Saudi PDPL
Saudi Arabia Personal Data Protection Law (Royal Decree M/19, 2021, amended 2023).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
Breach Notification
| Code | Title |
|---|---|
| Art.19 | Right Regarding Automated Processing |
Consent
| Code | Title |
|---|---|
| Art.6 | Conditions of Consent |
Controller Obligations
| Code | Title |
|---|---|
| Art.16 | Right to Correction or Erasure |
| Art.17 | Right to Restriction of Processing |
| Art.18 | Right to Stop Processing (Object) |
| Art.20 | Security of Personal Data |
| Art.21 | Data Protection Impact Assessment (DPIA) |
| Art.25 | Grievance Against UAE Data Office Decisions |
| Art.28 | Data Retention and Destruction |
| Art.29 | Registration (Repealed by 2023 Amendment) |
| Art.7 | General Obligations of the Controller |
| IR.Art.21 | Data Protection Impact Assessment |
| IR.Art.30 | Awareness and Training |
| IR.Art.5 | Privacy by Design and Default |
Cross-Border
| Code | Title |
|---|---|
| Art.23 | Cross-Border Transfers (Appropriate Safeguards) |
| Art.24 | Complaints to UAE Data Office |
DPO
| Code | Title |
|---|---|
| Art.27 | Data Protection Officer (DPO) |
Data Subject Rights
| Code | Title |
|---|---|
| Art.22 | Cross-Border Transfers (Adequacy) |
| Art.30 | Data Subject Right to Correction |
| Art.31 | Data Subject Right to Erasure |
| Art.32 | Data Subject Right to Transfer (Portability) |
| Art.34 | Right to Complain to SDAIA |
| Art.4 | Cases Where Consent Is Not Required |
Enforcement
| Code | Title |
|---|---|
| Art.35 | Penalties for Disclosure of Sensitive Data |
| Art.36 | Administrative Fines |
| Art.37 | Compensation for Harm |
Lawful Processing
| Code | Title |
|---|---|
| Art.5 | Personal Data Processing Controls and Principles |
Principles
| Code | Title |
|---|---|
| Art.10 | Appointment of Data Protection Officer |
| Art.11 | Duties of the Data Protection Officer |
Sensitive Data
| Code | Title |
|---|---|
| Art.13 | Right to Receive Information |
| Art.14 | Right of Access |
| Art.15 | Right to Request Transfer (Portability) |
Your Compliance Coverage
If you comply with Saudi PDPL, you already cover:
Maps to 620 other frameworks
Frequently Asked Questions
What is Saudi PDPL?
Saudi PDPL is a compliance framework from Saudi Arabia with 10 domains and 32 controls. Saudi Arabia Personal Data Protection Law (Royal Decree M/19, 2021, amended 2023). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Saudi PDPL have?
Saudi PDPL has 32 controls organised across 10 domains. The largest domains are Controller Obligations (12 controls), Data Subject Rights (6 controls), Enforcement (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Saudi PDPL map to?
Saudi PDPL maps to 620 other compliance frameworks. The top mapping partners are EU AI Act (38% coverage), Chile Personal Data Protection Law (Law No. 21.719) (38% coverage), LGPD (34% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Saudi PDPL compliance?
Start your Saudi PDPL compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Saudi PDPL requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 32 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.
Get Started Free →Free forever — no credit card required