🎉 Get 20% OFF the first C-DPO cohort! Code:
20KSACDPO
ChatGPT Summarize Button
GCC Data Protection Logo

Our YouTube channel has lots of webinars and short videos talking about compliance.

These are the two foundational documents. You have the text of the PDPL and the Implementing Regulation. The PDPL is split into 43 Articles but repeatedly refers to Regulations. The Implementing Regulations are also mandatory – in many instances they interpret, build upon and explain the PDPL – in other cases, the Regulations fill gaps.

Both documents should be read together. To make this easier, we have published a side-by-side comparison at:

https://www.linkedin.com/posts/bgdp_ksa-pdpl-law-regs-summary-activity-7194758614996205568-eGGP?utm_source=share&utm_medium=member_desktop&rcm=ACoAABO-c3YBIZ1zHp6vflqmSVHboz42J7u0ujM

Personal Data Protection Law

https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf

The Implementing Regulation (and Regulation on Personal Data Transfer outside the Kingdom)

https://sdaia.gov.sa/en/SDAIA/about/Documents/ExecutiveRegulations.pdf

You may remember that early drafts of the PDPL made sending data outside of the Kingdom impossible. Thankfully, a more practical set of Regulations has been published. However, it needs to be read carefully and in conjuction with the Risk Assessment Guidelines, which were published in February 2025.

We still await SDAIA’s list of adequate countries, which should make life easier in international data transfers – at the moment, we mostly seem to have to rely on Standard Contract Clauses, which a lot of companies outside KSA are unlikely to sign – simply because they won’t understand them.

Regulation on Personal Data Transfer Outside the Kingdom

https://sdaia.gov.sa/Documents/RegulationonPersonalDataEN.pdf

Guidelines for Binding Common Rules (BCR) for Personal Data Transfers

https://sdaia.gov.sa/Documents/CommonRulesBCRForPersonalDataTransferEN.pdf

Standard Contractual Clauses (SCC) for Personal Data Transfers

https://sdaia.gov.sa/Documents/StandardContractualClausesForPersonalDataTransferEN.pdf

Transfer Risk Assessment

https://sdaia.gov.sa/en/SDAIA/about/Documents/RisksTransferringDataOutsideKingdomEn.pdf

A lot of data protection laws around the world require data controllers to register with the supervisory authority. The PDPL is similar – you will need to register as a data controller (with separate rules if you are a government entity).

In addition, you may need a Data Protection Officer (DPO) and this person should also be registered with SDAIA.

The guidance is available, but please note that decided what ‘large-scale’ is is tricky – you will need to make a judgement call. Once you have decided, you will need to register the relevant person – but they will need to have the relevant expertise as required in the Regulations

The Rules Governing the National Register of Controllers within the Kingdom

https://sdaia.gov.sa/Documents/TheRulesGoverningTheNationalRegisterOfControllersWithinTheKingdomPublicEN.pdf


Registration of Private Entities as a Data Controller

https://dgp.sdaia.gov.sa/wps/portal/pdp/Registration/private

Registration of Government Entities as a Data Controller

https://dgp.sdaia.gov.sa/wps/portal/pdp/Registration/government

Rules for Appointing a Personal Data Protection Officer (DPO)

https://sdaia.gov.sa/en/SDAIA/about/Documents/RulesforAppointingPersonalDataProtectionOfficer.pdf

Guidance tool to identify whether or not the Appointment of a DPO is Mandatory

https://dgp.sdaia.gov.sa/wps/portal/pdp/services/servicesdetails/TooltoDeterminingDataProtectionOfficer/

It took Europe a long time, through development of caselaw and consensus among so many countries to start producing guidance. SDAIA has done well to produce so much in so short a time. People will be critical that it still leaves so many gaps – that is the nature of guidance and trying to answer every question.

While the guidance documents are just guidance, we would advise clients to stick to them as closely as possible and if they diverge, to have a very strong basis for this – when SDAIA starts to enforce, it will likely refer to these guidance documents and, much like other regulators have in their early days, treat them as law

Elaboration and Developing Privacy Policy Guideline

https://sdaia.gov.sa/Documents/PrivacyPolicyGuideline.pdf

Minimum Personal Data Determination Guideline

https://sdaia.gov.sa/Documents/MinmumPDGuideline.pdf

Personal Data Destruction, Anonymization, and Pseudonymisation Guideline

https://sdaia.gov.sa/Documents/PersonalDataDestructionAnonymizationAndEncryptionGuideline.pdf

Personal Data Disclosure Cases Guideline

https://sdaia.gov.sa/Documents/PersonalDataDisclosureCasesGuideline.pdf

Personal Data Processing Activities Records Guideline (RoPA)

https://sdaia.gov.sa/Documents/PersonalDataProcessingActivitiesRecordsGuideline.pdf

Self-Assessment Guidelines

https://sdaia.gov.sa/ar/Research/Documents/pre%20assesment%20draft%20Guidance%2021.06.2023%20v2%20(2).pdf

PDPL Compliance Self-Assessment

https://dgp.sdaia.gov.sa/wps/portal/pdp/services/servicesdetails/selfassessment

Privacy Impact Assessment (PIA)

https://dgp.sdaia.gov.sa/wps/portal/pdp/services/details/PrivacyImpactAssessment

Breaches and complaints are what organizations dread – these are more likely than anything else to drive SDAIA’s regulatory action. The guidance on breaches might, depending on how you interpret it, suggest that all breaches are reported, or only serious ones. These documents are useful to show how SDAIA will handle things when something goes wrong, but more than any other guidance, this is where you will need to know how to react – for example, how will you know what to report, how is that assessed through a rigid framework that is consistent and defensible? These pieces of guidance raise more questions than the answer!

Personal Data Breach Notification

https://dgp.sdaia.gov.sa/wps/portal/pdp/services/details/PersonalDataBreachNotification

Reports & Complaints about PDPL Violations

https://dgp.sdaia.gov.sa/wps/portal/pdp/services/details/ReportsandComplaints

Every week on a Tuesday we publish a newsletter on the PDPL. It is packed with practical insights on how to comply with the law as well as analysis of privacy trends. 

We have the highest-rated introductory course to the KSA PDPL on Udemy. It is normally $19.99 but contact us for a voucher that will get you access for free.