WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Middle East

Saudi Arabia Privacy & Data Protection Laws

Every regime below can apply to a business handling Saudi Arabia residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

September 14, 2023 (compliance grace period ended September 14, 2024)
Personal Data Protection Law
Saudi PDPL
Verify details

Applies to any processing of personal data within Saudi Arabia, and extraterritorially to any entity outside the Kingdom that processes personal data relating to Saudi residents — broader than GDPR's test, since it does not require the foreign processor to be actively 'targeting' or monitoring Saudi residents; mere processing of a Saudi resident's data by any means triggers applicability. Exempts processing by individuals for purely personal/family use where data isn't disclosed beyond that private circle; no confirmed general exemption for government agencies, nonprofits, or health/financial sectors beyond this. The Implementing Regulations and the separate Regulations on Personal Data Transfer Outside the Kingdom (both issued in 2023, with the transfer rules subsequently amended) supply the operative detail on lawful bases, records of processing, impact assessments, and the risk-assessment route for outbound transfers. SDAIA is the current regulator, with supervision expected to move to a dedicated authority.

Royal Decree No. M/19 of 9/2/1443H (Sep 16, 2021), as amended by Royal Decree No. M/148 of 5/9/1444H (Mar 27, 2023); Implementing Regulations and Data Transfer Regulations issued 2023Read regulation →

Cross-Border Data Transfer · 1

Art. 29 permits transfer or disclosure outside the Kingdom only for defined purposes — performing an obligation under an agreement to which Saudi Arabia is a party, serving the Kingdom's interests, performing an obligation to which the data subject is a party, or other purposes set out in the Regulations — and subjects every transfer to two overriding limits: it must not prejudice national security or the Kingdom's vital interests, and it must be confined to the minimum personal data necessary. The separate Data Transfer Regulation supplies the mechanics, including the risk-assessment requirement and the appropriate-safeguard routes (standard contractual clauses and binding common rules). Marked 'check': the transfer regulation has been amended since issue, the operative texts are Arabic-language originals, and SDAIA's supervisory role is expected to move to a dedicated authority.

Royal Decree No. M/19 (as amended by Royal Decree No. M/148), Art. 29; Regulation on Personal Data Transfer outside the Geographical Boundaries of the Kingdom (issued September 7, 2023, subsequently amended)Read regulation →

Data Security & Breach Notification · 1

September 14, 2023 (compliance grace period ended September 14, 2024)
Personal Data Protection Law — notification of personal data breaches
Saudi PDPL Art. 20
Verify details

On becoming aware of a breach that may harm the personal data or the data subject's rights, the controller must notify SDAIA within 72 hours, and must notify affected data subjects without undue delay where the breach is likely to cause them serious harm. The notification to SDAIA must describe the incident and how it occurred, the category and estimated number of individuals affected, an assessment of the likely consequences, and the containment and prevention measures taken or planned. Like South Africa and Ghana, Saudi Arabia applies no materiality threshold to the regulator-facing limb once the harm-risk description is met. Marked 'check' on one specific point: independent sources cite the 72-hour deadline to different articles of the Implementing Regulations (Art. 20 and Art. 24 both appear), so confirm the provision you are relying on against the Arabic original before citing it. Note also the reach described in the comprehensive-law entry — the PDPL applies to any entity outside the Kingdom processing Saudi residents' data, so this duty can bind a business with no Saudi establishment.

Royal Decree No. M/19 (as amended by Royal Decree No. M/148), Art. 20; Implementing Regulations (issued September 7, 2023)Read regulation →

Other Middle East jurisdictions