🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
SA v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing15 sources retrieved model claude-sonnet-5 · 2026-08-05

Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

Saudi Arabia

SA schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 43 claims · 22 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
43Claimsbaseline..claims[]
3Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 26 August 2026.

Lead Signal

Saudi Arabia's Personal Data Protection Law has entered its first sustained enforcement phase. SDAIA's specialized enforcement committees issued 48 decisions against PDPL violators over the year preceding a February 2026 report, the first substantive enforcement wave since the law became fully enforceable on 14 September 2024. The most commonly cited violation was sending marketing and promotional messages without prior consent, a pattern SDAIA found widespread across retail, telecommunications, and financial services. SDAIA also identified processing without a lawful basis, unlawful collection or processing, and insufficient technical and organizational security controls among its common findings. The wave coincided with SDAIA's 16 February 2026 publication of Rules Governing the Issuance of Accreditation Certificates for Controllers and Processors, adding a formal certification layer to the compliance ecosystem.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus statute in force with an operational regulator, implementing regulations, and an active registration platform.

Primary frameworkPersonal Data Protection Law (PDPL), Royal Decree M/19 (17 Sept 2021), as amended 21 March 2023, with Implementing Regulations and Cross-Border Data Transfer Regulation (effective 14 Sept 2023, fully enforceable 14 Sept 2024)
Traffic-light rationale — GreenComprehensive omnibus statute in force with an operational regulator, implementing regulations, and an active registration platform.

Sub-modules (5)

Regulator And AuthorityGreen

SDAIA is the designated data protection regulator under the PDPL, exercising quasi-judicial enforcement powers through specialized committees.

Claims (1):

  • The Saudi Data and Artificial Intelligence Authority (SDAIA) is the designated regulator for the Personal Data Protection Law.

Act And InstrumentsGreen

The PDPL, as amended, together with its Implementing Regulations and the Regulations on Personal Data Transfers, form the primary instrument set.

Claims (1):

  • The Personal Data Protection Law was implemented by Royal Decree M/19 of 17 September 2021 approving Resolution No. 98, and amended on 21 March 2023.

Material ScopeGreen

The PDPL covers personal data processing principles (purpose limitation, minimization), controller obligations, registration/ROPA, data subject rights, and penalties.

Claims (1):

  • The PDPL covers key principles such as purpose limitation and data minimization, controller obligations including registration and maintenance of data processing records, data subject rights, and penalties for breach of provisions.

Territorial ScopeGreen

The PDPL has extraterritorial effect, applying to entities inside and outside the Kingdom that process personal data of Saudi citizens or residents.

Claims (1):

  • The PDPL applies to all entities, whether based inside or outside the Kingdom, that process the personal data of Saudi citizens or residents, and also extends to individuals who collect personal data of others.

Regulator Registration And FilingAmber

Controllers must register via an electronic portal (National Data Governance Platform) with an annual fee and maintain a Record of Processing Activities (ROPA) registered with SDAIA.

Claims (2):

  • Data controllers must register via an electronic portal which includes an annual registration fee.
  • Data controllers must create and maintain a record of how they process personal data, and it must be registered with the SDAIA.
Category narrative57 words

Saudi Arabia's Personal Data Protection Law (PDPL), enacted by Royal Decree M/19 and amended in March 2023, is a GDPR-style omnibus statute administered by the Saudi Data and Artificial Intelligence Authority (SDAIA). The law and its Implementing Regulations/Cross-Border Data Transfer Regulation have been fully in force and enforceable since 14 September 2024, following a phased transition period.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. UncertainOneTrust DataGuidance — The Saudi Data and Artificial Intelligence Authority (SDAIA) is the designated regulator for the Personal Data Protection Law.observed
  2. UncertainOneTrust DataGuidance — The Personal Data Protection Law was implemented by Royal Decree M/19 of 17 September 2021 approving Resolution No. 98, and amended on 21 March 2023.observed
  3. UncertainOneTrust DataGuidance — The PDPL covers key principles such as purpose limitation and data minimization, controller obligations including registration and maintenance of data processing records, data subject rights, and penalties for breach of provisions.observed
  4. UncertainIAPP — The PDPL applies to all entities, whether based inside or outside the Kingdom, that process the personal data of Saudi citizens or residents, and also extends to individuals who collect personal data of others.observed
  5. UncertainIAPP — Data controllers must register via an electronic portal which includes an annual registration fee.observed
  6. UncertainIAPP — Data controllers must create and maintain a record of how they process personal data, and it must be registered with the SDAIA.observed

#

Lawful-basis regime is narrower than GDPR (fewer enumerated grounds; legitimate interest only added by 2023 amendment and excluded for sensitive data), creating residual compliance friction.

