Skip to content
NUEXUS Technologies
Saudi Arabia

Saudi Personal Data Protection Law

Saudi Arabia's personal data protection law, governing how personal data of individuals in the Kingdom may be collected, used and transferred.

NUEXUS delivers readiness, gap assessment, implementation support and evidence preparation. NUEXUS is not an accredited certification body and not an auditor, and cannot certify you, issue an attestation, or sign off on a result.

How it is organised

Controller obligations, familiar in shape

The law works in terms recognisable from other modern privacy regimes: a lawful basis for processing, purpose limitation, individual rights, breach handling and accountability. If you have done GDPR work, the shape will be familiar, but the details and the regulator are not the same and cannot be assumed.

Transfers out of the Kingdom are the sharp edge

Cross-border transfer is where compliant-elsewhere architectures most often fail, particularly where a SaaS stack processes or stores data outside Saudi Arabia by default. This is usually the first genuine finding in an assessment.

Records and accountability

Being compliant is not enough on its own; you have to be able to demonstrate it. Records of processing activities and evidence of the decisions you made are what turn a position into a defensible one.

What an assessor will ask to see

  • A record of processing activities that reflects reality
  • Documented lawful basis for each processing purpose
  • Privacy notices in the language of the data subject
  • A workable process for handling individual rights requests within the required timeframes
  • Transfer assessments for anything leaving the Kingdom
  • Breach detection and notification procedures that have been tested

Where it usually goes wrong

  • A GDPR programme assumed to satisfy PDPL without a delta assessment
  • No inventory of where personal data actually lives across SaaS tools
  • Cross-border transfers happening by default through a cloud provider's region choice
  • Rights-request handling that has never been tested against the clock