All Masterclasses
    Past Masterclass June 8, 2026

    Privacy Notice and Transparency Management under Saudi PDPL

    The privacy notice is an organization's outward-facing commitment about what it does with personal data, and increasingly a regulator's first read on program maturity under the Saudi PDPL. This masterclass examines the notice as an operational deliverable rather than a static legal text, one that drifts out of alignment as processing activities, technologies, and transfers change. It addresses the required contents under Articles 12 and 13 of the PDPL and Article 4 of the Implementing Regulations, the PDPL-distinctive statement of whether providing data is mandatory or optional, when an Arabic notice is advisable, and why an inaccurate or absent notice is a credible enforcement trigger rather than a formality.

    Presenters

    Richard Chudzynsky
    Richard Chudzynsky
    Partner, KONEXO/Eversheds Sutherland
    Joe Corina
    Joe Corina
    Head of Data Privacy Operations, Teya

    Recording

    We'll email you the link and passcode.Read the Blog Post

    Key takeaways

    • The privacy notice, termed a "privacy policy" under the Saudi Personal Data Protection Law (PDPL) and used interchangeably with "privacy notice," is the organization's outward-facing statement of what it does with personal data, and often a regulator's first read on program maturity.
    • The legal foundation sits in Articles 12 and 13 of the PDPL and Article 4 of the Implementing Regulations, which set the notice's required contents, its timing before collection and processing, and the standard that purposes be specific, clear, and explicit rather than open-ended.
    • The clearest PDPL-distinctive element is the statement of whether providing personal data is mandatory or optional, which has no direct GDPR equivalent.
    • Purposes stated in the notice must align to what is recorded in the Record of Processing Activities (RoPA). A notice update is downstream of a RoPA update: when the RoPA changes, the notice is reviewed as a matter of course.
    • A notice is updated primarily when processing activities or data types change. Updates should be batched into a disciplined periodic cadence rather than made continuously.
    • An inaccurate or absent notice breaches the transparency obligation and the duty to maintain a notice, exposing the organization to admonishment, fines, lost consumer trust, reputational damage, and increased data subject complaints.
    • Artificial intelligence lowers the regulator's cost of detection. The Saudi Data and AI Authority (SDAIA), or an activist privacy group as seen in Europe, can now scan large volumes of published notices and surface non-compliant ones for enforcement.
    • Where personal data is collected from a source other than the data subject, the controller must inform the data subject within 30 days, including the data categories and the source. Defined exceptions apply, for instance where the data subject already knew or where a law specifically allows the collection.
    • Higher-risk processing triggers additional mandatory disclosures in the notice under the Implementing Regulations, beyond the baseline elements.
    • The SDAIA privacy policy guideline is not legally binding but usefully elaborates what each section should contain. Where SDAIA guidance is silent, for example on communicating with children, guidance from other regulators such as the UK ICO can responsibly fill the gap.
    • An Arabic notice is advisable rather than strictly required given the audience, and the Arabic text of the law is the authoritative source, not the English translation. Where the data subject lacks complete legal capacity, language and format are tailored accordingly.
    • The notice should be drafted in plain, layered language rather than legalese, and published across all relevant channels rather than buried on a single page, with the version sent to each audience logged.
    • The notice stands on the rest of the privacy program, the RoPA, Data Protection Impact Assessments (DPIAs), and lawful basis and Legitimate Interest Assessment records, making it an inherently cross-functional deliverable evidenced through maintained, version-controlled documentation.
    • The most common pitfalls are copy-pasting another organization's notice, treating it as a one-time exercise, and carrying indefinite "we keep data forever" retention claims into the notice rather than defining real periods.

    Frequently Asked Questions