Law note · Saudi Arabia

Personal Data Protection Law, enforcement and penalties

cite Royal Decree No. M/19, Arts. 35-36 stage IN FORCE in force since 2023-09-14 kind Enforcement supervision binds public and private bodies reviewed 2026-08-29

What it requires

  • An app operating in Saudi Arabia must not disclose or publish an individual's Sensitive Data, including identifying biometric data, in violation of the Law, since doing so with intent to harm the Data Subject or gain personal benefit is a criminal offense; other violations are subject to administrative fines up to SAR 5,000,000.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

What we found

Art. 35 imposes criminal penalties, imprisonment up to two years or a fine up to SAR 3,000,000, or both, doubled on recidivism, on any individual who discloses or publishes Sensitive Data (including identifying biometric data) with intent to harm the Data Subject or gain personal benefit, prosecuted by the Public Prosecution before the competent court. Art. 36 sets administrative fines up to SAR 5,000,000, doubled on repeat violation, for other violations.

No civil private-right-of-action provision letting a Data Subject sue a Controller directly for damages was found in the sections read; this is treated as not established rather than a confirmed negative pending a full read of any general civil-liability article.

← Back to the example  ·  Lint your app →