In 2021, the Kingdom of Saudi Arabia (“Kingdom”) introduced a Personal Data Protection Law (“PDPL”) with the aim of safeguarding personal information and upholding privacy rights. The PDPL was published in the Official Gazette on 24 September 2021. Amended in March 2023, the PDPL came into effect on 14 September 2023 and is fully enforceable as of 14 September 2024. The Saudi Data & Artificial Intelligence Authority (“SDAIA”) serves as the initial competent authority for supervising the implementation of the PDPL and has recently issued various updates and guidelines to supplement the PDPL. This briefing discusses the impact of the PDPL and these new guidelines on businesses.
1. Introduction
The PDPL is a comprehensive and modern data protection framework that aligns with international standards and shares similarities with the EU’s GDPR, often described as the gold standard for data protection. The introduction of the PDPL is a progressive step in a series of legal reforms recently implemented by the Kingdom as part of its Vision 2030 initiative to diversify the Saudi economy and foster digital transformation.
While the PDPL was already introduced in 2021, organisations were granted a one-year grace period that started on 14 September 2023 to fully comply with its broad scope of obligations. Following an amendment to the PDPL in March 2023, a set of Implementing Regulations was released in September 2023.
By the end of the one-year grace period on 14 September 2024, organisations subject to the PDPL should have already established data compliance processes in line with the PDPL and should have begun to foster a culture of data compliance within their organisations, including through staff training.
Data protection compliance, however, does not end with the implementation of a data compliance system. Instead, businesses are required to constantly monitor the legal landscape for important data protection updates and adjust their processes accordingly. The SDAIA has recently published new guidelines and amendments addressing various key data protection aspects, such as privacy policies, controller registration requirements, records of processing activities (“RoPA”), cross-border transfers and data protection officer (“DPO”) appointments. Following these updates, businesses will need to reevaluate the data protection processes already in place and amend them where necessary.
2. What are the key features of the PDPL?
The PDPL regulates, among other things, the collection, processing, disclosure, transfer and retention of personal data of individuals. The PDPL sets out certain requirements for data processing and provides for specific rights for individuals regarding the processing of their personal data (“Data Subject Rights”). The PDPL further requires businesses to disclose any incidents where personal data has been compromised and outlines penalties for non-compliance.
3. What updates have been introduced by SDAIA?
Among other updates, SDAIA has recently introduced regulations on cross border transfers to better align with international standards (“Regulation on Personal Data Transfer Outside the Kingdom”). Businesses are obliged to implement appropriate safeguards when transferring personal data to countries that SDAIA does not consider to provide an adequate level of data protection. Since SDAIA is authorized to publish adequacy decisions on its official website (“White List”), organisations are well advised to regularly check SDAIA’s website for updates on these adequacy decisions. The following three safeguards are available: Standard contractual clauses (“SCCs”), binding common rules (“BCRs”) and certificates of accreditation. SDAIA has published pre-approved SCCs for personal data transfers, along with guidelines for BCRs on its website. Businesses are required to carry out a risk assessment before transferring or disclosing personal data if they use appropriate safeguards to transfer data outside the Kingdom, or if sensitive data is transferred or disclosed to organisations outside the Kingdom on an ongoing or widespread basis. SDAIA has further published the “Rules Governing the National Register of Controllers Within the Kingdom”, which require various entities and individuals to register with SDAIA in accordance with the applicable registration procedure. This includes controllers that are public entities, controllers whose main activity is based on personal data processing, controllers processing sensitive personal data and individuals who process personal data for purposes exceeding personal or family use.
Additionally, SDAIA has made available the “Rules for Appointing Personal Data Protection Officer”. These include, among other things, the criteria for when a DPO must be appointed and the DPO’s responsibilities.
Furthermore, SDAIA has published various other guidelines that provide detailed guidance on selected aspects of the PDPL, including the “Elaboration and Developing Privacy Policy Guide line”, the “Personal Data Destruction, Anonymization, and Pseudonymisation Guideline”, the “Personal Data Disclosure Cases Guideline”, the “Personal Data Processing Activities Records Guideline” and the “Minimum Personal Data Determination Guide line”. These guidelines provide businesses with valuable insights into key principles and measures to consider under the PDPL for data compliance.
4. What measures do organisations need to take?
Following the publication of the guidelines by the SDAIA, organisations should assess whether they need to amend their existing processes or introduce new ones. For example, organisations should consider the following:
− Is the organisation required to register on the National Register of Controllers?
− Is the organisation required to appoint a DPO?
− Does the organisation document the personal data it holds?
− Does the organisation maintain sufficient records of processing activities?
− Has the organisation introduced data privacy policies in line with the PDPL?
− Are the organisation’s data transfer mechanisms in line with the updated “Regulation on Personal Data Transfer Outside the Kingdom”?
− Has the organisation considered the SCC’s published by SDAIA?
The PDPL’s broad geographical scope, which extends beyond the borders of the Kingdom, means that it is also applicable to non-Saudi organisations that handle personal data relating to individuals residing in the Kingdom. Therefore, even businesses not based in the Kingdom are advised to check their data flows to identify whether they handle personal data of Saudi residents.
5. Conclusion and Outlook
The PDPL itself has a strong legal and regulatory framework to ensure its effective implementation and over-sight. While the PDPL offers individuals a higher level of data protection and security, organisations face an increased administrative burden as they navigate the data compliance process, which may prove challenging for some. However, it is critical for organisations subject to the PDPL to establish and maintain a strong compliance management program to protect themselves and ensure long-term customer trust and loyalty. Non-compliant organisations are at constant risk of losing business and damaging their reputation due to penalties for non-compliance and the subsequent publication of those violations.
As part of their compliance obligations, organisations subject to the PDPL are required to monitor the legal landscape for relevant updates and adapt their data compliance programs as needed. Organisations should regularly check the official channels for updates. It is expected that over the coming months, SDAIA will continue to publish official guidelines to clarify legal requirements and further support businesses in implementing appropriate data protection regimes.

Dr. Constantin Frank-Fahle, LL.M.
Founding Partner