Primary frameworkPDPL (as amended) Arts. 5-6 and Implementing Regulation Art. 16
Traffic-light rationale — AmberLawful-basis regime is narrower than GDPR (fewer enumerated grounds; legitimate interest only added by 2023 amendment and excluded for sensitive data), creating residual compliance friction.

Sub-modules (4)

Lawful BasesAmber

Consent remains the primary basis; the 2023 amendment added a legitimate-interest ground (not applicable to sensitive data).

Claims (1):

  • The 2023 PDPL amendments permit processing on the basis of legitimate/lawful interest of the controller or another person where it does not prejudice the data subject's rights, but this basis does not apply to sensitive personal data.

Special CategoriesAmber

Special categories include health, genetic, credit/financial data, and (uniquely versus GDPR) tribal origin, with Articles 26-27 imposing additional restrictive measures for health and credit data.

Claims (2):

  • The PDPL's special-category definitions differ from GDPR notably in referencing tribal origin and credit data as sensitive categories.
  • Implementing Regulation Articles 26-27 impose additional restrictive and specific measures for processing health and credit data, including a need-to-know access approach.

Pseudonymisation And AnonymisationGreen

SDAIA has issued guidelines assisting entities in determining when personal data should be destroyed or anonymized.

Claims (1):

  • SDAIA's guidance materials include guidelines to assist entities in determining when personal data should be destroyed or anonymized.
Category narrative40 words

The PDPL originally made consent the primary lawful basis, with the 2023 amendments introducing a legitimate-interest basis (excluded for sensitive data). Special categories include health, genetic, credit/financial, and tribal-origin data, subject to additional safeguards; SDAIA has also issued anonymization/destruction guidance.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. UncertainOneTrust DataGuidance — The 2023 PDPL amendments permit processing on the basis of legitimate/lawful interest of the controller or another person where it does not prejudice the data subject's rights, but this basis does not apply to sensitive personal data.observed
  2. UncertainIAPP — Implementing Regulation Article 28 requires controllers to obtain consent before processing data for promotional/awareness purposes, but includes an indirect exemption where there was a previous interaction between controller and data subject; Article 29 imposes consent for direct-marketing communications without that exemption.observed
  3. UncertainOneTrust DataGuidance — The PDPL's special-category definitions differ from GDPR notably in referencing tribal origin and credit data as sensitive categories.observed
  4. UncertainIAPP — Implementing Regulation Articles 26-27 impose additional restrictive and specific measures for processing health and credit data, including a need-to-know access approach.observed
  5. UncertainIAPP — SDAIA's guidance materials include guidelines to assist entities in determining when personal data should be destroyed or anonymized.observed

#

Core rights exist and are binding, but response-window specificity and portability provisions are thinner than GDPR, creating operational ambiguity flagged by practitioners.

Primary frameworkPDPL (as amended), Implementing Regulation Arts. on data subject requests
Traffic-light rationale — AmberCore rights exist and are binding, but response-window specificity and portability provisions are thinner than GDPR, creating operational ambiguity flagged by practitioners.

Sub-modules (5)

Access RightAmber

Data subjects may submit requests, including verbal requests under an authentication mandate in the Implementing Regulation.

Claims (1):

  • The Implementing Regulation permits verbal data subject requests under an authentication mandate, which is regarded as an operational burden on controllers.

Rectification And ErasureAmber

Controllers may reject excessive/repetitive DSRs with justification but cannot charge fees for them.

Claims (1):

  • There is no allowance under the Implementing Regulation for data controllers to charge data subjects for DSRs deemed excessive or repetitive, though controllers can reject such requests with justification.

Restriction And ObjectionAmber

A right to object to profiling/direct marketing is provided via Implementing Regulation Art. 28, paralleling GDPR Art. 21.

Claims (1):

  • Implementing Regulation Article 28 allows data controllers to rely on legitimate interest, subject to the data subject's right to object, for profiling and direct-marketing purposes.

Data PortabilityRed

No explicit data-portability right was identified in the PDPL or Implementing Regulation text reviewed.

Deadlines And Response WindowsRed

No fixed statutory response-window (e.g., a GDPR-style 30-day deadline) for DSR responses was located in the sources reviewed; the Implementing Regulation instead emphasizes justification for rejection rather than timing.

