GCC compliance

Saudi PDPL for SaaS companies: controller duties, transfers and breach notice

If your SaaS product processes personal data of people in Saudi Arabia, the PDPL applies even if you are based abroad. Here is what it asks of SaaS providers and their customers.

Short answer

Saudi PDPL for SaaS companies means meeting the Personal Data Protection Law, enforced by SDAIA, whenever your product processes personal data of people in Saudi Arabia, even from abroad. As a processor you act on the customer's instructions under contract; as a controller you need a lawful basis, a privacy policy, 72-hour breach notice and lawful transfers.

Key takeaways

  • The PDPL reaches processing outside the Kingdom of data about people residing there.
  • It has been fully enforceable since the grace period ended on 14 September 2024.
  • Breaches that may harm people are notified to SDAIA within 72 hours.
  • Transfers outside the Kingdom follow the Personal Data Transfer Regulation.

Controller or processor?

Most B2B SaaS providers are processors for their customers' data and controllers for their own account, billing and marketing data. As a processor, act only on documented instructions, protect the data and support your customer's obligations. As a controller, you need a lawful basis, a published privacy policy, records of processing and a way to answer data subject requests.

DutyArticleWhat a SaaS provider does
Lawful basisArt. 5–6Record the basis for each purpose of your own processing
ProcessorsArt. 8Sign data processing terms with customers and sub-processors
SecurityArt. 19Apply organisational, administrative and technical measures
Breach noticeArt. 20Notify SDAIA within 72 hours under the Implementing Regulations
TransfersArt. 29Assess transfers to cloud regions outside the Kingdom
RecordsArt. 31Keep records of processing activities

Hosting and transfers

Transfers of personal data outside the Kingdom are allowed under the conditions in the PDPL and the Personal Data Transfer Regulation, such as adequate protection in the destination or appropriate safeguards. For SaaS, that means knowing which regions hold Saudi customer data and documenting the basis for each. Sector rules can add hosting requirements; government and critical infrastructure customers may also need NCA cloud controls.

Penalties and enforcement

Administrative fines reach SAR 5 million per violation and can be doubled for repeat violations; unlawful disclosure of sensitive data can bring imprisonment of up to two years or a fine of up to SAR 3 million. SDAIA's violation review committees have issued decisions since the law became fully enforceable.

Checklist

PDPL readiness for SaaS providers

0 of 6 done

Put this into practice on QULDEX

Frequently asked questions

Does the Saudi PDPL apply to SaaS companies outside Saudi Arabia?

Yes, when they process personal data of people residing in Saudi Arabia.

How quickly must a SaaS provider report a breach under the Saudi PDPL?

Breaches that may harm data subjects are notified to SDAIA within 72 hours under the Implementing Regulations. A processor should tell its controller customer quickly so the customer can meet that deadline.

Can Saudi customer data be hosted outside the Kingdom?

Yes, under the conditions of the PDPL and the Personal Data Transfer Regulation, unless a sector rule or customer contract requires hosting in the Kingdom.

Sources

  1. Personal Data Protection Law and Implementing Regulations, SDAIA
  2. Saudi Data and Artificial Intelligence Authority: data protection, SDAIA
  3. Data protection and cyber security laws in Saudi Arabia, CMS