Past Masterclass March 9, 2026
Data Subject Requests (DSARs) under Saudi PDPL
Data subject requests are among the most operationally demanding aspects of Saudi PDPL compliance, requiring organizations to locate and disclose personal data across complex systems while meeting a strict statutory timeline. As public awareness of PDPL rights grows, these requests arrive more frequently and through informal channels. This masterclass examines how to recognize a valid request, manage it through a repeatable lifecycle within the 30-day response window, verify identity proportionately, and decide when a request can be narrowed, partially fulfilled, or refused. It addresses the redaction, documentation, and cross-functional coordination that make a DSAR response defensible to SDAIA.
Presenters

Joe Corina
Head of Data Privacy Operations, Teya

Richard Chudzynsky
Partner, KONEXO/Eversheds Sutherland
Recording
We'll email you the link and passcode.Read the Blog Post
Key takeaways
- Data subject rights are becoming an active compliance issue in Saudi Arabia. As awareness of the Saudi Personal Data Protection Law (PDPL) grows and privacy notices become clearer, individuals are exercising their rights more frequently.
- Data subject access requests (DSARs) are both legal and operational events. Mishandling them can trigger regulatory complaints, reputational damage, and increased scrutiny from the Saudi Data and AI Authority (SDAIA).
- Controllers generally have 30 days to respond, and the clock starts when the organization receives the request, not when the privacy team becomes aware of it.
- The PDPL grants data subjects a defined set of rights, each requiring a different operational process to fulfil.
- A DSAR requires no formal language or specific channel and may arrive through customer service, HR, email, or phone, so frontline teams must be trained to recognize and escalate requests quickly before the response clock is lost.
- Common DSAR triggers include marketing communications, employment disputes, grievance processes, and concerns about how personal data is being used.
- Identity verification is a critical first step and must be proportionate to the sensitivity of the data. Over-verification, demanding more identification than necessary, is itself a PDPL concern.
- Broad requests should be clarified early. When an individual asks for "all my data," engaging to narrow scope produces a more useful and manageable response.
- Not every inquiry is a rights request. Organizations must distinguish DSARs from complaints, service issues, and marketing opt-outs.
- The PDPL allows certain requests to be limited or refused on narrow grounds, such as where they are unjustifiably repetitive or require extraordinary effort, though practical guidance on these thresholds remains limited. Partial fulfilment is often preferable to outright refusal.
- Deletion requests must be assessed against legal retention obligations, since other laws may require certain records to be preserved.
- The Record of Processing Activities (RoPA) is the backbone of effective DSAR handling, identifying where personal data sits and which systems and vendors hold it, while data discovery and retrieval across platforms is often the hardest step.
- Redaction is a critical safeguard: disclosures must not reveal third-party personal data or other legally protected information, and responses should clearly explain what is provided, what is withheld, and the legal basis for any limitation.
- Every decision in the process should be documented, intake, interpretation, searches conducted, and disclosure rationale, supported by a DSAR toolkit, because preparedness matters most when events such as breaches drive spikes in requests.
Frequently Asked Questions
Controllers must respond to a verified data subject request within 30 days. The clock begins when the organization receives the request, not when the privacy team becomes aware of it. A further 30-day extension is permitted where the request is complex or where the controller has received multiple requests from the same data subject.
The PDPL grants the rights to be informed of the legal basis and purpose of processing, to access personal data, to obtain a copy in a readable format, to request correction or completion, and to request destruction when data is no longer needed. The Implementing Regulations elaborate on the withdrawal of consent.
Yes, on narrow grounds. The PDPL permits limitation or refusal where requests are unjustifiably repetitive, require extraordinary effort, would compromise the rights of others, conflict with another legal obligation, or cannot be verified. Refusals must be reasoned, documented, and communicated to the requester along with information on escalation rights.
Verification must be proportionate to the sensitivity of the data and the risk of unauthorized disclosure. Over-verification, requesting more identification than necessary, is itself a PDPL concern. The verification approach should be documented in the DSAR procedure so it is applied consistently and is defensible to SDAIA.
No. A DSAR requires no specific format, language, or submission channel and may arrive through customer service, HR, email, phone, or other informal channels. Frontline teams must be trained to recognize rights requests and escalate them so the 30-day response clock is not lost.
The PDPL does not provide for fees in ordinary circumstances, so controllers should respond to verified requests free of charge. A fee may be considered only where a request is manifestly unfounded or excessive, a narrow exception that requires documented justification rather than a default posture.
