creation, reuse it for analytics, copy it into support tooling and retain it in backups. Each step needs to be understood rather than hidden behind one general purpose.

Records of processing activities should remain accurate and current. Under the implementing framework, records must be retained for the processing period and for the specified period afterwards.

Processors need written control

Controllers must select processors that provide sufficient guarantees. Agreements should identify the purpose, data categories, duration, breach notification, relevant foreign-law exposure and subprocessors.

A contract saying the supplier will use “industry-standard security” is unlikely to answer who may access data, where it goes, when an incident is reported or how deletion is verified.

Controllers should also ensure that instructions can be implemented technically. A processor cannot honour a deletion or restriction instruction if customer data is mixed across unindexed systems.

Breach reporting has a 72-hour element

The implementing regulations require a controller to notify the competent authority within no more than 72 hours after awareness where the incident may harm personal data or the data subject, or conflict with rights or interests.

Affected individuals must be notified without undue delay where the breach may cause relevant damage or prejudice. Notifications should clearly describe the incident, likely risks, mitigating measures and contact route.

Saudi reporting may exist alongside National Cybersecurity Authority or sector-specific obligations. Incident playbooks should therefore identify overlapping clocks and avoid assuming that one submission satisfies every regulator.

Transfers are governed, not automatically prohibited

International transfers require a valid route under the PDPL and transfer regulation. Depending on the destination and circumstances, organisations may need adequacy, appropriate safeguards such as approved contractual or binding rules, or a permitted derogation.

A transfer assessment should consider the destination, purpose, sensitivity, safeguards, national interests and practical ability to protect rights. Onward transfers and remote access must be included.

The operational checklist

Controllers and processors should maintain:

  1. A Saudi data inventory and processing-purpose register.
  2. Clear privacy notices and rights-request procedures.
  3. Processor due diligence and contract controls.
  4. Security measures aligned with applicable Saudi cybersecurity requirements.
  5. Impact assessments for higher-risk processing and products.
  6. A 72-hour authority-notification workflow.
  7. Individual-notification criteria and message templates.
  8. Transfer mechanisms, risk assessments and onward-transfer controls.
  9. Current processing records and evidence of deletion.

Local law needs local ownership

An existing GDPR programme is a useful starting point because inventories, rights handling and security controls can be reused. It is not the finish line.

Saudi requirements should have an accountable owner who follows local regulations, regulator guidance and sector controls. Without that ownership, a global privacy programme can look complete while missing the deadlines and documentation that matter in the Kingdom.

Official sources

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *