Country:沙特阿拉伯 · Data Privacy
Saudi Arabia · Data Privacy
Saudi Arabia's Personal Data Protection Law (PDPL, Royal Decree M/19, effective 2023-09-14, full enforcement 2024-09-14) is the country's first comprehensive data protection law, applying domestically and extraterritorially. Data processing requires a lawful basis (mainly consent) with notice, security measures, and DPIA obligations. Cross-border transfers must be based on adequacy determinations or SCC/BCR. The regulator is SDAIA; 48 penalties have been issued between 2025 and 2026, with enforcement becoming routine.
Key points
- PDPL effective September 2023, full enforcement September 2024; regulator is SDAIA.
- Lawful basis mainly consent; data subjects have access, rectification, erasure, and portability rights.
- Data breaches must be reported to SDAIA within 72 hours.
- Cross-border transfers: no adequacy whitelist yet; must use SCC (SDAIA mandatory template) or BCR with a risk assessment.
- DPO required in specific cases; penalties: unlawful sensitive data processing up to 2 years imprisonment and/or SAR 3 million fine.
- China data export obligations (pkulaw verified 2026-07): transfers/return of data to China must use one of three routes — security assessment (CAC Order No. 11), standard contract (Order No. 13), or certification (CAC·SAMR Order No. 20, effective 2025-10-14); the 2024–2025 regulatory stance has relaxed — the Provisions on Promoting and Regulating Cross-Border Data Flows (Order No. 16) and the Regulations on Network Data Security Administration (State Council Order No. 790) exempt some situations.
Procedure
- Conduct personal data inventory and mapping.
- Publish privacy notices and manage consent (itemized, verifiable).
- High-risk processing requires a DPIA; appoint a DPO where applicable.
- Cross-border transfers require SDAIA SCCs and a transfer impact assessment (TIA).
- Establish a 72-hour breach notification and registration mechanism.
Hard requirements
- Lawful basis; notice; security measures; DPO (specific cases); SCC/BCR for cross-border transfers.
Costs
Compliance system building; DPO; cross-border transfer documents and assessments.⏱ ⏱ Timeline:Full enforcement since September 2024; continuous compliance required.⚠ Common risks
- China not on the adequacy whitelist; cross-border transfers require SCCs and risk assessments.
- Penalized for consent defects (e.g., pre-checked consent invalid).
- Failure to report breaches within 72 hours faces penalties.
- Extraterritorial application: entities without a Saudi establishment may still be covered.
Handbook
📘 Step-by-Step Handbook (with owner / timeline / cost / penalties)
Applies to:Chinese companies processing Saudi residents' personal data in Saudi Arabia, or transferring it back to China (governed by the PDPL Royal Decree M/19, effective 2023-09-14, full enforcement 2024-09-14, supervised by SDAIA with extraterritorial effect).
Prerequisites
- Processing activities and lawful bases (mainly consent) clarified.
- Assessment of whether a DPO is required (specific cases).
- Budget reserved for cross-border SCC templates and risk assessments.
| Step | Action | Owner | Timeline | Cost | Official form / system | Notes & penalties |
|---|---|---|---|---|---|---|
| 1 | Personal data inventory and mapping. Map personal data categories, processing purposes, and recipients; establish processing records. | Legal/IT department. | 2 weeks | Internal cost. | Data inventory, processing records. | Extraterritorial effect applies. Penalty:Sensitive data violations up to 2 years imprisonment and/or SAR 3 million fines. |
| 2 | Publish privacy notices and manage consent. Publish privacy notices and obtain itemized, verifiable consent (pre-checked consent invalid). | Legal | 1–2 weeks. | Internal cost. | Privacy notice, consent records. | Must support withdrawal. Penalty:Same as step 1. |
| 3 | Conduct a DPIA for high-risk processing and appoint a DPO. Conduct a DPIA for high-risk or large-scale processing; appoint a DPO in specific cases. | Compliance/management | 2–4 weeks | DPO staffing | DPIA report, DPO appointment | SDAIA enforcement is routine (48 penalties issued) Penalty:Penalized for missing DPIA or DPO. |
| 4 | Cross-border transfers require SDAIA SCCs and a TIA. China is not on the adequacy whitelist; sign the SDAIA mandatory-template SCC and complete a TIA, linked to PIPL export requirements. | Legal | 3–6 weeks | Internal/lawyer fees | SDAIA SCC, TIA, PIPL export documents | Or use BCR with a risk assessment Penalty:Penalized for transfers without a lawful mechanism. |
| 5 | 72-hour breach notification. Personal data breaches must be reported to SDAIA within 72 hours, with a registration mechanism. | DPO/IT | Within 72 hours | Internal cost | SDAIA breach notification | Set automatic triggers Penalty:Failure to notify within 72 hours faces penalties. |
| 6 | Data subject rights response. Establish response mechanisms for access, rectification, erasure, portability, etc. | DPO/customer service | Ongoing | Internal cost | DSAR process | Must be recorded Penalty:Refusing to respond faces penalties. |
| 7 | Continuous compliance and annual review. Regular reviews, policy updates, and training. | Compliance | Annual | Internal cost | Annual audit | Enforcement is routine Penalty:Continuous violation accumulation risk. |
✅ Self-check list
⚠ Common pitfalls
China not on the whitelist but transferring without SCC影响:Violation (stacked with PIPL penalties)规避:Sign SDAIA SCC and complete a TIA
Pre-checked consent影响:Penalized for invalid consent规避:Obtain itemized, verifiable consent
Ignoring PIPL export for data return to China影响:Dual violation规避:Handle China-side mechanisms in parallel
Breach reported after 72 hours影响:Penalties规避:Set automatic reporting triggers
DPO not appointed when required影响:Penalized规避:Appoint per the circumstances
Assuming extraterritorial non-applicability影响:Compliance gaps规避:PDPL extraterritorial application
📅 Ongoing post-incorporation obligations
- DPO duties (where applicable)
- 72-hour breach notification to SDAIA
- Continuous DSAR response
- SCC/TIA and China PIPL export mechanisms remain effective
- Annual review and training
🔗 Official portals
📎 Source:Saudi Data and AI Authority (SDAIA); Personal Data Protection Law (PDPL, Royal Decree M/19); Cross-Border Transfer Regulations (full enforcement 2024-09); https://www.cac.gov.cn
Want to turn this into an actionable compliance workflow?
CompliGo · Outbound Compliance Automation
You now have the essentials. Hand it to CompliGo: auto-generate compliance documents, real-time validation, and one-click regulatory alerts. Free trial for new users.
CompliGo is an independent SaaS operated by the outbound team. This knowledge base only drives acquisition and never handles funds or collects/pays on your behalf.