Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Solutions / PDPL · SAUDI ARABIA
SAUDI PDPL · SDAIA · DATA ACCOUNTABILITY

Saudi Arabia’s PDPL requires more than a policy. It requires operational proof.

Saudi Arabia’s Personal Data Protection Law now sits beyond its compliance grace period. Organizations need documented processing purposes, valid consent or another permitted basis, responsive data-subject workflows, maintained processing records, transfer safeguards and a tested 72-hour breach process. Captain Compliance helps privacy teams discover data activity, document decisions and coordinate the evidence behind an accountable PDPL program.

Consent and legal-basis recordsFive-year processing records72-hour breach workflow

The risk is not just collecting data. It is failing to show why, where and under what controls.

SAR 5M
Administrative fine

Other PDPL violations may result in warnings or fines up to SAR 5 million, with the maximum potentially doubled for repeat violations. A separate criminal provision applies to intentional disclosure of sensitive data; the two should not be merged.

72 hours
Breach reporting

The regulator must be notified within 72 hours after awareness when the breach may harm personal data or individuals, or conflict with their rights or interests. Not every security event is automatically reportable.

30 + 30
Rights response

Requests generally must be addressed within 30 days, with a possible extension of an additional 30 days, no more than that when the regulatory conditions are satisfied and the individual is notified in advance with the reason.

5 years
Processing records

Written processing records must be maintained throughout the activity and for five years after that processing activity ends.

Purpose
Lawful and limited processing

Identify a clear, specific and lawful purpose before collecting or processing personal data. Limit collection to the minimum data necessary, avoid processing that conflicts with the stated purpose, and document the applicable processing basis.

Consent
Consent and withdrawal

When relying on consent, obtain it freely, explain each specific purpose and retain evidence of when and how it was provided. Obtain separate consent for separate purposes. Make withdrawal as easy as giving consent and stop consent-based processing without undue delay after withdrawal. Explicit consent is required for sensitive data, credit data and solely automated decisions.

Notice
Notices and transparency

Provide the controller’s identity and contact details, DPO information where applicable, the legal basis, specific purposes, retention information, rights and withdrawal instructions before or when collecting data. When data comes from another source, notice generally must be provided without undue delay and within 30 days unless an exception applies.

Rights
Data-subject rights

Enable individuals to be informed, access their personal data, obtain a readable copy, request correction, completion or updating, and request destruction subject to applicable conditions and exceptions. Verify identity proportionately, document requests including oral requests, and manage the 30-day response period.

Security
Security, processors and retention

Use appropriate organizational, administrative and technical measures to protect personal data. Select processors that provide sufficient guarantees, define their instructions contractually and monitor their performance. Destroy or properly anonymize data when its purpose ends unless a lawful retention requirement applies.

DPIA
DPIAs, DPOs and governance

Conduct a documented impact assessment for sensitive-data processing and other prescribed high-risk activities, including certain large-scale monitoring, linked datasets, new technologies and solely automated decisions. Appoint a DPO when the controller falls within the regulatory triggers — not every organization must appoint one.

RoPA
Records of processing

Maintain written, accurate and current processing records covering purposes, data and individual categories, recipients, retention, transfers, safeguards and relevant contact information. Keep the records during processing and for five years after each processing activity ends.

Transfers
Breach and transfer controls

Assess incidents against the Saudi notification threshold, coordinate the 72-hour SDAIA workflow and notify affected individuals without undue delay when required. Map transfers outside the Kingdom and document their purpose, destination, legal mechanism, safeguards, minimization and required risk assessment. Saudi Arabia does not impose an absolute localization rule.

Connect discovery, decisions and response in one accountable operating record.

Captain Compliance helps privacy, legal, security, marketing and engineering teams understand where personal data is collected, document the controls applied to it and coordinate ongoing PDPL responsibilities. A privacy notice describes intended behavior; production systems determine what actually happens. Use the platform to identify new processing, route it for review, document the applicable purpose and basis, deploy the appropriate control and preserve the resulting evidence. Configure Arabic and English experiences where they help the intended audience understand the processing, but bilingual content is not a substitute for accurate legal analysis, and the platform preserves human review for legal interpretations and risk decisions.