Category narrative44 words

The PDPL provides a GDPR-style suite of data subject rights (access, correction, deletion, restriction, objection), but the Implementing Regulation gives less granular guidance on scope and timelines than GDPR; no explicit data-portability provision or fixed statutory response deadline was identified in the materials reviewed.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. UncertainIAPP — The Implementing Regulation permits verbal data subject requests under an authentication mandate, which is regarded as an operational burden on controllers.observed
  2. UncertainIAPP — There is no allowance under the Implementing Regulation for data controllers to charge data subjects for DSRs deemed excessive or repetitive, though controllers can reject such requests with justification.observed
  3. UncertainIAPP — Implementing Regulation Article 28 allows data controllers to rely on legitimate interest, subject to the data subject's right to object, for profiling and direct-marketing purposes.observed

#

Core accountability infrastructure (DPIA, DPO, ROPA, breach notification) is binding and operative, but the immediate data-subject breach notification standard (rather than a risk-based threshold) is flagged by commentators as operationally stringent and under-specified.

Primary frameworkPDPL (as amended) Arts. 20-23, Implementing Regulation (DPIA, breach, security provisions)
Traffic-light rationale — AmberCore accountability infrastructure (DPIA, DPO, ROPA, breach notification) is binding and operative, but the immediate data-subject breach notification standard (rather than a risk-based threshold) is flagged by commentators as operationally stringent and under-specified.

Sub-modules (7)

Accountability And DpiaGreen

DPIAs are mandated in nine defined processing scenarios, paralleling GDPR Art. 35.

Claims (1):

  • The Implementing Regulation mandates data controllers conduct documented privacy impact assessments in nine different scenarios of personal data processing, including anonymization, sensitive personal data, and use of new technologies.

Dpo RequirementsAmber

SDAIA's DPO Rules require appointment of a data protection officer under specified conditions, including for public entities.

Claims (1):

  • SDAIA's Rules on Appointing a Personal Data Protection Officer define the DPO role and clarify that controllers must appoint a DPO where, among other conditions, the controller is a public entity.

Ropa RequirementsAmber

Controllers must maintain and register a Record of Processing Activities with SDAIA; the PDPL does not explicitly extend this obligation to processors as GDPR does.

Claims (1):

  • The PDPL requires controllers, but does not explicitly require processors, to maintain data processing records, unlike the GDPR which imposes this duty on both.

Joint Controller ArrangementsAmber

No dedicated joint-controller regime distinct from general controller/processor duties was identified; controllers assume sole accountability for processor compliance.

Claims (1):

  • Data controllers are required to periodically conduct compliance assessments of selected data processors, assuming sole accountability for processor processing activities before SDAIA and data subjects.

Security MeasuresGreen

Article 23 requires controllers to implement necessary security/technical measures, referencing National Cybersecurity Authority (NCA) standards where applicable.

Claims (1):

  • Article 23 of the Implementing Regulation requires data controllers to implement necessary security and technical measures, referencing National Cybersecurity Authority standards where the NCA regulates the controller, or best international cybersecurity standards otherwise.

Breach NotificationAmber

Breach notification requires reporting to SDAIA within 72 hours and immediate notification to affected data subjects.

Claims (1):

  • The Implementing Regulation requires organizations to notify SDAIA of a data breach within 72 hours and to notify affected data subjects immediately.

Retention And DisposalAmber

SDAIA guidance addresses when personal data should be destroyed or anonymized, though no fixed statutory retention period was located.

Claims (1):

  • SDAIA has published guidelines to assist entities in determining when personal data should be destroyed or anonymized.
Category narrative41 words

Controllers face DPIA obligations across nine defined scenarios, DPO appointment rules for public entities and certain processing profiles, ROPA maintenance, periodic processor-compliance assessments, NCA-referenced security measures, and a dual-track breach notification regime (72 hours to SDAIA; immediate to affected data subjects).

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (7)
  1. UncertainIAPP — The Implementing Regulation mandates data controllers conduct documented privacy impact assessments in nine different scenarios of personal data processing, including anonymization, sensitive personal data, and use of new technologies.observed
  2. UncertainOneTrust DataGuidance — SDAIA's Rules on Appointing a Personal Data Protection Officer define the DPO role and clarify that controllers must appoint a DPO where, among other conditions, the controller is a public entity.observed
  3. UncertainOneTrust DataGuidance — The PDPL requires controllers, but does not explicitly require processors, to maintain data processing records, unlike the GDPR which imposes this duty on both.observed
  4. UncertainIAPP — Data controllers are required to periodically conduct compliance assessments of selected data processors, assuming sole accountability for processor processing activities before SDAIA and data subjects.observed
  5. UncertainIAPP — Article 23 of the Implementing Regulation requires data controllers to implement necessary security and technical measures, referencing National Cybersecurity Authority standards where the NCA regulates the controller, or best international cybersecurity standards otherwise.observed
  6. UncertainIAPP — The Implementing Regulation requires organizations to notify SDAIA of a data breach within 72 hours and to notify affected data subjects immediately.observed
  7. UncertainIAPP — SDAIA has published guidelines to assist entities in determining when personal data should be destroyed or anonymized.observed

#

Transfer mechanisms are now GDPR-aligned in structure, but no specific adequacy decisions (received or granted) were identified in the reviewed sources, leaving practical cross-border flows dependent on SCCs/BCRs and TIAs.

