Saudi Arabia’s Personal Data Protection Law (PDPL) came into force on 14 September 2023, and organisations were expected to comply from 14 September 2024. It is supervised by the Saudi Data and Artificial Intelligence Authority (SDAIA). If your app or website collects names, phone numbers, emails, locations, IDs or payment details from people in Saudi Arabia, the PDPL applies to how you design it. This checklist turns the law into product and engineering tasks.
Who it applies to
The PDPL covers the processing of personal data in the Kingdom, and processing outside the Kingdom that relates to people living in Saudi Arabia. In practice, most Saudi-facing apps, websites and online stores are in scope, including those run by companies abroad.
The checklist
- Map your data. List what personal data each screen, form and integration collects, why, where it is stored and who can see it.
- Choose a legal basis for each purpose. Consent is the main basis under the PDPL, and people must be able to withdraw it. Do not bundle marketing consent with sign-up.
- Publish a clear privacy notice in Arabic and English, shown at the point of collection, explaining what you collect, why, how long you keep it and who you share it with.
- Collect only what you need. Every extra field is extra risk. Remove optional fields you never use.
- Support user rights. Build a simple way for users to access, get a copy of, correct and delete their data, and a process for your team to answer requests.
- Secure the data. Encrypt data in transit and at rest, limit admin access by role, log access to sensitive records and keep secrets out of the app code.
- Plan for breaches. The PDPL requires notifying SDAIA within 72 hours of becoming aware of a breach, and informing affected people without undue delay where it could harm them. Decide now who does what.
- Check your vendors. Hosting, analytics, SMS, email and payment providers process data for you. Use contracts that set out their obligations.
- Decide where data is hosted. Transfers outside the Kingdom are allowed only with an adequate level of protection or appropriate safeguards, so choose hosting regions deliberately.
- Appoint a data protection officer if required, for example when you process sensitive data or monitor people at large scale.
- Register if required. Many controllers must register on SDAIA’s National Data Governance Platform.
- Be careful with sensitive data such as health, genetic, credit and biometric data, which carries stricter rules and higher penalties.
What happens if you get it wrong
Violations can lead to warnings or fines of up to SAR 5 million, and courts can double fines for repeat offences. Disclosing sensitive data with intent to harm can lead to imprisonment of up to two years and a fine of up to SAR 3 million.
Building PDPL into an app from day one
It is far cheaper to design consent screens, privacy notices, data exports and deletion flows at the start than to retrofit them after launch. On our projects we agree data-protection requirements, including hosting location, at the start and design the system around them, from websites and mobile apps to healthcare platforms that handle sensitive data. Hosting choices are covered by our cloud and DevOps work.
This article is general information, not legal advice. For your specific situation, consult a qualified lawyer and SDAIA’s official guidance (SDAIA: Personal Data Protection Law).


