Saudi Arabia’s PDPL requires more than a policy. It requires operational proof.
Saudi Arabia’s Personal Data Protection Law now sits beyond its compliance grace period. Organizations need documented processing purposes, valid consent or another permitted basis, responsive data-subject workflows, maintained processing records, transfer safeguards and a tested 72-hour breach process. Captain Compliance helps privacy teams discover data activity, document decisions and coordinate the evidence behind an accountable PDPL program.
The risk is not just collecting data. It is failing to show why, where and under what controls.
Other PDPL violations may result in warnings or fines up to SAR 5 million, with the maximum potentially doubled for repeat violations. A separate criminal provision applies to intentional disclosure of sensitive data; the two should not be merged.
The regulator must be notified within 72 hours after awareness when the breach may harm personal data or individuals, or conflict with their rights or interests. Not every security event is automatically reportable.
Requests generally must be addressed within 30 days, with a possible extension of an additional 30 days, no more than that when the regulatory conditions are satisfied and the individual is notified in advance with the reason.
Written processing records must be maintained throughout the activity and for five years after that processing activity ends.
Identify a clear, specific and lawful purpose before collecting or processing personal data. Limit collection to the minimum data necessary, avoid processing that conflicts with the stated purpose, and document the applicable processing basis.
When relying on consent, obtain it freely, explain each specific purpose and retain evidence of when and how it was provided. Obtain separate consent for separate purposes. Make withdrawal as easy as giving consent and stop consent-based processing without undue delay after withdrawal. Explicit consent is required for sensitive data, credit data and solely automated decisions.
Provide the controller’s identity and contact details, DPO information where applicable, the legal basis, specific purposes, retention information, rights and withdrawal instructions before or when collecting data. When data comes from another source, notice generally must be provided without undue delay and within 30 days unless an exception applies.
Enable individuals to be informed, access their personal data, obtain a readable copy, request correction, completion or updating, and request destruction subject to applicable conditions and exceptions. Verify identity proportionately, document requests including oral requests, and manage the 30-day response period.
Use appropriate organizational, administrative and technical measures to protect personal data. Select processors that provide sufficient guarantees, define their instructions contractually and monitor their performance. Destroy or properly anonymize data when its purpose ends unless a lawful retention requirement applies.
Conduct a documented impact assessment for sensitive-data processing and other prescribed high-risk activities, including certain large-scale monitoring, linked datasets, new technologies and solely automated decisions. Appoint a DPO when the controller falls within the regulatory triggers — not every organization must appoint one.
Maintain written, accurate and current processing records covering purposes, data and individual categories, recipients, retention, transfers, safeguards and relevant contact information. Keep the records during processing and for five years after each processing activity ends.
Assess incidents against the Saudi notification threshold, coordinate the 72-hour SDAIA workflow and notify affected individuals without undue delay when required. Map transfers outside the Kingdom and document their purpose, destination, legal mechanism, safeguards, minimization and required risk assessment. Saudi Arabia does not impose an absolute localization rule.
Connect discovery, decisions and response in one accountable operating record.
Captain Compliance helps privacy, legal, security, marketing and engineering teams understand where personal data is collected, document the controls applied to it and coordinate ongoing PDPL responsibilities. A privacy notice describes intended behavior; production systems determine what actually happens. Use the platform to identify new processing, route it for review, document the applicable purpose and basis, deploy the appropriate control and preserve the resulting evidence. Configure Arabic and English experiences where they help the intended audience understand the processing, but bilingual content is not a substitute for accurate legal analysis, and the platform preserves human review for legal interpretations and risk decisions.
Continuous website discovery
Scan websites for cookies, pixels, scripts, tags and similar technologies. Monitor changes over time and flag newly detected activity for classification before undocumented processing becomes part of the production environment.
Consent and preference records
Deploy configurable consent experiences, including Arabic and English presentation where appropriate. Record purposes, choices, timestamps, notice versions and withdrawals so the organization can demonstrate how an individual’s preference was captured.
Dynamic privacy notices
Connect notices to actual processing purposes, categories, recipients, rights, retention and transfer information. Maintain versions and an audit history as processing activities and disclosures change.
Data-subject request workflows
Receive, verify, assign and track access, copy, correction, updating and destruction requests. Maintain request history, response evidence, decisions and the applicable 30-day deadline.
