Back to Blog
    September 30, 2026
    Insights

    Saudi PDPL: What It Means for Your Software, Apps and AI

    PDPL Saudi Arabia explained for software: consent, 30-day data requests, 72-hour breach notice, transfers and what to build into your CRM, app or AI.

    Saudi PDPL: What It Means for Your Software, Apps and AI

    PDPL Saudi Arabia refers to the Personal Data Protection Law, which governs how any organisation collects, stores and uses personal data about people in the Kingdom. It covers processing inside Saudi Arabia and processing of residents' data from abroad, so a CRM hosted in Europe or an app built by an overseas team is still in scope.

    At a glance: collect only what you need, record consent properly, let people see, correct and delete their data within 30 days, delete data when its purpose ends, report serious breaches to SDAIA within 72 hours, and check the transfer rules before data leaves the Kingdom. Built in from the start, these are cheap.

    This article is general information, not legal advice. Check your own situation with a qualified Saudi adviser.

    What the PDPL is and who it applies to

    The law was issued by Royal Decree No. M/19 of 1443H and amended by Royal Decree No. M/148 of 1444H. The Saudi Data and Artificial Intelligence Authority (SDAIA) supervises it, and its National Data Governance Platform runs the controller register, breach notifications and complaints.

    Personal data is anything that can identify a person directly or indirectly: names, ID numbers, addresses, phone numbers, bank and card numbers, photos and video. Some data is sensitive and gets stricter rules, including health, genetic and biometric data.

    The controller decides why and how data is processed: usually you, the business. The processor handles data on the controller's behalf, such as a hosting provider. The only broad exemption is an individual using data purely for personal or family purposes.

    Consent and the other legal bases

    By default, you need a person's consent to process their data or to change the purpose you collected it for, and they can withdraw that consent. The law lists exceptions where consent is not needed, for example when processing is required by another law, is needed for an agreement the person is party to, or serves the controller's legitimate interests without harming the person's rights (this last one never applies to sensitive data).

    The Implementing Regulation adds detail that affects your screens and database:

    • Consent must be recorded so it can be proved later, including when and how it was given.
    • Each purpose needs its own consent, so one catch-all tick box is not enough.
    • Consent must be explicit for sensitive data, credit data and decisions made entirely by automated processing.
    • Marketing messages need the recipient's consent and a clear way to opt out.

    Rights your system must support

    People have the right to be told the legal basis and purpose for collecting their data, to access it, to receive a copy in a clear, readable format, to have it corrected or completed, and to have it destroyed when it is no longer needed.

    The Implementing Regulation says requests must be handled within 30 days, extendable by up to 30 more days if you tell the person in advance and explain why. You must also verify the requester's identity. In practice, that means an admin screen to find, export, correct and delete everything held on one person.

    A practical build checklist

    PDPL requirementWhat it means in your software
    Collect the minimum data neededRemove "nice to have" fields, and destroy data you no longer need.
    A privacy policy available at collectionLink it on every sign-up and data form, covering purpose, storage, destruction and rights.
    Destroy data when the purpose endsSet retention rules per record type and run automatic deletion or anonymisation. Keep data longer only where another law requires it or a court case needs it.
    Breach notificationAccess logs, alerts and an incident plan so you know what leaked, when and whose data.
    Impact assessmentAssess the privacy impact of any product or service offered to the public.

    On retention, SDAIA's own FAQ confirms there is no single fixed period: you keep data only as long as the purpose, or another Saudi law, requires.

    Developer reviewing PDPL build checklist on laptop with sign-up form and deletion workflow

    Breaches, transfers and data protection officers

    Breaches. Under the Implementing Regulation, the controller must notify SDAIA within 72 hours of becoming aware of a breach if it could harm the data or the person. People affected must be told in plain language when the breach could harm them.

    Transfers outside the Kingdom. The law allows transfers for set purposes, such as performing an obligation the person is party to, provided national security is not harmed, the destination offers an adequate level of protection and only the minimum data is sent. The transfer regulation lets controllers use safeguards such as SDAIA's standard contractual clauses, binding common rules within a group, or an accreditation certificate. This matters for cloud hosting and AI services abroad.

    Data protection officer (DPO). SDAIA's rules require a controller to appoint a DPO if it is a public body processing data on a large scale, or if its core activities involve regular, systematic monitoring of people or processing sensitive data.

    Penalties. The law allows a warning or a fine of up to SAR 5 million for breaching it or its regulations, doubled for repeat violations. Disclosing sensitive data to harm someone or for personal gain can mean up to two years in prison and a fine of up to SAR 3 million.

    What this means for CRMs, apps and AI agents

    CRMs hold the most personal data, so role-based permissions, per-purpose consent flags and a deletion workflow that also clears linked records matter most. Mobile apps need clear consent screens, an in-app way to request access or deletion, and care with analytics tools that track users continuously, which may count as systematic monitoring.

    CRM role permissions, mobile consent screen and AI agent with consent flags shown together

    AI agents and chatbots need extra thought. Check where the AI model provider processes data, since that may be a transfer outside the Kingdom. Avoid sending ID numbers or health details to the model unless needed, and get explicit consent if the agent makes decisions without a human, for example rejecting an application. Our guide to Arabic AI chatbots covers the build side.

    If an off-the-shelf tool already offers consent logs, data export, deletion and a hosting region that suits your transfer assessment, using it is often the simplest route.

    How Rinaztec can help

    We build custom web applications, customer portals and integrations with multi-user roles and permissions, and you own the full source code with all accounts in your name. We are not lawyers, so we work from the requirements you agree with your adviser and turn them into consent records, export and deletion screens, retention jobs and access logs. See our custom software development service: projects start from $15,000 and take 6 to 10 weeks.

    Is your system ready for PDPL requests and breach reporting? Book a free 30-minute call and we will look at your setup with you.

    Sources

    Keep exploring our insights

    View All Stories