Past Masterclass April 2, 2026
Data Retention, Minimization and Deletion Programs under Saudi PDPL
Data retention, minimization, and deletion are core operational requirements under the Saudi PDPL. Organizations are expected to keep personal data only as long as a defined purpose requires, then delete it in a structured and documented way. This masterclass examines how to design defensible, category-based retention schedules tied to purpose, legal obligation, and sensitivity, rather than applying a single blanket period. It addresses why archiving is not deletion, how legal holds operate as narrow and tracked exceptions, and why a deletion request from a data subject often results in partial rather than complete erasure once statutory retention obligations are applied.
Presenters

Anurag Sushant
DPO Consultant, Salam, Data Privacy Expert
Recording
We'll email you the link and passcode.Read the Blog Post
Key takeaways
- Deletion is a core compliance requirement under the Saudi Personal Data Protection Law (PDPL), not merely a technical housekeeping task.
- Retention without a defined, current purpose creates privacy, security, operational, and regulatory risk. "Future value" is not itself a sufficient legal purpose for keeping personal data.
- Over-retention compounds cost and exposure: it raises storage and audit burden, enlarges the blast radius of any security incident, and complicates deletion requests, and it makes legacy systems and cloud migrations riskier when historical data has accumulated indefinitely.
- Retention and deletion are shaped by the core principles of data minimization, purpose limitation, storage limitation, and legal-hold obligations.
- Personal data should be retained only while the original purpose, or a documented secondary purpose such as recordkeeping or audit, still applies.
- The PDPL sets principles rather than universal retention periods, so organizations must define category-based schedules tied to purpose, legal obligation, and sensitivity, and document the rationale, rather than applying one blanket period to everything.
- The Record of Processing Activities (RoPA) is the foundational tool for retention governance, establishing what data is held, why, where it sits, and how long it should be kept.
- Sector regulators, such as SAMA, the Ministry of Health, and CST, may impose specific retention requirements that operate as floors beneath the PDPL framework.
- Legal holds and statutory retention obligations are documented exceptions to deletion. They should be applied narrowly to relevant datasets and tracked, never used as a blanket reason to retain everything.
- Archiving is not deletion. Archiving is a security and access-control practice; the data still exists, remains subject to PDPL obligations, and must still be deleted when retention expires.
- Deletion should follow a defined schedule rather than being handled ad hoc when a request arises, and automation is strongly preferred because manual deletion is inconsistent and hard to monitor. Where automation is unavailable, controls, validations, and audit checks should enforce the schedule.
- Deletion logs are an important accountability artifact: even after data is gone, the organization should be able to evidence what was deleted and when.
- Data subject deletion requests must be assessed against statutory retention obligations and often result in partial rather than full deletion, as where labor-law obligations require certain employment records to be retained.
- Retention and deletion cannot stand alone. They depend on the broader privacy program, including the RoPA, governance, stakeholder engagement, and technical implementation, and the business owner must be able to articulate a legitimate purpose or retention should not continue.
Frequently Asked Questions
Personal data may be retained only for as long as the original purpose, or a documented secondary purpose such as audit or recordkeeping, still applies. The PDPL does not prescribe universal retention periods, so organizations must define category-based schedules tied to purpose, legal obligation, and sensitivity, and document the rationale.
No. The PDPL sets principles, purpose limitation, storage limitation, and minimization, rather than prescriptive periods. Organizations must define category-based schedules and document the basis for each. Sector regulators such as SAMA, the Ministry of Health, and CST may impose specific retention requirements that operate as floors under the PDPL framework.
No. Archiving is a security and access-control practice; the data still exists and remains subject to PDPL obligations. Once the retention period expires, archived data must be deleted. Treating archiving as deletion is one of the most common retention failures surfaced during audits.
A deletion request must be assessed against statutory retention obligations and typically results in partial deletion. KSA labor law and GOSI requirements may require certain employment records to be retained for defined periods, so the request often produces partial fulfilment rather than complete erasure of all records.
A legal hold is a documented exception to deletion, applied where data is needed for litigation, regulatory investigation, or statutory retention. Holds should be applied narrowly to the relevant datasets, tracked in a register, and lifted when no longer necessary, rather than used as a blanket justification for indefinite retention.
