Data Controller
Under PDPL, the entity that decides why and how personal data is processed. Controllers bear primary legal responsibility for compliance and must register on the National Data Governance Platform.
Sources
Related terms
PDPL
Saudi Arabia's Personal Data Protection Law. The national framework governing how businesses collect, store, and transfer personal data. In full force since September 2024.
Data Processor
Under PDPL, any party that processes personal data on behalf of a controller — payment processors, POS vendors, cloud providers. Bound by a written processing agreement with the controller.
Sensitive Personal Data
A protected category under PDPL covering health data, biometrics, genetic data, religious beliefs, and criminal records. Mishandling carries fines up to SAR 3M plus up to 2 years in prison.
Data Subject Rights
The rights PDPL grants individuals over their personal data: access, correction, deletion, objection to processing, and data portability. Controllers must respond to requests within 30 days.
Need help getting PDPL-compliant? Wateer makes it the default.
Talk to Sales