PDPL in Practice: What the Implementing Regulations Changed

The Personal Data Protection Law stopped being a reading exercise some time ago. The general compliance grace period ended on 14 September 2024, and the Implementing Regulations and the Transfer Regulation are in force. They are also moving: SDAIA consulted on a third round of amendments to the Implementing Regulations in April and May 2025 (among the proposals: deleting the 90-day complaint window and adding a 10-business-day deadline for answering SDAIA compliance inquiries), and the final text had not been published at the time of writing. The interesting subject in 2026 is not what the law says. It is which obligations bite in practice, and where programs are still exposed.

What changed since the 2021 text

Three things matter more than the original royal decree. First, the 2023 amendments reshaped the law substantially, most visibly on cross-border transfers and the addition of legitimate interest as a lawful basis. Second, the Implementing Regulations turned principles into mechanics: response clocks, notification duties, records, and the conditions attached to each legal basis. Third, the Personal Data Transfer Regulation created a workable transfer regime (adequacy decisions, standard contractual clauses, binding common rules, accreditation certificates, and the transfer risk assessment) where the original text imposed a materially more restrictive framework.

A program built against the 2021 reading and never revisited is now wrong in both directions: stricter than required on transfers, and looser than required on notices, records, and response clocks.

The penalty reality, corrected

A persistent misreading caps PDPL exposure at SAR 3 million. That figure is the criminal penalty for disclosing or publishing sensitive data with intent to harm or to gain benefit: up to two years’ imprisonment and/or a fine of up to SAR 3m, imposed by the courts, and the fine can itself double for recidivism (Article 35). The administrative regime is separate and larger: a warning or an administrative fine of up to SAR 5 million for a violation, potentially doubled for repetition (Article 36). Administrative penalties are decided by committees formed under the law, subject to approval, and are appealable; the criminal track is judicial. Budget conversations that anchor on “three million riyals” are anchoring on the wrong number and the wrong regime.

The five obligations that bite

1. The notice, before or at collection. A privacy policy somewhere on a website does not by itself satisfy the duty to inform data subjects before or at the time of collection: purpose, basis, their rights, and how to exercise them, available where the data subject can actually see them. Forms are where this fails. The notice exists, but the person handing over their data never meets it.

2. The data subject request clock. Plan for 30 days, extendable once by up to a further 30 where fulfilling the request requires disproportionate effort or the controller receives multiple requests from the same data subject, with the data subject told of the extension and its reasons in advance. The failure mode is not refusing requests; it is having no intake channel, so the clock starts on an email nobody owns.

3. Breach notification: a clock with a threshold. If a breach may harm personal data or data subjects, or conflict with their rights or interests, notify SDAIA within 72 hours of becoming aware of it, and notify affected individuals without undue delay where that harm test is met for them. The operational test: who in your organization knows they own that threshold judgment at 11pm on a Thursday, and does the incident severity matrix name the trigger? If breach notification lives only in the privacy policy and not in the incident-response plan, it does not exist.

4. Transfers need a purpose first, then a mechanism. Post-amendment, cross-border transfer is workable, but it rests on two legs. The transfer must serve a purpose the law and the Transfer Regulation recognize and respect the general restrictions. The law’s default gate is an adequacy decision for the destination, but as of mid-2026 SDAIA has not published the adequacy list, so in practice every transfer proceeds under an approved safeguard: SDAIA’s standard contractual clauses (issued September 2024), binding common rules within a group, or an accreditation certificate. A transfer risk assessment is required for transfers relying on those exemption provisions, as well as for continuous or large-scale transfers of sensitive data; SDAIA’s Risk Assessment Guideline for transfers (February 2025) sets out the four-step assessment to use. A provider’s DPA alone does not establish PDPL transfer compliance; assess the recipient, the onward transfers, and which safeguard actually applies.

5. Legitimate interest exists, with homework attached. The amended law allows legitimate interest as a basis for non-sensitive data: for controllers other than public entities, and conditional on a lawful purpose, the data subject’s reasonable expectations, a balancing of interests, necessity, and a documented assessment. Used honestly, it solves real problems (security logging is the classic case). Used as a label for “we wanted the data,” it fails the first question anyone asks: show me the assessment.

A worked example, live

Rather than describe these mechanics in the abstract: this site’s own Privacy Notice is an illustrative PDPL artifact: per-activity legal bases, a consent-withdrawal consequence, the named processor and its subprocessor chain, retention criteria, the 30+30 response commitment, and the 90-day SDAIA complaint window (running from the incident or from awareness of it). It is a small controller’s notice, deliberately. The point is that the mechanics scale down as well as up.

Where this sits in the wider stack

PDPL is one layer of the Saudi data stack, not the whole of it. Public entities and their partners carry NDMO standards on top. NCA’s Data Cybersecurity Controls (DCC) apply to government organizations and their entities, to CNI owners and operators, and to private-sector organizations hosting critical national infrastructure (with wider adoption encouraged), governing the cybersecurity of the same data whose processing the PDPL governs. Scoping the layers is the first deliverable of any program. The KSA regulatory applicability matrix maps who carries what.

Verify against the current official publications (the PDPL, its Implementing Regulations, and the Transfer Regulation as amended) before relying on any statement here. Related: From the assessor’s chair · Eight ways KSA programs fail.