All Masterclasses
    Past Masterclass April 23, 2026

    Legal Basis and Legitimate Interest Assessments (LIA) under Saudi PDPL

    Lawful basis is the first and most critical decision in any personal data processing under the Saudi PDPL: without a valid basis, processing is unlawful regardless of the security controls around it. This masterclass examines how to move beyond defaulting to consent toward a structured, defensible approach to selecting and documenting a lawful basis, and the role of the Legitimate Interest Assessment (LIA) in supporting compliant operations. It addresses the firewall between consent and legal obligation, why sensitive data cannot rest on legitimate interest, the consent requirement for direct marketing under Article 25, and why a lawful basis must be reassessed whenever purposes change.

    Presenters

    Muneeb Imran
    Muneeb Imran
    Data Privacy & AI Governance Expert, DPO, and Co-Author 'Data Privacy: Practical Handbook for Governance & Operations'

    Recording

    We'll email you the link and passcode.Read the Blog Post

    Key takeaways

    • Lawful basis is the first and most critical decision in any processing activity. Without a valid basis, processing is unlawful regardless of the security controls wrapped around it.
    • The operative question is always why personal data is being collected and processed, settled before how it will be protected, and the answer is fact-specific justification rather than checkbox selection.
    • The Saudi Personal Data Protection Law (PDPL) recognizes a defined set of lawful bases, with consent as the default baseline but not always the most appropriate or practical choice.
    • There is a firewall between consent and legal obligation. Where a law or regulator mandates processing, such as SAMA requirements, the basis is legal obligation, and asking for consent is misleading because withdrawal cannot stop the processing.
    • Over-reliance on consent creates operational risk through withdrawal rights and compliance burden, which is why alternative bases warrant consideration rather than being defaulted past.
    • Legitimate interest must be used cautiously and is defensible only with a formal, documented Legitimate Interest Assessment (LIA).
    • Sensitive personal data cannot be processed under legitimate interest under the PDPL; it requires consent, statutory authority, or another permitted basis with documented justification.
    • The LIA applies a structured, documented test weighing the processing purpose, its necessity against less intrusive alternatives, and the balance against data subject rights, and it should be signed and reassessed when purposes change.
    • Data minimization and proportionality apply throughout: collect only what the defined purpose requires.
    • Misclassifying marketing as service communications is a key compliance risk, since direct marketing generally requires consent under Article 25 of the PDPL while service communications tied to an existing contract may rely on other bases.
    • Lawful basis decisions must be documented in the Record of Processing Activities (RoPA) and supported by evidence such as LIAs and Data Protection Impact Assessments (DPIAs).
    • Transparency obligations apply regardless of lawful basis: individuals must still be informed through the privacy notice.
    • Lawful basis must be reassessed whenever processing purposes change or expand, and a material change without reassessment is one of the most common gaps identified in regulatory audits.
    • Lawful basis is cross-functional and ultimately a control layer: business teams define the purpose, the DPO ensures compliance, and strong signed documentation determines whether processing is valid at all.

    Frequently Asked Questions