Past Masterclass June 8, 2026
Privacy Notice and Transparency Management under Saudi PDPL
The privacy notice is an organization's outward-facing commitment about what it does with personal data, and increasingly a regulator's first read on program maturity under the Saudi PDPL. This masterclass examines the notice as an operational deliverable rather than a static legal text, one that drifts out of alignment as processing activities, technologies, and transfers change. It addresses the required contents under Articles 12 and 13 of the PDPL and Article 4 of the Implementing Regulations, the PDPL-distinctive statement of whether providing data is mandatory or optional, when an Arabic notice is advisable, and why an inaccurate or absent notice is a credible enforcement trigger rather than a formality.
Presenters

Richard Chudzynsky
Partner, KONEXO/Eversheds Sutherland

Joe Corina
Head of Data Privacy Operations, Teya
Recording
We'll email you the link and passcode.Read the Blog Post
Key takeaways
- The privacy notice, termed a "privacy policy" under the Saudi Personal Data Protection Law (PDPL) and used interchangeably with "privacy notice," is the organization's outward-facing statement of what it does with personal data, and often a regulator's first read on program maturity.
- The legal foundation sits in Articles 12 and 13 of the PDPL and Article 4 of the Implementing Regulations, which set the notice's required contents, its timing before collection and processing, and the standard that purposes be specific, clear, and explicit rather than open-ended.
- The clearest PDPL-distinctive element is the statement of whether providing personal data is mandatory or optional, which has no direct GDPR equivalent.
- Purposes stated in the notice must align to what is recorded in the Record of Processing Activities (RoPA). A notice update is downstream of a RoPA update: when the RoPA changes, the notice is reviewed as a matter of course.
- A notice is updated primarily when processing activities or data types change. Updates should be batched into a disciplined periodic cadence rather than made continuously.
- An inaccurate or absent notice breaches the transparency obligation and the duty to maintain a notice, exposing the organization to admonishment, fines, lost consumer trust, reputational damage, and increased data subject complaints.
- Artificial intelligence lowers the regulator's cost of detection. The Saudi Data and AI Authority (SDAIA), or an activist privacy group as seen in Europe, can now scan large volumes of published notices and surface non-compliant ones for enforcement.
- Where personal data is collected from a source other than the data subject, the controller must inform the data subject within 30 days, including the data categories and the source. Defined exceptions apply, for instance where the data subject already knew or where a law specifically allows the collection.
- Higher-risk processing triggers additional mandatory disclosures in the notice under the Implementing Regulations, beyond the baseline elements.
- The SDAIA privacy policy guideline is not legally binding but usefully elaborates what each section should contain. Where SDAIA guidance is silent, for example on communicating with children, guidance from other regulators such as the UK ICO can responsibly fill the gap.
- An Arabic notice is advisable rather than strictly required given the audience, and the Arabic text of the law is the authoritative source, not the English translation. Where the data subject lacks complete legal capacity, language and format are tailored accordingly.
- The notice should be drafted in plain, layered language rather than legalese, and published across all relevant channels rather than buried on a single page, with the version sent to each audience logged.
- The notice stands on the rest of the privacy program, the RoPA, Data Protection Impact Assessments (DPIAs), and lawful basis and Legitimate Interest Assessment records, making it an inherently cross-functional deliverable evidenced through maintained, version-controlled documentation.
- The most common pitfalls are copy-pasting another organization's notice, treating it as a one-time exercise, and carrying indefinite "we keep data forever" retention claims into the notice rather than defining real periods.
Frequently Asked Questions
The mandatory elements are set out in Articles 12 and 13 of the PDPL and Article 4 of the Implementing Regulations. They include the controller's identity, the Data Protection Officer's details where required, the lawful basis, the purposes and types of personal data processed, the recipients, and a statement of whether providing the data is mandatory or optional. Purposes must be specific, clear, and explicit, and must align to the organization's RoPA. The PDPL refers to this document as a "privacy policy," used interchangeably with "privacy notice."
The notice must be made available before personal data is collected and before processing begins. Where data is collected from a source other than the data subject, the controller has 30 days to inform the data subject, including the data categories and the source. Exceptions apply, for instance where the data subject already knew, where notification is impossible, or where a law specifically allows the collection.
An Arabic notice is not a strict legal requirement, but it is strongly advisable where the audience of customers and employees is Arabic-speaking. The authoritative text of the PDPL is the Arabic version, not the English translation, so Arabic should be treated as the primary reference point. Where the data subject lacks complete legal capacity, the language and format must be tailored to that audience.
The primary trigger is a change to processing activities or data types, which typically surfaces through a RoPA update. Other triggers include changes to the Data Protection Officer's details, new data sharing or cross-border transfers, changes to storage, retention, or destruction, and the introduction of new technologies such as AI or biometrics. Rather than updating continuously, organizations should log changes as they arise and apply them in a disciplined periodic update tied to the RoPA review cycle.
Benchmark the GDPR requirements against the PDPL list, as roughly 80 to 90 percent overlaps. The clearest PDPL-specific addition is the statement of whether providing the personal data is mandatory or optional, which has no direct GDPR equivalent. Because many differences arise in how data is actually processed in-country rather than in the legal text, the more defensible approach is a distinct Saudi section or appendix rather than conflating jurisdictions in a single block.
Where processing involves large-scale or frequent processing, vulnerable individuals, continuous monitoring, emerging technologies, or automated decision-making, the Implementing Regulations require three additional disclosures. These are the means and methods of collecting and processing sensitive data, the measures in place to protect that data, and whether decisions will be made solely on automated processing. Building these sections into the notice template from the start ensures the team is prompted to check them whenever a high-risk activity is added.
