Published: October 9, 2026 1:11 pm

SDAIA Opens Public Consultation on Proposed Amendments to the PDPL Implementing Regulation

The Saudi Data & AI Authority (SDAIA) has launched a public consultation on proposed amendments to the Implementing Regulation of the Personal Data Protection Law (PDPL).

The proposed amendments aim to provide further clarity on the procedures and controls under the Implementing Regulation, support compliance with the PDPL and strengthen its enforcement.

Some of the key proposed changes include:

  • Data localization: A new requirement would expressly require Controllers to store Personal Data within Saudi Arabia, while transfers or disclosures outside the Kingdom would remain permitted subject to compliance with the PDPL and its Implementing Regulation.
  • Definitions: A new defined term is introduced for the “Competent Authority’s Platform”, referring to the National Data Governance Platform, an electronic platform supporting the enforcement of the PDPL and its Implementing Regulation, including services relating to the National Register of Controllers. In addition, the standalone definitions of “Direct Marketing” and “Personal Data Breach” are also removed from the definitions article, with related references updated accordingly throughout the Implementing Regulation.
  • Data subject rights: The existing 30-day response period would remain, but a request not fulfilled within the prescribed period would be deemed rejected. Data subjects would also be able to submit a complaint to SDAIA where the deadline expires without a response.
  • Privacy policies and transparency: Information provided to data subjects would need to use appropriate and simplified language. A new provision expressly require Privacy Policies to be drafted in clear and simplified language that takes into account the varying levels of understanding of data subjects and is consistent with the language customarily used for the relevant products or services.
  • Consent and automated decision-making: The consent requirements are refined to provide that consent must be given freely by an individual with full legal capacity, introducing a capacity requirement alongside the existing requirement that consent must not be obtained through misleading methods. The trigger for additional safeguards relating to automated processing is also reframed. The proposed provision would apply where automated processing results in decisions that affect the rights or interests of data subjects, rather than focusing solely on decisions made exclusively through automated processing.
  • Data minimization obligation: Controllers must continue to limit the Personal Data collected to the minimum amount necessary and ensure that the data collected is linked to the purposes of processing. However, the proposed amendments remove the express reference to “data maps” as a required means of demonstrating compliance and instead permit Controllers to use appropriate means more generally.
  • DPIAs: The circumstances requiring a Data Protection Impact Assessment would be expanded and restructured, including processing involving Sensitive Data, minors or individuals with partial or no legal capacity, large-scale or systematic monitoring, and the use of emerging technologies.
  • DPO requirements: The circumstances triggering mandatory appointment of a Data Protection Officer would be refined. Controllers would also be required to document the appointment and notify SDAIA of the DPO’s contact details through the Competent Authority’s Platform.
  • Retention period: Records of Personal Data processing activities would need to be retained for the duration of the relevant processing activity and for an additional five years following its completion. This revises the existing formulation requiring records to be maintained during processing and for a period of up to five years after the processing activity ends.
  • National Register of Controllers: Registration requirements would be incorporated directly into the Implementing Regulation, including specific triggers relating to the nature of the Controller and its processing activities, including certain cross-border transfers or disclosures.
  • Security and data breaches: The proposed amendments refine Controllers security obligations and the circumstances triggering the 72-hour notification requirement, while streamlining the information required as part of a breach notification.
  • Marketing: The consent framework for promotional and direct marketing activities would be revised, including strengthened withdrawal and opt-out requirements.
  • Regulatory requests and complaints: A new 20-business-day period would apply for responding to SDAIA requests concerning implementation of the PDPL and its Implementing Regulation. The amendments would also introduce a 90-day period for data subjects to submit complaints, subject to SDAIA’s discretion to accept late complaints on reasonable grounds.
  • Supporting rules: Certain matters currently addressed through separate SDAIA rules—including DPO appointment and National Register requirements—would instead be incorporated directly into the Implementing Regulation.

If adopted, the amendments could have significant practical implications for organizations processing Personal Data in Saudi Arabia.

The consultation remains open until 5 November 2026, providing participants with an opportunity to review the proposed amendments and submit feedback before they are finalized.

Key Contacts

David Yates

Partner, Head of Digital & Data

d.yates@tamimi.com