Skip to content

Stratgik — technology strategy and business systems engineering.
Delivery across the USA, UK, UAE and India.

Talk about a problem

Saudi PDPLFully enforceable since 14 September 2024

Saudi PDPL compliance before SDAIA comes asking. Fixed fees from SAR 6,500.

SDAIA is issuing enforcement decisions, and organisations get only days to respond once notified. We map your personal data, set up notices, consent, breach reporting and data subject rights, and document cross-border transfers, inside the systems you actually run.

  • Fixed fees in SAR
  • Implemented in your systems, not just a policy
  • Engineers, working alongside your lawyers

What is at stake

Enforcement under the Personal Data Protection Law (PDPL) enforced by SDAIA

Once notified, organisations have very short response windows, so procedural readiness matters as much as the controls themselves.

  1. SAR 5m

    Violations of the PDPL and its regulations, doubled for repeat offences

  2. SAR 3m + prison

    Disclosing sensitive personal data with intent to harm: up to 2 years’ imprisonment

  3. Publication

    Committees can also issue warnings and order the penalty to be published

What the law asks, in plain words

Eight things to get right in Saudi Arabia

  • Privacy policy

    A clear policy explaining the purpose, legal basis, recipients and retention of personal data, available before collection.

  • Legal basis and consent

    Process data only with a valid legal basis. Consent must be specific and can be withdrawn.

  • 72-hour breach notification

    Notify SDAIA within 72 hours of becoming aware of a breach that may harm individuals, and inform affected people where required.

  • Data subject rights

    Rights to be informed, access, correct, destroy and obtain a copy of data. Respond within 30 days.

  • Records of processing

    Maintain records of processing activities and make them available to SDAIA on request.

  • Cross-border transfers

    Transfers outside the Kingdom must follow the Transfer Regulation, with a risk assessment where required.

  • Security and impact assessments

    Appropriate security controls and impact assessments for high-risk processing.

  • Registration and DPO

    Some controllers must register on the National Data Governance Platform and appoint a data protection officer.

Free self-check

How ready is your organisation?

Ten questions, two minutes. Nothing is sent anywhere unless you ask for help.

0/ 100

Answer the questions to see your score

0 of 10 answered

  1. 1Do you have a data inventory covering systems that hold data of people in Saudi Arabia?
  2. 2Is your privacy policy available in Arabic and English before data is collected?
  3. 3Is each processing purpose tied to a legal basis or consent?
  4. 4Could you notify SDAIA within 72 hours of a breach?
  5. 5Can you respond to access, correction and destruction requests within 30 days?
  6. 6Do you maintain records of processing activities?
  7. 7Are transfers outside the Kingdom assessed and documented?
  8. 8Have you checked whether you must register or appoint a DPO?
  9. 9Is there an authorised representative ready to respond to SDAIA notices?
  10. 10Are vendors processing data bound by PDPL-compliant contracts?

How we get you compliant

Four steps, done with your team

  1. 1

    Discover

    Find every copy of personal data

    Website, apps, CRM, ERP, spreadsheets, messaging tools and vendors.

  2. 2

    Decide

    Rank the gaps by risk

    Each gap scored against enforcement exposure and effort, so the serious ones get fixed first.

  3. 3

    Implement

    Fix it in your systems

    Notices, consent, request workflows, access controls, retention and vendor terms.

  4. 4

    Hand over

    Train people, rehearse a breach

    A live session for the staff who handle data and a practice run of breach reporting.

Pricing

Fixed fees. No surprises.

For organisations with one website or product and up to five systems holding personal data. Larger scope is quoted in writing before you pay anything.

Readiness Audit

Know where you stand under the PDPL.

SAR6,500one-time
+ VAT

Report in 7 working days

Choose Readiness Audit
  • Discovery session with an engineer
  • Data map across website, apps, ERP, CRM and vendors (up to 5 systems)
  • Gap report against the PDPL and its regulations
  • Gaps ranked by enforcement risk
  • 90-day action plan

Recommended

Compliance Setup

We implement the controls in your systems.

SAR19,500one-time
+ VAT

Typically 4 to 6 weeks

Choose Compliance Setup
  • Everything in Readiness Audit
  • Arabic and English privacy policy
  • Consent capture and records
  • Rights request workflow with 30-day tracking
  • Breach playbook with 72-hour SDAIA template
  • Records of processing and transfer assessments
  • Enforcement response protocol
  • Live staff training session

PDPL Care

Stay ready as SDAIA guidance and your systems change.

SAR2,450per month
+ VAT

Cancel any month

Choose PDPL Care
  • Rights request handling support
  • Quarterly review of systems and vendors
  • Breach support during Saudi business hours
  • Updates when SDAIA guidance changes
  • Annual refresher training

Free readiness call

Talk to an engineer, not a salesperson

An engineer replies within one working day with a suggested approach and a fixed quote.

  1. 1
    You send the formTwo minutes. Tell us the problem, not the solution.
  2. 2
    We talk it throughA short call at a time that suits your working hours.
  3. 3
    You get a fixed quoteIn writing, in SAR. Nothing is billed until you approve it.

Book your free readiness call

Interested in

See our privacy policy.

Questions

Saudi PDPL questions we get asked

Also see how Stratgik works with Saudi Arabia businesses.

Does the PDPL apply to companies outside Saudi Arabia?

Yes. It applies to processing of personal data of individuals residing in the Kingdom, including by entities outside it.

What are the penalties under the PDPL?

Fines of up to SAR 5 million per violation, which can be doubled for repeat violations. Disclosing sensitive data with intent to harm can lead to imprisonment of up to two years and a fine of up to SAR 3 million.

How quickly must a breach be reported?

Within 72 hours of becoming aware of it, where it may harm individuals’ data or rights.

Can personal data be stored outside Saudi Arabia?

Transfers are allowed only in the circumstances set out in the Transfer Regulation, and some require a risk assessment. Some sectors have stricter localisation rules.

Is this legal advice?

No. Stratgik is a technology firm. We implement the controls and records in your systems and work with your legal counsel for legal opinions.

Are prices fixed?

Yes, for organisations with up to five systems holding personal data. Larger scope is quoted in writing first. VAT is added where applicable.

Find the gaps before a regulator does.

A readiness audit takes 7 working days and gives you a ranked, costed plan.

The Stratgik model

Strategy first. Technology that follows through.

Four stages, in order. Most businesses need them one at a time.