Saudi PDPL vs. GDPR: Registration, Transfers, and Penalties Compared

By Recording Law Editorial Team20 min read
Saudi PDPL vs. GDPR: Registration, Transfers, and Penalties Compared

Frequently Asked Questions

Does Saudi Arabia's PDPL require companies to register with the regulator?

Yes, in a way GDPR does not require. PDPL Article 30(4)(C) authorizes SDAIA to maintain a National Register of Controllers, and Implementing Regulation Article 34 has SDAIA separately determine which categories of controllers must register. GDPR abolished general prior notification and registration in 2018 in favor of an accountability-based model, so this is a structural difference, not a stylistic one.

Can a company transfer personal data from Saudi Arabia to the United States or the EU without extra safeguards?

Not automatically. SDAIA has published no adequacy decision for any country, so there is no PDPL equivalent of transferring to a country already on the EU's adequacy list. In practice, transfers run on SDAIA-approved Standard Contractual Clauses or Binding Common Rules, and a documented risk assessment is separately required where the transfer is continuous, large-scale, or involves sensitive data.

Does the PDPL require personal data to be stored inside Saudi Arabia?

No. This is a common misreading. The PDPL and its Data Transfer Regulation govern the conditions under which data may leave the Kingdom; they do not require data to be stored inside it as a default rule. A direct search of the official texts found no general localization requirement.

Does the PDPL give data subjects a right to object to processing or opt out of automated decisions, like GDPR does?

No. PDPL Article 4 grants only four rights: to be informed, to access, to correction, and to destruction. There is no right to object to processing comparable to GDPR Article 21, and no right relating to automated decision-making or profiling comparable to GDPR Article 22. Neither provision appears anywhere in the Law or its Implementing Regulation.

Can a Saudi controller rely on legitimate interest the same way it would under GDPR?

Not on the same terms. PDPL Article 6's legitimate-interest ground is available to private controllers only, is never available where sensitive data is involved, and Implementing Regulation Article 16 requires a mandatory documented impact assessment before a controller can rely on it. GDPR's Article 6(1)(f) balancing test carries no equivalent blanket pre-assessment requirement.

Is credit or financial data treated as sensitive personal data under the PDPL?

No. Credit Data is defined separately under PDPL Article 1(15) and regulated under its own provision, Article 24, which cross-references the Credit Information Law. It is not part of the Article 1(11) Sensitive Data definition, even though it receives its own enhanced controls, including explicit consent verification and subject notice on disclosure.

How does breach notification timing compare between the PDPL and GDPR?

They land in a similar place through different routes. The PDPL's own Article 20 sets no numeric deadline and defers to the Implementing Regulation, whose Article 24(1) sets a 72-hour deadline to notify SDAIA, matching GDPR Article 33's 72-hour standard. Individual notice under both laws uses a 'without undue delay' standard rather than a fixed hour count.

What is the maximum penalty for a PDPL violation, and how does it compare to GDPR's fines?

The PDPL's administrative track caps out at SAR 5,000,000, doubled to SAR 10,000,000 for a repeat violation, with no revenue-percentage mechanism like GDPR's 4% of global turnover. Saudi Arabia adds something GDPR does not: a criminal offense under Article 35 for intentionally disclosing sensitive data to harm someone or for personal gain, carrying up to two years' imprisonment and/or a fine of up to SAR 3,000,000.

Updates

SDAIA held a third public consultation on proposed amendments to the Implementing Regulation. As of the most recent check, these amendments have not been finalized or adopted; the live regulatory text still reflects the pre-amendment version, and businesses should not treat the consultation draft as current law.

SDAIA issued its Risk Assessment Guideline for Transferring Personal Data Outside the Kingdom, providing implementing guidance for the mandatory risk assessments the Data Transfer Regulation requires under Article 8.

The PDPL's three-year grace period ended, making the Law fully enforceable, including registration, breach-notification, and both the administrative and criminal penalty tracks.

SDAIA issued its standard-model Standard Contractual Clauses for cross-border data transfers under the Data Transfer Regulation, the primary safeguard mechanism controllers use in the continued absence of any adequacy decision.

Sources and References

  1. Personal Data Protection Law (Royal Decree No. M/19, as amended by Royal Decree No. M/148) — official English translation(sdaia.gov.sa).gov
  2. Implementing Regulation of the Personal Data Protection Law, including the Data Transfer Regulation chapter — official English translation(sdaia.gov.sa).gov
  3. SDAIA — Regulations and Policies index (registration rules, SCC model, Risk Assessment Guideline, live regulatory status)(sdaia.gov.sa).gov
  4. SDAIA — Data Protection research and regulatory overview(sdaia.gov.sa).gov
  5. Regulation (EU) 2016/679 (General Data Protection Regulation)(eur-lex.europa.eu).gov
Share: