Saudi Arabia's Personal Data Protection Law (PDPL) regulates the processing of personal data. The National Data Management Office (NDMO) oversees implementation. This guide covers lawful basis and consent, data subject rights, cross-border transfer, processors, and penalties. See anti-bribery, employment, and e-commerce.
Overview
The PDPL applies to the processing of personal data (any data that identifies or could identify a natural person) carried out by controllers and processors in Saudi Arabia or that relates to data subjects in Saudi Arabia. It sets out principles (lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, security, accountability) and grants data subjects rights. Cross-border transfer is restricted. Implementing regulations and NDMO guidance specify details; compliance is mandatory for businesses that process personal data.
PDPL and NDMO
The Personal Data Protection Law was enacted to align Saudi Arabia with international data protection standards. The National Data Management Office (NDMO) is the supervisory authority: it issues regulations and guidance, receives complaints, and can impose penalties. Controllers may need to register or notify in certain cases; check the implementing regulations. Keep abreast of NDMO announcements and sector-specific rules (e.g. health, finance).
Lawful Basis and Consent
Personal data may only be processed on a lawful basis. Common bases include: consent of the data subject; performance of a contract; legal obligation; vital interests; or legitimate interests (where permitted and not overridden by the data subject's rights). Consent must be freely given, specific, informed, and unambiguous. Document the lawful basis for each processing activity and ensure privacy notices are clear and accessible. For sensitive data (e.g. health, biometrics), stricter conditions may apply.
Data Subject Rights
Data subjects have rights including: access to their data; correction of inaccuracies; erasure (in specified circumstances); restriction of processing; objection; and data portability where applicable. Controllers must respond within the time limits set by the PDPL and regulations. Establish procedures to receive and handle requests and to verify the identity of the requester. Refusal must be justified and communicated; data subjects can complain to the NDMO.
Cross-Border Transfer
Transfer of personal data outside Saudi Arabia is restricted unless the destination country is deemed adequate by the NDMO, or another exception applies (e.g. explicit consent, necessity for contract performance, standard contractual clauses or other approved mechanisms, or NDMO approval). Transfer to group companies or to cloud providers in other countries must be assessed and documented. Non-compliance can result in significant fines and orders to cease processing. Plan data flows and put in place transfer mechanisms before transferring.
Processors and Contracts
Where a controller engages a processor (e.g. IT vendor, payroll provider), the processing must be governed by a contract that meets PDPL requirements: subject matter, duration, nature and purpose of processing, type of data, obligations of the processor (confidentiality, security, sub-processor rules, assistance with subject rights and breaches). The controller remains responsible for ensuring the processor complies. Map all processors and sub-processors and update contracts.
Penalties
The PDPL and regulations provide for administrative fines and other sanctions for violations (e.g. processing without lawful basis, failure to honour data subject rights, unlawful cross-border transfer, breach of security). Fines can be substantial (up to SAR 5 million or more for serious violations, depending on the implementing rules). The NDMO can also order cessation of processing and require remediation. Implement a compliance program and document your lawful basis, policies, and procedures.
PDPL Compliance Checklist
- Map personal data processing (what, why, where, who); identify lawful basis for each activity.
- Update privacy notices and obtain consent where consent is the basis; document consent.
- Implement procedures to respond to data subject rights (access, correction, erasure, etc.) within deadlines.
- Assess cross-border transfers; use adequate country, consent, or approved transfer mechanism.
- Put processor contracts in place and ensure security measures and breach response procedures.