What Is Personal Data Protection Law (Royal Decree M/19)?
The Personal Data Protection Law (PDPL), Royal Decree M/19, was issued 16 September 2021 and amended by Royal Decree M/148, which changed the commencement period from 180 to 720 days and expressly cancelled the original decree's five-year delay of Article 33(1)-(2) — a currentness trap for any source that still describes that provision as exempt. The PDPL and its Implementing Regulation (SDAIA Administrative Decision 1516) entered full force on 14 September 2023. A general one-year corrective/grace period followed and ended 14 September 2024; SDAIA's own guidance states penalties were not applied during that period, and post-grace enforcement activity has since occurred. The original decree does still permit SDAIA to grant individual controllers additional adjustment periods for justified reasons, but no current public list of such extensions was located. SDAIA is the current operating authority under the original Council of Ministers Decision 98, which contemplated a possible future transfer to a National Data Management Office (NDMO); no official instrument establishing a separate authority or transferring jurisdiction away from SDAIA has been located.
At a glance
- Full name
- Personal Data Protection Law (Royal Decree M/19)
- Short code
- PDPL
- Jurisdiction
- Saudi Arabia
- Enacted
- 2021
- Last major update
- Amendment Royal Decree M/148 changed commencement to 720 days and cancelled the original 5-year Article 33 delay; PDPL and Implementing Regulation in full force since 14 September 2023, with the general one-year corrective/grace period ending 14 September 2024
- Regulator
- Saudi Data and Artificial Intelligence Authority (SDAIA)
- Private right of action
- Yes
Scope, who PDPL covers
Protected data
Data subject rights
Right to know the legal basis and purpose of processing
Right of access, restrictable to protect the subject or others from harm, or for public-controller security/legal/judicial reasons
Right to obtain a readable, clear copy of personal data
Right to correction, completion, and updating, including temporary processing restriction pending verification
Right to destruction of personal data on request, when no longer necessary, or when unlawfully processed
Right to withdraw consent at any time, at least as easily as giving it
Right to complain to the competent authority (Article 34)
Right to compensation for material or moral damage via the competent court (Article 40)
Right to object to direct marketing, with an easy free opt-out
Notable features
The PDPL's enforcement history is unusually staged: an original 180-day commencement was extended to 720 days by amendment, followed by a one-year corrective/grace period that itself ended over a year before 7 September 2026. Controller rights-request deadlines are 30 days, extendable once by up to 30 additional days for unexpected or unusual effort. A separate 2024 Regulation on Personal Data Transfer Outside the Kingdom (SDAIA Decision 1840) requires the competent authority to publish and periodically review an adequacy list, but no accessible current adequacy list was located.
Enforcement & penalties
Regulator: Saudi Data and Artificial Intelligence Authority (SDAIA)
Penalties: Two-tier structure under the current, amended text: intentional unlawful disclosure or publication of sensitive data with intent to harm or gain (Article 35) — up to 2 years' imprisonment, a fine up to SAR 3,000,000, or either, doubled to SAR 6,000,000 for recidivism; other violations by covered private persons or entities (Article 36) — a warning or a fine up to SAR 5,000,000, doubled to SAR 10,000,000 for a repeat violation. The original PDPL contained a separate, lower Article 29-linked penalty that was replaced by M/148 and is no longer part of the current Article 35 text.
Private right of action: Article 40 provides a right to compensation for material or moral damage via the competent court, separate from the SDAIA complaint route. A complaint to SDAIA must generally be filed within 90 days of the incident or of the data subject becoming aware of it, with SDAIA retaining discretion to accept late complaints for justified factual reasons; no statutory deadline for SDAIA to complete its investigation or issue an outcome was located.
Relevance to data brokers
No Saudi-specific data-broker or public-record-aggregator complaint or deletion route has been located across Bureau of Experts, Umm Al-Qura, SDAIA, and National Data Governance Platform materials in both Arabic and English. Only the general PDPL rights process and SDAIA complaint platform exist. The PDPL's public-source collection permission (Articles 10, 15) allows lawful collection from public sources but does not exempt a broker from the law's other rights and obligations.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is Saudi Arabia's PDPL currently in force, or is it still in a transition period?+
The PDPL and its Implementing Regulation have been in full legal force since 14 September 2023. A general one-year corrective/grace period followed and ended 14 September 2024 — no general transition period remains active, though SDAIA can still grant individual controllers case-by-case adjustment periods for justified reasons.
How do I file a complaint under the PDPL?+
File with SDAIA generally within 90 days of the incident or of becoming aware of it, including the violation's location and time, your identity and contact details, the respondent's information, and evidence. No statutory deadline for SDAIA to complete its investigation or issue an outcome was located in the current Implementing Regulation.
Does the PDPL cover data collected from public sources?+
The PDPL permits collecting from and disclosing data from a publicly available source under specific conditions (Articles 10 and 15), but this is not a general exemption from the rest of the law — the data subject's other rights and the controller's other obligations still apply.
Official sources & citations
Other international privacy regimes
PDPL sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
