Guide
Saudi PDPL and AI systems: what the Implementing Regulation asks of a controller
Saudi Arabia’s Personal Data Protection Law (PDPL) says nothing about artificial intelligence, but the Implementing Regulation issued under it by the Saudi Data & AI Authority (SDAIA) reaches most AI systems in production that use personal data. Article 25 requires a written impact assessment where processing involves sensitive data or links personal data from different sources, and where a controller’s activity includes, on a large scale or repeatedly, processing based on newly adopted technologies or decisions based on automated processing. Article 4 adds notice duties for controllers whose activities include those on the same scale, including whether any decision is made solely by automated processing, and Article 11 requires explicit consent for such decisions where consent is the basis. A breach goes to SDAIA within 72 hours (Article 24), records of processing are kept until five years after the processing ends (Article 33), and some controllers must appoint a data protection officer and register on SDAIA’s National Data Governance Platform. Each duty ends up as something the system produces: an assessment, a notice, a log or a register entry.
Saudi PDPL. Saudi Arabia’s Personal Data Protection Law, issued by Royal Decree M/19 of 9/2/1443H and amended by Royal Decree M/148 of 5/9/1444H, read with the Implementing Regulation and the rules that SDAIA issues as its competent authority.
Checked . The Law, the Implementing Regulation, the Regulation on Personal Data Transfer outside the Kingdom, SDAIA’s rules for appointing a data protection officer and for the National Register of Controllers, its breach procedural guide and its AI Ethics Principles were read in SDAIA’s English versions on sdaia.gov.sa, the Implementing Regulation also in SDAIA’s Arabic text, and the National Data Governance Platform on dgp.sdaia.gov.sa, on this date. SDAIA revises its rules and guidance, so check the current text before you rely on it. This page is not legal advice.
A data law with no AI chapter that still reaches most AI systems
Saudi Arabia’s Personal Data Protection Law, نظام حماية البيانات الشخصية, is a general data-protection statute, issued by Royal Decree M/19 of 9/2/1443H and amended by Royal Decree M/148 of 5/9/1444H [2]. Neither the Law nor the Implementing Regulation that SDAIA issued under it uses the words artificial intelligence [1, 2]. Read them as an AI team would, though, and the regulation’s triggers describe what an AI system in production does: it links personal data from different sources, and it relies on newly adopted technologies and decisions based on automated processing, on a large scale or repeatedly [2, 10].
It also reaches further than people expect. Article 2 of the Law covers any processing of personal data in the Kingdom, and processing of personal data about individuals residing in the Kingdom by any party outside it [1]. A UK or US company running a model for Saudi customers is inside the Law wherever that model runs. SDAIA is the competent authority, as its own rules state [4, 5], and the Law leaves the powers of the Saudi Central Bank where they were [1].
The penalties are set in the Law itself. A violation of the Law or the regulations can bring a warning or a fine of up to five million riyals, which may be doubled for a repeat. Disclosing or publishing sensitive data with intent to harm someone or for personal benefit carries up to two years in prison, a fine of up to three million riyals, or both, and anyone harmed by a violation can go to court for compensation [1].
Public bodies are controllers like everyone else. The Law defines a public entity as any ministry, department, public institution or public authority [1], and several of the duties below name public entities directly.
The duties an AI system triggers, and what each one leaves behind
Here is the regulation read the way an AI team has to read it. The first column is where each duty sits. The second is my reading of what it asks of an AI system. The third is the artefact that shows the duty was met, which is what a data protection officer, an auditor or SDAIA will ask to see.
