Data Security & Breach Notification
Personal Data Protection Law — notification of personal data breaches
Saudi Arabia · September 14, 2023 (compliance grace period ended September 14, 2024)
Verify detailsOn becoming aware of a breach that may harm the personal data or the data subject's rights, the controller must notify SDAIA within 72 hours, and must notify affected data subjects without undue delay where the breach is likely to cause them serious harm. The notification to SDAIA must describe the incident and how it occurred, the category and estimated number of individuals affected, an assessment of the likely consequences, and the containment and prevention measures taken or planned. Like South Africa and Ghana, Saudi Arabia applies no materiality threshold to the regulator-facing limb once the harm-risk description is met. Marked 'check' on one specific point: independent sources cite the 72-hour deadline to different articles of the Implementing Regulations (Art. 20 and Art. 24 both appear), so confirm the provision you are relying on against the Arabic original before citing it. Note also the reach described in the comprehensive-law entry — the PDPL applies to any entity outside the Kingdom processing Saudi residents' data, so this duty can bind a business with no Saudi establishment.
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.