Personal Data Protection Law, enforcement and penalties
Royal Decree No. M/19, Arts. 35-36
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 14 September 2023.
An enforcement supervision rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app operating in Saudi Arabia must not disclose or publish an individual's Sensitive Data, including identifying biometric data, in violation of the Law, since doing so with intent to harm the Data Subject or gain personal benefit is a criminal offense; other violations are subject to administrative fines up to SAR 5,000,000.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Art. 35 imposes criminal penalties, imprisonment up to two years or a fine up to SAR 3,000,000, or both, doubled on recidivism, on any individual who discloses or publishes Sensitive Data (including identifying biometric data) with intent to harm the Data Subject or gain personal benefit, prosecuted by the Public Prosecution before the competent court. Art. 36 sets administrative fines up to SAR 5,000,000, doubled on repeat violation, for other violations.
No civil private-right-of-action provision letting a Data Subject sue a Controller directly for damages was found in the sections read; this is treated as not established rather than a confirmed negative pending a full read of any general civil-liability article.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
official statute text, SDAIA document library
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.