Gulf — Saudi Arabia
Saudi Personal Data Protection Law (PDPL) Assessment
Data discovery, processing assessment and control validation against the Kingdom's Personal Data Protection Law and its implementing regulations.
What the law requires
The Saudi Personal Data Protection Law establishes obligations for organisations processing the personal data of individuals in the Kingdom, administered by the Saudi Data and AI Authority. It sets requirements around lawful basis for processing, data subject rights, security of processing, breach notification, cross-border transfer, and the appointment of a personal data protection officer in defined circumstances.
The law and its implementing regulations have been subject to amendment since first issuance. Confirm the current text, the implementing regulations and the enforcement position with Saudi legal counsel — we assess technical and organisational controls against the requirements as your legal advisers determine them. We are not a law firm and do not provide legal opinions on your obligations.
What we assess
- Data discovery and mapping — what personal data you hold, where it lives, where it came from and where it goes. Almost every programme stalls here first, because the answer is rarely documented.
- Processing inventory — purpose, lawful basis, retention period and recipients for each processing activity.
- Cross-border transfers — where personal data leaves the Kingdom, including via cloud services, and whether the transfer conditions are met.
- Data subject rights — whether you can actually locate, extract, correct and delete an individual's data within the required timeframe.
- Security of processing — the technical and organisational controls protecting personal data, assessed against the risk of the processing.
- Breach detection and notification — whether you would detect a personal data breach and could notify within the required window.
- Third-party processors — contractual terms and, more importantly, whether processor compliance is actually monitored.
Existing compliance reduces the work
The transfer question
Cross-border transfer is where most organisations in the Kingdom have genuine exposure, and it is frequently invisible: a SaaS CRM hosted outside the Kingdom, a support function with offshore access, a backup replicated to a foreign region. Data mapping surfaces these, and they are usually a surprise to the people who commissioned the assessment.
How the engagement runs
-
1
Scoping
Establish the entities, systems and processing activities in scope, with your legal advisers.
-
2
Data discovery
Locate personal data across the estate, including in unstructured storage and third-party services.
-
3
Processing assessment
Document purpose, lawful basis, retention and recipients for each activity.
-
4
Transfer analysis
Identify every cross-border flow, including those hidden inside cloud and support arrangements.
-
5
Control assessment
Test the technical and organisational controls protecting the data.
-
6
Gap and roadmap
Report gaps with a prioritised remediation plan.
What you receive
Frequently asked questions
Related services
Not sure this is the framework that binds you?
Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.
Request a proposal