Jurisdiction Guides / Middle East
Saudi Arabia Privacy & Data Protection Laws
Every regime below can apply to a business handling Saudi Arabia residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Applies to any processing of personal data within Saudi Arabia, and extraterritorially to any entity outside the Kingdom that processes personal data relating to Saudi residents — broader than GDPR's test, since it does not require the foreign processor to be actively 'targeting' or monitoring Saudi residents; mere processing of a Saudi resident's data by any means triggers applicability. Exempts processing by individuals for purely personal/family use where data isn't disclosed beyond that private circle; no confirmed general exemption for government agencies, nonprofits, or health/financial sectors beyond this. The Implementing Regulations and the separate Regulations on Personal Data Transfer Outside the Kingdom (both issued in 2023, with the transfer rules subsequently amended) supply the operative detail on lawful bases, records of processing, impact assessments, and the risk-assessment route for outbound transfers. SDAIA is the current regulator, with supervision expected to move to a dedicated authority.
Cross-Border Data Transfer · 1
Art. 29 permits transfer or disclosure outside the Kingdom only for defined purposes — performing an obligation under an agreement to which Saudi Arabia is a party, serving the Kingdom's interests, performing an obligation to which the data subject is a party, or other purposes set out in the Regulations — and subjects every transfer to two overriding limits: it must not prejudice national security or the Kingdom's vital interests, and it must be confined to the minimum personal data necessary. The separate Data Transfer Regulation supplies the mechanics, including the risk-assessment requirement and the appropriate-safeguard routes (standard contractual clauses and binding common rules). Marked 'check': the transfer regulation has been amended since issue, the operative texts are Arabic-language originals, and SDAIA's supervisory role is expected to move to a dedicated authority.
Data Security & Breach Notification · 1
On becoming aware of a breach that may harm the personal data or the data subject's rights, the controller must notify SDAIA within 72 hours, and must notify affected data subjects without undue delay where the breach is likely to cause them serious harm. The notification to SDAIA must describe the incident and how it occurred, the category and estimated number of individuals affected, an assessment of the likely consequences, and the containment and prevention measures taken or planned. Like South Africa and Ghana, Saudi Arabia applies no materiality threshold to the regulator-facing limb once the harm-risk description is met. Marked 'check' on one specific point: independent sources cite the 72-hour deadline to different articles of the Implementing Regulations (Art. 20 and Art. 24 both appear), so confirm the provision you are relying on against the Arabic original before citing it. Note also the reach described in the comprehensive-law entry — the PDPL applies to any entity outside the Kingdom processing Saudi residents' data, so this duty can bind a business with no Saudi establishment.
Other Middle East jurisdictions