Saudi Arabia Data Protection (PDPL): Compliance Guide 2026

Personal Data Protection Law: consent, lawful basis, data subject rights, cross-border transfer, and NDMO compliance.

Saudi Arabia's Personal Data Protection Law (PDPL) regulates the processing of personal data. The National Data Management Office (NDMO) oversees implementation. This guide covers lawful basis and consent, data subject rights, cross-border transfer, processors, and penalties. See anti-bribery, employment, and e-commerce.

Overview

The PDPL applies to the processing of personal data (any data that identifies or could identify a natural person) carried out by controllers and processors in Saudi Arabia or that relates to data subjects in Saudi Arabia. It sets out principles (lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, security, accountability) and grants data subjects rights. Cross-border transfer is restricted. Implementing regulations and NDMO guidance specify details; compliance is mandatory for businesses that process personal data.

PDPL and NDMO

The Personal Data Protection Law was enacted to align Saudi Arabia with international data protection standards. The National Data Management Office (NDMO) is the supervisory authority: it issues regulations and guidance, receives complaints, and can impose penalties. Controllers may need to register or notify in certain cases; check the implementing regulations. Keep abreast of NDMO announcements and sector-specific rules (e.g. health, finance).

Lawful Basis and Consent

Personal data may only be processed on a lawful basis. Common bases include: consent of the data subject; performance of a contract; legal obligation; vital interests; or legitimate interests (where permitted and not overridden by the data subject's rights). Consent must be freely given, specific, informed, and unambiguous. Document the lawful basis for each processing activity and ensure privacy notices are clear and accessible. For sensitive data (e.g. health, biometrics), stricter conditions may apply.

Data Subject Rights

Data subjects have rights including: access to their data; correction of inaccuracies; erasure (in specified circumstances); restriction of processing; objection; and data portability where applicable. Controllers must respond within the time limits set by the PDPL and regulations. Establish procedures to receive and handle requests and to verify the identity of the requester. Refusal must be justified and communicated; data subjects can complain to the NDMO.

Cross-Border Transfer

Transfer of personal data outside Saudi Arabia is restricted unless the destination country is deemed adequate by the NDMO, or another exception applies (e.g. explicit consent, necessity for contract performance, standard contractual clauses or other approved mechanisms, or NDMO approval). Transfer to group companies or to cloud providers in other countries must be assessed and documented. Non-compliance can result in significant fines and orders to cease processing. Plan data flows and put in place transfer mechanisms before transferring.

Processors and Contracts

Where a controller engages a processor (e.g. IT vendor, payroll provider), the processing must be governed by a contract that meets PDPL requirements: subject matter, duration, nature and purpose of processing, type of data, obligations of the processor (confidentiality, security, sub-processor rules, assistance with subject rights and breaches). The controller remains responsible for ensuring the processor complies. Map all processors and sub-processors and update contracts.

Penalties

The PDPL and regulations provide for administrative fines and other sanctions for violations (e.g. processing without lawful basis, failure to honour data subject rights, unlawful cross-border transfer, breach of security). Fines can be substantial (up to SAR 5 million or more for serious violations, depending on the implementing rules). The NDMO can also order cessation of processing and require remediation. Implement a compliance program and document your lawful basis, policies, and procedures.

PDPL Compliance Checklist

  • Map personal data processing (what, why, where, who); identify lawful basis for each activity.
  • Update privacy notices and obtain consent where consent is the basis; document consent.
  • Implement procedures to respond to data subject rights (access, correction, erasure, etc.) within deadlines.
  • Assess cross-border transfers; use adequate country, consent, or approved transfer mechanism.
  • Put processor contracts in place and ensure security measures and breach response procedures.

Frequently Asked Questions

Does PDPL apply to employee data?
Yes. Employee personal data is subject to the PDPL. Lawful basis may include contract performance, legal obligation (e.g. labour, tax), or consent where appropriate. Ensure HR processing is documented and privacy notices are provided. See employment contract.
Do we need to register with the NDMO?
The implementing regulations may require registration or notification in certain cases (e.g. high-risk processing, large-scale processing). Check the current NDMO requirements and sector rules.
Can we use consent for B2B marketing?
Marketing to individuals (including business contacts who are natural persons) involves personal data. You need a lawful basis; consent is one option and must be specific and easy to withdraw. Unsubscribe and consent management are important.
What if our cloud provider is outside Saudi Arabia?
Storing or processing personal data on servers abroad is a cross-border transfer. Ensure the provider is in an adequate country or put in place an approved transfer mechanism (e.g. NDMO-approved standard contractual clauses) and a processor contract that complies with the PDPL.
Is there a data breach notification requirement?
The PDPL and regulations typically require notification of serious breaches to the NDMO and, in certain cases, to affected data subjects. Implement an incident response plan and document any breach and notification.
How does PDPL interact with sector laws (e.g. banking)?
Sector regulators (e.g. SAMA, CMA) may impose additional data and confidentiality requirements. Comply with both the PDPL and sector rules; where they conflict, the more specific or stringent may apply. See fintech for financial sector context.

Data protection

Need PDPL Compliance Support?

We help with data mapping, lawful basis, cross-border transfer, and NDMO compliance.

Related guides

What Comes Next