Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Privacy law

Saudi Arabia · PDPL

Breach records & 72-hour SDAIA notice.

Applies to: Controllers handling Saudi personal data. Built · in force 14 Sep 2023

What the signed record shows

Breach incident records, processor-coordination signals, and breach detail for SDAIA notification.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: PDPL (RD M/19, am. M/148); Implementing Regs

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Personal Data Protection Law (Saudi PDPL), issued by Royal Decree No. M/19 of 2021, as amended by Royal Decree No. M/148 of 2023. Detail is set by the Implementing Regulations (SDAIA). Provisions addressed: Breach notification to SDAIA within 72 hours of becoming aware where the incident may harm personal data, data subjects, or their rights (Implementing Regulations; submitted via the National Data Governance Platform), with required content; notify data subjects without undue delay.

Art. 8
Processor obligations (follow breach-notice requirements in coordination with the controller). Records of processing activities and security measures (Law + Implementing Regulations); retain copies of documents submitted to SDAIA and corrective-action records. In force 14 September 2023; compliance grace period to 14 September 2024.

Taken from the Regulayer entry for this instrument, which is built against the primary text.