All Masterclasses
    Past Roundtable May 13, 2026

    Saudi PDPL Enforcement: What Regulators Are Doing in Practice

    Saudi PDPL enforcement has moved decisively from anticipation to action. This masterclass offers a ground-level account of how SDAIA and sectoral regulators are operating in practice, drawing on engagements with organizations under active investigation. It examines what is actually triggering enforcement, how SDAIA's specialist committees hear cases and require evidence, and why enforcement has become, in effect, an evidence phase in which policies and frameworks no longer suffice. It addresses the structural gaps that continue to leave organizations exposed, particularly an under-empowered DPO and over-reliance on tooling, and why a proactive, transparent posture toward the regulator consistently de-escalates.

    Presenters

    Basmah Alsubaie
    Basmah Alsubaie
    CEO, Privacy Professionals, former regulator
    Richard Chudzynsky
    Richard Chudzynsky
    Partner, KONEXO/Eversheds Sutherland
    Tahir Latif
    Tahir Latif
    IAPP Country Leader - UAE, KSA & Qatar

    Recording

    Delivered live β€” no recording available for roundtable sessions to encourage candid exchange.

    Key takeaways

    • The "wishful thinking" phase is over. The Saudi Data and AI Authority (SDAIA) and sectoral regulators are decisively in an active enforcement posture, and organizations treating the Personal Data Protection Law (PDPL) as a future concern are materially behind.
    • SDAIA issued 48 formal enforcement decisions in 2025 alone, spanning multiple sectors and covering violations such as marketing without consent, inaccurate privacy notices, and missing lawful basis.
    • Saudi Arabia's accession to the Global Privacy Assembly has raised SDAIA's regional and global profile and introduced enforcement standards it is now expected to meet.
    • Enforcement is, in practice, an evidence phase. Regulators are no longer satisfied with policies and frameworks; they expect documented proof that controls operate as described.
    • SDAIA's enforcement machinery runs through specialist committees of legal, IT, and technology experts that hear cases, summon parties, require evidence, and issue binding resolutions, with cases escalating to judicial review.
    • Investigations are set off by a recognizable range of triggers, the most consequential of which are within an organization's control.
    • Ignoring SDAIA communications or failing to provide requested documentation tends to escalate matters unnecessarily, while proactive, transparent engagement consistently de-escalates.
    • Sectoral regulators are active too. The financial regulator has run in-depth quarterly audits for two years, often producing 20 to 30 findings of varying severity, and other sectoral regulators are building comparable capabilities.
    • Healthcare and financial services appear to be priority sectors, reflecting the sensitivity of the data and the maturity of sectoral oversight.
    • Public awareness is rising sharply, and younger residents in particular understand their PDPL rights and will file complaints, so enforcement risk is now driven by data subjects, not only regulators.
    • The empowerment of the Data Protection Officer (DPO) remains one of the most significant structural gaps: DPOs often sit too low, are excluded from early decisions, and are engaged only after processing has begun, creating "privacy debt" that is expensive to remediate.
    • DPOs should report at C-suite level, typically to the General Counsel, Chief Risk Officer, or Chief Data Officer; reporting into IT or security creates a structural conflict that would not be acceptable in more mature jurisdictions.
    • Over-reliance on technology is itself a compliance risk. Organizations have spent heavily on tooling without first establishing governance, ownership, and human capability, and human-in-the-loop oversight remains essential.
    • Claims of "100 percent PDPL compliance," including those backed by third-party certifications, are a red flag rather than a reassurance, since no mature privacy program anywhere claims full compliance.
    • The Record of Processing Activities (RoPA) remains the foundation of a defensible program and is the first artifact regulators request. Organizations should fix fundamentals before extending into AI, and documentation discipline, named owners, review dates, and audit trails, matters as much as the controls themselves.

    Frequently Asked Questions