Regulatory Enforcement Roundtable II: From Understanding Enforcement to Demonstrating Compliance
PDPL enforcement in Saudi Arabia has moved from awareness to active audit, and organizations of every size are now being asked for evidence rather than intent. In this second Pyxos enforcement roundtable, Basmah Alsubaie, Richard Chudzynsky and Tahir Latif compared what they have seen since May: corrective action notices with fixed deadlines, periodic audits that return to verify remediation, sector regulators building their own inspection capability, and a public that reports violations directly to SDAIA. The discussion set out how an inspection opens and what is requested first, why sanctioned organizations are not yet named and when that is likely to change, the early signs of private litigation and extraterritorial enforcement, and why AI adoption is forcing the budget conversation the DPO could not win alone.
Presenters



Recording
Delivered live β no recording available for roundtable sessions to encourage candid exchange.
Read the Blog PostKey takeaways
- SDAIA has shifted from awareness campaigns to enforcement action: audits, evidence requests, corrective action notices, and in some cases suspending non-compliant features within live applications.
- Enforcement is not selective by size. The panel cited ministries and public authorities alongside a thirty-patient clinic instructed to appoint a DPO within a set deadline.
- Following the 48 decisions published in January 2026, a further round of penalties in June widened the enforced scope to organizations without a DPO, unreported breaches, and unanswered data subject requests.
- Cross-border transfers and data inventory have drawn the most scrutiny since May: regulators want to know where personal data sits and which safeguards apply.
- The audit approach has hardened. Eighteen months ago it was a questionnaire and gap assessment; regulated financial entities now face unannounced visits and audits every three to six months, with findings, deadlines, and a return visit to verify corrective action.
- No enterprise client of the panel has received a fully clean audit result. The follow-up work to close findings on deadline is now the main pressure on privacy teams.
- Examiners have become technically fluent: they ask where SaaS platforms are hosted, where backups reside, whether data leaves the Kingdom, and how personal data is used in AI models.
- SDAIA does not yet publish the names of sanctioned organizations. The panel expects it to follow the Ministry of Commerce's e-commerce precedent and begin naming repeat violators as its practice matures.
- Extraterritorial enforcement is being actively pursued against foreign organizations processing the personal data of individuals in the Kingdom.
- Article 36 of the PDPL sets fines up to SAR 5 million, doubled for repeat violations; Article 35 adds imprisonment and fines up to SAR 3 million for unlawful disclosure of sensitive data.
- Private litigation for breaches is nascent but expected to grow, following the UK pattern where access requests now generate substantial litigation volume.
- Public awareness is a live enforcement channel. Individuals report suspected violations on social media and tag SDAIA directly, and a single campaign can force executive attention overnight.
- Sector regulators are maturing in parallel: SAMA and the Insurance Authority run their own audits, healthcare regulators have markedly increased activity, and a breach may require notifying several authorities at once.
- SAMA audits now ask whether a privacy technology platform is in place; it is not mandated, but a negative answer lowers the score.
- On a first inspection, SDAIA asks for the RoPA, the data inventory, and data mapping evidence. A complaint, incident, or breach triggers an entirely different set of questions, and every valid complaint is investigated.
