Short answer
Saudi PDPL for SaaS companies means meeting the Personal Data Protection Law, enforced by SDAIA, whenever your product processes personal data of people in Saudi Arabia, even from abroad. As a processor you act on the customer's instructions under contract; as a controller you need a lawful basis, a privacy policy, 72-hour breach notice and lawful transfers.
Key takeaways
- The PDPL reaches processing outside the Kingdom of data about people residing there.
- It has been fully enforceable since the grace period ended on 14 September 2024.
- Breaches that may harm people are notified to SDAIA within 72 hours.
- Transfers outside the Kingdom follow the Personal Data Transfer Regulation.
Controller or processor?
Most B2B SaaS providers are processors for their customers' data and controllers for their own account, billing and marketing data. As a processor, act only on documented instructions, protect the data and support your customer's obligations. As a controller, you need a lawful basis, a published privacy policy, records of processing and a way to answer data subject requests.
| Duty | Article | What a SaaS provider does |
|---|---|---|
| Lawful basis | Art. 5–6 | Record the basis for each purpose of your own processing |
| Processors | Art. 8 | Sign data processing terms with customers and sub-processors |
| Security | Art. 19 | Apply organisational, administrative and technical measures |
| Breach notice | Art. 20 | Notify SDAIA within 72 hours under the Implementing Regulations |
| Transfers | Art. 29 | Assess transfers to cloud regions outside the Kingdom |
| Records | Art. 31 | Keep records of processing activities |
Hosting and transfers
Transfers of personal data outside the Kingdom are allowed under the conditions in the PDPL and the Personal Data Transfer Regulation, such as adequate protection in the destination or appropriate safeguards. For SaaS, that means knowing which regions hold Saudi customer data and documenting the basis for each. Sector rules can add hosting requirements; government and critical infrastructure customers may also need NCA cloud controls.
Penalties and enforcement
Administrative fines reach SAR 5 million per violation and can be doubled for repeat violations; unlawful disclosure of sensitive data can bring imprisonment of up to two years or a fine of up to SAR 3 million. SDAIA's violation review committees have issued decisions since the law became fully enforceable.
Checklist
PDPL readiness for SaaS providers
0 of 6 done
Put this into practice on QULDEX
Frequently asked questions
Does the Saudi PDPL apply to SaaS companies outside Saudi Arabia?
Yes, when they process personal data of people residing in Saudi Arabia.
How quickly must a SaaS provider report a breach under the Saudi PDPL?
Breaches that may harm data subjects are notified to SDAIA within 72 hours under the Implementing Regulations. A processor should tell its controller customer quickly so the customer can meet that deadline.
Can Saudi customer data be hosted outside the Kingdom?
Yes, under the conditions of the PDPL and the Personal Data Transfer Regulation, unless a sector rule or customer contract requires hosting in the Kingdom.