1. Home
  2. PDPL compliance for fintechs

PDPL compliance for fintechs

Saudi Arabia's Personal Data Protection Law (PDPL) has been fully enforceable since September 2024. For a fintech that means registration with SDAIA, a data protection officer, rules on transfers abroad and a 72-hour breach clock, with tighter rules now in draft.

The PDPL framework at a glance

InstrumentDetail
Personal Data Protection LawRoyal Decree M/19 dated 9/2/1443H (16 September 2021), amended by Royal Decree M/148 dated 5/9/1444H (27 March 2023)
CommencementIn force 14 September 2023; fully enforceable from 14 September 2024 after a one-year grace period
Implementing RegulationsIssued 7 September 2023
Regulation on Personal Data Transfer outside the KingdomIssued 7 September 2023; re-issued with amendments on 1 September 2024
Rules for Appointing a Personal Data Protection OfficerIssued 27 August 2024
RegulatorSaudi Data & AI Authority (SDAIA)
Registration and notificationsNational Data Governance Platform, dgp.sdaia.gov.sa

Dates for the amending decree, the regulations and the DPO rules come from law-firm reporting. Most sources give a one-year grace period; one source claims a longer one.

SDAIA runs the regime through the national data governance platform

SDAIA supervises the PDPL. Its National Data Governance Platform at dgp.sdaia.gov.sa opens onto a personal data protection portal. Published guidance describes it as the place for controller registration, the National Register of Controllers, DPO details and breach notification. Law-firm reporting adds that the Saudi Business Center is used to authorise the representative who registers the entity.

Enforcement is under way. The Committees for Reviewing PDPL Violations are issuing decisions, according to published commentary, so a fintech should treat its PDPL file as something an examiner or complainant can test today.

Why fintechs carry more PDPL risk than most

Payment, lending, wallet and investment businesses process identity documents, account data, transaction histories and device data in volume. Much of it lives in cloud services, and much of it is shared with banks, identity-verification vendors and group companies outside the Kingdom.

Each of those flows needs a lawful basis and a record. Where data leaves Saudi Arabia, it needs a route under the Transfer Regulation and a documented transfer assessment. Most gaps we find sit in the flows nobody thought of as a transfer: offshore support desks, analytics tools and group reporting.

Draft amendments open for comment until 5 November 2026

Draft articleProposalWhat it would mean for a fintech
Art. 23Personal data stored inside the Kingdom by default; transfers still allowed under the PDPLReview where production data, backups and logs are held
Art. 24Notify SDAIA within 72 hours of a breach, without a harm thresholdIncident triage could no longer screen out low-harm breaches
Arts. 28 and 29Evidence of consent for marketingKeep a retrievable record of each marketing consent
Art. 34Mandatory controller registration, including where data is transferred abroadRegistration on the platform becomes a firm requirement

Proposals only. Draft amendments to the Implementing Regulations were published on Istitlaa, the public consultation platform, for comment from 6 October to 5 November 2026, as reported by Clyde & Co. They are not in force and may change.

Practical PDPL compliance steps

  1. Map your data

    A record of processing that covers customers, merchants, staff and counterparties: what you collect, why, where it is stored, who receives it and how long you keep it.

  2. Register and appoint

    Check whether you must register as a controller on the National Data Governance Platform today, plan for the draft that would make registration mandatory, and appoint a DPO under SDAIA's rules.

  3. Assess transfers

    For every flow out of the Kingdom, identify the basis under the Transfer Regulation and document a transfer impact assessment. Cloud regions, offshore KYC vendors and group reporting are the usual gaps.

  4. Write notices and consents

    Privacy notices in Arabic and English, consent records for marketing, and a working process for data subject requests.

  5. Prepare for breaches

    A playbook that gets you to a notification decision inside 72 hours, tied to your incident response and to the reporting you owe your financial regulator.

  6. Contract and test

    Processor terms with every vendor, then periodic testing of the controls. See ongoing compliance.

How the PDPL fits with SAMA, NCA and CST rules

The PDPL is one layer. A SAMA or CMA licensee also answers to its regulator's own cyber security and outsourcing requirements, and the regulator will read your data protection set-up through that lens. Those regulator rules are separate from the PDPL and are not summarised here.

Two other bodies affect the same decisions. The National Cybersecurity Authority's Cloud Cybersecurity Controls (CCC-2:2024) apply to cloud providers and tenants and were updated for data-localisation changes. The Communications, Space & Technology Commission registers cloud providers in tiers. A fintech choosing a cloud provider should check CST registration, the provider's class and data location against the PDPL transfer rules and its regulator's outsourcing rules at the same time.

In practice we build one data and cloud map that answers the PDPL transfer questions, the outsourcing questions your regulator will ask and the cloud control questions together. The security side is covered in cybersecurity compliance.

Common questions

When did the PDPL become enforceable?

The law came into force on 14 September 2023 and became fully enforceable on 14 September 2024, after a one-year grace period, according to most published sources.

Is storing data in Saudi Arabia now mandatory?

Not under the rules in force. Draft amendments open for comment from 6 October to 5 November 2026 propose in-Kingdom storage as the default while still allowing transfers under the PDPL. Until SDAIA issues a final text, the current Transfer Regulation applies.

How quickly must a personal data breach be reported?

Within 72 hours to SDAIA. The draft amendments would remove the harm threshold, so more incidents would become reportable.

Do we need a data protection officer?

SDAIA issued Rules for Appointing a Personal Data Protection Officer on 27 August 2024. A fintech processing financial data at scale should expect to appoint one and record the DPO's details on the national data governance platform.

Primary sources

Last reviewed: 11 October 2026

General information, not legal advice. Saudi rules change; we confirm every requirement against the regulator's current text before you file.

Start with a 30-minute
licensing call

Tell us your model and where you are. We'll tell you which licence fits, what it takes and what we'd do first.

Book a consultation