The PDPL framework at a glance
| Instrument | Detail |
|---|---|
| Personal Data Protection Law | Royal Decree M/19 dated 9/2/1443H (16 September 2021), amended by Royal Decree M/148 dated 5/9/1444H (27 March 2023) |
| Commencement | In force 14 September 2023; fully enforceable from 14 September 2024 after a one-year grace period |
| Implementing Regulations | Issued 7 September 2023 |
| Regulation on Personal Data Transfer outside the Kingdom | Issued 7 September 2023; re-issued with amendments on 1 September 2024 |
| Rules for Appointing a Personal Data Protection Officer | Issued 27 August 2024 |
| Regulator | Saudi Data & AI Authority (SDAIA) |
| Registration and notifications | National Data Governance Platform, dgp.sdaia.gov.sa |
Dates for the amending decree, the regulations and the DPO rules come from law-firm reporting. Most sources give a one-year grace period; one source claims a longer one.
SDAIA runs the regime through the national data governance platform
SDAIA supervises the PDPL. Its National Data Governance Platform at dgp.sdaia.gov.sa opens onto a personal data protection portal. Published guidance describes it as the place for controller registration, the National Register of Controllers, DPO details and breach notification. Law-firm reporting adds that the Saudi Business Center is used to authorise the representative who registers the entity.
Enforcement is under way. The Committees for Reviewing PDPL Violations are issuing decisions, according to published commentary, so a fintech should treat its PDPL file as something an examiner or complainant can test today.
Why fintechs carry more PDPL risk than most
Payment, lending, wallet and investment businesses process identity documents, account data, transaction histories and device data in volume. Much of it lives in cloud services, and much of it is shared with banks, identity-verification vendors and group companies outside the Kingdom.
Each of those flows needs a lawful basis and a record. Where data leaves Saudi Arabia, it needs a route under the Transfer Regulation and a documented transfer assessment. Most gaps we find sit in the flows nobody thought of as a transfer: offshore support desks, analytics tools and group reporting.
Draft amendments open for comment until 5 November 2026
| Draft article | Proposal | What it would mean for a fintech |
|---|---|---|
| Art. 23 | Personal data stored inside the Kingdom by default; transfers still allowed under the PDPL | Review where production data, backups and logs are held |
| Art. 24 | Notify SDAIA within 72 hours of a breach, without a harm threshold | Incident triage could no longer screen out low-harm breaches |
| Arts. 28 and 29 | Evidence of consent for marketing | Keep a retrievable record of each marketing consent |
| Art. 34 | Mandatory controller registration, including where data is transferred abroad | Registration on the platform becomes a firm requirement |
Proposals only. Draft amendments to the Implementing Regulations were published on Istitlaa, the public consultation platform, for comment from 6 October to 5 November 2026, as reported by Clyde & Co. They are not in force and may change.
Practical PDPL compliance steps
Map your data
A record of processing that covers customers, merchants, staff and counterparties: what you collect, why, where it is stored, who receives it and how long you keep it.
Register and appoint
Check whether you must register as a controller on the National Data Governance Platform today, plan for the draft that would make registration mandatory, and appoint a DPO under SDAIA's rules.
Assess transfers
For every flow out of the Kingdom, identify the basis under the Transfer Regulation and document a transfer impact assessment. Cloud regions, offshore KYC vendors and group reporting are the usual gaps.
Write notices and consents
Privacy notices in Arabic and English, consent records for marketing, and a working process for data subject requests.
Prepare for breaches
A playbook that gets you to a notification decision inside 72 hours, tied to your incident response and to the reporting you owe your financial regulator.
Contract and test
Processor terms with every vendor, then periodic testing of the controls. See ongoing compliance.
How the PDPL fits with SAMA, NCA and CST rules
The PDPL is one layer. A SAMA or CMA licensee also answers to its regulator's own cyber security and outsourcing requirements, and the regulator will read your data protection set-up through that lens. Those regulator rules are separate from the PDPL and are not summarised here.
Two other bodies affect the same decisions. The National Cybersecurity Authority's Cloud Cybersecurity Controls (CCC-2:2024) apply to cloud providers and tenants and were updated for data-localisation changes. The Communications, Space & Technology Commission registers cloud providers in tiers. A fintech choosing a cloud provider should check CST registration, the provider's class and data location against the PDPL transfer rules and its regulator's outsourcing rules at the same time.
In practice we build one data and cloud map that answers the PDPL transfer questions, the outsourcing questions your regulator will ask and the cloud control questions together. The security side is covered in cybersecurity compliance.
Common questions
When did the PDPL become enforceable?
The law came into force on 14 September 2023 and became fully enforceable on 14 September 2024, after a one-year grace period, according to most published sources.
Is storing data in Saudi Arabia now mandatory?
Not under the rules in force. Draft amendments open for comment from 6 October to 5 November 2026 propose in-Kingdom storage as the default while still allowing transfers under the PDPL. Until SDAIA issues a final text, the current Transfer Regulation applies.
How quickly must a personal data breach be reported?
Within 72 hours to SDAIA. The draft amendments would remove the harm threshold, so more incidents would become reportable.
Do we need a data protection officer?
SDAIA issued Rules for Appointing a Personal Data Protection Officer on 27 August 2024. A fintech processing financial data at scale should expect to appoint one and record the DPO's details on the national data governance platform.
Primary sources
Last reviewed: 11 October 2026
General information, not legal advice. Saudi rules change; we confirm every requirement against the regulator's current text before you file.



