The Personal Data Protection Law (PDPL) is Saudi Arabia's comprehensive privacy law, regulated by SDAIA, governing how organisations collect and process the personal data of individuals in the Kingdom. If you already run a GDPR programme much of the substance will feel familiar - but the differences, particularly around transfers and registration, are where organisations get caught out.
Who it applies to
- Any entity processing personal data of individuals residing in Saudi Arabia.
- Entities outside the Kingdom that process the personal data of residents - the law has extraterritorial reach.
- Both public and private sector, with certain exemptions.
As with the GDPR, the roles matter: a controller decides why and how data is processed; a processor acts on the controller's instructions.
Core obligations
- Lawful basis. Consent is central, with defined exceptions such as legitimate interests, contractual necessity, legal obligation and vital interests. Consent must be informed and freely given, and individuals can withdraw it.
- Purpose limitation and minimisation. Collect only what the stated purpose requires, and do not repurpose data without a fresh basis.
- Privacy notice. Tell individuals who you are, why you are processing, what you collect and who you share it with.
- Records of processing. Maintain a record of processing activities and be able to produce it.
- Security measures. Appropriate technical and organisational safeguards proportionate to the risk.
- Impact assessments for higher-risk processing.
- Processor contracts binding vendors to equivalent protections.
- Retention and destruction. Delete data when the purpose ends.
Rights of individuals
- To be informed about how their data is used
- To access their personal data
- To request correction of inaccurate or incomplete data
- To request destruction of data that is no longer needed
- To obtain a copy of their data in a readable format
Have a documented request-handling process with an owner and a clock. Ad-hoc handling is how deadlines get missed.
Build your privacy programme once
GRC Copilot maps your privacy controls across the PDPL, GDPR and ISO 27701, keeps the evidence behind each obligation, and shows the gaps before a regulator or customer does.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Where the PDPL differs from the GDPR
- Transfers outside the Kingdom are more tightly framed, with conditions and assessment requirements. Do not assume a GDPR transfer mechanism satisfies the PDPL.
- Data localisation expectations apply in some sectors - confirm sector rules alongside the PDPL itself.
- Registration and notification duties toward the regulator differ from the GDPR model.
- The right to erasure is narrower - framed around destruction when the purpose ends rather than a broad right to be forgotten.
- No direct portability equivalent in the GDPR sense, though individuals may obtain a copy of their data.
- Sensitive data categories and rules on health, credit and genetic data carry specific handling requirements.
The implementing regulations carry much of the operational detail, and guidance evolves. Confirm current requirements with SDAIA or qualified counsel before finalising your programme - this article is orientation, not legal advice.
Getting started
- Build a data inventory - what personal data you hold, where it lives, and why.
- Map cross-border flows, including cloud hosting, backups and support access.
- Establish and document a lawful basis for each processing activity.
- Publish a compliant privacy notice in Arabic and English.
- Stand up rights-request and breach-response processes with named owners.
- Put processor agreements in place with vendors.
- Reuse your ISO 27001 and ISO 27701 controls - the security obligations overlap heavily.
Frequently asked questions
Does the PDPL apply to companies outside Saudi Arabia?
Yes, where they process the personal data of individuals residing in the Kingdom. Non-resident entities may also face representation requirements.
Is GDPR compliance enough for the PDPL?
No, though it is a strong head start. The security, notice, records and vendor obligations map closely, but transfers, registration duties and some rights differ and must be addressed directly.
Do we need a data protection officer?
A responsible person for personal data protection is expected in defined circumstances - for example larger-scale or sensitive processing. Document your assessment either way.
How does ISO 27701 help?
ISO 27701 extends an ISO 27001 ISMS into a privacy management system. It gives you the control structure and evidence base to demonstrate PDPL and GDPR obligations from one programme.
Key takeaways
- The PDPL applies extraterritorially to data of residents in the Kingdom.
- Consent is central, with defined lawful exceptions.
- Cross-border transfer rules differ from the GDPR - check them specifically.
- Reuse ISO 27001 and 27701 evidence rather than building a separate programme.