S

Continuous website discovery

Scan websites for cookies, pixels, scripts, tags and similar technologies. Monitor changes over time and flag newly detected activity for classification before undocumented processing becomes part of the production environment.

C

Consent and preference records

Deploy configurable consent experiences, including Arabic and English presentation where appropriate. Record purposes, choices, timestamps, notice versions and withdrawals so the organization can demonstrate how an individual’s preference was captured.

N

Dynamic privacy notices

Connect notices to actual processing purposes, categories, recipients, rights, retention and transfer information. Maintain versions and an audit history as processing activities and disclosures change.

R

Data-subject request workflows

Receive, verify, assign and track access, copy, correction, updating and destruction requests. Maintain request history, response evidence, decisions and the applicable 30-day deadline.

P

Processing records and ownership

Centralize processing purposes, data categories, individual categories, recipients, retention periods, transfers, safeguards and accountable owners. Preserve records and their history for the applicable processing and post-processing periods.

A

DPIA and risk documentation

Create structured impact-assessment workflows, connect identified risks to safeguards and remediation tasks, and retain review and approval evidence for sensitive, large-scale, monitored or technology-driven processing.

T

Vendor and transfer mapping

Record processors, subprocessors, countries, transfer purposes, safeguards, contracts and risk assessments. Connect overseas website vendors and cloud services to the processing activities and data categories they support.

B

Breach-response coordination

Coordinate incident intake, assessment, ownership, affected data, individual impact, regulatory decisions and notification evidence. Tracks the 72-hour deadline when the regulatory threshold may be met, without making that legal determination for you.

Your website can create PDPL obligations before a form is submitted.

Cookies, pixels, analytics tags, advertising tools, device identifiers, chat technologies and session-replay software can collect or generate personal data when they directly or indirectly identify an individual. The PDPL is not a cookie-specific law and does not prescribe one universal banner design, but the underlying collection and processing still need an appropriate purpose, legal basis, notice and supporting controls. A scanner can reveal which technologies load and what changes over time; it cannot determine the legal basis by itself. Privacy and legal teams still need to classify each technology, identify its purposes and recipients, determine whether consent or another lawful ground is appropriate, and confirm whether the resulting data leaves Saudi Arabia. Direct marketing requires particular attention: controllers processing personal data for direct-marketing purposes must obtain consent, identify the sender and provide an easy, free mechanism for stopping marketing. Sensitive personal data must not be processed for marketing, even with consent. In practice that means: discover cookies, pixels and session replay; block nonessential technology when required; record consent by purpose and notice version; map vendors and overseas destinations; and monitor changes after deployment.

Book a Saudi PDPL review
A PRACTICAL SAUDI PDPL ROLLOUT
  • Day 1 — Website and processing baseline — Scan public websites, identify trackers and forms, inventory major systems, locate existing notices and map high-priority processors and transfers
  • Week 1 — Purposes, notices and consent — Document purposes and processing bases, correct consent implementation, connect Arabic and English disclosures where appropriate, and establish preference and withdrawal records
  • Week 2 — Rights, RoPA and retention — Configure the request workflow, assign business owners, assemble processing records and connect each data category to a retention or destruction rule
  • Week 3 — DPIA, DPO and transfer controls — Identify mandatory impact assessments, confirm whether the DPO triggers apply, review processors and document international-transfer mechanisms and risk assessments
  • Ongoing — Monitoring and incident readiness — Continuously monitor website changes, update records and notices, review vendors, rehearse the 72-hour breach process and track new SDAIA rules and guidance

From scattered documents to a defensible operating record.

Without an operating program
  • Website trackers are not connected to documented purposes
  • Consent evidence is scattered across screenshots and systems
  • Legitimate interests is used without a completed assessment
  • Processing records become outdated soon after creation
  • Rights requests depend on email and individual memory
  • Overseas vendors are not connected to transfer safeguards
  • DPIA triggers are identified inconsistently
  • The 72-hour breach process has not been rehearsed
With Captain Compliance
  • Website technologies are continuously discovered and reviewed
  • Purposes, choices, notices and withdrawals create an evidence trail
  • Legitimate-interest decisions are documented and assigned
  • Processing records have owners and a maintained history
  • Rights requests are verified, routed and deadline-tracked
  • Vendors, destinations and transfer mechanisms are mapped
  • Risk assessments connect findings to remediation
  • Incident decisions and notification tasks are coordinated

Saudi Arabia’s PDPL, answered plainly.

