SDAIA compliance and PDPL enforcement

    Reviewed by the Pyxos team · Last reviewed September 2026

    SDAIA is the supervisory authority for the Saudi PDPL. It registers controllers, issues guidance, investigates complaints and issues enforcement decisions through its violation committees. Organisations that can produce evidence on request are in a very different position from those that cannot.

    What SDAIA looks at

    • Whether you are registered and your details are current
    • Whether your record of processing matches reality
    • Whether you can evidence lawful basis and consent where you rely on it
    • How you handle data subject requests, and how quickly
    • Whether breaches were assessed and notified correctly
    • How transfers outside the Kingdom are justified and documented
    • Whether your privacy notices say what you actually do. See privacy notices and transparency.

    How PDPL enforcement works in practice

    Enforcement follows complaints, breach notifications and proactive review. Decisions turn on documentation. The question is rarely whether you intended to comply. It is whether you can show what you did, when, and on what basis. Our analysis of published decisions is in PDPL enforcement signals and the enforcement roundtable.

    What a SDAIA audit looks like

    An audit is an evidence exercise. Expect requests for the record of processing, DPIAs for the processing in scope, request logs, breach files, processor contracts and transfer assessments, each with dates and approvals attached. See audit, assurance and regulatory engagement and the recap of that session.

    Being ready

    Pyxos keeps the evidence layer current as the work happens, rather than assembling it under pressure. Records, assessments, request logs and breach files stay in one place, each with a reviewed trail behind it. See the platform and PDPL compliance in Saudi Arabia.

    Keep up with enforcement

    Registration and the National Data Governance Platform

    SDAIA maintains a National Register of Controllers and has issued rules setting out which controllers must register. Where registration applies, the entity details, processing purposes, DPO appointment and transfer activity are recorded on the National Data Governance Platform and are expected to stay current. A registration that no longer matches the business is itself a finding, so registration is best treated as a record to maintain rather than a form to submit once.

    The same principle runs through the rest of the regime. Whoever is named as answerable has to be the party actually making the decisions, which is why controller and processor classification is worth settling before a regulator settles it for you.

    Breach notification: what SDAIA expects

    A breach that may cause harm has to reach SDAIA within 72 hours of the organisation becoming aware of it, and affected individuals have to be told without undue delay where there is a risk of harm to them. In practice the clock is the easy part. The hard part is the assessment behind it: what data was involved, how many people, what harm is foreseeable, what has been contained and what remains open.

    Organisations that handle this well have decided in advance who assesses, who signs off and what the notification says. Those that do not spend the first day of an incident deciding who is in the room. See breach notification and incident response and the recap of that session.

    Data subject requests under supervisory review

    Requests are one of the most common routes to a complaint, and a complaint is one of the most common routes to SDAIA. The statutory window is 30 days, extendable once by a further 30 days where that is justified. A reviewer will look for the date the request arrived, how identity was verified, what was searched, what was withheld and why, and the date the response went out.

    Spreadsheets survive a quiet quarter and fail an audit. See handling DSARs under the PDPL.

    Cross border transfers and the evidence behind them

    Transfers outside the Kingdom are permitted under adequacy or approved safeguards such as Standard Contractual Clauses or Binding Common Rules, supported by a documented transfer risk assessment. Remote access from outside the Kingdom counts as a transfer, which catches support teams, cloud administration and group shared services that were never described as transfers internally.

    SDAIA will ask which mechanism you relied on, who assessed the risk and when. See cross border transfers under the PDPL and vendor and processor governance.

    The evidence pack a regulator will ask for

    • The current record of processing, with the date it was last reviewed
    • DPIAs for the processing in scope, with the decision and the approver recorded
    • The request log, with dates in and dates out
    • Breach files, including incidents assessed as not notifiable and the reasoning
    • Processor contracts and the transfer assessments that sit behind them
    • Retention schedules and evidence that they were applied
    • Training and awareness records. See privacy culture and training.

    Penalties and why documentation decides the outcome

    Administrative penalties run from warnings to fines of up to SAR 5 million per violation, doubled for repeat violations. Disclosure of sensitive personal data with intent to harm or for personal gain carries up to 2 years imprisonment and a fine of up to SAR 3 million. The law came into force on 14 September 2023 and the grace period ended on 14 September 2024, so enforcement is active rather than prospective.

    Between an organisation that acted reasonably and can show it, and one that acted reasonably and cannot, only the first has a defence. That is the whole argument for keeping the evidence layer current.

    SDAIA compliance FAQs

    Related reading

    See how Pyxos carries out this work for your team.