Saudi Market5 min read
PDPL Compliance: What 48 SDAIA Decisions Mean for You

Key takeaways
- In January 2026 SDAIA’s committees reported 48 decisions confirming Personal Data Protection Law (PDPL) violations and imposing penalties on data controllers.
- The cases covered unlawful processing, disclosure without legal justification, weak security measures and marketing messages sent without consent.
- PDPL compliance is now an operations task: map your data, fix consent, secure systems and rehearse a 72-hour breach response.
PDPL compliance is no longer a paper exercise for Saudi companies. In January 2026 the Saudi Data and AI Authority (SDAIA) reported that its violation committees had issued 48 decisions in the previous year confirming breaches of the Personal Data Protection Law and imposing penalties. For owners and managers in logistics, healthcare, retail and real estate, the message is simple: regulators are now checking how you handle customer data.
What SDAIA announced about PDPL enforcement
On 16 January 2026 the Saudi Press Agency reported that the Committees for Reviewing Violations of the Personal Data Protection Law and its Regulations at SDAIA had issued 48 decisions confirming violations and enforcing the legally prescribed penalties on data controllers. The committees act under Article 36 of the law.
The announcement named four kinds of violation:
- Collecting and processing personal data without a valid basis.
- Disclosing personal data without legal justification.
- Failing to apply appropriate organisational, administrative and technical measures to protect personal data.
- Sending advertising and marketing messages to people without their consent.
IAPP described the decisions as the first substantive wave of adjudications under the law. None of these are exotic. They are everyday activities: a customer list, a shared spreadsheet, a WhatsApp promotion.
What the penalties can be
Law firms summarising the PDPL report that most breaches can lead to a warning or a fine of up to SAR 5 million, and that a court may double the fine for repeat offences. Disclosing sensitive data with intent to harm the person or to gain a personal benefit is a criminal offence carrying up to two years in prison and a fine of up to SAR 3 million. A&O Shearman also notes that the law can reach organisations outside the Kingdom that handle the data of people in Saudi Arabia.
Treat these as ceilings, not predictions. The practical risk for a mid-sized business is a warning, a fine, an order to fix a practice, and the cost of doing that under pressure.
The PDPL compliance duties managers overlook
The Implementing Regulations, issued on 7 September 2023, turned the law into specific duties. According to Clyde & Co, they include:
- Reporting a personal data breach to SDAIA within 72 hours of discovering it, and telling affected people without undue delay.
- Keeping records of processing activities for as long as the processing continues, plus five years.
- Recording consent that is freely given, with clear and specific purposes, and a separate record for each purpose.
- Letting people stop receiving marketing at any time.
- Answering requests from individuals within 30 days, extendable by another 30 for complex cases.
The regulations also set out when a data protection officer is required, for example for organisations whose main activity is regular monitoring of individuals or processing sensitive data at scale.
A PDPL compliance checklist for the next 60 days
- Map your data: list every system that holds customer, patient, tenant, student or employee data, including spreadsheets, shared drives and WhatsApp groups.
- Name the lawful basis for each use, and stop collecting data you do not need.
- Fix marketing consent: confirm that every promotional message goes to people who agreed, and that opting out is one step.
- Tighten access: give each person only the data their job needs, remove leavers, and turn on multi-factor sign-in.
- Review disclosures: check what you share with suppliers, agents and software vendors, and put the terms in writing.
- Write a one-page breach plan with an owner, a contact for SDAIA and a clock that starts at discovery.
- Prepare a simple process for access and deletion requests, with a 30-day tracker.
- Appoint one accountable person, even if a data protection officer is not mandatory for you.
PDPL compliance when you add AI
AI tools multiply the places where personal data travels. A customer-service chatbot stores conversations, a document reader sees IDs and invoices, and an internal assistant may index staff files. Before launching any of them, decide what data the tool receives, where it is hosted, how long it is kept and who can see it.
Ask every AI provider where your data is hosted and processed, and get the answer in the contract. Building these controls in from the start is cheaper than retrofitting them after a complaint.
Where to start
Begin with the data map and the marketing consent check, because they address the violations SDAIA has already named. If you plan to use AI in customer service, finance or operations, our AI Architecture Audit reviews your systems and data flows so the first project is compliant by design. You can book a free discovery call with Scalor Systems at scalorsystems.com/contact.
This article is general information, not legal advice. Confirm your specific obligations with qualified Saudi counsel.
Sources
- Saudi Press Agency: Personal Data Protection Law Committees to Impose Penalties on Confirmed Violations (16 January 2026)
- A&O Shearman: Enforcement of the Saudi Personal Data Protection Law (27 January 2026)
- IAPP: Saudi Arabia’s data protection authority steps up enforcement (25 February 2026)
- DLA Piper: Data Protection Laws of the World, Enforcement in Saudi Arabia
- Clyde & Co: Saudi Arabia issues Implementing Regulations to the Personal Data Protection Law (September 2023)


