Our Team

STA's Team of Lawyers in Abu Dhabi, Bahrain, Doha, UAE, Luxembourg, Moscow, RAK, Sharjah, and Singapore. Find a Lawyer. ..

Read more information

Saudi Arabia implemented Personal Data Protection Law (PDPL)

Saudi Arabia implemented Personal Data Protection Law (PDPL)


The Personal Data Protection Law (PDPL) was implemented by Royal Decree M/19 of 17 September 2021 approving Resolution No.98 dated 14 September 2021, and amended on 21 March 2023. The Saudi Data & Artificial Intelligence Authority ('SDAIA') regulates the statute. The PDPL marks the introduction of Saudi Arabia's first data protection law and was published in the Official Gazette on 24 September 2021.

The aim of the PDPL is to guarantee the privacy of personal data, regulate data sharing, and prevent personal data abuse. Remarkably, the PDPL covers key principles like, purpose restriction and data minimisation, controller obligations, including registration and maintenance of data processing records, data subject rights, and penalties for breach of provisions.

The PDPL will bring Saudi Arabia into closer alignment with the two its Middle East counterparts as well as international standards. Meantime, the National Data Management Office has fostered the National Data Governance Interim Regulations which envelop the Personal Data Protection Interim Regulations and the Data Sharing Interim Regulations. The Data Protection Interim Regulations cover key principles like accountability, transparency, data disclosure, and data subject rights, while the Data Sharing Interim Regulations address data security, legal basis, and ethical data use.

towards the end of November 2022, SDAIA conducted a public consultation on proposed amendments to the PDPL and was approved by the Saudi Council of Ministers on 21 March 2023. According to Article 43 of the PDPL, as amended, the same will come into force 720 days from the date of publication in the Official Gazette, namely on 14 September 2023. Furthermore, according to the preamble of the PDPL, as amended, entities will have a one-year transition period from such date to bring their operations into consistance.

On September 7, 2023, the PDPL Implementing Regulations and the Regulations on personal data transfers were published in the Official Gazette of Saudi Arabia after public consultation by SDAIA in July 2023. Both sets of regulations will be into force with the PDPL on September 14, 2023.