Saudi PDPL Data Security: Technical and Organizational Measures (TOMs)
Security controls do not satisfy Saudi PDPL obligations simply by existing on paper. They must be appropriate to the risk, implemented in practice, and capable of being evidenced, and organizations routinely discover during audits or after an incident that controls written into policy were never operationalized. This masterclass examines data security and technical and organizational measures (TOMs) as a continuous discipline rather than a one-time exercise, grounded in Article 19 of the PDPL and Article 23 of the Implementing Regulations and situated within Saudi Arabia's dual regulatory regime, where the NCA's controls apply alongside PDPL. It addresses how to calibrate measures to genuine risk rather than over-engineer what most organizations already have.
Presenters


Recording
Key takeaways
- Technical and organizational measures (TOMs) do not satisfy Saudi Personal Data Protection Law (PDPL) obligations by existing on paper. They must be appropriate to the risk, implemented in practice, and capable of being evidenced, since organizations routinely discover during audits that controls documented in policy were never operationalized.
- The legal foundation sits in Article 19 of the PDPL and Article 23 of the Implementing Regulations, which require necessary organizational, administrative, and technical measures whenever personal data is processed.
- Security controls follow a continuous, risk-driven lifecycle rather than a one-time setup, and are re-tested as threats, systems, and standards change. A named owner is needed to keep them current.
- Controls degrade over time, so a measure judged adequate today may become insufficient tomorrow. A deprecated encryption or hashing algorithm is the clearest example.
- Controls are reassessed on defined internal and external triggers.
- Appropriate measures span the recognized control domains, selected to fit the organization's risk rather than adopted wholesale. Applying every control uniformly is both meaningless and overkill, since the risk of a furniture purchase differs entirely from a cloud analytics platform.
- Risk identification is the foundational and most consequential step. It warrants formal documentation, alignment with the enterprise-wide risk definition, and executive sign-off, because the organization's risk appetite shapes which controls it selects.
- Saudi Arabia imposes a dual regulatory obligation: the National Cybersecurity Authority (NCA) Essential Cybersecurity Controls and sector-specific controls apply alongside PDPL data-protection requirements, with recognized best-practice standards as the alternative where NCA controls are not mandated.
- Recognized control benchmarks include ISO 27701, NIST SP 800-53, and the NCA's standards. ISO 27701 became a standalone standard in 2025, separated from ISO 27001.
- Sensitive categories carry enhanced requirements. Health and credit data attract additional controls under the PDPL and applicable sectoral rules.
- When disclosing personal data to a recipient such as a processor, the controller must assess that the recipient provides sufficient guarantees and a comparable level of security.
- A documented and tested breach notification policy and procedure is itself an organizational measure, making engagement with the Saudi Data and AI Authority (SDAIA) faster when an incident occurs.
- A defensible program is evidenced through maintained documentation an auditor can trace to live operations.
- Internal audit, as the third line of defense, is central to checking control effectiveness. It is most useful when treated as a partner that surfaces deficiencies, not as a policing function, with its findings feeding the monitor-and-improve step.
- TOMs are inherently cross-functional: legal handles the PDPL nuance, IT and cyber implement, and the privacy function brings the teams together. The recurring practical message is not to over-engineer what most organizations already have.
