All Masterclasses
    Past Masterclass March 9, 2026

    Data Subject Requests (DSARs) under Saudi PDPL

    Data subject requests are among the most operationally demanding aspects of Saudi PDPL compliance, requiring organizations to locate and disclose personal data across complex systems while meeting a strict statutory timeline. As public awareness of PDPL rights grows, these requests arrive more frequently and through informal channels. This masterclass examines how to recognize a valid request, manage it through a repeatable lifecycle within the 30-day response window, verify identity proportionately, and decide when a request can be narrowed, partially fulfilled, or refused. It addresses the redaction, documentation, and cross-functional coordination that make a DSAR response defensible to SDAIA.

    Presenters

    Joe Corina
    Joe Corina
    Head of Data Privacy Operations, Teya
    Richard Chudzynsky
    Richard Chudzynsky
    Partner, KONEXO/Eversheds Sutherland

    Recording

    We'll email you the link and passcode.Read the Blog Post

    Key takeaways

    • Data subject rights are becoming an active compliance issue in Saudi Arabia. As awareness of the Saudi Personal Data Protection Law (PDPL) grows and privacy notices become clearer, individuals are exercising their rights more frequently.
    • Data subject access requests (DSARs) are both legal and operational events. Mishandling them can trigger regulatory complaints, reputational damage, and increased scrutiny from the Saudi Data and AI Authority (SDAIA).
    • Controllers generally have 30 days to respond, and the clock starts when the organization receives the request, not when the privacy team becomes aware of it.
    • The PDPL grants data subjects a defined set of rights, each requiring a different operational process to fulfil.
    • A DSAR requires no formal language or specific channel and may arrive through customer service, HR, email, or phone, so frontline teams must be trained to recognize and escalate requests quickly before the response clock is lost.
    • Common DSAR triggers include marketing communications, employment disputes, grievance processes, and concerns about how personal data is being used.
    • Identity verification is a critical first step and must be proportionate to the sensitivity of the data. Over-verification, demanding more identification than necessary, is itself a PDPL concern.
    • Broad requests should be clarified early. When an individual asks for "all my data," engaging to narrow scope produces a more useful and manageable response.
    • Not every inquiry is a rights request. Organizations must distinguish DSARs from complaints, service issues, and marketing opt-outs.
    • The PDPL allows certain requests to be limited or refused on narrow grounds, such as where they are unjustifiably repetitive or require extraordinary effort, though practical guidance on these thresholds remains limited. Partial fulfilment is often preferable to outright refusal.
    • Deletion requests must be assessed against legal retention obligations, since other laws may require certain records to be preserved.
    • The Record of Processing Activities (RoPA) is the backbone of effective DSAR handling, identifying where personal data sits and which systems and vendors hold it, while data discovery and retrieval across platforms is often the hardest step.
    • Redaction is a critical safeguard: disclosures must not reveal third-party personal data or other legally protected information, and responses should clearly explain what is provided, what is withheld, and the legal basis for any limitation.
    • Every decision in the process should be documented, intake, interpretation, searches conducted, and disclosure rationale, supported by a DSAR toolkit, because preparedness matters most when events such as breaches drive spikes in requests.

    Frequently Asked Questions