Skip to content

Gulf — Saudi Arabia

Saudi Personal Data Protection Law (PDPL) Assessment

Data discovery, processing assessment and control validation against the Kingdom's Personal Data Protection Law and its implementing regulations.

What the law requires

The Saudi Personal Data Protection Law establishes obligations for organisations processing the personal data of individuals in the Kingdom, administered by the Saudi Data and AI Authority. It sets requirements around lawful basis for processing, data subject rights, security of processing, breach notification, cross-border transfer, and the appointment of a personal data protection officer in defined circumstances.

The law and its implementing regulations have been subject to amendment since first issuance. Confirm the current text, the implementing regulations and the enforcement position with Saudi legal counsel — we assess technical and organisational controls against the requirements as your legal advisers determine them. We are not a law firm and do not provide legal opinions on your obligations.

What we assess

  • Data discovery and mapping — what personal data you hold, where it lives, where it came from and where it goes. Almost every programme stalls here first, because the answer is rarely documented.
  • Processing inventory — purpose, lawful basis, retention period and recipients for each processing activity.
  • Cross-border transfers — where personal data leaves the Kingdom, including via cloud services, and whether the transfer conditions are met.
  • Data subject rights — whether you can actually locate, extract, correct and delete an individual's data within the required timeframe.
  • Security of processing — the technical and organisational controls protecting personal data, assessed against the risk of the processing.
  • Breach detection and notification — whether you would detect a personal data breach and could notify within the required window.
  • Third-party processors — contractual terms and, more importantly, whether processor compliance is actually monitored.

Existing compliance reduces the work

ISO 27001 SAMA CSF NCA ECC Shared evidence Assess once, reportseparately Usually the largest savingavailable on a multi-frameworkengagement.
GDPR alignment transfers much of the data mapping — it does not eliminate the gap.

The transfer question

Cross-border transfer is where most organisations in the Kingdom have genuine exposure, and it is frequently invisible: a SaaS CRM hosted outside the Kingdom, a support function with offshore access, a backup replicated to a foreign region. Data mapping surfaces these, and they are usually a surprise to the people who commissioned the assessment.

How the engagement runs

  1. 1

    Scoping

    Establish the entities, systems and processing activities in scope, with your legal advisers.

  2. 2

    Data discovery

    Locate personal data across the estate, including in unstructured storage and third-party services.

  3. 3

    Processing assessment

    Document purpose, lawful basis, retention and recipients for each activity.

  4. 4

    Transfer analysis

    Identify every cross-border flow, including those hidden inside cloud and support arrangements.

  5. 5

    Control assessment

    Test the technical and organisational controls protecting the data.

  6. 6

    Gap and roadmap

    Report gaps with a prioritised remediation plan.

What you receive

Personal data inventory and data flow mapping
Records of processing covering purpose, basis, retention and recipients
Cross-border transfer register with risk assessment
Technical and organisational control gap assessment
Data subject rights readiness assessment
Breach detection and notification readiness review
Prioritised remediation roadmap

Frequently asked questions

No. We are IT auditors, not lawyers. We assess whether your technical and organisational controls meet the requirements as interpreted by your legal advisers, and we produce the evidence and data mapping that legal analysis depends on. Engage Saudi counsel for the legal position — most PDPL programmes need both, and they work well in parallel.

It gives you a significant head start — the data mapping, records of processing and security controls largely transfer. But the two regimes differ in specific requirements including transfer conditions, notification timelines and localisation expectations. Treat GDPR compliance as reducing the work, not eliminating it, and have counsel confirm the differences that apply to you.

It is the longest phase in most programmes. For a mid-sized organisation with a handful of core systems, three to six weeks. For an organisation with substantial unstructured data, legacy systems and undocumented integrations, considerably longer. Budget for it honestly — a compliance programme built on an incomplete data map will fail.

Related services

Not sure this is the framework that binds you?

Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.

Request a proposal
Top