Past Masterclass July 15, 2026
Personal Data Breach Notification and Incident Response under Saudi PDPL
Personal data breach notification under the Saudi PDPL runs on a 72-hour clock that starts the moment an organization becomes aware of an incident, not when its privacy team is told. This masterclass, led by Richard Chudzynsky and Skanda Reddy of Konexo (Eversheds Sutherland), covered what the law counts as a personal data breach, when and how to notify the Saudi Data & AI Authority (SDAIA) and affected data subjects under Article 20 of the PDPL and Article 24 of the Implementing Regulations, and how to build an incident response posture that holds under regulatory scrutiny, from triage and risk assessment through documentation and post-incident improvement.
Presenters

Richard Chudzynsky
Partner, KONEXO/Eversheds Sutherland

Skanda Reddy
Senior Associate, KONEXO/Eversheds Sutherland
Recording
We'll email you the link and passcode.Read the Blog Post
Key takeaways
- The Implementing Regulations define a personal data breach broadly: any incident leading to disclosure, destruction, or unauthorized access to personal data, whether intentional or accidental, automated or manual. Accidental exposure is a breach in law, not a lesser event.
- A security incident and a personal data breach are not the same thing. If no personal data is affected, PDPL notification obligations are not triggered, so triage that distinguishes the two is the first capability an incident response posture needs.
- Article 20 of the PDPL and Article 24 of the Implementing Regulations govern notification. SDAIA must be notified within 72 hours of the organization becoming aware of a breach that may potentially harm the personal data or the data subject; potential harm, not actual harm, is the trigger.
- The clock starts at organizational awareness, wherever in the business that occurs, not when the DPO is informed. The moment of occurrence and the moment of awareness are separate timestamps, and both belong in the notification.
- The 72-hour deadline can be extended, but only after an initial notification with a justification for the delay. The presenters' counsel was early, proactive engagement with SDAIA, supplying detail as it firms up.
- Data subjects must be notified without undue delay where a breach may damage their data or conflict with their rights or interests. SDAIA guidance frames that harm as impaired rights, physical danger such as stalking or assault, or economic damage such as fraud and identity theft.
- Notification is made by the DPO through the national data governance platform, and controllers need to be registered on the portal before an incident, not during one. The DPO is the direct point of contact with the competent authority.
- The controller retains ultimate accountability for notification. A contract can allocate operational duties to a processor, but the presenters advised keeping the decision to notify, its timing, and its documentation in the controller's hands.
- Most breaches begin inside the organization. The presenters put the employee-originated share at 60 to 80 percent, which makes training, internal controls, and awareness the highest-yield prevention available.
- Third parties are among the largest breach sources. Vendor due diligence, contractual safeguards, and technical controls determine whether a supplier's weakness becomes your notification obligation.
- Novel technologies, AI included, expand the attack surface faster than controls mature. Sandboxing, containment, and close coordination between the DPO and information security are the counterweights.
- A current record of processing (RoPA) is the breach-response accelerator: it identifies in hours which data, data subjects, recipients, and transfers a compromised system touches, while its absence consumes the notification window in discovery.
- Cross-border breaches and dual regulation multiply obligations. SAMA, the Ministry of Health, the NCA, and other authorities carry their own notification expectations, which is why regulatory mapping is the first step in building a breach plan.
- A defensible position is a documented one. The records that evidence the response, from the decision log to correspondence with SDAIA and data subjects, are what demonstrate accountability after the event.
- Breach handling does not end at recovery. Root cause analysis, verified remediation, updated controls, and refreshed training convert an incident into a stronger posture, and the mismanaged alternative carries reputational and financial costs that can threaten the business itself.
Frequently Asked Questions
The Implementing Regulations define a personal data breach as any incident that leads to the disclosure, destruction, or unauthorized access to personal data, whether intentional or accidental, and whether by automated or manual means. The definition is deliberately wide: a misdirected email carrying personal data qualifies just as a cyberattack does. A security incident that involves no personal data is not a personal data breach under the PDPL.
The clock starts when the organization becomes aware of the incident, not when the DPO or privacy team is informed. Awareness anywhere in the business opens the window, and the notification to SDAIA records two separate timestamps: when the breach occurred and when the organization became aware of it. Evidence such as security monitoring logs or message timestamps is typically used to fix the moment of awareness.
Under Article 24 of the Implementing Regulations, the notification, submitted through the national data governance platform, includes a description of the breach, the actual or approximate number of data subjects affected, when the breach occurred and when it was discovered, the types of personal data involved, the risks the breach may cause, its actual or potential impact on data subjects, the measures taken to limit and mitigate those risks, the future measures planned to prevent recurrence, confirmation of whether data subjects have been notified, and the contact details of the controller or the DPO.
Data subjects must be notified without undue delay where the breach may damage their data or conflict with their rights or interests. SDAIA guidance frames that harm as impairment of their ability to exercise their rights, physical harm such as stalking or assault, or economic damage such as fraud or identity theft. Notification can be made by text, email, or another appropriate method, and for very large affected populations, media channels such as a national newspaper or the organization's website may be used.
Yes, but only after an initial notification. The Implementing Regulations allow the controller to justify a delay and supply the remaining information as soon as possible, provided SDAIA is notified first with the reasons more time is needed. In practice the safer posture is early engagement: notify within the window with what is known, then supplement.
No. An incident is reportable only if it is a personal data breach and may potentially cause harm to the personal data or the data subject. Detailed regulatory guidance on that threshold is still limited, so organizations assess the nature and sensitivity of the data, the likelihood of misuse, and the potential impact on individuals, informed by their own risk appetite, and err toward engagement with the regulator where the assessment is uncertain.
