Skip to content

Privacy Policy in Saudi Arabia

The Personal Data Protection Law makes a privacy policy a standalone statutory obligation rather than a by-product of notice duties. Article 12 requires the controller to use a privacy policy and make it available before data is collected, and lists what it must specify. The Law reaches processing carried out from outside the Kingdom where it concerns individuals residing in Saudi Arabia.

Governing law

Privacy notices are governed by the Personal Data Protection Law, Royal Decree No. M/19 dated 9/2/1443H as amended by Royal Decree No. M/148 dated 5/9/1444H, and its Implementing Regulation, both published by the Saudi Data and Artificial Intelligence Authority.

Implementing Regulation of the Personal Data Protection Law, Art. 1, citing Royal Decree No. M/19 dated 9/2/1443H as amended by Royal Decree No. M/148 dated 5/9/1444H (SDAIA)

What a privacy policy has to contain in Saudi Arabia

Form, notarisation and registration

What catches drafters out

Privacy Policy in Saudi Arabia: common questions

Does Saudi law require a written privacy policy?
Yes. Article 12 of the Personal Data Protection Law requires the controller to use a privacy policy and make it available to data subjects for their information before collecting their personal data. The policy must specify the purpose of collection, the data to be collected, the means used for collection, processing, storage and destruction, and information about data subject rights and how to exercise them.
Does the PDPL apply to a company outside Saudi Arabia?
Article 2(1) of the Personal Data Protection Law applies it to any processing of personal data of individuals taking place in the Kingdom by any means, and expressly includes processing by a party outside the Kingdom of personal data relating to individuals residing in the Kingdom. Article 29 then governs when data may be transferred or disclosed outside the Kingdom.
How long is there to respond to a data subject request?
Article 3(1)(a) of the Implementing Regulation requires the controller to act on the request within 30 days and without delay. The period may be extended by a further 30 days where implementation requires disproportionate effort or where the controller receives multiple requests from the same data subject, provided the data subject is notified in advance of the extension and the reasons for it.

Sources

Every statement on this page is drawn from one of these. All were fetched on .

The same document elsewhere

Other Saudi Arabia documents

Privacy Policy: the jurisdiction-neutral guideBack to Document Library