forumNew topic

Saudi Personal Data Protection Law: We read the executive regulations PDF — where do we even start with implementation?

RRecep K***MemberCommunity member
Joined
Mar 2023
Message
41
#1

We are a 22-person industrial equipment supplier based in Riyadh. Together with our legal counsel we went through the PDF of Saudi Arabia's new personal data protection law and the executive regulations issued by the authorities from cover to cover. The text is packed with legal obligations penalties and general frameworks, but on the operational side, it's completely unclear what we're supposed to do first thing tomorrow morning when we walk into the office.

Our annual turnover is around 6 million SAR and our database contains contact details of local clients passport or iqama copies for over 200 supplier representatives, and payroll records for our employees. The clauses in the regulations regarding records of processing activities, explicit consent forms, and cross-border data transfers are really intimidating.

What is the bare minimum documentation we must have ready on our desks before facing an audit, and at what concrete point should we begin our technical preparations?

LLale Y***MemberCommunity member
Joined
Jul 2025
Message
378
Most Helpful#2

Short answer: You should start not by drafting exhaustive legal texts, but by creating a data inventory that shows what data sits where within the company. Any consent forms or privacy agreements you draft without an up-to-date inventory and a corresponding retention policy on your desk won't hold up in an audit.

For the first phase, open a spreadsheet and fill in these four fields department by department: 1) What data are we collecting, 2) On what legal basis and for which process are we processing this data, 3) Which server or physical file holds the data, 4) After how many years will we destroy this data. Since identity documents like the passport and iqama copies you hold can be directly classified as sensitive data, you especially need to clarify their archiving purpose.

In the second step, draft your internal Personal Data Protection and Destruction Policy document as the data controller. This text is different from the privacy notice you'll put on your website; it defines who internally can access which data under what authority, as well as the destruction schedule. Also, check via the official portal whether you are required to register with the local authorities' registration system.

The third step is the technical side. If your cloud backups, accounting software, or email servers are located outside Saudi Arabia, you are subject to cross-border data transfer rules. Identify the server locations where your data is hosted and sign standard data processing addendums with your service providers. Once you complete these three steps, you'll be able to prove your good-faith compliance process in the event of an inspection.

SSimgeMember
Job title
Event organizer
Joined
May 2024
Message
88

Doki · Log management setup · 2025

#3

Sit down with HR and accounting first thing tomorrow morning. Clean out all the unnecessary scanned copies of IDs, iqamas, or driver's licenses sitting around on shared company network drives. Just deleting old job applications you no longer need will instantly cut your risk in half.

VVildan Ş***Expert
Job title
Agency Founder
Sector
Freight
Organization type
cooperative
Joined
Sep 2023
Message
113

Doki · Server maintenance contract · 2026

#4

Pay close attention to the cross-border data transfer issue. If your accounting software or CRM system is hosted in a cloud region outside the Gulf, review the transfer conditions in the executive regulations. Request encryption standards and server locations from your vendor in writing.

YYağmur P***MemberCommunity member
Joined
Jun 2025
Message
286
#5

If you get audited, the first documents an inspector will ask for are: 1) An up-to-date data inventory sheet, 2) Privacy notices and consent forms drafted for employees and suppliers, 3) Data retention and destruction procedure, 4) Information security incident response plan. If these four documents aren't on the table, the audit starts off on the wrong foot.

MMelikeExpert
Job title
E-commerce Manager
Organization type
boutique agency
Joined
Sep 2023
Message
178
#6

We're a 40-person distribution company in Riyadh. Before hiring outside consultants, we put together the inventory ourselves and it took 4 weeks. We found 3,000 old customer records and unnecessary ID scans in our CRM that hadn't been touched in 8 years. Just doing the cleanup alone took 50 hours of operational work.

CCem I***MemberCommunity member
Joined
Sep 2025
Message
4
#7

Are your clients public sector or private sector? If you bid on government tenders in Saudi Arabia regulatory compliance is audited much more strictly. Also, are your servers hosted in a local data center or with international public cloud providers?

BBurak B***Veteran
Job title
Software developer
Sector
Printing
Organization type
40-person manufacturing company
Joined
Mar 2023
Message
252
#8

don't let that thick PDF scrae you, regulatory texts are always written based on the worst-case scenario then the key is being able to document that the company is making an effort and isn't just scattering data all over the place haphazardly. just prepare the essential forms and document your steps that's enough.

note: I wrote this based on my own experience, it might not apply to everyone.

BBora A***MemberCommunity member
Joined
Sep 2024
Message
177
#9

we're in a similar boat do we also need to add a separate checkbox for the name and email coming from a basic contact form on our website? the old forms are just sitting there as is.

PPolat M***Expert
Job title
Network Administrator
Sector
Livestock
Organization type
medium-sized business
Joined
Aug 2024
Message
136

Doki · Interface design · 2024

#10

Exactly like that. If permission and scope aren't in writing, don't start that test.

Just leaving this note it might be useful.

EEfe K***Expert
Job title
Field sales representative
Sector
Chemistry
Organization type
8-person team
Joined
Apr 2024
Message
136
#11

I have no experience with personal data protection law, so Im asking. I mean if you scold false alarms, nobody will report again.

If you have questions, write them; I'll answer as best I can.

LLevent C***MemberCommunity member
Joined
May 2022
Message
193
#12

You're right. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

BBarış V***Member
Job title
Front office accounting
Sector
Food wholesale
Organization type
a company within a holding
Joined
Jan 2023
Message
2
#13

I'm a small business let me explain from my side. btw everything goes well for the first three months; problems arise in the fourth.

Correct me if I'm wrong.

UUğurMember
Job title
Outdoor advertising
Organization type
regional distributor
Joined
Feb 2024
Message
94
#14

I'd appreciate it if you shared the outcome.

GGamze G***Expert
Job title
Human Resources Manager
Sector
Security services
Organization type
medium-sized business
Joined
Apr 2022
Message
218

Doki · Phishing awareness training · 2025

#15

There's one point I'm curious about. When making decisions, write down the worst-case scenario too, not just the best.

Of course, it varies if your situation is different.

EEsra G***Member
Job title
Quality control inspector
Sector
Electrical-electronics
Organization type
boutique agency
Joined
Jan 2022
Message
178
#16

Let me summarize what's been said so far. Processes without records never improve because you don't know what to fix.

Hope this helps.

ZZeynep K***MemberCommunity member
Joined
Feb 2024
Message
41
#17

It's rare to find an explanation this clear.

YYasemin T***New memberCommunity member
Joined
Aug 2026
Message
68
#18

let me share what happened to me; it might be useful but if you get three differeent answers on a topic, the question was asked wrong.

if you have questions, write them; I'll answer as best I can.

AAleyna K***New member
Job title
Quality control inspector
Sector
Livestock
Organization type
120-person company
Joined
Jun 2026
Message
1
#19

I agree, and I'd like to emphasize that. If permission and scope aren't in writing, don't start that test.

That's all, sorry if I went on too long.

JJale G***Member
Job title
Data entry clerk
Sector
Packaging
Organization type
40-person manufacturing company
Joined
Apr 2025
Message
27
#20

let me summarize the topic, since several different answers were given. dont hesitate to ask; those who dont ask always pay more.

if I were you, I'd go this route.

This topic has been closed.The moderator marked the topic as resolved. If you have a similar issue, you can open a new topic.
New topic