Primary frameworkRegulations on Personal Data Transfers 2023 (Cross-Border Data Transfer Regulation), PDPL Art. 28 (as amended)
Traffic-light rationale — AmberTransfer mechanisms are now GDPR-aligned in structure, but no specific adequacy decisions (received or granted) were identified in the reviewed sources, leaving practical cross-border flows dependent on SCCs/BCRs and TIAs.

Sub-modules (6)

Transfer MechanismsGreen

Transfers are permitted on three grounds: adequacy decision, appropriate safeguards, or derogations, per the Cross-Border Data Transfer Regulation.

Claims (1):

  • The Cross-Border Data Transfer Regulation allows transfer of personal data on three grounds, organized in a manner broadly in line with the GDPR.

Adequacy ReceivedRed

No inbound adequacy decisions (i.e., other regimes recognizing Saudi Arabia as adequate) were identified in the sources reviewed.

Absence provenance: unavailable. Searched: Saudi Arabia adequacy decision received EU UK, Saudi PDPL adequacy status.

Adequacy GrantedAmber

SDAIA/the competent authority is empowered to issue adequacy decisions for destination countries, sectors, and international organizations, but no published list of adequate jurisdictions was located.

Claims (1):

  • Adequacy decisions for destination countries, other sectors, and international organizations are to be determined and issued by the competent authority, with defined assessment criteria and revision frequency.

Sccs And BcrsGreen

SDAIA has issued Standard Contractual Clauses (SCCs) and Binding Common Rules (BCRs) guidance for data transfers.

Claims (1):

  • SDAIA's Standard Contractual Clauses (SCCs) and Binding Common Rules (BCRs) guide data transfers, requiring adherence to the PDPL and Implementing Regulations.

Transfer Impact AssessmentGreen

A Transfer Impact Assessment is mandated for transfers to countries lacking an adequacy decision, incorporating post-Schrems II style risk assessment.

Claims (1):

  • The transfer regulation mandates a Transfer Impact Assessment to transfer data to countries without adequacy decisions, incorporating mechanisms introduced after the Schrems II decision.

Data LocalisationAmber

The PDPL's original default was a prohibition on transfers outside Saudi Arabia; the 2023 amendment rewrote the transfer article to be permissive, reducing localisation stringency but retaining stop/prohibition triggers including national security.

Claims (2):

  • The PDPL as originally published adopted a restrictive starting point, prohibiting transfers of personal data outside Saudi Arabia except where the executive regulations provided otherwise.
  • A transfer must be stopped or prohibited if it impacts national security or the Kingdom's interests, among other listed scenarios such as high risk shown by a TIA.
Category narrative55 words

The PDPL's original restrictive, prohibition-first stance on cross-border transfers was substantially liberalized in the 2023 amendments and the September 2023 Cross-Border Data Transfer Regulation, which permits transfer on three grounds (adequacy decision, appropriate safeguards including SCCs/BCRs, or derogations), and mandates a Transfer Impact Assessment (TIA) for transfers to non-adequate jurisdictions, modeled on post-Schrems II practice.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. UncertainIAPP — The Cross-Border Data Transfer Regulation allows transfer of personal data on three grounds, organized in a manner broadly in line with the GDPR.observed
  2. UncertainIAPP — Adequacy decisions for destination countries, other sectors, and international organizations are to be determined and issued by the competent authority, with defined assessment criteria and revision frequency.observed
  3. UncertainOneTrust DataGuidance — SDAIA's Standard Contractual Clauses (SCCs) and Binding Common Rules (BCRs) guide data transfers, requiring adherence to the PDPL and Implementing Regulations.observed
  4. UncertainIAPP — The transfer regulation mandates a Transfer Impact Assessment to transfer data to countries without adequacy decisions, incorporating mechanisms introduced after the Schrems II decision.observed
  5. UncertainOneTrust DataGuidance — The PDPL as originally published adopted a restrictive starting point, prohibiting transfers of personal data outside Saudi Arabia except where the executive regulations provided otherwise.observed
  6. UncertainIAPP — A transfer must be stopped or prohibited if it impacts national security or the Kingdom's interests, among other listed scenarios such as high risk shown by a TIA.observed

#

Financial and health/credit sector overlays are well-documented and binding; employment, education, and insurance sector-specific DP rules were not located and are flagged as gaps.

