Past Masterclass April 23, 2026
Legal Basis and Legitimate Interest Assessments (LIA) under Saudi PDPL
Lawful basis is the first and most critical decision in any personal data processing under the Saudi PDPL: without a valid basis, processing is unlawful regardless of the security controls around it. This masterclass examines how to move beyond defaulting to consent toward a structured, defensible approach to selecting and documenting a lawful basis, and the role of the Legitimate Interest Assessment (LIA) in supporting compliant operations. It addresses the firewall between consent and legal obligation, why sensitive data cannot rest on legitimate interest, the consent requirement for direct marketing under Article 25, and why a lawful basis must be reassessed whenever purposes change.
Presenters

Muneeb Imran
Data Privacy & AI Governance Expert, DPO, and Co-Author 'Data Privacy: Practical Handbook for Governance & Operations'
Recording
We'll email you the link and passcode.Read the Blog Post
Key takeaways
- Lawful basis is the first and most critical decision in any processing activity. Without a valid basis, processing is unlawful regardless of the security controls wrapped around it.
- The operative question is always why personal data is being collected and processed, settled before how it will be protected, and the answer is fact-specific justification rather than checkbox selection.
- The Saudi Personal Data Protection Law (PDPL) recognizes a defined set of lawful bases, with consent as the default baseline but not always the most appropriate or practical choice.
- There is a firewall between consent and legal obligation. Where a law or regulator mandates processing, such as SAMA requirements, the basis is legal obligation, and asking for consent is misleading because withdrawal cannot stop the processing.
- Over-reliance on consent creates operational risk through withdrawal rights and compliance burden, which is why alternative bases warrant consideration rather than being defaulted past.
- Legitimate interest must be used cautiously and is defensible only with a formal, documented Legitimate Interest Assessment (LIA).
- Sensitive personal data cannot be processed under legitimate interest under the PDPL; it requires consent, statutory authority, or another permitted basis with documented justification.
- The LIA applies a structured, documented test weighing the processing purpose, its necessity against less intrusive alternatives, and the balance against data subject rights, and it should be signed and reassessed when purposes change.
- Data minimization and proportionality apply throughout: collect only what the defined purpose requires.
- Misclassifying marketing as service communications is a key compliance risk, since direct marketing generally requires consent under Article 25 of the PDPL while service communications tied to an existing contract may rely on other bases.
- Lawful basis decisions must be documented in the Record of Processing Activities (RoPA) and supported by evidence such as LIAs and Data Protection Impact Assessments (DPIAs).
- Transparency obligations apply regardless of lawful basis: individuals must still be informed through the privacy notice.
- Lawful basis must be reassessed whenever processing purposes change or expand, and a material change without reassessment is one of the most common gaps identified in regulatory audits.
- Lawful basis is cross-functional and ultimately a control layer: business teams define the purpose, the DPO ensures compliance, and strong signed documentation determines whether processing is valid at all.
Frequently Asked Questions
The PDPL recognizes consent, contractual necessity, legal obligation, legitimate interest, public interest, actual interest, and vital interest. Lawful basis must be identified before processing begins and documented in the RoPA. Selection is fact-specific, and treating it as a checkbox is one of the most common audit findings.
No. The PDPL excludes sensitive personal data from the legitimate-interest basis. Sensitive categories, including health, religious, ethnic, biometric, genetic, and credit data, require consent, statutory authority, or another permitted basis with documented justification. Using legitimate interest for sensitive data is a structural compliance failure.
An LIA is a documented three-part test: the purpose test (why the processing is needed), the necessity test (whether less intrusive alternatives exist), and the balancing test (whether data subject rights are overridden by controller interests). LIAs should be signed, evidenced, and reassessed whenever purposes change.
A Data Protection Impact Assessment (DPIA) assesses risks to data subjects before high-risk processing begins. An LIA determines whether legitimate interest is an appropriate lawful basis and whether controller interests override data subject rights. DPIAs are triggered by risk; LIAs by lawful basis selection. They can overlap but answer distinct questions.
No. There is a firewall between the two. Where processing is mandated by law or a regulator, such as SAMA anti-money-laundering obligations, the lawful basis is legal obligation, not consent. Asking for consent in these scenarios is misleading, because consent withdrawal cannot stop processing the organization is legally required to perform.
Direct marketing generally requires consent under Article 25 of the PDPL, which restricts the use of personal communication channels such as post, email, and phone for advertising or awareness materials, with the Implementing Regulations elaborating. Service communications tied to an existing contract may rely on other lawful bases.
