All Masterclasses
    Past Masterclass July 15, 2026

    Personal Data Breach Notification and Incident Response under Saudi PDPL

    Personal data breach notification under the Saudi PDPL runs on a 72-hour clock that starts the moment an organization becomes aware of an incident, not when its privacy team is told. This masterclass, led by Richard Chudzynsky and Skanda Reddy of Konexo (Eversheds Sutherland), covered what the law counts as a personal data breach, when and how to notify the Saudi Data & AI Authority (SDAIA) and affected data subjects under Article 20 of the PDPL and Article 24 of the Implementing Regulations, and how to build an incident response posture that holds under regulatory scrutiny, from triage and risk assessment through documentation and post-incident improvement.

    Presenters

    Richard Chudzynsky
    Richard Chudzynsky
    Partner, KONEXO/Eversheds Sutherland
    Skanda Reddy
    Skanda Reddy
    Senior Associate, KONEXO/Eversheds Sutherland

    Recording

    We'll email you the link and passcode.Read the Blog Post

    Key takeaways

    • The Implementing Regulations define a personal data breach broadly: any incident leading to disclosure, destruction, or unauthorized access to personal data, whether intentional or accidental, automated or manual. Accidental exposure is a breach in law, not a lesser event.
    • A security incident and a personal data breach are not the same thing. If no personal data is affected, PDPL notification obligations are not triggered, so triage that distinguishes the two is the first capability an incident response posture needs.
    • Article 20 of the PDPL and Article 24 of the Implementing Regulations govern notification. SDAIA must be notified within 72 hours of the organization becoming aware of a breach that may potentially harm the personal data or the data subject; potential harm, not actual harm, is the trigger.
    • The clock starts at organizational awareness, wherever in the business that occurs, not when the DPO is informed. The moment of occurrence and the moment of awareness are separate timestamps, and both belong in the notification.
    • The 72-hour deadline can be extended, but only after an initial notification with a justification for the delay. The presenters' counsel was early, proactive engagement with SDAIA, supplying detail as it firms up.
    • Data subjects must be notified without undue delay where a breach may damage their data or conflict with their rights or interests. SDAIA guidance frames that harm as impaired rights, physical danger such as stalking or assault, or economic damage such as fraud and identity theft.
    • Notification is made by the DPO through the national data governance platform, and controllers need to be registered on the portal before an incident, not during one. The DPO is the direct point of contact with the competent authority.
    • The controller retains ultimate accountability for notification. A contract can allocate operational duties to a processor, but the presenters advised keeping the decision to notify, its timing, and its documentation in the controller's hands.
    • Most breaches begin inside the organization. The presenters put the employee-originated share at 60 to 80 percent, which makes training, internal controls, and awareness the highest-yield prevention available.
    • Third parties are among the largest breach sources. Vendor due diligence, contractual safeguards, and technical controls determine whether a supplier's weakness becomes your notification obligation.
    • Novel technologies, AI included, expand the attack surface faster than controls mature. Sandboxing, containment, and close coordination between the DPO and information security are the counterweights.
    • A current record of processing (RoPA) is the breach-response accelerator: it identifies in hours which data, data subjects, recipients, and transfers a compromised system touches, while its absence consumes the notification window in discovery.
    • Cross-border breaches and dual regulation multiply obligations. SAMA, the Ministry of Health, the NCA, and other authorities carry their own notification expectations, which is why regulatory mapping is the first step in building a breach plan.
    • A defensible position is a documented one. The records that evidence the response, from the decision log to correspondence with SDAIA and data subjects, are what demonstrate accountability after the event.
    • Breach handling does not end at recovery. Root cause analysis, verified remediation, updated controls, and refreshed training convert an incident into a stronger posture, and the mismanaged alternative carries reputational and financial costs that can threaten the business itself.

    Frequently Asked Questions