What PDPL (KSA) actually requires
Saudi Arabia's first comprehensive data protection law. The PDPL introduces consent-based processing, data subject rights, cross-border transfer rules and significant penalties — including criminal liability for certain offences. Enforced primarily by the Saudi Data and Artificial Intelligence Authority (SDAIA).
Key requirements
- Obtain consent before collecting or processing personal data, with narrow exceptions
- Provide a clear privacy notice in Arabic explaining purposes and rights
- Restrict cross-border transfers to jurisdictions that meet SDAIA's adequacy criteria
- Allow data subjects to access, correct and delete their data
- Notify SDAIA and affected users of qualifying personal-data breaches
- Register with SDAIA where required and appoint a representative for foreign controllers
At a glance
Full name
Personal Data Protection Law (Saudi Arabia)
Region
Saudi Arabia
Status
Fully enforceable since September 2024
Who it affects
Any entity processing personal data of individuals residing in Saudi Arabia, including organisations outside the Kingdom whose activity targets people inside it.
Penalties
Administrative fines up to SAR 5 million per violation, with a possible doubling for repeat offences. Some sensitive-data offences also carry criminal penalties, including imprisonment.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
