Loading…
Loading…
The PDPL applies to any processing of personal data of Saudi residents regardless of where the controller or processor is located, giving it explicit extraterritorial reach. Core obligations crystallised at the end of the one-year grace period on 14 September 2024:
involve regular and systematic monitoring of large-scale personal data, processing of sensitive data, or that act as public-sector controllers.
hours of becoming aware of a personal-data breach that may cause harm to data, individuals, or violate their rights/interests; data subjects must be notified without undue delay where harm is likely.
Kingdom require compliance with the SDAIA Data Transfer Regulation (Regulations on Personal Data Transfers outside KSA), which permits transfers under (i) an adequacy assessment of the destination, (ii) SDAIA-prescribed SCCs, (iii) binding common rules for intra-group transfers, or (iv) explicit consent / narrow public-interest derogations. SDAIA published four SCC templates in 2024 covering the C2C, C2P, P2P, and P2C transfer patterns.
duty for controllers, and DPIAs required for high-risk processing including sensitive data, automated decision-making, or large-scale monitoring.
banks operating Vision-2030-linked workloads must execute SDAIA SCCs (or qualify for adequacy / BCR routes) before continuing outbound personal-data flows; intra-group HR and customer-data pipelines re-papered through 2024-2025.
thresholds for DPO and DPIA bite first for clinical trials, insurance, and digital-health platforms scaling under Saudi Vision-2030 health-sector reforms.
and broader GCC trend toward GDPR-adjacent baseline; meaningful divergence remains on consent, localisation triggers, and the SCC catalogue specifics.
2024 onwards establish the precedent set for fines (up to SAR 5m per violation, doubling for repeats, plus criminal exposure for unlawful transfers of sensitive data abroad).
and whether the regulator front-loads guidance over fines.
jurisdictions (UK, EEA, Singapore) that would reduce the SCC papering burden.
framework, NCA Essential Cybersecurity Controls) where overlap with PDPL data-handling duties creates a compound compliance perimeter.