In June 2026 the Saudi Press Agency published a story most companies scrolled past: the committees for reviewing violations of the Personal Data Protection Law have started hearing cases and imposing sanctions. Among the violations named: failing to take the organisational and technical measures that keep personal data safe, and failing to appoint a data protection officer.
Put plainly: the awareness phase is over. The law issued by Royal Decree M/19 of 1443H, in force since September 2023, is now being actively enforced under the supervision of the Saudi Data and AI Authority (SDAIA). The question that matters to a business owner today is not "does the PDPL apply to me?" — it applies to any processing of personal data carried out in the Kingdom — but "which of its obligations am I violating right now without knowing it, and what does that cost?"
The penalty map, in numbers
The law does not set one penalty; it sets a whole ladder. These are its main rungs:
| Violation | Basis | Maximum penalty |
|---|---|---|
| Disclosing or publishing sensitive data with intent to harm or for personal gain | Article 35 | Up to 2 years in prison and a fine up to SAR 3 million, or either |
| Transferring data outside the Kingdom in breach of Article 29 | Article 35 | Up to 1 year in prison and a fine up to SAR 1 million, or either |
| All other violations of the law and its implementing regulation | Article 36 | Warning, or a fine up to SAR 5 million per violation |
| Repeat violations | Article 36 | Fine may be doubled, up to SAR 10 million |
Two points usually go missing from the conversation:
First: the SAR 5 million fine is not reserved for catastrophic leaks. "All other violations" covers purely procedural failures: a missing or incomplete privacy policy, collecting data without a defined purpose, retaining data you no longer need, or not giving data subjects their rights of access, correction and destruction.
Second: the penalty applies "per violation." A company collecting data at five points — a hiring form, an online store, a loyalty program, CCTV, a newsletter — answers for each point separately.
The 72-hour window: the obligation everyone discovers too late
Article 24 of the implementing regulation requires the controller to notify SDAIA within 72 hours of becoming aware of any incident of leakage, damage or illegitimate access to personal data.
Three details make this article more dangerous than it looks:
- The clock starts at awareness, not at intrusion. A March intrusion discovered in August starts its 72 hours in August. You gain nothing by delaying verification, but you lose everything by ignoring a confirmed alert.
- There is no materiality threshold. Unlike the GDPR, which lets you assess the level of risk, the Saudi text does not give you the authority to judge a breach "too small to report."
- 72 hours pass faster than you think. Teams without a prepared response plan spend the entire first day on a single question: what data do we even hold, and where?
That is why we built the free data breach notification deadline calculator — it runs entirely in your browser: enter the moment you became aware and where the affected people live, and it shows the deadline for every authority involved — SDAIA, and the European authorities if EU residents are among those affected. No detail leaves your machine.
The obligations companies violate without knowing
Based on the cases the committees have reviewed and the requirements SDAIA audits against, these are the most common gaps in small and mid-sized companies:
The record of processing activities. The law assumes you know what data you collect, why, where it is stored, and who can reach it. Most companies have no written answer to that — and it is the first thing requested in any investigation.
Appointing a data protection officer. Explicitly listed among the violations the committees have sanctioned. Appointing one does not necessarily mean a new hire, but it does mean a named person who carries the responsibility.
Transfers outside the Kingdom. Every foreign cloud service, every external API, every AI model hosted by a party outside the Kingdom is a data transfer governed by Article 29 and its controls. We covered this angle in detail in your AI stack is a cross-border transfer under the Saudi PDPL, because the newest violations come from exactly here: a team wires its system to a foreign LLM API without realising it is moving customer data across the border.
Data security itself. "Failing to take the technical measures that ensure protection" is a standalone violation. If your company has never run a real security assessment, start by understanding the common security risks in small businesses and how to audit them.
What to do this week
Five practical steps, ordered by impact:
- Map your data. One table: what data, collected where, stored where, accessed by whom, destroyed when. That is your record of processing activities in its first form.
- Name a data protection officer. A written management decision, and a person who knows they are accountable.
- Inventory your outbound transfers. Every cloud provider and every external API: does personal data pass through it, and on what Article 29 basis?
- Prepare a breach response plan before you need one. Who decides, who notifies SDAIA, where the notification template lives — and test the deadline on the calculator above.
- Reread your privacy policy. Does it state the purpose of every data type you actually collect? The gap between what the policy says and what the systems do is a violation in itself.
The gap is usually in the systems, not the intentions
Most companies that violate the PDPL do not do it on purpose. They do it because their data is spread across systems nobody holds a complete map of: an online store here, an accounting system there, scattered spreadsheets, and external integrations added over the years.
That is exactly what we work on at Noqta: we map the data flows across your systems, establish where you stand today against the law's obligations, and automate what can be automated — from the processing record to the audit trail. If you would rather learn where your company stands from a diagnostic than from an official letter, book a free diagnostic session and we will walk through your data map and your most expensive exposure points together.