Saudi Arabia’s Personal Data Protection Law (PDPL) becomes fully enforceable today, following a one-year grace period.
Key points
- Controllers must implement organisational, administrative and technical security measures.
- Breaches must be notified to SDAIA within 72 hours.
- Transfers outside the Kingdom are restricted.
- The law has extraterritorial reach.
UK organisations processing data about individuals in Saudi Arabia need to meet PDPL requirements. Implementing regulations add rules on data transfers, registration and appointing a data protection officer in certain cases. UK organisations offering goods or services to people in Saudi Arabia should review transfer mechanisms and incident response for the 72-hour SDAIA deadline.
Source: Personal Data Protection Law and regulations (SDAIA)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.