Back to News & Updates
Saudi Regulatory Update

Saudi Arabia's Personal Data Protection Law: What Foreign Companies Must Do to Comply in 2026

Published September 8, 2026· Northman Sterling Legal
Saudi Arabia's Personal Data Protection Law: What Foreign Companies Must Do to Comply in 2026

If your company does business with Saudi Arabia in any way, PDPL compliance in Saudi Arabia is not something you can put off any longer. Saudi Arabia's Personal Data Protection Law (PDPL) is no longer a compliance item companies can defer. The law, issued by Royal Decree No. M/19, took effect on 14 September 2023. After a grace period that closed on 14 September 2024, the Saudi Data & AI Authority (SDAIA) has moved into active enforcement. By early 2026, SDAIA had issued dozens of formal enforcement decisions across multiple industries, with fines reaching into the millions of Saudi Riyals.

For foreign companies operating in, entering, or simply processing data connected to Saudi Arabia, this shift changes the calculus. Data protection compliance is no longer a document sitting in a drawer for the day a regulator asks. It is an operational requirement, and it is actively checked.

Does the PDPL Apply to Your Company?

The PDPL applies to the processing of personal data of individuals residing in the Kingdom, by any means, including processing carried out by entities located outside Saudi Arabia. In practice, this means a company does not need a Saudi office or a Saudi-registered entity to fall within scope. If your business collects, stores, or otherwise processes personal data belonging to people in Saudi Arabia, whether customers, employees, job applicants, or website visitors, the law applies to you. It does not matter where your servers or your headquarters sit.

This is the single most common misunderstanding we see among foreign investors researching how to comply with Saudi data protection law: assuming that because incorporation, licensing, or day-to-day operations are still being finalized, PDPL obligations have not yet started. They have, from the moment Saudi resident personal data is touched.

Core PDPL Compliance Requirements for Data Controllers

The PDPL is built around a familiar set of data protection principles: transparency, purpose limitation, data minimization, accuracy, and accountability. Its practical requirements, however, are specific and enforceable. At minimum, companies processing personal data connected to Saudi Arabia should have in place:

  • A lawful basis and clear consent mechanism for collecting and using personal data, with consent that is specific, informed, and easily withdrawn.
  • Registration on SDAIA's National Data Governance Platform, particularly where the company processes sensitive data, conducts cross-border transfers, or handles data belonging to children or vulnerable individuals.
  • A designated data protection officer, or an equivalent function, responsible for oversight and for acting as the point of contact with SDAIA.
  • Documented processes for responding to individual rights requests, including access, correction, and deletion of personal data, within the timeframes the law requires.
  • A breach response plan capable of notifying SDAIA within 72 hours of becoming aware of an incident. Notification is mandatory once a breach may cause harm to the data or the data subject. The law does not allow a controller to self-assess materiality and withhold notification on that basis.

Cross-Border Data Transfers Under Saudi Law

Many foreign companies route Saudi customer or employee data through group systems, cloud providers, or HR platforms hosted outside the Kingdom. SDAIA's Regulation on Personal Data Transfer Outside the Kingdom, issued in September 2024, sets specific conditions before such transfers are permitted. Saudi Arabia has not yet published a list of jurisdictions treated as offering adequate protection. This means most cross-border data transfers currently require additional safeguards, such as standard contractual clauses or binding common rules, rather than relying on the destination country's status alone.

This is a point worth flagging early to any group IT or HR function: a data flow that is routine in your home jurisdiction may need a separate legal basis once Saudi resident data is involved.

PDPL Penalties and Fines in Saudi Arabia

The PDPL provides for fines of up to SAR 5,000,000 for general violations, and up to SAR 3,000,000 specifically for the unlawful disclosure or publication of sensitive data. Fines can be doubled for repeat offenders, and enforcement decisions to date have included operational restrictions alongside financial penalties. Given SDAIA's confirmed shift into active enforcement, these are no longer theoretical maximums. They are figures being applied against real companies right now.

A Practical PDPL Compliance Checklist

For a foreign company already operating in Saudi Arabia, or in the process of entering the market, a realistic first pass at PDPL readiness should cover:

  1. Map what personal data you actually collect, from whom, and why. You cannot build lawful bases or consent language for data flows no one has documented.
  2. Determine whether registration on the National Data Governance Platform is required for your specific processing activities.
  3. Review every cross-border transfer, including group intercompany transfers and third-party SaaS providers, against SDAIA's transfer regulation.
  4. Put a breach notification procedure in writing, with clear internal ownership, so the 72-hour clock can realistically be met.
  5. Update employment contracts, HR systems, and privacy notices to reflect PDPL consent and rights requirements, not just your home jurisdiction's data protection law.

How Northman Sterling Legal Can Help

We advise foreign companies on regulatory and compliance matters across Saudi Arabia, including data protection readiness alongside company formation, employment law, and ongoing regulatory obligations. If your business is entering the Saudi market, or has not yet reviewed its data processing activities against the PDPL, our team can help you assess your exposure and put a compliant framework in place.

Official Sources and References

This article draws on the official text of the PDPL and guidance published by the Saudi Data & AI Authority (SDAIA), as well as independent legal analysis of Saudi Arabia's active enforcement record:

This article is for general informational purposes and does not constitute legal advice. For guidance specific to your company's data processing activities, speak with our team.