Saudi Arabia Personal Data Protection Law (PDPL): AI Compliance Requirements
Saudi Arabia's Personal Data Protection Law (Royal Decree M/19, September 2021) became fully enforceable on September 14, 2024, after a one-year extended compliance period. Modelled closely on the GDPR, the PDPL applies to any organization processing personal data of Saudi residents — including foreign organizations. The Saudi Data & AI Authority (SDAIA) administers and enforces the law. AI-specific obligations arise from the Implementing Regulations: automated decisions based on personal data trigger enhanced obligations. Any org doing large-scale automated AI processing, new technology deployment, or systematic profiling must appoint a DPO, conduct privacy impact assessments, and notify SDAIA of high-risk processing. Cross-border AI data transfers to non-approved countries require prior SDAIA approval.
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
September 14, 2023
September 14, 2024
SAR 5,000,000 (~$1.3M USD) administrative fine ceiling under Article 36 for PDPL violations generally (doubled for a repeat violation, capped at SAR 10,000,000 total — not a flat "SAR 15,000,000" figure). Separately, Article 35 imposes a CRIMINAL penalty — up to 2 years imprisonment or a fine up to SAR 3,000,000, or both — specifically for unauthorized disclosure/publication of sensitive data done with intent to harm the data subject or gain personal benefit (not a general cross-border-transfer provision).
What Your Business Must Do
4 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
Lawful Basis for AI Data Processing
CriticalEvery AI system processing personal data of Saudi residents requires a lawful basis. Saudi PDPL permits: explicit consent, contractual necessity, legal obligation, vital interests, or legitimate interests (with proportionality balancing). Consent for sensitive data (health, biometric, financial) must be explicit. Document the lawful basis for each AI system processing personal data of Saudi residents.
Deadline: September 14, 2023
Saudi PDPL, general processing-conditions provisions (lawful-basis grounds); Art. 36 (administrative-fine enforcement)Automated Decision Transparency & Impact Assessment
High PriorityUnder the PDPL Implementing Regulations: organizations performing continuous large-scale processing, systematic monitoring, or automated decisions based on personal data must: (1) Conduct a Privacy Impact Assessment (PIA) before deployment. (2) Notify SDAIA of high-risk processing activities. (3) Allow data subjects to contest automated decisions with legal or significant effects. Document your automated decision-making systems and maintain PIA records.
AI Data Transfer Approval (Cross-Border)
High PriorityIf your AI systems transfer Saudi residents' personal data outside the Kingdom (e.g., to US or EU cloud AI providers), prior SDAIA approval is required unless the destination country provides an equivalent protection level. Ensure Data Processing Agreements with all AI vendors include SDAIA-compliant cross-border transfer clauses.
Data Protection Officer (DPO) Appointment
Medium PriorityA DPO is required if your organization performs large-scale processing of Saudi residents' personal data using new technologies (including AI), or engages in systematic monitoring of individuals. Register the DPO with SDAIA. The DPO must be involved in all AI deployment decisions affecting personal data.
Who Does This Apply To?
Applies to: any controller or processor that processes the personal data of individuals in Saudi Arabia, including organisations established outside the Kingdom that process Saudi residents' data (the PDPL has extraterritorial reach). There is no general small-business exemption — the obligations attach to the processing activity, not company size. Enhanced AI duties trigger when an organisation conducts large-scale automated processing, deploys new technologies, or performs systematic profiling of individuals: it must then appoint a Data Protection Officer registered with SDAIA, conduct a privacy impact assessment before deployment, and notify SDAIA of high-risk processing. Automated decisions based on personal data give the data subject a right to be informed and, under Article 30, to object and request human review. Cross-border transfers of Saudi residents' data to non-adequate countries require prior SDAIA approval. Sensitive data (health, biometric, financial, genetic) requires explicit consent. Administered and enforced by the Saudi Data & AI Authority (SDAIA); the law became fully enforceable on 14 September 2024 after a one-year grace period.
Recent Enforcement Actions
Against:
Recent Regulatory Guidance
SDAIA — PDPL Implementing Regulations and AI Ethics Framework (2023-2024)
SDAIA issued the PDPL Implementing Regulations (Regulation No. SDAIA/01/2023) operationalizing the law, alongside the AI Ethics Framework setting expectations for AI deployment in Saudi Arabia. Key obligations clarified: (1) controllers must register on the National Data Governance Platform; (2) data subjects must be informed when AI is used for automated decisions affecting them and have the right to object and request human review under Article 30; (3) cross-border transfers require SDAIA authorization or an adequacy determination; (4) Vision 2030 sectoral regulators (SAMA for banking, MoH for healthcare, CITC for telecoms) layer additional AI governance requirements on top of the PDPL floor.
Key Case Law & Precedent
EU Schrems II — Data Protection Commissioner v. Facebook Ireland (CJEU C-311/18)
Court of Justice of the European Union · 2020While Saudi Arabia is not bound by EU jurisprudence, SDAIA's PDPL cross-border-transfer regime explicitly mirrors the GDPR/Schrems II framework — adequacy determinations, supplementary measures, and risk assessments for transfers to jurisdictions without equivalent protection. SDAIA cites Schrems II as a reference framework when assessing controller transfers from Saudi Arabia to third countries that lack PDPL-equivalent protection.
Outcome: Privacy Shield invalidated; SCCs upheld with supplementary measures requirement
Case referenceIndustry Playbooks covering Saudi Arabia Personal Data Protection Law (PDPL)
These industry playbooks include jurisdiction-specific checklist items and guidance for Saudi Arabia Personal Data Protection Law (PDPL).
Frequently Asked Questions
Does Saudi Arabia Personal Data Protection Law (PDPL) apply to my business?
Saudi Arabia's Personal Data Protection Law (Royal Decree M/19, September 2021) became fully enforceable on September 14, 2024, after a one-year extended compliance period. Modelled closely on the GDPR, the PDPL applies to any organization… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under Saudi Arabia Personal Data Protection Law (PDPL) is: SAR 5,000,000 (~$1.3M USD) administrative fine ceiling under Article 36 for PDPL violations generally (doubled for a repeat violation, capped at SAR 10,000,000 total — not a flat "SAR 15,000,000" figure). Separately, Article 35 imposes a CRIMINAL penalty — up to 2 years imprisonment or a fine up to SAR 3,000,000, or both — specifically for unauthorized disclosure/publication of sensitive data done with intent to harm the data subject or gain personal benefit (not a general cross-border-transfer provision).. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with Saudi Arabia Personal Data Protection Law (PDPL)?
The 4 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://sdaia.gov.sa/en/SDAIA/about/Pages/RegulationsAndPolicies.aspxLast updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan