Law / Saudi Arabia

Personal Data Protection Law, comprehensive regime and lawful basis

Royal Decree M/19 (9/2/1443H, 16 September 2021), comprehensive regime; Implementing Regulations Arts. 4, 11-12

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 14 September 2023.

A comprehensive regime rule binding public and private bodies.

As of 29 August 2026.

What it requires

  • An app that collects, uses, or discloses the personal data of an individual in Saudi Arabia must establish a lawful basis under the Personal Data Protection Law, most commonly the Data Subject's consent, following the consent mechanics set out in the Implementing Regulations.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Personal Data Protection Law is Saudi Arabia's comprehensive personal-data statute, with the Implementing Regulations supplying the operative consent-mechanics detail (Arts. 4, 11-12). Consent is the default lawful basis; other grounds are set out in the Law's Art. 6 area, not individually enumerated. A Controller/Processor structure is present.

SDAIA is the Competent Authority for most sectors (Law Art. 1(3)), with the Saudi Central Bank (SAMA) designated as the Competent Authority for its own regulated financial sector, a sector-split enforcement structure.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

official statute and Implementing Regulations text, SDAIA document library

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app