Privacy Policy in Saudi Arabia
The Personal Data Protection Law makes a privacy policy a standalone statutory obligation rather than a by-product of notice duties. Article 12 requires the controller to use a privacy policy and make it available before data is collected, and lists what it must specify. The Law reaches processing carried out from outside the Kingdom where it concerns individuals residing in Saudi Arabia.
Governing law
Privacy notices are governed by the Personal Data Protection Law, Royal Decree No. M/19 dated 9/2/1443H as amended by Royal Decree No. M/148 dated 5/9/1444H, and its Implementing Regulation, both published by the Saudi Data and Artificial Intelligence Authority.
What a privacy policy has to contain in Saudi Arabia
Article 2(1) applies the Law to any processing of personal data of individuals taking place in the Kingdom, expressly including processing from outside the Kingdom of data relating to individuals residing in it.
Article 12 requires the controller to use a privacy policy and make it available to data subjects before collecting their data, specifying the purpose of collection, the data collected, the means of collection, processing, storage and destruction, and data subject rights and how to exercise them.
Article 13 requires a controller collecting directly to state the legal basis, the purpose and which data is mandatory or optional, the collector's identity, the recipients and whether data goes outside the Kingdom, the risks of not providing it, and the Article 4 rights.
Article 4 of the Implementing Regulation adds the controller's contact details and data protection channels, the data protection officer's contact details where applicable, the retention period or the criteria for it, and how to withdraw consent.
Implementing Regulation of the Personal Data Protection Law, Art. 4 (SDAIA)
Article 5 makes processing and any change of purpose conditional on consent except in the cases stated in the Law and allows withdrawal at any time. Article 7 bars making consent a condition of a service or benefit unless the service is directly related to the processing consented to.
Article 3(1)(a) of the Implementing Regulation requires the controller to act on a rights request within 30 days and without delay, extendable by a further 30 days on prior notice with reasons where implementation requires disproportionate effort or multiple requests are received.
Implementing Regulation of the Personal Data Protection Law, Art. 3(1)(a) (SDAIA)
Form, notarisation and registration
Article 33 of the Implementing Regulation requires written records of processing activities, kept during processing and for five years after, accurate and up to date, and made available to the Competent Authority on request.
Implementing Regulation of the Personal Data Protection Law, Art. 33 (SDAIA)
Article 24(1) of the Implementing Regulation requires notification to the Competent Authority within 72 hours of becoming aware of a personal data breach that may harm the data or the data subject or conflict with their rights.
Implementing Regulation of the Personal Data Protection Law, Art. 24 (SDAIA)
What catches drafters out
Article 29 permits transfer outside the Kingdom only for the listed purposes and, subject to an extreme necessity exception, only where national security and the Kingdom's vital interests are not prejudiced, protection abroad is at least equivalent as assessed by the Competent Authority, and the transfer is the minimum needed.
Article 29 of the Implementing Regulation requires consent before direct marketing, an opt-out at least as easy as giving consent, the sender's identity stated without anonymisation, and marketing to stop immediately on withdrawal.
Implementing Regulation of the Personal Data Protection Law, Art. 29 (SDAIA)
Article 35 punishes disclosing or publishing sensitive data in violation of the Law with intent to harm or gain by up to two years' imprisonment, a fine up to three million riyals, or both. Article 36 covers other violations with a warning or a fine up to five million riyals.
Privacy Policy in Saudi Arabia: common questions
- Does Saudi law require a written privacy policy?
- Yes. Article 12 of the Personal Data Protection Law requires the controller to use a privacy policy and make it available to data subjects for their information before collecting their personal data. The policy must specify the purpose of collection, the data to be collected, the means used for collection, processing, storage and destruction, and information about data subject rights and how to exercise them.
- Does the PDPL apply to a company outside Saudi Arabia?
- Article 2(1) of the Personal Data Protection Law applies it to any processing of personal data of individuals taking place in the Kingdom by any means, and expressly includes processing by a party outside the Kingdom of personal data relating to individuals residing in the Kingdom. Article 29 then governs when data may be transferred or disclosed outside the Kingdom.
- How long is there to respond to a data subject request?
- Article 3(1)(a) of the Implementing Regulation requires the controller to act on the request within 30 days and without delay. The period may be extended by a further 30 days where implementation requires disproportionate effort or where the controller receives multiple requests from the same data subject, provided the data subject is notified in advance of the extension and the reasons for it.
Sources
Every statement on this page is drawn from one of these. All were fetched on .
- Implementing Regulation of the Personal Data Protection Law, Art. 1, citing Royal Decree No. M/19 dated 9/2/1443H as amended by Royal Decree No. M/148 dated 5/9/1444H (SDAIA)
- Personal Data Protection Law, Royal Decree No. M/19 dated 9/2/1443H as amended by Royal Decree No. M/148 dated 5/9/1444H, Art. 2(1) (SDAIA)
- Personal Data Protection Law, Royal Decree No. M/19 dated 9/2/1443H as amended by Royal Decree No. M/148 dated 5/9/1444H, Art. 12 (SDAIA)
- Personal Data Protection Law, Royal Decree No. M/19 dated 9/2/1443H as amended by Royal Decree No. M/148 dated 5/9/1444H, Art. 13 (SDAIA)
- Implementing Regulation of the Personal Data Protection Law, Art. 4 (SDAIA)
- Personal Data Protection Law, Royal Decree No. M/19 dated 9/2/1443H as amended by Royal Decree No. M/148 dated 5/9/1444H, Arts. 5 and 7 (SDAIA)
- Implementing Regulation of the Personal Data Protection Law, Art. 3(1)(a) (SDAIA)
- Implementing Regulation of the Personal Data Protection Law, Art. 33 (SDAIA)
- Implementing Regulation of the Personal Data Protection Law, Art. 24 (SDAIA)
- Personal Data Protection Law, Royal Decree No. M/19 dated 9/2/1443H as amended by Royal Decree No. M/148 dated 5/9/1444H, Art. 29 (SDAIA)
- Implementing Regulation of the Personal Data Protection Law, Art. 29 (SDAIA)
- Personal Data Protection Law, Royal Decree No. M/19 dated 9/2/1443H as amended by Royal Decree No. M/148 dated 5/9/1444H, Arts. 35 and 36 (SDAIA)
The same document elsewhere
Other Saudi Arabia documents
- Employment Contract
- Non-Compete Agreement
- Termination Letter
- Independent Contractor Agreement
- Non-Disclosure Agreement (NDA)
- Service Agreement
- Residential Lease Agreement
- Commercial Lease Agreement
- Eviction Notice
- Power of Attorney
- Last Will and Testament
- LLC Operating Agreement
- Shareholder Agreement
- Loan Agreement
Privacy Policy: the jurisdiction-neutral guideBack to Document Library