| Dimension | Where it sits | What it asks of an AI system | The artefact |
|---|---|---|---|
| Impact assessment | Implementing Regulation Article 25; Law Article 22 | A written assessment where processing involves sensitive data or links personal data from different sources, or where the controller’s activity includes newly adopted technologies or automated decisions on a large scale or repeatedly, with a copy to any processor acting for you | One assessment per use case, redone when it finds harm |
| Notice | Implementing Regulation Article 4; Law Article 13 | The usual notice, including whether data will be transferred, disclosed or processed outside the Kingdom; and where the controller’s activities include new technologies or automated decisions on a large scale or repeatedly, how the data is protected and whether decisions will be made solely by automated processing | Notice text for each channel the system collects through, under version control |
| Explicit consent | Implementing Regulation Article 11 | Where consent is the basis, explicit consent for decisions made solely by automated processing, a separate consent for each purpose, and a record that can be verified later | Consent records with the time, the means and the purpose |
| Processor terms | Implementing Regulation Article 17; Law Article 8 | A contract with each model or hosting provider stating the purpose, the data, the duration, breach notice, whether the provider is subject to other countries’ regulations and which subcontractors it uses, with your prior acceptance of new ones | A processor agreement and a sub-processor list for each provider |
| Breach notice | Implementing Regulation Article 24; Law Article 20 | SDAIA told within 72 hours of becoming aware of a breach that could cause harm, affected people told without undue delay, and copies of the reports kept | A breach runbook, and logs that can say whose data was exposed |
| Records of processing | Implementing Regulation Article 33; Law Article 31 | A written, current record of purposes, data, people, recipients, retention, transfers outside the Kingdom with their legal basis and security measures, kept until five years after the processing ends | A record entry per AI use case that names each model endpoint outside the Kingdom |
| Officer and register | Implementing Regulation Articles 32 and 34; SDAIA’s officer and register rules | A data protection officer where a public entity processes at scale or the core activity is sensitive data or regular and systematic monitoring; registration where the controller is a public entity, its main activity is processing personal data or it processes sensitive data | A written appointment and a registration certificate |
The first column is from the Law [1], the Implementing Regulation [2] and SDAIA’s rules [4, 5]. Two duties do not fit in a table row. Data minimisation is written partly as a documentation duty: the regulation asks for data maps that link each item of personal data to the purpose it serves [2], which for an AI system means knowing which fields reach the prompt. And destruction reaches copies, because Article 8 asks for every copy in the controller’s systems to be destroyed, backups included [2].
The middle column is my reading, not SDAIA’s, and this page is not legal advice.
Article 25 is the duty most AI projects meet first
Article 25 lists four situations in which a controller must write down an assessment of the impacts and risks for the people whose data it processes, and any one of them is enough [2].
- Sensitive data
- As the Law defines it: health data, biometric or genetic data used to identify a person, ethnic origin, religious, intellectual or political belief, criminal convictions, and data showing that a person’s parents are unknown [1].
- Linked datasets
- “Collecting, comparing, or linking two or more datasets of Personal Data obtained from different sources” [2]. A retrieval system that answers from the customer record and the ticket history together does exactly this.
- New technology or automated decisions
- In SDAIA’s English version: “The activity of the Controller includes - large scale and repetitive - Processing of Personal Data of those who lack full or partial legal capacity, or processing operations that by their nature require constant monitoring of Data Subjects, or Processing Personal Data based on newly adopted technologies, or making decisions based on automated Personal Data Processing” [2].
- Serious harm
- A product or service that involves personal data and is likely to cause serious harm to people’s privacy [2].
The qualifier sits between dashes straight after “includes”, so it reads most naturally as covering all four kinds of activity in that clause, not only the first. The Arabic text reads “على نطاق واسع أو بصورة متكررة”, on a large scale or repeatedly, where the English version says large scale and repetitive [2, 10]. Where the two differ, I work from the Arabic. In practice, a production AI system that runs every day on customer data will usually meet “repeatedly”, and a one-off pilot may not. The sensitive-data and linked-datasets triggers carry no such qualifier, which is why a typical retrieval system is caught either way.
Put a language model in front of customer data in 2026 and I would not try to argue it is anything other than a newly adopted technology. Look closely at the wording on decisions, too. Article 25 says decisions based on automated processing, without the word “solely” that Articles 4 and 11 use [2]. A person reviewing every output may change your notice and consent position. On my reading it does not take you out of the assessment.
