All Masterclasses
    Past Masterclass April 2, 2026

    Data Retention, Minimization and Deletion Programs under Saudi PDPL

    Data retention, minimization, and deletion are core operational requirements under the Saudi PDPL. Organizations are expected to keep personal data only as long as a defined purpose requires, then delete it in a structured and documented way. This masterclass examines how to design defensible, category-based retention schedules tied to purpose, legal obligation, and sensitivity, rather than applying a single blanket period. It addresses why archiving is not deletion, how legal holds operate as narrow and tracked exceptions, and why a deletion request from a data subject often results in partial rather than complete erasure once statutory retention obligations are applied.

    Presenters

    Anurag Sushant
    Anurag Sushant
    DPO Consultant, Salam, Data Privacy Expert

    Recording

    We'll email you the link and passcode.Read the Blog Post

    Key takeaways

    • Deletion is a core compliance requirement under the Saudi Personal Data Protection Law (PDPL), not merely a technical housekeeping task.
    • Retention without a defined, current purpose creates privacy, security, operational, and regulatory risk. "Future value" is not itself a sufficient legal purpose for keeping personal data.
    • Over-retention compounds cost and exposure: it raises storage and audit burden, enlarges the blast radius of any security incident, and complicates deletion requests, and it makes legacy systems and cloud migrations riskier when historical data has accumulated indefinitely.
    • Retention and deletion are shaped by the core principles of data minimization, purpose limitation, storage limitation, and legal-hold obligations.
    • Personal data should be retained only while the original purpose, or a documented secondary purpose such as recordkeeping or audit, still applies.
    • The PDPL sets principles rather than universal retention periods, so organizations must define category-based schedules tied to purpose, legal obligation, and sensitivity, and document the rationale, rather than applying one blanket period to everything.
    • The Record of Processing Activities (RoPA) is the foundational tool for retention governance, establishing what data is held, why, where it sits, and how long it should be kept.
    • Sector regulators, such as SAMA, the Ministry of Health, and CST, may impose specific retention requirements that operate as floors beneath the PDPL framework.
    • Legal holds and statutory retention obligations are documented exceptions to deletion. They should be applied narrowly to relevant datasets and tracked, never used as a blanket reason to retain everything.
    • Archiving is not deletion. Archiving is a security and access-control practice; the data still exists, remains subject to PDPL obligations, and must still be deleted when retention expires.
    • Deletion should follow a defined schedule rather than being handled ad hoc when a request arises, and automation is strongly preferred because manual deletion is inconsistent and hard to monitor. Where automation is unavailable, controls, validations, and audit checks should enforce the schedule.
    • Deletion logs are an important accountability artifact: even after data is gone, the organization should be able to evidence what was deleted and when.
    • Data subject deletion requests must be assessed against statutory retention obligations and often result in partial rather than full deletion, as where labor-law obligations require certain employment records to be retained.
    • Retention and deletion cannot stand alone. They depend on the broader privacy program, including the RoPA, governance, stakeholder engagement, and technical implementation, and the business owner must be able to articulate a legitimate purpose or retention should not continue.

    Frequently Asked Questions