Saudi Arabia PDPL for Healthcare & Life Sciences
It fails when it cannot prove Arabic consent was captured, which processors received patient data, where that data currently resides, and whether cross-border transfer justification exists. Consentica and Privault provide operational proof — not documentation.
Zero integration. Unlimited consents. Live within 48 hours.
Launch your DPDP-ready consent flow fast, validate it with real users, and scale when you're ready.
The Personal Data Protection Law governs the processing of personal data of individuals in the Kingdom of Saudi Arabia. It applies to any entity that processes personal data of individuals residing in Saudi Arabia, including entities located outside the Kingdom that process such data in relation to offering goods or services to individuals in Saudi Arabia.
PDPL places specific emphasis on Arabic-language notice and consent, and imposes stricter controls on cross-border data transfer than most comparable regimes.
PDPL's cross-border transfer restrictions are stricter than DPDPA's — an offshore transfer without documented transfer justification is independently enforceable, separate from any consent violation.
Saudi PDPL imposes financial penalties of up to SAR 5 million*, doubled for repeat violations, and imprisonment of up to 2 years* for violations involving unlawful disclosure of sensitive personal data. Enforcement sits with SDAIA and the National Data Management Office.
Maximum penalties under Saudi PDPL for key categories of non-compliance. *Verify current SAR figures before publishing.
| Violation Category | Maximum Penalty |
|---|---|
Unlawful disclosure or publication of sensitive personal data | Up to SAR 3M + up to 2 yrs imprisonment* |
Processing without a valid legal basis | Up to SAR 5M* |
Cross-border transfer without documented justification | Up to SAR 5M* |
Failure to implement adequate security safeguards | Up to SAR 5M* |
Failure to notify SDAIA of a personal data breach | Up to SAR 5M* |
Repeat violations | Penalty may be doubled* |
Important: *Exact SAR figures and imprisonment terms should be verified against the current Implementing Regulation before publishing — PDPL penalty provisions have been amended since original enactment.
The most critical areas where organisations face SDAIA enforcement exposure.
Presenting notices or capturing consent only in English, without an Arabic-language equivalent.
Moving personal data outside the Kingdom without a documented PDPL transfer basis.
Processing health, biometric, or other sensitive personal data without heightened safeguards.
Failing to implement technical and organisational measures appropriate to the risk.
Failing to notify SDAIA and affected individuals within the required timeframe.
Processing personal data without consent or another valid legal basis under PDPL.
The DPBI is a fully digital quasi-judicial body established under Chapter V of the DPDP Act. It is not a policy regulator — its sole function is investigation, adjudication, and enforcement.
An inquiry can be initiated by:
SDAIA / the National Data Management Office can conduct inspections and request documentation without a prior complaint.
A complaint, breach notification, or regulator-initiated inspection begins the process.
The regulator reviews documentation, consent records, and processor/transfer registers.
The organisation is notified of findings and given an opportunity to respond.
The regulator issues a corrective order, administrative fine, and/or refers the matter for criminal prosecution where sensitive data was unlawfully disclosed.
The organisation may appeal the decision before the Board of Grievances (Diwan Al Mazalim).
Key point: PDPL enforcement can run administrative (fine) and criminal (prosecution) tracks in parallel for the same violation when sensitive data disclosure is involved.
Penalty severity under PDPL is assessed against the following factors.
Nature, severity, and duration of the violation.
Whether sensitive personal data was involved — sensitive data attracts materially higher penalties.
Whether the violating entity has prior PDPL violations on record.
The extent of harm caused to affected individuals.
The organisation's cooperation during the investigation.
Steps taken to remedy the violation and prevent recurrence.
As with most data protection regimes, prompt breach reporting and demonstrated cross-border transfer documentation materially reduce enforcement severity under PDPL.
PDPL carries criminal penalties — up to 2 years imprisonment* for unlawful disclosure of sensitive personal data.
The majority of PDPL enforcement actions are administrative fines rather than criminal referrals.
Unlike DPDPA, PDPL does provide for imprisonment in specific circumstances — primarily unlawful disclosure or publication of sensitive personal data with intent to harm or for financial gain.
Most day-to-day compliance failures — missing Arabic consent, undocumented transfers, security gaps — are addressed through administrative fines, not criminal referral.
Important milestones in Saudi Arabia's data protection regulation timeline.
Saudi Arabia's first comprehensive personal data protection law is enacted.
Key amendments refine consent, cross-border transfer, and enforcement provisions.
Detailed compliance rules come into force.
Full enforcement begins after the transitional compliance period.
PDPL combines GDPR-style principles with Saudi-specific requirements — Arabic-language consent and strict cross-border transfer controls chief among them.
For healthcare organisations processing Saudi patient data, the two most commonly audited gaps are Arabic consent evidence and an accurate offshore processor registry with documented transfer justification.
Cross-border transfer without documented justification is independently enforceable under PDPL — it does not require a separate consent failure to trigger a penalty.
No. Saudi PDPL shares privacy principles with GDPR but has distinct requirements around consent, sensitive data categories (including health data), Arabic communication obligations, SDAIA regulator expectations, and cross-border data transfer controls. Pages and controls designed for GDPR need to be adapted for PDPL specifically.