The assessment has eight minimum parts: the purpose and legal basis, the nature of the processing, its scope, its context, necessity and proportionality, the impact on people and its likelihood, the measures to prevent or reduce the risks, and whether those measures are enough [2]. The controller gives a copy to any processor acting for it, and if the assessment shows the processing will harm people’s privacy, the controller addresses the causes and does the assessment again [2]. SDAIA’s National Data Governance Platform lists an impact assessment service [5, 9].
A private-sector controller that relies on legitimate interest rather than consent has a second assessment to write first, because Article 16 asks for a documented balancing test before that processing starts, and the basis is not available for sensitive data or to a public entity [2]. Before either document, it helps to score each AI use case before it is built, so the effort goes to the ones that carry the most risk.
“Solely automated” is where design choices change the duties
Two provisions turn on whether a decision is made solely by automated processing. Article 4 requires a controller whose activities include new technologies or automated decisions, on a large scale or repeatedly in the Arabic text, to tell people whether decisions will be made that way [2, 10], and Article 11 requires their consent to be explicit when they are and consent is the basis [2].
The regulation does not define “solely”. My reading is that a person who sees the inputs, has the time to disagree and can change the outcome takes a decision out of that category, while a reviewer who approves every output without the information to challenge it probably does not. That is a design choice as much as a legal one: the review screen, the override button and the log of how often reviewers actually override. Confirm the reading with your own counsel before a system depends on it.
For public bodies the questions are different, not lighter. A public entity cannot rely on legitimate interest [2]. When it collects data other than directly from the person, reuses it for another purpose or asks for it to be disclosed in the public interest, Article 21 asks it to show the public interest is clearly defined and within its legal mandate, to limit the harm, to keep to the minimum data and to record the processing in its records [2]. A ministry piloting an assistant on case files should expect all of that, plus registration, which every public entity needs, and an officer if it provides services that process personal data at scale [4, 5].
What sits on top: sector rules, transfers and SDAIA’s AI ethics
Health and credit data carry extra rules inside the regulation itself. Article 26 requires controllers processing health data to adopt the requirements of the Ministry of Health, the Saudi Health Council, the Saudi Central Bank and the Council of Health Insurance, to document every stage of processing with a named person in charge, and to put the same duties into their processor contracts [2]. Article 27 does the same for credit data against the Saudi Central Bank’s requirements and the Credit Information Law [2]. A bank or an insurer reads the PDPL alongside its sector regulator, never instead of it.
Sending personal data to a model hosted outside the Kingdom is a transfer. SDAIA’s Regulation on Personal Data Transfer outside the Kingdom, version 2.0 of August 2024, sets out three safeguards (standard contractual clauses, binding common rules and a certificate of accreditation) and requires a risk assessment before a transfer that relies on them, or one that moves sensitive data continuously or on a wide scale [3]. Which region actually runs the model is a separate question, and our guide to Gulf AI data residency sets out what to ask a cloud or model vendor about it.
SDAIA also publishes AI Ethics Principles, which on their own text apply to everyone designing, developing, deploying or using AI systems in the Kingdom [7]. They grade AI systems by risk: systems posing high risk to basic rights “must undergo pre- and post-conformity assessments”, and systems posing an unacceptable risk, such as social profiling, are not allowed [7]. Registration under them is optional [7]. The same SDAIA page lists generative AI guidelines for government and for the public [8], and the National Data Governance Platform’s menu, read in Arabic, lists an AI ethics assessment beside the personal data services [9].
A 30-day build for one AI use case
This is the order I would work in for one use case with a named owner. It is a plan built from the regulation, not a timetable SDAIA sets, and a controller with no register entry, no officer and no records at all has that work to do first.
- Week 1: map and trigger
- List the data the system reads and writes, its sources, its users and every model endpoint, with the region each one runs in. Map each personal data field to its purpose. Decide which Article 25 triggers apply, and whether the controller needs an officer or a register entry.
