Loading Vaultize
Skip to main content

Compliance/Global/SDAIA PDPL

Forty-three articles: fifteen leave evidence in the file.

The Law makes the controller responsible for personal data processed in the Kingdom, including data about residents processed from abroad. Vaultize adds records that stay with the file.

  • Royal Decree No. M/19 of 1443H
  • In force 14 September 2023
  • Amended 27 March 2023
  • Capability mapping, not legal advice

4(5)Rights of the data subject

The right to request a Destruction of their Personal Data held by the Controller when such Personal Data is no longer needed by Data Subject, without prejudice to the provisions of Article (18) of this Law.

Vaultize Secure

  1. A

    Definitions and scope

    0 of 3

    • 1
    • 2
    • 3
  2. B

    Rights of the data subject

    1 of 1

    • 4
  3. C

    Collection, purpose and consent

    4 of 13

    • 5
    • 6
    • 7
    • 8
    • 9
    • 10
    • 11
    • 12
    • 13
    • 14
    • 15
    • 16
    • 17
  4. D

    Security, breach and destruction

    3 of 3

    • 18
    • 19
    • 20
  5. E

    Controller duties

    2 of 8

    • 21
    • 22
    • 23
    • 24
    • 25
    • 26
    • 27
    • 28
  6. F

    Transfer outside the Kingdom

    1 of 1

    • 29
  7. G

    Authority and penalties

    3 of 14

    • 30
    • 31
    • 32
    • 33
    • 34
    • 35
    • 36
    • 37
    • 38
    • 39
    • 40
    • 41
    • 42
    • 43
15of 43 articles, in 6 of 7 groups

The answer in 30 seconds

Vaultize adds file-level records to fifteen provisions across fourteen articles in six of the page's seven groups: the rights of the data subject, collection, purpose and consent, security, breach and destruction, controller duties, transfer outside the Kingdom, and the competent authority's records. Definitions and scope, consent itself, direct marketing, impact assessment, licensing and the penalties themselves sit outside a governed file, with the organisation and its counsel.

The Law in one view

Seven groups. Forty-three articles. Where file evidence lands.

The Law has no chapters. It runs in forty-three articles, numbered straight through. The seven groups below are ours, built from the article subjects in article order. Select a group to see which of its articles a governed file can evidence.

ABCDEFG

A

Definitions and scope

Articles 1 to 3. The Law's definitions, its territorial scope over data processed in the Kingdom, and its relationship to other laws and agreements that offer better protection.

Outcomes the file can evidence

None on this page.

    How Vaultize contributes
    Definitions, territorial scope and the relationship to other laws are matters for counsel. A governed file adds no evidence here.
    Evidence to retain
    None from Vaultize.

    Article by article

    What each provision asks. What the file can answer.

    Wording is quoted from SDAIA's official English translation of the Law. Longer provisions are excerpted. Each row is a capability mapping, not legal advice. Read the Law and take advice on applicability, roles and technical implementation.

    Using this page

    Where these rows fit in a PDPL programme.

    The Law has applied since 14 September 2023. The rows above are evidence for the obligations that touch documents.

    1. 1

      Confirm scope

      Articles 2 and 3. Whether the processing takes place in the Kingdom or involves residents of the Kingdom, and whether another law or agreement gives better protection.

    2. 2

      Establish lawful collection and consent

      Articles 5 to 17. The lawful bases for processing, the privacy policy and notice a controller must give, and the rules on collection, disclosure and correction.

    3. 3

      Secure and destroy the data

      Articles 18 and 19. Destroy personal data once it is no longer needed, and implement the organisational, administrative and technical measures that protect it. These rows belong here.

      Bring the fifteen rows above as evidence of the destruction and security measures Articles 18 and 19 require.

    4. 4

      Report a breach

      Article 20. Notify the competent authority of a breach, and notify the data subject when it may cause them damage or prejudice.

    5. 5

      Assess a transfer outside the Kingdom

      Article 29. The purposes and conditions that allow personal data to leave the Kingdom or be disclosed to a party outside it.

    Responsibility boundary

    Controls support compliance. They are not legal advice.

    Vaultize contributes technical measures and evidence for documents and files a controller processes under the Law. It does not decide whether the Law applies, obtain or manage a data subject's consent, assess the impact of processing, appoint a personal data protection officer, or decide whether a transfer outside the Kingdom meets Article 29 in full. This page is a capability mapping, not legal advice. Read the Law and take qualified advice before relying on it.

    “The Controller shall implement all the necessary organizational, administrative and technical measures to protect Personal Data, including during the Transfer of Personal Data, in accordance with the provisions and controls set out in the Regulations.”

    Article 19, Personal Data Protection Law of the Kingdom of Saudi Arabia (PDPL)

    A practical next step

    Bring one document a controller processes under the Law.

    We will show which articles the governed document can evidence today. We will name the owner responsible for the rest.

    Request a compliance mapping session