When did Saudi Arabia’s PDPL become enforceable?+
The PDPL took effect on September 14, 2023. Organizations generally received a one-year period to bring their processing into compliance, and that grace period ended on September 14, 2024. The law and its Implementing Regulations should now be treated as current operational requirements, not future obligations.
Who must comply with the Saudi PDPL?+
The law applies to personal-data processing that takes place in Saudi Arabia. It also applies to processing conducted outside Saudi Arabia involving personal data of individuals residing in the Kingdom. Domestic scope is not limited to Saudi citizens, and foreign organizations can fall within the law when their processing meets the extraterritorial condition.
Does every processing activity require consent?+
No. Consent is an important processing basis, but the PDPL recognizes defined circumstances in which processing may occur without consent. Each activity needs a documented basis that actually fits the statutory conditions. An organization should not use one broad consent statement to cover unrelated purposes, or label every activity “legitimate interests”.
When can legitimate interests be used?+
A private-sector controller may rely on legitimate interests only when the purpose is lawful, the processing is necessary, the controller’s interests are properly balanced against the data subject’s rights and interests, and the activity falls within the individual’s reasonable expectations. The controller must document the assessment. Public entities cannot use this basis, and it cannot be used for sensitive personal data.
Does the Saudi PDPL require an Arabic cookie banner or privacy notice?+
The PDPL requires information and consent requests to be clear and understandable to the intended individual, but the law should not be summarized as imposing one universal Arabic-only or bilingual banner format. Arabic-first or bilingual presentation is often prudent for Saudi-facing services because it improves accessibility and the quality of consent. Applicable sector rules and the actual audience should also be considered.
What rights do individuals have under the PDPL?+
Individuals have rights to be informed, access their personal data, obtain a readable copy, request correction, completion or updating, and request destruction, subject to statutory conditions and exceptions. Controllers generally must act without delay and within 30 days. A qualifying extension may add no more than 30 days if the individual is notified in advance and receives the reason.
When must a breach be reported to SDAIA?+
A controller must notify the competent authority within no more than 72 hours after becoming aware of an incident if it may harm personal data or a data subject, or conflict with the individual’s rights or interests. If complete information is unavailable, the controller should provide what it has and supplement the notification as soon as possible with an explanation. Affected individuals must be notified without undue delay when the separate individual-notification threshold is met.
Must every organization appoint a DPO?+
No. The Implementing Regulations establish defined DPO triggers. These include public entities providing services involving large-scale processing, controllers whose primary activities require regular and systematic monitoring, and controllers whose core activities involve sensitive personal data. A DPO may be an executive, employee or external contractor, subject to applicable appointment requirements.
Can personal data be transferred outside Saudi Arabia?+
Yes. The PDPL does not impose an absolute ban on overseas transfers. The transfer must satisfy the permitted-purpose and general protection conditions. Depending on the destination and circumstances, the controller may need an adequacy basis, approved Binding Common Rules, Standard Contractual Clauses, certification with enforceable commitments, or a limited exception. A documented transfer risk assessment is required in specified cases.
What penalties can apply under the PDPL?+
Other violations of the PDPL may result in warnings or fines of up to SAR 5 million, and the maximum fine may be doubled for a repeat violation. A separate criminal provision applies to intentionally disclosing or publishing sensitive data in violation of the law with the intent to harm the data subject or obtain personal benefit; that offense may result in up to two years imprisonment, a fine up to SAR 3 million, or both. Individuals may also seek compensation for qualifying material or moral damage.

Make PDPL responsibilities visible, assigned and repeatable.

Captain Compliance helps privacy, legal, security, marketing and engineering teams connect data discovery to the records and workflows behind Saudi PDPL operations. Discover website technologies, document purposes and preferences, coordinate individual requests, maintain processing evidence, map transfers and prepare for breach response from one operating environment. Captain Compliance provides privacy technology and operational support, not legal services.

Book a Saudi PDPL review View pricing