Primary frameworkPDPL Implementing Regulation Arts. 26-27; SAMA IT Governance/Cybersecurity Framework; NCA Essential Cybersecurity Controls
Supervisory authoritySaudi Central Bank (SAMA)
Traffic-light rationale — AmberFinancial and health/credit sector overlays are well-documented and binding; employment, education, and insurance sector-specific DP rules were not located and are flagged as gaps.

Sub-modules (7)

Financial Sector OverlayGreen

SAMA's IT Governance Framework and Cybersecurity Framework apply to banks, insurance/reinsurance companies, financing companies and credit bureaus regulated by SAMA.

Claims (2):

  • SAMA's Cybersecurity Framework applies to institutions including banks, insurance and reinsurance companies, financing companies, and credit bureaus.
  • SAMA's IT Governance Framework, issued 12 December 2021, requires SAMA-regulated Member Organisations to identify and address IT risks and periodically self-assess compliance.

Health Sector OverlayAmber

Implementing Regulation Article 26 imposes need-to-know-basis and documentation requirements specific to health data processing.

Claims (1):

  • Implementing Regulation Article 26 requires a restrictive, need-to-know-basis approach and documentation of all processing stages, with a specified owner for each stage, when processing health data.

Telecoms And EprivacyAmber

The NCA's Essential Cybersecurity Controls (2018) apply to government entities and private-sector organizations operating Critical National Infrastructure, with CITC having separately drafted an ICT-sector cybersecurity framework.

Claims (1):

  • The National Cybersecurity Authority's Essential Cybersecurity Controls, in force since 2018, apply to government organizations and private-sector organizations owning, operating, or hosting Critical National Infrastructure.

Employment DataRed

No dedicated employment-data DP overlay distinct from general PDPL obligations was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Saudi PDPL employment data employee monitoring.

Credit And ScoringAmber

Credit data is treated as a special category under the PDPL, with Implementing Regulation Article 27 imposing restrictive measures on credit-data processing.

Claims (1):

  • Implementing Regulation Article 27 imposes restrictive and specific measures for processing credit data, similar to those for health data.

EducationRed

No education-sector-specific DP overlay was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Saudi PDPL education sector student data.

InsuranceAmber

Insurance companies fall within SAMA's regulated financial-sector cybersecurity/IT governance perimeter but no insurance-specific DP overlay beyond this was identified.

Claims (1):

  • SAMA's Cybersecurity Framework applies to institutions including banks, insurance and reinsurance companies, financing companies, and credit bureaus.
Category narrative65 words

Financial-sector data processing is overlaid by SAMA's IT Governance and Cybersecurity Frameworks applying to banks, insurers, financing companies and credit bureaus; health and credit data receive additional PDPL Implementing Regulation restrictions (Arts. 26-27); telecoms/CNI-linked processing intersects with the National Cybersecurity Authority's Essential Cybersecurity Controls and a CITC draft ICT cybersecurity framework. No dedicated employment-data, education-sector, or insurance-specific DP overlay beyond general PDPL/NCA rules was identified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. UncertainOneTrust DataGuidance — SAMA's Cybersecurity Framework applies to institutions including banks, insurance and reinsurance companies, financing companies, and credit bureaus.observed
  2. UncertainOneTrust DataGuidance — SAMA's IT Governance Framework, issued 12 December 2021, requires SAMA-regulated Member Organisations to identify and address IT risks and periodically self-assess compliance.observed
  3. UncertainIAPP — Implementing Regulation Article 26 requires a restrictive, need-to-know-basis approach and documentation of all processing stages, with a specified owner for each stage, when processing health data.observed
  4. UncertainOneTrust DataGuidance — The National Cybersecurity Authority's Essential Cybersecurity Controls, in force since 2018, apply to government organizations and private-sector organizations owning, operating, or hosting Critical National Infrastructure.observed
  5. UncertainIAPP — Implementing Regulation Article 27 imposes restrictive and specific measures for processing credit data, similar to those for health data.observed

#

Direct-marketing consent rules are binding and actively enforced; cookie/tracker, dark-pattern, opt-out-signal, and clean-room coverage are gaps in the current PDPL framework as researched.

Primary frameworkPDPL Implementing Regulation Arts. 28-29 (direct marketing)
Traffic-light rationale — AmberDirect-marketing consent rules are binding and actively enforced; cookie/tracker, dark-pattern, opt-out-signal, and clean-room coverage are gaps in the current PDPL framework as researched.