- Week 2: assess
- Write the impact assessment against its eight parts, and the legitimate-interest assessment if that is the basis. Decide, on paper, whether any decision is solely automated, and send the assessment to the processors acting for you.
- Week 3: tell and contract
- Update the notice for each channel, build consent capture where consent is the basis, and put Article 17’s terms into each model and hosting contract, including the sub-processor list. Record the transfer safeguard for each endpoint outside the Kingdom.
- Week 4: log and rehearse
- Turn on logging that can answer whose data, what data and how many people within 72 hours, write the record of processing entry, build deletion that reaches backups and indexes, and rehearse a breach notification end to end, through the platform service SDAIA’s breach guide describes [6].
Thirty days is realistic when the owner can make decisions and the data sources are known. It is not realistic when nobody can say which systems hold personal data, and in that case the map is the project.
Where 1AYM fits
The work on this page is what we sell as AI governance implementation: the impact assessment, the records and the logging built into the system they describe, so the evidence comes from the system rather than from a document written beside it. We work with clients across the UK, the US and the Gulf. We have built Arabic-language AI, including bilingual Arabic and English search and Arabic document OCR, which matters here because a Saudi system often reads personal data written in Arabic.
Our closest published work in the region is the production estate of a government-accredited EdTech in the Middle East, whose database we replatformed into Google Cloud’s Doha region, me-central1, to meet Gulf data-residency requirements. That was a Qatar-region decision rather than a Saudi one, and I mention it for the method: every store with a named region, and the evidence written down. Once a scope is signed, a fixed-scope build can start within a day, and if you already have a scoped job, we can resource it on contract from the collective of associates who work with us, held to the same standard. Whether the result satisfies SDAIA stays with your officer and your counsel. The call is booked from the end of this page.
For engineers: data maps, logging, deletion and the 72-hour clock
The duties above in engineering terms. Each item is something an officer or an auditor can check in configuration, code or logs rather than by asking someone.
- Data map as code
- Keep a field-level map from each personal data field to the purpose that justifies it (Articles 18 and 19), and enforce it where context is assembled, so a field with no purpose for this use case never reaches the prompt.
- Endpoint register
- Record every model and embedding endpoint with its provider, region, deployment type and transfer safeguard. It feeds the record of processing, which has to describe transfers outside the Kingdom and their legal basis (Article 33).
- Prompt and output logs
- Logs of prompts, retrieved documents and outputs are personal data themselves. Restrict who can read them, state their retention in the record, and keep enough structure (subject identifiers, data categories, counts) to scope a breach inside 72 hours.
- Breach detection
- The regulation defines a breach as any incident leading to disclosure, destruction or unauthorised access, intentional or accidental. Treat a prompt injection that makes a tool return another person’s record as a candidate breach, and alert on it.
- Deletion that reaches copies
- Article 8 asks for every copy to be destroyed, backups included. Build delete-by-subject across the source systems, caches, vector index entries, evaluation sets and any fine-tuning data, and test it.
- Anonymisation claims
- Article 9 requires re-identification to be impossible after anonymisation, and an assessment of that risk. Treat embeddings and summaries of personal text as personal data unless you have tested otherwise.
- Decision records
- For each decision, log whether a person reviewed it, what they saw and whether they changed the outcome. That record is your evidence on “solely automated” under Articles 4 and 11.
- Sub-processor changes
- A processor needs your prior acceptance before adding a sub-processor (Article 17). Pin the vendors in configuration and alert when a provider publishes a change to its sub-processor list.
