Mandatory scheme
Personal Data Protection Law (PDPL) compliance
Personal Data Protection Law (PDPL) compliance — mandatory scheme, Saudi Arabia. It binds entities processing personal data in Saudi Arabia.
- Jurisdiction
- Saudi Arabia
- Record class
- Mandatory scheme
- Last verified
Where this applies
This record is scoped to Saudi Arabia. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.
Instrument
Personal Data Protection Law, Royal Decree M/19 (9/2/1443H)
Who it binds
Entities processing personal data in Saudi Arabia
What it requires
SDAIA's official English PDPL text (V2, 23 April 2023), read directly: Art. 35 sets a criminal penalty of up to 2 years' imprisonment and/or a fine of up to 3,000,000 SAR for certain violations (doubled on repeat offence, Public Prosecution competent); Art. 36 sets an administrative penalty of a warning or a fine of up to 5,000,000 SAR, decided by a committee of at least 3 members with a right of appeal; Art. 43 sets the law's effective date as 720 days after its Official Gazette publication. The competent supervisory authority is designated by Council of Ministers decision.
Route to the authority
Last verified:
Related records and requirements
- Personal Information Protection and Electronic Documents Act (PIPEDA) (Canada) — PIPEDA is Canada's federal general-compliance data-protection law, binding organisations that collect, use or disclose personal information in the course of commercial activity.
- Act Respecting the Protection of Personal Information in the Private Sector (Québec) (Canada) — Québec's own private-sector privacy law is the general-compliance regime for private-sector businesses handling personal information within Québec — it takes the place of PIPEDA for that in-province activity.
- Privacy Act 1988 — Australian Privacy Principles (Australia) — The Privacy Act 1988 binds Australian government agencies and covered organisations to 13 Australian Privacy Principles — the small-business turnover exemption has documented exceptions.
- Act on the Protection of Personal Information (APPI) compliance (Japan) — APPI's general obligations (Art. 21(1) purpose notification, Art. 23 security-management measures) bind business operators handling personal information in Japan.
- Personal Data (Privacy) Ordinance compliance (Hong Kong SAR China) — Hong Kong's Cap. 486 sets six Data Protection Principles binding data users in Hong Kong, overseen by the PCPD.
- Personal data protection compliance (Vietnam) — Vietnam's Decree 13/2023 and, from 1 January 2026, Law 91/2025 bind organisations processing personal data in Vietnam to a general data-protection compliance regime.
- Federal personal data protection compliance (Mexico) — Mexico's federal private-sector data-protection law, replaced in full on 20 March 2025, binds private-sector personal-data processing nationwide.
- Federal personal data protection compliance (United Arab Emirates) — The UAE's federal PDPL (Federal Decree-Law No. 45 of 2021) binds organisations processing personal data inside or outside the UAE where the processing relates to the UAE — separate from DIFC's and ADGM's own free-zone regimes.
This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.