signzy

API Marketplace

downArrow
Logo
Responsive
Decorative line

Personal Data Protection Law

Saudi Arabia

Saudi Arabia

2021

Privacy

Overview

Saudi Arabia's Personal Data Protection Law (PDPL) was enacted by Royal Decree M/19 in 2021 and came into force in March 2022. It establishes a national framework for regulating the collection, processing, storage, and transfer of personal data. The law is overseen by the Saudi Data and Artificial Intelligence Authority (SDAIA), with full enforcement scheduled from September 2024.
The law applies to banks, telecommunication providers, e-commerce platforms, government entities, and other public and private organizations processing personal data in or targeting Saudi Arabia. It introduces obligations related to consent, purpose limitation, data subject rights, and data transfer restrictions.

Key Obligations

  • Obtain explicit consent before collecting or processing personal data
  • Use personal data only for clearly defined and legitimate purposes
  • Grant individuals rights to access, correct, delete, and object to the use of their data
  • Restrict cross-border data transfers, which are generally prohibited unless specific exemptions apply
  • Conduct impact assessments for high-risk processing activities
  • Implement security measures to protect personal data from loss, misuse, or unauthorized access
  • Notify SDAIA and affected individuals in the event of a data breach

FAQ

Who regulates the PDPL in Saudi Arabia?

The Saudi Data and Artificial Intelligence Authority (SDAIA) is the primary regulator.

When will the law be fully enforced?

Full enforcement begins on September 14, 2024, following a two-year grace period.

Can personal data be transferred outside Saudi Arabia?

Generally no, unless SDAIA grants specific exemptions or the transfer meets legal conditions.

What rights do individuals have under the law?

They have the right to access, correct, delete, and object to the processing of their personal Data.