Sub-modules (6)

Cookies And TrackersRed

No PDPL-specific cookie/tracker consent regime distinct from general lawful-basis rules was identified.

Absence provenance: unavailable. Searched: Saudi PDPL cookies tracker consent.

Dark PatternsRed

No PDPL dark-pattern prohibition provision was identified in sources reviewed.

Absence provenance: unavailable. Searched: Saudi PDPL dark patterns interface design.

Opt Out SignalsRed

No PDPL recognition of technical opt-out signals (e.g., Global Privacy Control) was identified.

Absence provenance: unavailable. Searched: Saudi PDPL Global Privacy Control opt-out signal.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room specific rule was identified under the PDPL.

Absence provenance: unavailable. Searched: Saudi PDPL data clean room data collaboration.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context advertising concept was identified under the PDPL.

Absence provenance: unavailable. Searched: Saudi PDPL cross-context advertising data sale share.

Direct MarketingAmber

Implementing Regulation Arts. 28-29 require consent for promotional/marketing communications, and marketing-without-consent violations are the most frequently cited SDAIA enforcement finding.

Claims (2):

  • Implementing Regulation Article 29 mandates data controllers collect consent from data subjects before processing data for direct marketing communications, without the prior-interaction exemption found in Article 28.
  • A notable share of SDAIA's 2025 enforcement decisions involved sending marketing and promotional messages without obtaining prior consent, a violation remaining widespread across retail, telecommunications, and financial services.
Category narrative44 words

The PDPL Implementing Regulation regulates direct marketing consent (Arts. 28-29), and marketing/promotional messaging without prior consent is among the most commonly cited SDAIA enforcement violations. No PDPL-specific cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal (e.g., GPC) recognition, clean-room framework, or CPRA-style cross-context-advertising rule was identified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (2)
  1. UncertainIAPP — Implementing Regulation Article 29 mandates data controllers collect consent from data subjects before processing data for direct marketing communications, without the prior-interaction exemption found in Article 28.observed
  2. UncertainIAPP — A notable share of SDAIA's 2025 enforcement decisions involved sending marketing and promotional messages without obtaining prior consent, a violation remaining widespread across retail, telecommunications, and financial services.observed

#

Profiling-objection and genetic-data coverage are binding; AI risk-assessment instruments remain largely non-binding policy/guidance; biometric-specific rules and ADM transparency rights are gaps.

Primary frameworkPDPL Implementing Regulation Art. 28; SDAIA AI Ethics Principles / draft Responsible AI Policy (non-binding guidance)
Traffic-light rationale — AmberProfiling-objection and genetic-data coverage are binding; AI risk-assessment instruments remain largely non-binding policy/guidance; biometric-specific rules and ADM transparency rights are gaps.

Sub-modules (6)

Profiling RestrictionsAmber

Implementing Regulation Art. 28 provides a right to object to profiling and direct marketing, paralleling GDPR Art. 21.

Claims (1):

  • Implementing Regulation Article 28 allows reliance on legitimate interest for profiling and direct marketing purposes, subject to the data subject's right to object, similar to GDPR Article 21.

Automated Decision Making TransparencyRed

No standalone ADM-transparency or explanation right distinct from the profiling-objection provision was identified.

Absence provenance: unavailable. Searched: Saudi PDPL automated decision-making transparency explanation right.

Ai Risk AssessmentsAmber

SDAIA opened public consultation on a draft Responsible AI Policy aimed at balancing AI adoption with risk mitigation, and has separately joined the OECD AI Recommendation.

Claims (1):

  • SDAIA opened a public consultation on a draft Responsible AI Policy aiming to balance AI adoption and responsible use while mitigating risks.

Biometric RegimeRed

No PDPL-specific biometric-data regime (facial recognition, fingerprint, gait) distinct from general special-category rules was identified.

Absence provenance: unavailable. Searched: Saudi PDPL biometric data facial recognition regime.

Genetic DataGreen

Genetic data is explicitly included among special/sensitive categories falling under PDPL scope.

Claims (1):

  • Information such as genetic, health, credit, and financial data falls within the scope of the PDPL and is subject to additional regulation.

State Surveillance CarveoutsAmber

Cross-border transfers must be stopped where they impact national security or the Kingdom's interests, functioning as a state-security carve-out.

