Don’t do SECURITY. Do business SECURELY.

Saudi Arabia’s PDPL becomes fully enforceable

Saudi Arabia’s Personal Data Protection Law is now fully enforceable after a one-year grace period.

Saudi Arabia’s Personal Data Protection Law (PDPL) becomes fully enforceable today, following a one-year grace period.

Key points

  • Controllers must implement organisational, administrative and technical security measures.
  • Breaches must be notified to SDAIA within 72 hours.
  • Transfers outside the Kingdom are restricted.
  • The law has extraterritorial reach.

UK organisations processing data about individuals in Saudi Arabia need to meet PDPL requirements. Implementing regulations add rules on data transfers, registration and appointing a data protection officer in certain cases. UK organisations offering goods or services to people in Saudi Arabia should review transfer mechanisms and incident response for the 72-hour SDAIA deadline.

Source: Personal Data Protection Law and regulations (SDAIA)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights