The SDAIA publishes draft amendments to the Implementing Regulations of the PDPL

  • Legal Development 2026年10月8日 2026年10月8日
  • 中东

  • Tech & AI evolution

  • 数据保护与隐私权

The Saudi Data and Artificial Intelligence Authority (“SDAIA”) has published draft amendments to the Implementing Regulations of the Personal Data Protection Law issued pursuant to Royal Decree No. (M/19) dated 09/02/1443 H (corresponding to 16/09/2021 G), as amended (the “PDPL”), for public consultation (the “Proposed Amendments”). If approved, the Proposed Amendments would revise a number of practical compliance obligations under the Kingdom of Saudi Arabia’s (“KSA” or the “Kingdom”) data protection framework.

The public consultation began on 6 October 2026 and shall end on 5 November 2026. If adopted, the Proposed Amendments would continue SDAIA’s efforts to mature the Kingdom’s data protection framework and provide greater clarity on practical compliance obligations.

Key developments include the introduction of express data localisation requirements, stricter personal data breach notification obligations, codified timelines for responding to SDAIA investigations, enhanced rules governing marketing activities, new privacy policy requirements, revised data protection officer obligations, and formal registration requirements through the National Register of Controllers. If adopted, the Proposed Amendments would have significant compliance implications for organisations processing personal data in or relating to the Kingdom.  

Background:

The PDPL was issued in September 2021 and subsequently amended in March 2023. Following those amendments, the PDPL entered into force on 14 September 2023, with organisations afforded a one year grace period to achieve compliance with the law and its implementing framework. That grace period expired on 14 September 2024, following which the PDPL became fully enforceable.

Since then, KSA’s data protection framework has continued to mature through the publication of the Implementing Regulations, the Regulations on the Transfer of Personal Data outside the Kingdom, Standard Contractual Clauses and various guidance documents issued by SDAIA. The Kingdom has also entered an active enforcement phase, with the Committees for Reviewing Violations of the Provisions of the PDPL and its Implementing Regulations now reviewing alleged violations and issuing enforcement decisions for non-compliance.

Against this backdrop, SDAIA has published the Proposed Amendments with a view to providing additional regulatory clarity, formalising certain procedural requirements and introducing new compliance obligations in areas such as data localisation, incident reporting, marketing activities and controller registration.

This article provides a summary of key proposed amendments published by SDAIA.

Newly proposed data localisation requirement:

One of the most significant proposed changes is the introduction of an express localisation requirement under Article 23. Currently, cross-border transfers and disclosures of personal data are governed by Article 29 of the PDPL and the Regulations on the Transfer of Personal Data outside the Kingdom. Such transfers and disclosures are permitted only where they comply with the PDPL and are not prohibited under any other applicable law. However, the current framework does not impose a general requirement for personal data to be stored within KSA. The Proposed Amendments would change this position by requiring controllers to store personal data within the Kingdom, while continuing to permit transfers and disclosures outside KSA in accordance with the PDPL and its Implementing Regulations. 

If this proposal is approved, organisations using offshore hosting, regional infrastructure or cross-border service arrangements would need to assess both their storage model and the legal basis for any transfers or disclosures outside the Kingdom.

Stricter breach incident notification requirements:

If implemented, the Proposed Amendment to Article 24 would remove the current threshold requiring an assessment of potential harm before notification to SDAIA is triggered. Under the current position, controllers must notify SDAIA within 72 hours only where the breach is likely to cause harm to personal data, affect data subjects, or conflict with their rights or interests. The Proposed Amendments would require notification of personal data breaches, damage, or unauthorised access within 72 hours of awareness, regardless of whether harm is likely to result. Data subject notification would, however, continue to be subject to the existing damage-based assessment.

If adopted, the change would lower the threshold and broaden the circumstances in which notification to SDAIA is required, and would likely result in a higher volume of mandatory notifications. If that is the case, controllers would need to consider whether their incident-response procedures enable escalation, assessment and submission of the information specified in Article 24 within the 72-hour period, especially when processors and sub-processors are involved.

New compliance triggers:

If adopted, the Proposed Amendments would introduce new cases where Data Processing Impact Assessments and controller registrations may be required. In particular, the proposed changes to Article 25 would broaden the categories of processing activities that trigger a requirement to conduct a Data Processing Impact Assessment. In addition to the existing requirements, a Data Processing Impact Assessment would be required where personal data relating to minors or individuals lacking legal capacity is processed, where processing is carried out on a large scale or involves regular or systematic monitoring, where emerging technologies are used, or where processing results in automated decisions affecting the rights or interests of data subjects.

The Proposed Amendments would also significantly expand the registration requirements under Article 34. Most notably, registration with the National Register of Controllers would become mandatory where a Controller transfers or discloses Personal Data outside KSA. Given the prevalence of cross-border data transfers within multinational groups, cloud-hosting arrangements and outsourced service models, this proposal could substantially increase the number of organisations required to register with SDAIA if implemented. 

Formalising response deadlines for regulatory requests:

The draft regulations introduce a new Article 36 (Repeated), which requires entities subject to the PDPL to respond to requests from SDAIA regarding implementation of the PDPL and its regulations within 20 business days of receipt. Organisations that cannot comply within this timeframe may request an extension, which SDAIA may grant at its discretion where sufficient justification is provided.

This proposal would establish a formal response period for requests from SDAIA concerning implementation of the PDPL and its regulations. Organisations should ensure that escalation, document collection and internal approval processes enable them to respond within the prescribed timeframe or promptly prepare a justified extension request.

Stricter rules for responding to data subject requests:

If approved,  the Proposed Amendments to Article 3 would provide that, where a controller fails to respond to a data subject request within the statutory 30-day period (or any permitted extension period), the request will be deemed rejected. The proposed new paragraph (4) of Article 3 would also expressly provide that a data subject may submit a complaint to SDAIA where the controller fails to respond within the prescribed timeframe or where that period expires without a response.

These changes would formalise the complaint mechanism and increase the potential regulatory consequences of failing to maintain effective procedures for managing data subject requests.

New marketing and advertising provisions:

The Proposed Amendments would revise the marketing and advertising framework under Articles 28 and 29. Under the current Implementing Regulations, Article 28 requires consent before sending promotional or awareness materials where there is no prior interaction with the recipient and imposes requirements regarding identification of the sender, unsubscribe mechanisms and recordkeeping. The Proposed Amendments consolidate and expand these requirements by requiring controllers to verify that valid consent exists where a prior relationship is relied upon, retain evidence of consent and provide clear and accessible mechanisms enabling recipients to withdraw their consent.

In addition, the Proposed Amendments broaden Article 29 beyond the sending of direct marketing communications to the wider processing of personal data for marketing purposes. Most significantly, where a data subject withdraws consent, the controller would be required not only to cease marketing activities, but also to stop the underlying processing and destroy personal data generated as a result of that processing without undue delay.

If adopted, these amendments would require organisations to revisit their marketing consent practices, recordkeeping procedures and customer relationship management processes to ensure that consent can be demonstrated and that marketing related personal data can be effectively removed following withdrawal of consent.

Privacy notice requirements:

The Proposed Amendments would introduce a new Article 18 (Repeated), which prescribes new requirements for privacy policies. Controllers would be required to use clear, simplified and comprehensible language that accommodates the different levels of understanding among relevant categories of data subjects. The language used in the privacy policy would also need to be consistent with the language customarily used to provide services or products to those categories of data subjects, which in practice would likely require most organisations to publish privacy policies in Arabic and revisit existing privacy policies to ensure accessibility and readability.

DPO requirements:

The Proposed Amendments would revise the circumstances in which a Data Protection Officer (“DPO”) must be appointed and add administrative requirements. A public entity providing services involving the processing of personal data would be required to appoint a DPO, without the current large-scale qualifier. Appointment would also be required where a controller’s primary activities involve processing operations that, by their nature, require regular and systematic monitoring of data subjects on a large scale, or where its core activities are based on processing Sensitive Data. Controllers would need to document the appointment and, immediately upon appointment through SDAIA’s platform, provide the DPO’s contact details and update them when the DPO is replaced.

The Proposed Amendments would also reorganise and clarify the DPO’s responsibilities. These include acting as the direct point of contact with SDAIA; providing internal support and advice; promoting awareness; verifying that appropriate means are available for data subjects to exercise their rights; notifying SDAIA of personal data breach incidents; responding to data subject requests and complaints; monitoring processing records; addressing violations and corrective actions; and overseeing impact assessments and related audit and review reports.

Reaffirming controller registration requirements:

Should the Proposed Amendments be approved, Article 34 would significantly expand by introducing direct registration obligations for controllers through SDAIA's platform and the National Register of Controllers. Registration would be mandatory where the controller is a public entity, where its core activities require the processing of personal data, where it processes sensitive data or data relating to individuals lacking legal capacity, or where it transfers or discloses personal data outside Saudi Arabia. 

This would replace the current provision under which SDAIA issues separate rules for registration in the National Register of Controllers and would instead set out the registration criteria in the Implementing Regulations. Organisations should assess whether they fall within any of the proposed criteria and identify the processing records and other information that would need to be registered through SDAIA’s platform.

Additional proposals:

Other notable proposed amendments include:

  • Introduction of a dedicated SDAIA platform definition and recognition of its role in regulatory compliance and National Register services. 
  • Simplification of the requirements for records of processing activities by removing the minimum list of data that needs to be included in such records.
  • Simplification of privacy and transparency requirements by requiring information to be provided in appropriate and simplified language. 
  • Removal of separate accreditation body provisions and certain prescriptive record-keeping requirements. 
  • Extension of complaint-handling procedures and express powers for SDAIA to disclose complaint-related information where necessary.

Next steps:

The Proposed Amendments are open for public consultation from 6 October 2026 until 5 November 2026. Organisations and individuals wishing to respond may submit their comments through the Public Consultation Platform (Istitlaa) by the closing date.

Following the consultation period, SDAIA will review stakeholder feedback and determine whether to adopt the amendments in their current form or with further revisions. If approved, the amended regulations will enter into force 60 days following publication in the Official Gazette.

If you need assistance assessing the Proposed Amendments and drafting a response to the consultation, please contact Lamisse Bajunaid.

您也许对此感兴趣

结束

掌握其礼的最新消息

注册您的邮箱,获取其礼最新消息!