Sources
- [1]SDAIA, Personal Data Protection Law, Royal Decree M/19 of 9/2/1443H as amended by Royal Decree M/148 of 5/9/1444H, English version, read 30 September 2026
- [2]SDAIA, Implementing Regulation of the Personal Data Protection Law, English version, read 30 September 2026
- [3]SDAIA, Regulation on Personal Data Transfer outside the Kingdom, version 2.0 (August 2024), read 30 September 2026
- [4]SDAIA, Rules for Appointing Personal Data Protection Officer, version 1.0 (August 2024), read 30 September 2026
- [5]SDAIA, The Rules Governing the National Register of Controllers within the Kingdom, read 30 September 2026
- [6]SDAIA, Personal Data Breach Incidents Procedural Guide, issue 1.0 (October 2024), read 30 September 2026
- [7]SDAIA, AI Ethics Principles (2025 edition), read 30 September 2026
- [8]SDAIA, Regulations and Policies, the index of PDPL and AI instruments, read 30 September 2026
- [9]SDAIA, National Data Governance Platform, services menu (in Arabic), read 30 September 2026
- [10]SDAIA, اللائحة التنفيذية لنظام حماية البيانات الشخصية, the Implementing Regulation in Arabic, read 30 September 2026
Questions DPOs and AI leads ask
Does the Saudi PDPL apply to AI?
Yes, whenever an AI system processes personal data. Neither the Law nor its Implementing Regulation mentions artificial intelligence, but Article 25 of the regulation requires a written impact assessment where processing involves sensitive data or links personal data from different sources, and where the controller’s activity includes processing based on newly adopted technologies or decisions based on automated processing on a large scale or repeatedly, which a production AI system usually does. Articles 4 and 11 add notice and explicit-consent duties for decisions made solely by automated processing. This is not legal advice.
Does the PDPL apply to a company outside Saudi Arabia?
It can. Article 2 of the Law applies it to processing of personal data about individuals residing in the Kingdom by any party outside the Kingdom. SDAIA’s register rules for controllers inside the Kingdom say separate rules for controllers outside it will be issued, and the National Data Governance Platform lists a registration route for entities outside the Kingdom.
When is a PDPL impact assessment mandatory?
Under Article 25 of the Implementing Regulation, when processing involves sensitive data; when it collects, compares or links personal data from different sources; when the controller’s activity includes, on a large scale or repeatedly, processing based on newly adopted technologies, decisions based on automated processing, processing that requires constant monitoring or processing of data about people lacking legal capacity (the English version says large scale and repetitive; the Arabic text says large scale or repeated); or when a product or service is likely to cause serious harm to privacy.
What is the PDPL breach notification deadline?
72 hours. Article 24 of the Implementing Regulation requires the controller to notify SDAIA within 72 hours of becoming aware of a breach that could harm the data or the people it concerns, and to tell those people without undue delay. SDAIA’s breach guide says the notice goes through the breach service on the National Data Governance Platform, which requires registration.
Do we need a data protection officer under the PDPL?
You do if you are a public entity providing services that involve processing personal data on a large scale, or if your core activities are based on processing sensitive data or on processing that requires regular and systematic monitoring of people. SDAIA’s rules give behavioural analytics for risk assessment as an example of such monitoring, and the officer may be an employee or an external contractor.
Who must register in the National Register of Controllers?
SDAIA’s register rules require registration on the National Data Governance Platform where the controller is a public entity, where its main activity is based on processing personal data, where it processes sensitive data, or where an individual processes personal data beyond personal or family use. The registration certificate is valid for up to five years.
What are the penalties under the Saudi PDPL?
A warning or a fine of up to five million riyals for violating the Law or its regulations, which may be doubled for a repeat violation. Disclosing or publishing sensitive data with intent to harm or for personal benefit carries up to two years’ imprisonment, a fine of up to three million riyals, or both. People harmed by a violation can also claim compensation in court. This is not legal advice.
More in this topic
Getting reliable text out of Arabic scans and forms before any AI system, or any impact assessment, depends on it.
What Abu Dhabi’s Department of Health asks of an AI system used in healthcare, from risk tiers to keeping health data in the UAE.
Further
- AI governance implementation · The engagement that builds the assessment, the records and the logging into the system itself.
- Engagement file D-02 · A government-accredited EdTech in the Middle East, with every store placed in a named Gulf region.
We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.
Last reviewed · 1AYM