Law / Saudi Arabia

Saudi Arabia

privacy

Saudi Arabia's Personal Data Protection Law (Royal Decree No. M/19 of 9/2/1443H, 16 September 2021) is a three-instrument regime, all read at primary source directly from SDAIA's own document library, untruncated: the Law itself, Implementing Regulations that carry the operative consent-mechanics and destruction-duty detail, and a standalone Regulation on Personal Data Transfer Outside the Kingdom.

The Law folds biometric data directly into its Sensitive Data definition (Art. 1(11): "biometric or Genetic Data for the purpose of identifying the person"), with no separate "Biometric Data" definition and no worked example list, so a service creating an identity-linked voiceprint or faceprint needs the Data Subject's explicit consent under the Implementing Regulations.

The SDAIA-served text of the Law does not carry an amendment-history header in the pages read, so this document treats it as SDAIA's current, live consolidated text rather than an independently diffed 2021-versus-2023 comparison. Cross-border transfer is gated by a national-security-plus-adequacy-plus-minimization structure (Law Art. 29), operationalized by the 2023-era Transfer Regulation, the strictest posture read across the Gulf jurisdictions in this batch.

Enforcement is dual-track: criminal prosecution for unlawful disclosure of Sensitive Data and administrative fines for other violations; no private civil right of action was found.

14 instruments named 5 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Personal Data Protection Law, breach notification

cite Royal Decree No. M/19, Art. 20 stage IN FORCE in force since 2023-09-14 binds public and private bodies source official statute text, SDAIA document library
What it requires

Art. 20 requires the Controller to notify the Competent Authority upon knowing of any breach, damage, or illegal access to personal data, in accordance with the Implementing Regulations, and separately to notify the Data Subject of any breach that would cause damage to their data or prejudice their rights and interests.

No fixed notification window (hours or days) is stated in the Law itself; the specific timeline is deferred to the Implementing Regulations, whose exact notification-timeline article was not individually isolated in this research pass.

Comprehensive regime

Personal Data Protection Law, comprehensive regime and lawful basis

cite Royal Decree M/19 (9/2/1443H, 16 September 2021), comprehensive regime; Implementing Regulations Arts. 4, 11-12 stage IN FORCE in force since 2023-09-14 binds public and private bodies source official statute and Implementing Regulations text, SDAIA document library
What it requires

The Personal Data Protection Law is Saudi Arabia's comprehensive personal-data statute, with the Implementing Regulations supplying the operative consent-mechanics detail (Arts. 4, 11-12). Consent is the default lawful basis; other grounds are set out in the Law's Art. 6 area, not individually enumerated in this research pass. A Controller/Processor structure is present.

SDAIA is the Competent Authority for most sectors (Law Art. 1(3)), with the Saudi Central Bank (SAMA) designated as the Competent Authority for its own regulated financial sector, a sector-split enforcement structure.

Cross border transfer

Personal Data Protection Law, cross-border transfer

cite Royal Decree No. M/19, Art. 29; Regulation on Personal Data Transfer Outside the Kingdom stage IN FORCE in force since 2023-09-14 binds public and private bodies source official statute and Transfer Regulation text, SDAIA document library
What it requires

Law Art. 29 permits a Controller to transfer personal data outside the Kingdom only for one of four enumerated purposes (international-agreement obligation, Kingdom interests, a Data Subject's own contractual obligation, or a Regulations-specified purpose), and only where the transfer does not prejudice national security or Kingdom vital interests, an adequate level of protection at least equivalent to the Law's own applies per a Competent Authority assessment, and the transfer is limited to the minimum data needed.

The standalone Regulation on Personal Data Transfer Outside the Kingdom operationalizes this with defined "Appropriate Safeguards" the competent authority may impose where an exemption from the adequacy requirement is granted, and an "Operational Processes" basis for data tied to a controller's own internal operations.

No provision compelling in-Kingdom data storage as a default rule was found; this is a multi-factor national-security-and-adequacy gate rather than either a blanket ban or an open transfer policy, more restrictive in structure than the UAE's or Jordan's equivalent provisions in this batch.

The Regulation's url was corrected on review: the original sdaia.gov.sa path 404s, and the Regulation is now served from SDAIA's Digital Government Platform; the "Appropriate Safeguards" and "Operational Processes" quotes above were re-confirmed against the working url.

Enforcement supervision

Personal Data Protection Law, enforcement and penalties

cite Royal Decree No. M/19, Arts. 35-36 stage IN FORCE in force since 2023-09-14 binds public and private bodies source official statute text, SDAIA document library
What it requires

Art. 35 imposes criminal penalties, imprisonment up to two years or a fine up to SAR 3,000,000, or both, doubled on recidivism, on any individual who discloses or publishes Sensitive Data (including identifying biometric data) with intent to harm the Data Subject or gain personal benefit, prosecuted by the Public Prosecution before the competent court. Art. 36 sets administrative fines up to SAR 5,000,000, doubled on repeat violation, for other violations.

No civil private-right-of-action provision letting a Data Subject sue a Controller directly for damages was found in the sections read; this is treated as not established rather than a confirmed negative pending a full read of any general civil-liability article.

Sensitive categories

Personal Data Protection Law, sensitive data and biometric processing

cite Royal Decree No. M/19, Art. 1(11); Implementing Regulations Arts. 8, 11(2)(a) stage IN FORCE in force since 2023-09-14 binds public and private bodies source official statute and Implementing Regulations text, SDAIA document library
What it requires

Art. 1(11) folds "biometric... Data for the purpose of identifying the person" directly into the Sensitive Data definition, with no standalone "Biometric Data" term and no worked-example list, unlike the UAE, Oman, and ADGM statutes. Implementing Regulations Art. 11(2)(a) requires explicit consent whenever processing involves Sensitive Data, reaching identifying biometric data by the Art. 1(11) definition. No modality-specific (voice or face) language was found.

Implementing Regulations Art. 8 requires the Controller to destroy Personal Data on enumerated grounds (purpose fulfilled, consent withdrawn), notifying every party the data was disclosed to and destroying all system copies; this is the general destruction duty applying to biometric data as Sensitive Data, with no biometric-specific retention ceiling found.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.