Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Royal Decree No. M/19, Art. 20
stage IN FORCE in force since 2023-09-14
binds public and private bodies
source official statute text, SDAIA document library
What it requires →
Art. 20 requires the Controller to notify the Competent Authority upon knowing of any breach, damage, or illegal access to personal data, in accordance with the Implementing Regulations, and separately to notify the Data Subject of any breach that would cause damage to their data or prejudice their rights and interests.
No fixed notification window (hours or days) is stated in the Law itself; the specific timeline is deferred to the Implementing Regulations, whose exact notification-timeline article was not individually isolated in this research pass.
Comprehensive regime
What it requires →
The Personal Data Protection Law is Saudi Arabia's comprehensive personal-data statute, with the Implementing Regulations supplying the operative consent-mechanics detail (Arts. 4, 11-12). Consent is the default lawful basis; other grounds are set out in the Law's Art. 6 area, not individually enumerated in this research pass. A Controller/Processor structure is present.
SDAIA is the Competent Authority for most sectors (Law Art. 1(3)), with the Saudi Central Bank (SAMA) designated as the Competent Authority for its own regulated financial sector, a sector-split enforcement structure.
Cross border transfer
What it requires →
Law Art. 29 permits a Controller to transfer personal data outside the Kingdom only for one of four enumerated purposes (international-agreement obligation, Kingdom interests, a Data Subject's own contractual obligation, or a Regulations-specified purpose), and only where the transfer does not prejudice national security or Kingdom vital interests, an adequate level of protection at least equivalent to the Law's own applies per a Competent Authority assessment, and the transfer is limited to the minimum data needed.
The standalone Regulation on Personal Data Transfer Outside the Kingdom operationalizes this with defined "Appropriate Safeguards" the competent authority may impose where an exemption from the adequacy requirement is granted, and an "Operational Processes" basis for data tied to a controller's own internal operations.
No provision compelling in-Kingdom data storage as a default rule was found; this is a multi-factor national-security-and-adequacy gate rather than either a blanket ban or an open transfer policy, more restrictive in structure than the UAE's or Jordan's equivalent provisions in this batch.
The Regulation's url was corrected on review: the original sdaia.gov.sa path 404s, and the Regulation is now served from SDAIA's Digital Government Platform; the "Appropriate Safeguards" and "Operational Processes" quotes above were re-confirmed against the working url.
Enforcement supervision
What it requires →
Art. 35 imposes criminal penalties, imprisonment up to two years or a fine up to SAR 3,000,000, or both, doubled on recidivism, on any individual who discloses or publishes Sensitive Data (including identifying biometric data) with intent to harm the Data Subject or gain personal benefit, prosecuted by the Public Prosecution before the competent court. Art. 36 sets administrative fines up to SAR 5,000,000, doubled on repeat violation, for other violations.
No civil private-right-of-action provision letting a Data Subject sue a Controller directly for damages was found in the sections read; this is treated as not established rather than a confirmed negative pending a full read of any general civil-liability article.
Sensitive categories
What it requires →
Art. 1(11) folds "biometric... Data for the purpose of identifying the person" directly into the Sensitive Data definition, with no standalone "Biometric Data" term and no worked-example list, unlike the UAE, Oman, and ADGM statutes. Implementing Regulations Art. 11(2)(a) requires explicit consent whenever processing involves Sensitive Data, reaching identifying biometric data by the Art. 1(11) definition. No modality-specific (voice or face) language was found.
Implementing Regulations Art. 8 requires the Controller to destroy Personal Data on enumerated grounds (purpose fulfilled, consent withdrawn), notifying every party the data was disclosed to and destroying all system copies; this is the general destruction duty applying to biometric data as Sensitive Data, with no biometric-specific retention ceiling found.