Claims (1):

  • A transfer must be stopped or prohibited if it impacts national security or the Kingdom's interests, among other listed scenarios such as high risk shown by a TIA.
Category narrative69 words

The PDPL provides a right to object to profiling (Implementing Regulation Art. 28), and SDAIA has separately advanced AI governance instruments (draft Responsible AI Policy, AI Ethics Principles v2.0, generative-AI guidance) that interface with, but sit outside, the core PDPL. Genetic data is a recognized special category. National-security-linked carve-outs exist for cross-border transfer stoppage. No dedicated PDPL biometric-specific regime (facial recognition, gait, fingerprint) or standalone ADM-transparency/explanation right was identified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. UncertainIAPP — Implementing Regulation Article 28 allows reliance on legitimate interest for profiling and direct marketing purposes, subject to the data subject's right to object, similar to GDPR Article 21.observed
  2. UncertainOneTrust DataGuidance — SDAIA opened a public consultation on a draft Responsible AI Policy aiming to balance AI adoption and responsible use while mitigating risks.observed
  3. UncertainIAPP — Information such as genetic, health, credit, and financial data falls within the scope of the PDPL and is subject to additional regulation.observed

#

Only a general guardian/representative concept was located; no PDPL-specific child/vulnerable-group sub-regime (age thresholds, parental consent mechanics, minor profiling bans) was found despite targeted searches.

Primary frameworkPDPL definitional provisions (data subject includes representative/legal guardian)
Traffic-light rationale — RedOnly a general guardian/representative concept was located; no PDPL-specific child/vulnerable-group sub-regime (age thresholds, parental consent mechanics, minor profiling bans) was found despite targeted searches.

Sub-modules (5)

Age VerificationRed

No specific statutory age-of-consent threshold for data processing was identified.

Absence provenance: unavailable. Searched: Saudi PDPL age of consent minors data processing.

Minor Profiling BansRed

No minor-specific profiling ban was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Saudi PDPL minors profiling ban children.

Education SettingsRed

No education-settings-specific data protection rule was identified.

Absence provenance: unavailable. Searched: Saudi PDPL education settings student data minors.

Dependent AdultsRed

No dependent-adults (elderly/incapacitated) specific provision beyond the general guardian/representative concept was identified.

Absence provenance: unavailable. Searched: Saudi PDPL dependent adults incapacitated data subject.

Category narrative41 words

The PDPL's data-subject definition extends to a representative or legal guardian, implying protection for minors and incapacitated persons, but no specific statutory age of consent, dedicated parental-consent mechanism, minor-profiling ban, education-settings rule, or dependent-adults provision was identified in the sources reviewed.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — The definition of 'data subject' in the PDPL extends to the representative or legal guardian of the individual to whom personal data relates.observed

#

Regulator powers and penalties are well-evidenced and enforcement activity is demonstrably rising, but private rights of action and collective redress mechanisms are not evidenced in the sources reviewed, and regulator funding/capacity data is absent.

Primary frameworkPDPL Arts. on penalties; SDAIA committee enforcement structure; Licensing and Accreditation Rules (Feb 2026)
Traffic-light rationale — AmberRegulator powers and penalties are well-evidenced and enforcement activity is demonstrably rising, but private rights of action and collective redress mechanisms are not evidenced in the sources reviewed, and regulator funding/capacity data is absent.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

SDAIA's specialized committees hold quasi-judicial powers to investigate, review evidence, and impose sanctions; the PDPL provides for fines up to SAR 5 million and/or imprisonment up to two years.

Claims (2):

  • The PDPL provides for stringent penalties for breaches, including imprisonment of up to two years and/or fines of up to SAR 5 million (approximately EUR 1.1 million).
  • SDAIA's specialized committees are vested with quasi-judicial powers to investigate suspected infringements, review evidence, and impose administrative sanctions including warnings, fines, and remedial orders.

Enforcement Activity IndexAmber

SDAIA's specialized committees issued 48 decisions in the year preceding a February 2026 report, marking the first substantive enforcement wave since the PDPL became enforceable.

Claims (2):

  • SDAIA's specialized committees issued 48 decisions over the past year against organizations found in violation of the PDPL and its implementing regulations, representing the first substantive wave of adjudications since the PDPL became enforceable.
  • Common enforcement violations identified by SDAIA include processing without a lawful basis, unlawful collection and processing of personal data, and insufficient technical and organizational security controls.

Regulator Funding And CapacityRed

No specific data on SDAIA's data-protection enforcement budget or headcount was identified in the sources reviewed.

Absence provenance: unavailable. Searched: SDAIA data protection division budget headcount capacity.

Collective Redress And Class ActionsRed

No collective-redress or class-action mechanism for PDPL data subjects was identified in the sources reviewed.

Absence provenance: unavailable. Searched: Saudi PDPL class action collective redress data subjects.

