KSA compliance · SDAIA · NCA · SAMA

You cannot protect data you have not found.

PDPL attaches obligations to personal data wherever it sits. The NCA’s data controls index protection by classification. Both assume something most estates do not have — a current, complete inventory of where regulated data actually lives. That inventory is not the last deliverable of a compliance programme. It is the first.

A reference, not a determination. This sets out what the three regimes require and where the work starts. Whether an entity is in scope, what a lawful basis is on your facts, and whether a transfer is permitted are judgements to take with counsel. We are not an accreditation body for any of these frameworks and do not act as one.

Last reviewed

What applies to you

Four instruments, and most entities are inside more than one.

They are not alternatives and they do not merge. A bank sits inside PDPL and SAMA CSF at once; a ministry sits inside PDPL, ECC and DCC. The control sets are related and the evidence is not interchangeable.

PDPL

Personal Data Protection Law

SDAIA

Any entity processing the personal data of individuals in the Kingdom, wherever that entity sits.

Enforceable since 14 September 2024, after a one-year transition.

ECC-2:2024

Essential Cybersecurity Controls

National Cybersecurity Authority

Government entities and their companies, operators of critical national infrastructure, and certain private sector organisations.

Supersedes ECC-1:2018. Four domains and 28 subdomains.

DCC-1:2022

Data Cybersecurity Controls

National Cybersecurity Authority

The same population as ECC, applied specifically to data — structured and unstructured, physical and digital.

Published 1 November 2022. Built on a four-tier classification.

SAMA CSF

Cyber Security Framework

Saudi Central Bank

Banks, insurers, financing companies, credit bureaus and financial market infrastructure — and, through them, their service providers.

Version 1.0, May 2017. Four domains, with a minimum maturity target.

Where compliance actually starts

Every control on the list is downstream of an inventory.

Programmes in this market are usually bought in the opposite order — monitoring, then access governance, then classification as documentation at the end. That order produces controls scoped to the systems somebody remembered.

01

The obligation attaches to the data, not to the system

PDPL does not ask which applications you run. It attaches obligations to personal data wherever it sits, which includes the database a faculty or a department stood up years ago, the extract someone took for a migration and never deleted, and the reporting copy nobody has owned since the person who built it left. An inventory built from the application register misses all three, because none of them was ever an application.

02

Classification is a control in its own right

NCA’s data controls are built on a classification scheme, and the protection required follows the class. That inverts the usual order of work: the classification is not documentation produced after the controls are deployed, it is the input that decides which controls apply to what. An estate with no classification cannot demonstrate compliance with a control set that is indexed by it.

03

Every downstream control assumes an inventory

Access governance needs to know which stores hold regulated data before roles can be scoped to them. Retention needs record classes before a schedule means anything. Breach notification within 72 hours requires knowing, on the day, what was in the system that was reached. Each of these is usually bought first and each of them is downstream of the same missing thing.

04

Copies are where exposure usually starts

Production data reaches test, development and analytics environments as a matter of routine, and those environments are rarely held to production controls. The personal data in them carries the same obligations and almost never the same protection. Masking before the copy is made is the only version of this that survives an audit.

This is not a theoretical position. A Saudi higher education institution engaged us to find personal data across academic and administrative systems accumulated over decades, before any control was scoped to it.Read the case study →

What PDPL requires

Six obligations, and one clock.

01

Registration and a named officer

Controllers meeting the prescribed criteria register on the National Data Governance Platform before processing begins, and a data protection officer’s appointment is documented with contact details filed through the competent authority’s platform and kept current.

02

A lawful basis, and a record of processing

Processing requires a basis under the law, and controllers maintain records of their processing activities. The records obligation is one of the areas the proposed amendments to the Implementing Regulation would change — see the note on this page before building a programme around its current shape.

03

Breach notification within seventy-two hours

A controller notifies SDAIA within 72 hours of becoming aware of a breach that may harm the personal data or the rights of data subjects, and notifies affected individuals without undue delay where their rights or interests are at risk. Seventy-two hours is not long enough to first discover what the affected system contained.

04

Cross-border transfer is conditional

Transferring personal data outside the Kingdom is permitted on conditions rather than at will, and unauthorised transfer carries its own penalty. For a group running shared services, a regional data centre or an offshore support desk, this is an architecture question before it is a policy one.

05

Penalties reach criminal liability

Financial penalties run to SAR 5 million per violation, with the possibility of an increase for repeat offences. Disclosure of sensitive personal data with intent to harm or for personal gain carries imprisonment of up to two years alongside a fine. SDAIA has been issuing enforcement decisions since the transition ended, so this is an enforced regime rather than a stated one.

06

The frameworks overlap and do not merge

A bank in the Kingdom is inside PDPL and SAMA CSF at once; a government entity is inside PDPL, ECC and DCC. The control sets are related and the evidence is not interchangeable — a SAMA maturity assessment does not discharge an NCA control, and neither answers a data subject request. Mapping the overlap is what keeps one programme from becoming three.

What we deliver against it

Named products, in production, in Saudi government environments.

Three Saudi public sector engagements sit behind this — a government ministry, a higher education institution and a government authority. Described by sector and scope only: in public sector security work the existence of an engagement can itself be the sensitive fact.

Sensitive data discovery and classification

Discovery and classification

Scanning structured and unstructured estates to find personal and regulated data, then classifying it so controls attach to record classes rather than to servers. This is the inventory every other control depends on, and it is the work most programmes discover they need after buying something else.

Database activity monitoring

IBM Guardium Data Protection

Continuous monitoring of privileged access to production databases — who queried what, when, and from where — with policy-based alerting on privilege escalation and bulk extraction. Delivered in production for Saudi government and higher education environments.

Data privacy and lifecycle management

IBM Optim

Masking production data before it reaches test and development environments, and archiving and retention aligned to the record classes a regulator asks about. The copies of your data are where exposure usually starts.

Control mapping and the evidence pack

PDPL · NCA-ECC · DCC · SAMA CSF · ISO 27001

Gap assessment against the framework that applies to you, mapping between the overlapping ones, and the evidence a regulator or auditor will actually ask for. We hold ISO/IEC 27001:2022 in our own operations — the certificate is ours, not a partner’s.

The enterprise security practice →

Start with the inventory, not with the product.

A discovery and classification exercise tells you the size of the problem before you commit to the shape of the solution. It is also the deliverable that every subsequent control — monitoring, masking, retention, access governance — is scoped from.

NDA before scoping