forumNew topic

How should we clean three years of customer data before an audit under the Saudi personal data protection law?

LLevent A***MemberCommunity member
Joined
Feb 2022
Message
7
#1

We have been operating in the commercial kitchen equipment and technical service sector out of Riyadh for three years. Our system contains roughly 12,000 customer records across Saudi Arabia, including company names, commercial registration numbers, mobile numbers, locations, and billing histories. To date, this data has been stored in cloud spreadsheets and a basic order management app; candidly, we never collected explicit data processing consent, gathering it merely as part of doing business.

The recent increase in regulatory enforcement and corporate audits under the Saudi Personal Data Protection Law has us worried. Operationally, we don't know how to categorize this three-year backlog of data and bring it onto solid legal ground. We have hundreds of companies on file whose contracts ended long ago, yet their records still sit in our spreadsheets.

What concrete steps should we take to bring this three-year historical customer data into compliance with Saudi data protection regulations before an official audit hits? How should we destroy expired data, and how do we properly document consent?

OOrhan K***MemberCommunity member
Joined
May 2023
Message
83
Most Helpful#2

Short answer: You need to map and categorize your three-year data immediately, securely deleting or anonymizing any marketing data from expired contracts that lacks a statutory retention mandate. You must collect compliant explicit consent from active clients, while tax and invoicing records can simply be moved to a secured archive for the statutory retention period required by local commercial law.

Manage compliance across four stages: 1) Build a Data Inventory: List every data type stored in your spreadsheets and ordering software. Distinguish between what is required for statutory invoicing compliance versus what is kept purely for quoting or marketing. 2) Establish Legal Bases: Tax and commercial laws require keeping invoice details for a mandatory period; no separate consent is required for these, though access must be restricted. However, phone numbers or emails of leads who received a quote but haven't purchased in two years cannot be held without marketing consent. 3) Secure Disposal and Logging: Purge customer records that have expired or lack a legal basis. Document this internally with an audit log detailing the date and the authorized personnel who executed the deletion. 4) Refresh Consent: Update your records by sending a formal privacy notice via email or SMS to your active client roster.

Verify that your cloud servers are hosted within Saudi Arabia or in an approved jurisdiction. Implement role-based access controls immediately so unauthorized staff cannot download your 12,000-contact client list to a desktop in one click.

ZZehra K***MemberCommunity member
Joined
Mar 2025
Message
86
#3

Under the Saudi Personal Data Protection Law, your company must draft a formal Privacy Policy and integrate explicit privacy notices into your website and quote forms. We strongly recommend establishing written procedures for every action you take as a data controller.

BBurcu A***MemberCommunity member
Joined
May 2024
Message
146
#4

Cloud spreadsheets are your biggest audit risk because you can't track who exported what or when. Make the sheet read-only immediately, revoke permissions, and switch to a closed system with database logging while enforcing two-factor authentication.

SSinan K***Member
Job title
Country Manager
Sector
Construction
Organization type
workshop
Joined
Jan 2024
Message
335
#5

Follow this order when cleaning up your marketing data: 1) Separate passive companies that haven't placed an order in the last two years, 2) Delete non-business personal phone numbers and emails from the sheet, 3) Send a privacy notice to active customers via SMS, 4) Move the invoice archive to a separate encrypted folder.

AAlper C***Expert
Job title
Customer service representative
Sector
Software
Organization type
cooperative
Joined
Dec 2023
Message
74
#6

Out of the 12,000 registered customers, how many are corporate entities and how many are sole proprietorships? Under the law, B2B corporate billing info carries a completely different weight compared to directly identifiable personal data like mobile numbers and location.

note: I wrote this based on my own experience, it might not apply to everyone.

GGamze D***Veteran
Job title
Courier coordinator
Sector
Food wholesale
Organization type
300-person organization
Joined
Jan 2024
Message
209
#7

While prepping for a similar audit process, we realized that out of our 8,500-entry B2B customer list, almost 4,000 were outdated or duplicate records. We purged the unnecessary data and only sent privacy notices to the 4,500 active contacts, saved ourselves a huge headache.

PPınar G***MemberCommunity member
Joined
Jul 2024
Message
37
#8

Everyone panics as if fines will be slapped instantly but regulatory bodies usually prioritize companies that have suffered an actual data breach or received complaints. Still, keeping exposed data in a spreadsheet is practically begging for employee leaks; lock that down first.

IIrmak B***Member
Job title
Customer service representative
Sector
Machinery manufacturing
Organization type
sole proprietorship
Joined
Mar 2024
Message
155

Doki · Brand identity · 2025

#9

first thing we did was lock down those open excel sheets. anyway if an employee takes that list to a competitor tomorrow, you'll be in deep trouble under both data privacy laws and trade secret regulations.

FFerhat A***Member
Job title
Board member
Sector
Advertising and promotion
Organization type
20-person company
Joined
Jun 2024
Message
155
#10

The most actionable step you can take first thing tomorrow: revoke all staff permissions to download the customer list to their local machines. Designate a single authorized point person and permanently delete all other local copies from your systems.

NNuri Ç***Veteran
Job title
Site Manager
Sector
Software
Organization type
cooperative
Joined
Jan 2026
Message
20
#11

There's also a measurement aspect to this. When making decisions write down the worst-case scenario too, not just the best.

Trying to do this alone is the most expensive way. Just leaving this note it might be useful.

ÜÜmit A***Member
Job title
Store associate
Sector
Automotive aftermarket
Organization type
sole proprietorship
Joined
Nov 2024
Message
227
#12

good call startig this thread but mistakes made on the Saudi personal data protection law side are usually reversible but expensive.

just because everyonne does it doesn't mean it's right and if I were you I'd go this route.

VVeli T***MemberCommunity member
Joined
Oct 2023
Message
152
#13

Same here.

EEbru K***MemberCommunity member
Joined
Aug 2025
Message
113
#14

I felt relieved reading this answer, so it's not just me. Everything goes well for the first three months; problems arise in the fourth.

This is my opinion, I'm not claiming it's absolute truth.

HHasan E***MemberCommunity member
Joined
Aug 2022
Message
333
#15

Yes, that's exactly how it is with Saudi personal data protection law. Security isn't absolute; it's about making attacks not worth the effort.

OOkan T***VeteranCommunity member
Joined
Jan 2023
Message
7
#16

Same here. If it's your first time, start small; scaling comes later.

Good luck with that.

ÖÖzgür C***MemberCommunity member
Joined
Feb 2026
Message
32
#17

I'm writing this so you don't make the same mistake... Start with a small trial; don't commit to everything at once.

Correct me if I'm wrong.

OOğuzMember
Job title
Former founder
Organization type
early-stage startup
Joined
Aug 2023
Message
76
#18

The opposite happened to me, that's why I'm writing. Forgotten test environments are more often the entry point than live systems.

The answer varies greatly by industry; there is no one-size-fits-all rule. Good luck with that.

GGamze K***MemberCommunity member
Joined
Oct 2022
Message
3
#19

Exactly, and not many people know this. When we decide without measuring, we always end up in the same place.

I'm also curious if anyone does it differently.

AAyşe A***Member
Job title
Customer service representative
Sector
Automotive aftermarket
Organization type
chain store
Joined
Feb 2023
Message
29
#20

Thanks, that was the answer I was looking for.

Reply