Back to Blog

    KSA PDPL

    What SDAIA's Latest Enforcement Decisions Mean for Saudi DPOs

    Pyxos · 30 June 2026

    On June 29, SDAIA issued a new set of enforcement decisions under the Personal Data Protection Law (PDPL). The full announcement appears below in the original Arabic, with an English translation alongside it. For data protection officers in the Kingdom, the practical question is what these decisions signal about how SDAIA is enforcing the law, and what they should do in response.

    The announcement

    SDAIA announcement (Arabic original)

    SDAIA announcement on PDPL enforcement decisions (Arabic).

    English translation

    The Committee for Reviewing Violations of the Personal Data Protection Law Issues Decisions Against a Number of Entities in Breach of the Law

    The Committee for Reviewing Violations of the Provisions of the Personal Data Protection Law and its Regulations at the Saudi Data and AI Authority (SDAIA) issued a number of decisions, under its jurisdiction to review violations and impose penalties pursuant to Article 36 of the Law, after the violations were confirmed and the penalties prescribed by the system were imposed on entities subject to the Law and its Implementing Regulations. These included financial fines and warnings.

    The decisions imposed the legally prescribed penalties on the violating entities. Among the most prominent penalized violations were processing personal data for direct marketing purposes without the explicit consent of the data subject, and failure to adopt the technical, administrative, and organizational means that ensure a prompt response to data subject requests, in addition to failing to notify the Authority of personal data breach incidents within the legally specified period of (72) hours from becoming aware of the incident.

    The violations also included failing to take the procedures and the organizational, administrative, and technical means to safeguard personal data, alongside non-compliance with appointing a personal data protection officer despite the applicability of the cases requiring appointment under the provisions of the Law.

    These efforts fall within the tasks entrusted to SDAIA in supervising the application of the Personal Data Protection Law and its Implementing Regulations, as part of an integrated system that aims to apply the Law and its Regulations, entrench responsible practices in handling personal data, and raise the level of compliance with the relevant regulatory provisions, in order to achieve the Law's primary objective of protecting individuals' data and enhancing trust in digital transactions.

    SDAIA's official announcement, June 29, 2026. English translation by Pyxos. Image: SDAIA.

    What the announcement means for enforcement

    SDAIA's latest decisions are part of a clear and sustained increase in regulatory activity. The Committee imposed financial fines and warnings on entities found in breach, under its authority in Article 36 of the law. SDAIA does not name the entities or state whether they are public or private, so no sector breakdown should be inferred. The conduct that was penalized is the important detail: each item is a common compliance failure rather than an unusual or technical one.

    This increase is well evidenced. As discussed in our roundtable on PDPL enforcement in practice (13 May 2026), the Kingdom has moved from establishing the legal framework, through a transition period, to active enforcement. In January 2026, SDAIA reported 48 decisions issued over the previous year, across a range of sectors rather than only technology companies or critical infrastructure. In February 2026, it issued rules governing the licensing and accreditation of controllers and processors and the auditing and inspection of processing activities. In April 2026, it joined the Global Privacy Assembly, aligning its enforcement standards with those of established international regulators, as reported by Arab News. The latest decisions continue this pattern.

    What DPOs should take from it

    For a DPO, the penalized violations indicate where SDAIA is currently focusing, and each corresponds to a control the DPO owns:

    • Direct marketing without the explicit consent of the data subject, which Article 25 restricts.
    • Failure to respond to data subject requests within the required time.
    • Failure to notify the Authority of a breach within 72 hours of becoming aware of it.
    • Failure to apply the security measures required under Article 19.
    • Failure to appoint a data protection officer where the conditions for appointment are met.

    Two further points matter for how a DPO should read this. First, enforcement is largely complaint-driven. The Authority reviews every complaint it receives, a high number of complaints against a single organization can raise its profile, and a failure to register on the National Data Governance Platform or to respond to the regulator can each prompt an investigation. Second, the process moves quickly once it begins. An organization notified of an alleged violation has only five days to respond, the committee's decision is notified within fifteen days of its approval, and there is a sixty-day window to appeal. An organization that has not arranged authorized representation and a power of attorney in advance may miss the response deadline before its privacy team is even aware of the matter.

    What DPOs should do now

    The announcement points to a clear set of priorities, each of which an organization can act on before a complaint or inquiry arrives:

    • Maintain an accurate, current record of processing activities. It supports every other obligation and is the first document a regulator requests.
    • Confirm a valid lawful basis for each processing activity, and obtain explicit consent specifically for direct marketing.
    • Establish and test a process to respond to data subject requests within the statutory period.
    • Establish a process to detect and report a personal data breach to the Authority within 72 hours.
    • Apply and document the technical and organizational security measures required under Article 19.
    • Appoint and register a data protection officer where the conditions apply, and register the organization on the National Data Governance Platform.
    • Prepare for enforcement procedurally: identify the authorized representative, put a power of attorney in place, and confirm access to SDAIA's electronic platform, so the organization can respond within the five-day deadline.
    • Run internal reviews that test these processes before they are tested externally.

    Where manual processes cannot keep pace with the volume of data an organization handles, appropriate tooling helps close the gap, provided the necessary governance and people are in place to support it.

    Pyxos is an AI-native compliance platform that helps organizations operationalize these PDPL obligations and maintain the evidence regulators expect.

    Ready to start your PDPL compliance journey?

    Get expert guidance on Saudi Arabia's Personal Data Protection Law.