Processing records and ownership
Centralize processing purposes, data categories, individual categories, recipients, retention periods, transfers, safeguards and accountable owners. Preserve records and their history for the applicable processing and post-processing periods.
DPIA and risk documentation
Create structured impact-assessment workflows, connect identified risks to safeguards and remediation tasks, and retain review and approval evidence for sensitive, large-scale, monitored or technology-driven processing.
Vendor and transfer mapping
Record processors, subprocessors, countries, transfer purposes, safeguards, contracts and risk assessments. Connect overseas website vendors and cloud services to the processing activities and data categories they support.
Breach-response coordination
Coordinate incident intake, assessment, ownership, affected data, individual impact, regulatory decisions and notification evidence. Tracks the 72-hour deadline when the regulatory threshold may be met, without making that legal determination for you.
Your website can create PDPL obligations before a form is submitted.
Cookies, pixels, analytics tags, advertising tools, device identifiers, chat technologies and session-replay software can collect or generate personal data when they directly or indirectly identify an individual. The PDPL is not a cookie-specific law and does not prescribe one universal banner design, but the underlying collection and processing still need an appropriate purpose, legal basis, notice and supporting controls. A scanner can reveal which technologies load and what changes over time; it cannot determine the legal basis by itself. Privacy and legal teams still need to classify each technology, identify its purposes and recipients, determine whether consent or another lawful ground is appropriate, and confirm whether the resulting data leaves Saudi Arabia. Direct marketing requires particular attention: controllers processing personal data for direct-marketing purposes must obtain consent, identify the sender and provide an easy, free mechanism for stopping marketing. Sensitive personal data must not be processed for marketing, even with consent. In practice that means: discover cookies, pixels and session replay; block nonessential technology when required; record consent by purpose and notice version; map vendors and overseas destinations; and monitor changes after deployment.
Book a Saudi PDPL review- Day 1 — Website and processing baseline — Scan public websites, identify trackers and forms, inventory major systems, locate existing notices and map high-priority processors and transfers
- Week 1 — Purposes, notices and consent — Document purposes and processing bases, correct consent implementation, connect Arabic and English disclosures where appropriate, and establish preference and withdrawal records
- Week 2 — Rights, RoPA and retention — Configure the request workflow, assign business owners, assemble processing records and connect each data category to a retention or destruction rule
- Week 3 — DPIA, DPO and transfer controls — Identify mandatory impact assessments, confirm whether the DPO triggers apply, review processors and document international-transfer mechanisms and risk assessments
- Ongoing — Monitoring and incident readiness — Continuously monitor website changes, update records and notices, review vendors, rehearse the 72-hour breach process and track new SDAIA rules and guidance
From scattered documents to a defensible operating record.
- Website trackers are not connected to documented purposes
- Consent evidence is scattered across screenshots and systems
- Legitimate interests is used without a completed assessment
- Processing records become outdated soon after creation
- Rights requests depend on email and individual memory
- Overseas vendors are not connected to transfer safeguards
- DPIA triggers are identified inconsistently
- The 72-hour breach process has not been rehearsed
- Website technologies are continuously discovered and reviewed
- Purposes, choices, notices and withdrawals create an evidence trail
- Legitimate-interest decisions are documented and assigned
- Processing records have owners and a maintained history
- Rights requests are verified, routed and deadline-tracked
- Vendors, destinations and transfer mechanisms are mapped
- Risk assessments connect findings to remediation
- Incident decisions and notification tasks are coordinated
Saudi Arabia’s PDPL, answered plainly.
When did Saudi Arabia’s PDPL become enforceable?+
Who must comply with the Saudi PDPL?+
Does every processing activity require consent?+
When can legitimate interests be used?+
Does the Saudi PDPL require an Arabic cookie banner or privacy notice?+
What rights do individuals have under the PDPL?+
When must a breach be reported to SDAIA?+
Must every organization appoint a DPO?+
Can personal data be transferred outside Saudi Arabia?+
What penalties can apply under the PDPL?+
Make PDPL responsibilities visible, assigned and repeatable.
Captain Compliance helps privacy, legal, security, marketing and engineering teams connect data discovery to the records and workflows behind Saudi PDPL operations. Discover website technologies, document purposes and preferences, coordinate individual requests, maintain processing evidence, map transfers and prepare for breach response from one operating environment. Captain Compliance provides privacy technology and operational support, not legal services.
Book a Saudi PDPL review View pricing