Private Right Of ActionRed

No explicit private right of direct court action for data subjects distinct from SDAIA's administrative committee process was identified.

Absence provenance: unavailable. Searched: Saudi PDPL private right of action civil lawsuit data subject.

Recent Developments 180DGreen

Within the last 180 days, SDAIA published (16 February 2026) the Rules Governing the Issuance of Accreditation Certificates for Controllers and Processors and related licensing/auditing rules; SDAIA also reported a stepped-up enforcement posture (48 decisions) in a 25 February 2026 announcement.

Claims (2):

  • On 16 February 2026, SDAIA published the 'Rules Governing the Issuance of Accreditation Certificates for Controllers and Processors' and related rules governing licensing to issue such certificates and auditing.
  • SDAIA's specialized committees issued 48 decisions over the past year against organizations found in violation of the PDPL and its implementing regulations, representing the first substantive wave of adjudications since the PDPL became enforceable.
Category narrative79 words

SDAIA enforcement matured markedly in 2025-2026: specialized quasi-judicial committees issued 48 decisions in the year preceding a February 2026 report, covering unlawful processing, insufficient security controls, and consent-less marketing. Original PDPL penalties include fines up to SAR 5 million and/or up to two years' imprisonment. In February 2026, SDAIA published new Licensing/Accreditation Rules for controllers and processors. No explicit private right of action or collective-redress/class-action mechanism for data subjects was identified; redress currently flows through SDAIA's administrative committee process.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. UncertainOneTrust DataGuidance — The PDPL provides for stringent penalties for breaches, including imprisonment of up to two years and/or fines of up to SAR 5 million (approximately EUR 1.1 million).observed
  2. UncertainIAPP — SDAIA's specialized committees are vested with quasi-judicial powers to investigate suspected infringements, review evidence, and impose administrative sanctions including warnings, fines, and remedial orders.observed
  3. UncertainIAPP — SDAIA's specialized committees issued 48 decisions over the past year against organizations found in violation of the PDPL and its implementing regulations, representing the first substantive wave of adjudications since the PDPL became enforceable.observed
  4. UncertainIAPP — Common enforcement violations identified by SDAIA include processing without a lawful basis, unlawful collection and processing of personal data, and insufficient technical and organizational security controls.observed
  5. UncertainOneTrust DataGuidance — On 16 February 2026, SDAIA published the 'Rules Governing the Issuance of Accreditation Certificates for Controllers and Processors' and related rules governing licensing to issue such certificates and auditing.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct6.25
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Saudi Arabia
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 43 claim(s) (43 category placement(s)), 22 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiessecurity measures
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer impact assessment
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties, cross_border_and_adequacy, and enforcement_and_redress rest primarily on T2 (IAPP) sources cross-checked against T3 (DataGuidance) secondary tracker sources, giving Confirmed/Probable confidence on core PDPL mechanics (registration, DPIA, breach notification, transfer mechanisms, penalties, 2025-2026 enforcement activity). sectoral_watch relies on T3 sources for SAMA/NCA overlays with moderate confidence. adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups are only partially populated — direct-marketing consent, profiling-objection, genetic-data, and guardian-definition claims are evidenced, but cookie/tracker, dark-pattern, opt-out-signal, clean-room, ADM-transparency, biometric-regime, age-verification, and minor-profiling sub-modules returned no PDPL-specific findings despite targeted searches and are marked red with absent_field_provenance. No T1 (primary legal text) source was directly retrieved via search in this run; all statutory claims are sourced from T2/T3 secondary legal-tracker analysis of the PDPL, Implementing Regulations, and Cross-Border Data Transfer Regulation, which is a material limitation given the schema's preference for direct-anchor T1 citations.

Unresolved questions (7):

  • What are the specific, named jurisdictions (if any) covered by SDAIA-issued adequacy decisions under Cross-Border Data Transfer Regulation Arts. 3-4?
  • Is there a fixed statutory response-window (e.g., 30 days) for controller responses to data subject access/rectification/erasure requests under the Implementing Regulation?
  • Does the PDPL or Implementing Regulation provide an explicit data-portability right, and if so, in what form?
  • What is the specific age of consent / parental-consent mechanism (if any) under the PDPL for minors' personal data processing?
  • Is there a private right of action or class/collective-action mechanism available to Saudi data subjects independent of SDAIA's administrative committee process?
  • What are SDAIA's current data-protection-division funding and headcount levels?
  • Has the National Data Management Office (NDMO) formally assumed primary DP regulatory authority from SDAIA per the original two-year transition plan, or does SDAIA remain the sole regulator as of August 2026?

Escalate to primary-source review: yes