
22/06/2026
The Personal Data Protection Law (PDPL): What Every Company Needs to Know
A comprehensive overview of the Saudi Personal Data Protection Law and the key obligations it places on companies and organisations.
The Personal Data Protection Law (PDPL): A Compliance Guide for Companies
The Personal Data Protection Law (PDPL) was issued by Royal Decree No. M/19 of 1443H, and came into force in September 2023. The law requires all entities that process the personal data of individuals within the Kingdom of Saudi Arabia to comply with its provisions.
What Is Personal Data?
The law defines personal data as any information relating to an identified or identifiable natural person, directly or indirectly, including: name, ID number, contact details, location data, and health and financial data.
Key Obligations on Companies
1. Obtaining explicit consent: Explicit, clear consent must be obtained from the data subject before processing or disclosing their data.
2. Purpose limitation: Data may not be used for purposes other than those for which it was collected.
3. Right to access, correction, and deletion: The data subject has the right to access their data and request its correction or deletion.
4. Breach notification: The law requires entities to notify the Saudi Data and AI Authority (SDAIA) within 72 hours of discovering any data breach.
5. Data Protection Officer: Certain entities are required to appoint a qualified Data Protection Officer (DPO).
Penalties
Fines range between SAR 1 million and SAR 5 million in cases of unlawful disclosure of sensitive data, in addition to criminal penalties in serious cases.
How Can Your Company Achieve Compliance?
- Review and update your current privacy policy.
- Conduct a Data Protection Impact Assessment (DPIA).
- Train and qualify your internal team.
- Engage a legal consultant specialising in regulatory compliance.
The Trivo Legal Consulting team is ready to help your company through the full journey of PDPL compliance.
