PDPL
Saudi Arabia's Personal Data Protection Law. The national framework governing how businesses collect, store, and transfer personal data. In full force since September 2024.
Sources
Related terms
SDAIA
Saudi Data and Artificial Intelligence Authority. The national regulator for data protection and AI governance, and the body enforcing PDPL including licensing accredited auditors.
Data Controller
Under PDPL, the entity that decides why and how personal data is processed. Controllers bear primary legal responsibility for compliance and must register on the National Data Governance Platform.
Data Subject Rights
The rights PDPL grants individuals over their personal data: access, correction, deletion, objection to processing, and data portability. Controllers must respond to requests within 30 days.
ZATCA
Zakat, Tax and Customs Authority. The Saudi tax regulator that runs the mandatory e-invoicing (Fatoora) framework all businesses must comply with.
Need help getting PDPL-compliant? Wateer makes it the default.
Talk to Sales