#19 — Regulatory Enforcement Roundtable II: From Understanding Enforcement to Demonstrating Compliance



PDPL enforcement in Saudi Arabia has moved from awareness to active audit, and organizations of every size are now being asked for evidence rather than intent. In this second Pyxos enforcement roundtable, Basmah Alsubaie, Richard Chudzynsky and Tahir Latif compared what they have seen since May: corrective action notices with fixed deadlines, periodic audits that return to verify remediation, sector regulators building their own inspection capability, and a public that reports violations directly to SDAIA.
Key Takeaways from the Masterclass
- SDAIA has shifted from awareness campaigns to enforcement action: audits, evidence requests, corrective action notices, and in some cases suspending non-compliant features within live applications.
- Enforcement is not selective by size. The panel cited ministries and public authorities alongside a thirty-patient clinic instructed to appoint a DPO within a set deadline.
- Following the 48 decisions published in January 2026, a further round of penalties in June widened the enforced scope to organizations without a DPO, unreported breaches, and unanswered data subject requests.





