Saudi Arabia PDPL + SDAIA AI Ethics Framework + Vision 2030 AI Programme: AI Compliance Requirements
Saudi Arabia's PDPL enforced by SDAIA (Saudi Data and AI Authority) is one of the Gulf's most comprehensive data protection laws. It covers any processing of personal data of Saudi residents, regardless of where the organization is located. The Vision 2030 AI Programme and NDMO (National Data Management Office) regulations add AI governance requirements. Financial AI requires SAMA approval; healthcare AI requires MOH approval.
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
September 24, 2021
September 14, 2024
SAR 5,000,000 (~$1.3M USD) administrative fine ceiling for the organization under PDPL Article 36 (doubled on repeat violation, capped at SAR 10,000,000); SAR 3,000,000 personal/criminal liability under Article 35 for an individual's unauthorized disclosure of sensitive data with intent to harm or gain. SDAIA can also order processing suspension.
What Your Business Must Do
5 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
Data Collection Notice and Consent (PDPL Article 5)
CriticalPDPL Article 5 requires individuals to be informed of the purpose, categories, and parties receiving personal data before collection. Explicit consent required for sensitive data. AI systems collecting Saudi personal data must provide clear disclosures before the first data collection event.
Deadline: September 14, 2023
PDPL Art. 5Data Subject Rights (Access, Correction, Erasure, Objection)
CriticalPDPL Articles 14-18 grant Saudi residents rights to access their data, correct inaccuracies, request destruction, and object to automated profiling. Organizations must respond within 30 days. AI systems must support data portability and deletion of personal data used in training or inference.
Cross-Border Data Transfer Controls (PDPL Article 29)
High PriorityPDPL Article 29 prohibits transfer of Saudi personal data outside the Kingdom unless: the receiving country offers equivalent protection, or NDMO grants a specific exemption. Cloud AI services processing Saudi data must document transfer controls or keep data within Saudi regions.
Breach Notification to SDAIA (PDPL Article 20)
High PriorityPDPL Article 20 requires organizations to notify SDAIA of any personal data breach that harms or is likely to harm data subjects' interests, within 72 hours of discovering the breach. Organizations must also notify affected individuals without undue delay. AI system compromises, unauthorized model access, and inference attacks are all potential breach triggers. Maintain a breach register. SDAIA may impose processing suspension pending investigation.
SDAIA AI Ethics & National AI Governance Framework
Medium PrioritySDAIA published AI Ethics Principles requiring fairness, transparency, accountability, and human oversight. Vision 2030 AI programmes require regulated-sector organizations to conduct bias audits and maintain AI system documentation. Non-compliance may result in SDAIA enforcement action.
Who Does This Apply To?
PDPL applies to any processing of personal data of natural persons located in Saudi Arabia, regardless of where the processing organization is headquartered. Extraterritorial reach: a foreign company that collects, stores, or processes personal data of Saudi residents — including through an AI product with Saudi users — is subject to PDPL and must designate a local Saudi representative. Key thresholds: PDPL applies to all organizations without a size exemption; however, NDMO guidance suggests simplified obligations for micro-enterprises processing data of fewer than 500 individuals. Sensitive data categories (health, financial, religious beliefs, biometric) require explicit consent and enhanced protection — AI systems that infer sensitive categories from non-sensitive inputs (e.g., inferring health status from behavior data) are treated as processing sensitive data. Sector overlay: financial AI must obtain SAMA (Saudi Central Bank) FinTech approval; healthcare AI requires MOH (Ministry of Health) clearance; government AI systems require SDAIA certification.
Recent Regulatory Guidance
SDAIA AI Ethics Principles — National AI Governance Framework (2023)
SDAIA's AI Ethics Principles framework (published 2023, updated 2024) sets governance expectations for AI systems operating in Saudi Arabia: (1) Fairness and non-discrimination — AI must not discriminate based on gender, nationality, religion, or disability; (2) Transparency — AI decisions affecting individuals must be explainable on request; (3) Accountability — organizations must designate an accountable AI officer; (4) Human oversight — high-stakes AI decisions require human review; (5) Privacy by design — AI systems must build in PDPL compliance from the design phase. The framework is officially "aspirational" but SDAIA enforcement actions cite violations of these principles as aggravating factors.
NDMO Data Localization and Cross-Border Transfer Guidelines (2024)
The National Data Management Office issued updated cross-border transfer guidelines confirming that Saudi Arabia operates a "conditional adequacy" model — transfers are permitted to countries with equivalent data protection laws (EU, UK, selected Gulf states). For AI services, the guidelines require: (1) data processing agreements with cross-border AI vendors must include PDPL-equivalent protections; (2) sensitive data (health, financial, biometric) cannot leave Saudi borders without explicit NDMO exemption; (3) organizations using cloud-based AI APIs must document data routing and ensure Saudi personal data does not traverse non-approved jurisdictions. Approved jurisdictions list updated quarterly.
Quarterly Enforcement Digest
CYCLE 4 UPDATE (2026-08-22): Saudi Arabia's PDPL has been in full enforcement mode since 14 September 2024; SDAIA's enforcement committees issued 48 formal decisions in the following year (per the sister saudi_arabia_pdpl entry's R132 finding — SDAIA does not publish respondent names). CYCLE 4 REMOVED the previously stated "healthcare AI enforcement notice" and "NDMO Fintech AI refusal" claims — both were fabricated (unnamed respondents, unverifiable/dead source URLs; see enforcementActions comment above) — do not restate them. Vision 2030 continues accelerating AI adoption in Saudi regulated sectors (banking, healthcare, government). SDAIA's draft "Responsible AI Policy" consultation closed 2026-05 (four-tier risk framework) — not yet confirmed enacted. Priority actions: (1) audit all AI data flows for Saudi personal data crossing borders; (2) ensure cross-border transfer documentation or onshore processing for Saudi users; (3) implement explicit PDPL-compliant consent for sensitive data AI processing; (4) designate a Saudi-resident compliance representative if serving Saudi users from outside KSA.
Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.
Industry Playbooks covering Saudi Arabia PDPL + SDAIA AI Ethics Framework + Vision 2030 AI Programme
These industry playbooks include jurisdiction-specific checklist items and guidance for Saudi Arabia PDPL + SDAIA AI Ethics Framework + Vision 2030 AI Programme.
Frequently Asked Questions
Does Saudi Arabia PDPL + SDAIA AI Ethics Framework + Vision 2030 AI Programme apply to my business?
Saudi Arabia's PDPL enforced by SDAIA (Saudi Data and AI Authority) is one of the Gulf's most comprehensive data protection laws. It covers any processing of personal data of Saudi residents, regardless of where the organization is located. The… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under Saudi Arabia PDPL + SDAIA AI Ethics Framework + Vision 2030 AI Programme is: SAR 5,000,000 (~$1.3M USD) administrative fine ceiling for the organization under PDPL Article 36 (doubled on repeat violation, capped at SAR 10,000,000); SAR 3,000,000 personal/criminal liability under Article 35 for an individual's unauthorized disclosure of sensitive data with intent to harm or gain. SDAIA can also order processing suspension.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with Saudi Arabia PDPL + SDAIA AI Ethics Framework + Vision 2030 AI Programme?
The 5 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://sdaia.gov.sa/en/SDAIA/about/Documents/PersonalDataProtectionLawEn.pdfLast updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan