Personal Data Protection Law, breach notification
Royal Decree No. M/19, Art. 20
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 14 September 2023.
A breach notification rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app that suffers a breach, damage, or illegal access affecting the personal data of an individual in Saudi Arabia must notify the Competent Authority upon knowing of the breach, and must separately notify the Data Subject where the breach would cause damage to their data or prejudice their rights and interests, following the Implementing Regulations' procedure.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Art. 20 requires the Controller to notify the Competent Authority upon knowing of any breach, damage, or illegal access to personal data, in accordance with the Implementing Regulations, and separately to notify the Data Subject of any breach that would cause damage to their data or prejudice their rights and interests.
No fixed notification window (hours or days) is stated in the Law itself; the specific timeline is deferred to the Implementing Regulations, whose exact notification-timeline article was not individually isolated.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
Read the law
official statute text, SDAIA document library
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.