Law note · Saudi Arabia

Personal Data Protection Law, sensitive data and biometric processing

cite Royal Decree No. M/19, Art. 1(11); Implementing Regulations Arts. 8, 11(2)(a) stage IN FORCE in force since 2023-09-14 kind Sensitive categories binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that derives a faceprint, voiceprint, or other identity-linked biometric identifier from an individual in Saudi Arabia, for any purpose the purpose-based Sensitive Data definition would reach, must obtain the Data Subject's explicit consent before processing it, and must destroy it once the processing purpose is fulfilled or consent is withdrawn.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • trains_models
  • crawls_web
Excludes recording-derived identifiers
No

What we found

Art. 1(11) folds "biometric... Data for the purpose of identifying the person" directly into the Sensitive Data definition, with no standalone "Biometric Data" term and no worked-example list, unlike the UAE, Oman, and ADGM statutes. Implementing Regulations Art. 11(2)(a) requires explicit consent whenever processing involves Sensitive Data, reaching identifying biometric data by the Art. 1(11) definition. No modality-specific (voice or face) language was found.

Implementing Regulations Art. 8 requires the Controller to destroy Personal Data on enumerated grounds (purpose fulfilled, consent withdrawn), notifying every party the data was disclosed to and destroying all system copies; this is the general destruction duty applying to biometric data as Sensitive Data, with no biometric-specific retention ceiling found.

← Back to the example  ·  Lint your app →