These are the two foundational documents. You have the text of the PDPL and the Implementing Regulation. The PDPL is split into 43 Articles but repeatedly refers to Regulations. The Implementing Regulations are also mandatory – in many instances they interpret, build upon and explain the PDPL – in other cases, the Regulations fill gaps.
Both documents should be read together. To make this easier, we have published a side-by-side comparison at:
Personal Data Protection Law
The Implementing Regulation (and Regulation on Personal Data Transfer outside the Kingdom)
https://sdaia.gov.sa/en/SDAIA/
You may remember that early drafts of the PDPL made sending data outside of the Kingdom impossible. Thankfully, a more practical set of Regulations has been published. However, it needs to be read carefully and in conjuction with the Risk Assessment Guidelines, which were published in February 2025.
We still await SDAIA’s list of adequate countries, which should make life easier in international data transfers – at the moment, we mostly seem to have to rely on Standard Contract Clauses, which a lot of companies outside KSA are unlikely to sign – simply because they won’t understand them.
Regulation on Personal Data Transfer Outside the Kingdom
https://sdaia.gov.sa/Documents/RegulationonPersonalDataEN.pdf
Guidelines for Binding Common Rules (BCR) for Personal Data Transfers
https://sdaia.gov.sa/Documents/CommonRulesBCRForPersonalDataTransferEN.pdf
Standard Contractual Clauses (SCC) for Personal Data Transfers
https://sdaia.gov.sa/Documents/StandardContractualClausesForPersonalDataTransferEN.pdf
Transfer Risk Assessment
https://sdaia.gov.sa/en/SDAIA/about/Documents/RisksTransferringDataOutsideKingdomEn.pdf
A lot of data protection laws around the world require data controllers to register with the supervisory authority. The PDPL is similar – you will need to register as a data controller (with separate rules if you are a government entity).
In addition, you may need a Data Protection Officer (DPO) and this person should also be registered with SDAIA.
The guidance is available, but please note that decided what ‘large-scale’ is is tricky – you will need to make a judgement call. Once you have decided, you will need to register the relevant person – but they will need to have the relevant expertise as required in the Regulations
The Rules Governing the National Register of Controllers within the Kingdom
Registration of Private Entities as a Data Controller
https://dgp.sdaia.gov.sa/wps/
Registration of Government Entities as a Data Controller
https://dgp.sdaia.gov.sa/wps/
Rules for Appointing a Personal Data Protection Officer (DPO)
https://sdaia.gov.sa/en/SDAIA/about/Documents/RulesforAppointingPersonalDataProtectionOfficer.pdf
Guidance tool to identify whether or not the Appointment of a DPO is Mandatory
It took Europe a long time, through development of caselaw and consensus among so many countries to start producing guidance. SDAIA has done well to produce so much in so short a time. People will be critical that it still leaves so many gaps – that is the nature of guidance and trying to answer every question.
While the guidance documents are just guidance, we would advise clients to stick to them as closely as possible and if they diverge, to have a very strong basis for this – when SDAIA starts to enforce, it will likely refer to these guidance documents and, much like other regulators have in their early days, treat them as law
Elaboration and Developing Privacy Policy Guideline
https://sdaia.gov.sa/Documents/PrivacyPolicyGuideline.pdf
Minimum Personal Data Determination Guideline
https://sdaia.gov.sa/Documents/MinmumPDGuideline.pdf
Personal Data Destruction, Anonymization, and Pseudonymisation Guideline
https://sdaia.gov.sa/Documents/PersonalDataDestructionAnonymizationAndEncryptionGuideline.pdf
Personal Data Disclosure Cases Guideline
https://sdaia.gov.sa/Documents/PersonalDataDisclosureCasesGuideline.pdf
Personal Data Processing Activities Records Guideline (RoPA)
https://sdaia.gov.sa/Documents/PersonalDataProcessingActivitiesRecordsGuideline.pdf
Self-Assessment Guidelines
PDPL Compliance Self-Assessment
https://dgp.sdaia.gov.sa/wps/portal/pdp/services/servicesdetails/selfassessment
Privacy Impact Assessment (PIA)
https://dgp.sdaia.gov.sa/wps/portal/pdp/services/details/PrivacyImpactAssessment
Breaches and complaints are what organizations dread – these are more likely than anything else to drive SDAIA’s regulatory action. The guidance on breaches might, depending on how you interpret it, suggest that all breaches are reported, or only serious ones. These documents are useful to show how SDAIA will handle things when something goes wrong, but more than any other guidance, this is where you will need to know how to react – for example, how will you know what to report, how is that assessed through a rigid framework that is consistent and defensible? These pieces of guidance raise more questions than the answer!
Personal Data Breach Notification
https://dgp.sdaia.gov.sa/wps/
Reports & Complaints about PDPL Violations
https://dgp.sdaia.gov.sa/wps/
Every week on a Tuesday we publish a newsletter on the PDPL. It is packed with practical insights on how to comply with the law as well as analysis of privacy trends.
We have the highest-rated introductory course to the KSA PDPL on Udemy. It is normally $19.99 but contact us for a voucher that will get you access for free.