Data Breach Notification
PDPL requires controllers to notify SDAIA of any personal data breach within 72 hours of detection. Affected individuals must also be informed if the breach poses significant risk to their rights.
Sources
Related terms
PDPL
Saudi Arabia's Personal Data Protection Law. The national framework governing how businesses collect, store, and transfer personal data. In full force since September 2024.
SDAIA
Saudi Data and Artificial Intelligence Authority. The national regulator for data protection and AI governance, and the body enforcing PDPL including licensing accredited auditors.
Data Protection Officer (DPO)
An individual designated by a data controller to oversee PDPL compliance, handle data subject requests, and liaise with SDAIA. Required for high-risk processing or large-scale operations.
Need help getting PDPL-compliant? Wateer makes it the default.
Talk to Sales