PDPL
Personal Data Protection Law
SDAIA
Any entity processing the personal data of individuals in the Kingdom, wherever that entity sits.
Enforceable since 14 September 2024, after a one-year transition.
KSA compliance · SDAIA · NCA · SAMA
PDPL attaches obligations to personal data wherever it sits. The NCA’s data controls index protection by classification. Both assume something most estates do not have — a current, complete inventory of where regulated data actually lives. That inventory is not the last deliverable of a compliance programme. It is the first.
A reference, not a determination. This sets out what the three regimes require and where the work starts. Whether an entity is in scope, what a lawful basis is on your facts, and whether a transfer is permitted are judgements to take with counsel. We are not an accreditation body for any of these frameworks and do not act as one.
Last reviewed
What applies to you
They are not alternatives and they do not merge. A bank sits inside PDPL and SAMA CSF at once; a ministry sits inside PDPL, ECC and DCC. The control sets are related and the evidence is not interchangeable.
PDPL
SDAIA
Any entity processing the personal data of individuals in the Kingdom, wherever that entity sits.
Enforceable since 14 September 2024, after a one-year transition.
ECC-2:2024
National Cybersecurity Authority
Government entities and their companies, operators of critical national infrastructure, and certain private sector organisations.
Supersedes ECC-1:2018. Four domains and 28 subdomains.
DCC-1:2022
National Cybersecurity Authority
The same population as ECC, applied specifically to data — structured and unstructured, physical and digital.
Published 1 November 2022. Built on a four-tier classification.
SAMA CSF
Saudi Central Bank
Banks, insurers, financing companies, credit bureaus and financial market infrastructure — and, through them, their service providers.
Version 1.0, May 2017. Four domains, with a minimum maturity target.
Where compliance actually starts
Programmes in this market are usually bought in the opposite order — monitoring, then access governance, then classification as documentation at the end. That order produces controls scoped to the systems somebody remembered.
01
PDPL does not ask which applications you run. It attaches obligations to personal data wherever it sits, which includes the database a faculty or a department stood up years ago, the extract someone took for a migration and never deleted, and the reporting copy nobody has owned since the person who built it left. An inventory built from the application register misses all three, because none of them was ever an application.
02
NCA’s data controls are built on a classification scheme, and the protection required follows the class. That inverts the usual order of work: the classification is not documentation produced after the controls are deployed, it is the input that decides which controls apply to what. An estate with no classification cannot demonstrate compliance with a control set that is indexed by it.
03
Access governance needs to know which stores hold regulated data before roles can be scoped to them. Retention needs record classes before a schedule means anything. Breach notification within 72 hours requires knowing, on the day, what was in the system that was reached. Each of these is usually bought first and each of them is downstream of the same missing thing.
04
Production data reaches test, development and analytics environments as a matter of routine, and those environments are rarely held to production controls. The personal data in them carries the same obligations and almost never the same protection. Masking before the copy is made is the only version of this that survives an audit.
This is not a theoretical position. A Saudi higher education institution engaged us to find personal data across academic and administrative systems accumulated over decades, before any control was scoped to it.Read the case study →
What PDPL requires
01
Controllers meeting the prescribed criteria register on the National Data Governance Platform before processing begins, and a data protection officer’s appointment is documented with contact details filed through the competent authority’s platform and kept current.
02
Processing requires a basis under the law, and controllers maintain records of their processing activities. The records obligation is one of the areas the proposed amendments to the Implementing Regulation would change — see the note on this page before building a programme around its current shape.
03
A controller notifies SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the rights of data subjects, and notifies affected individuals without undue delay where their rights or interests are at risk. Seventy-two hours is not long enough to first discover what the affected system contained.
04
Transferring personal data outside the Kingdom is permitted on conditions rather than at will, and unauthorised transfer carries its own penalty. For a group running shared services, a regional data centre or an offshore support desk, this is an architecture question before it is a policy one.
05
Financial penalties run to SAR 5 million per violation, with the possibility of an increase for repeat offences. Disclosure of sensitive personal data with intent to harm or for personal gain carries imprisonment of up to two years alongside a fine. SDAIA has been issuing enforcement decisions since the transition ended, so this is an enforced regime rather than a stated one.
06
A bank in the Kingdom is inside PDPL and SAMA CSF at once; a government entity is inside PDPL, ECC and DCC. The control sets are related and the evidence is not interchangeable — a SAMA maturity assessment does not discharge an NCA control, and neither answers a data subject request. Mapping the overlap is what keeps one programme from becoming three.
What we deliver against it
Three Saudi public sector engagements sit behind this — a government ministry, a higher education institution and a government authority. Described by sector and scope only: in public sector security work the existence of an engagement can itself be the sensitive fact.
Discovery and classification
Scanning structured and unstructured estates to find personal and regulated data, then classifying it so controls attach to record classes rather than to servers. This is the inventory every other control depends on, and it is the work most programmes discover they need after buying something else.
IBM Guardium Data Protection
Continuous monitoring of privileged access to production databases — who queried what, when, and from where — with policy-based alerting on privilege escalation and bulk extraction. Delivered in production for Saudi government and higher education environments.
IBM Optim
Masking production data before it reaches test and development environments, and archiving and retention aligned to the record classes a regulator asks about. The copies of your data are where exposure usually starts.
PDPL · NCA-ECC · DCC · SAMA CSF · ISO 27001
Gap assessment against the framework that applies to you, mapping between the overlapping ones, and the evidence a regulator or auditor will actually ask for. We hold ISO/IEC 27001:2022 in our own operations — the certificate is ours, not a partner’s.
A discovery and classification exercise tells you the size of the problem before you commit to the shape of the solution. It is also the deliverable that every subsequent control — monitoring, masking, retention, access governance — is scoped from.
NDA before scoping