Law / Saudi Arabia

Saudi Arabia

9 of 14 named instruments researched to a stage, across three of the six areas of law we track: 9 in force. As of 16 September 2026.

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 3
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (196 words)

Saudi Arabia's Personal Data Protection Law (Royal Decree No. M/19 of 9/2/1443H, 16 September 2021) is a three-instrument regime, all read at primary source directly from SDAIA's own document library, untruncated: the Law itself, Implementing Regulations that carry the operative consent-mechanics and destruction-duty detail, and a standalone Regulation on Personal Data Transfer Outside the Kingdom.

The Law folds biometric data directly into its Sensitive Data definition (Art. 1(11): "biometric or Genetic Data for the purpose of identifying the person"), with no separate "Biometric Data" definition and no worked example list, so a service creating an identity-linked voiceprint or faceprint needs the Data Subject's explicit consent under the Implementing Regulations.

The SDAIA-served text of the Law does not carry an amendment-history header in the pages read, so it is treated here as SDAIA's current, live consolidated text rather than an independently diffed 2021-versus-2023 comparison. Cross-border transfer is gated by a national-security-plus-adequacy-plus-minimization structure (Law Art. 29), operationalized by the 2023-era Transfer Regulation, the strictest posture read across the Gulf jurisdictions in this batch.

Enforcement is dual-track: criminal prosecution for unlawful disclosure of Sensitive Data and administrative fines for other violations; no private civil right of action was found.

Breach notification

Personal Data Protection Law, breach notification

Royal Decree No. M/19, Art. 20official statute text, SDAIA document library

In force since 14 September 2023. Binds public and private bodies.

What this law does

Art. 20 requires the Controller to notify the Competent Authority upon knowing of any breach, damage, or illegal access to personal data, in accordance with the Implementing Regulations, and separately to notify the Data Subject of any breach that would cause damage to their data or prejudice their rights and interests.

No fixed notification window (hours or days) is stated in the Law itself; the specific timeline is deferred to the Implementing Regulations, whose exact notification-timeline article was not individually isolated.

What it requires

Comprehensive regime

Personal Data Protection Law, comprehensive regime and lawful basis

Royal Decree M/19 (9/2/1443H, 16 September 2021), comprehensive regime; Implementing Regulations Arts. 4, 11-12official statute and Implementing Regulations text, SDAIA document library

In force since 14 September 2023. Binds public and private bodies.

What this law does

The Personal Data Protection Law is Saudi Arabia's comprehensive personal-data statute, with the Implementing Regulations supplying the operative consent-mechanics detail (Arts. 4, 11-12). Consent is the default lawful basis; other grounds are set out in the Law's Art. 6 area, not individually enumerated. A Controller/Processor structure is present.

SDAIA is the Competent Authority for most sectors (Law Art. 1(3)), with the Saudi Central Bank (SAMA) designated as the Competent Authority for its own regulated financial sector, a sector-split enforcement structure.

What it requires

Cross border transfer

Personal Data Protection Law, cross-border transfer

Royal Decree No. M/19, Art. 29; Regulation on Personal Data Transfer Outside the Kingdomofficial statute and Transfer Regulation text, SDAIA document library

In force since 14 September 2023. Binds public and private bodies.

What this law does

Law Art. 29 permits a Controller to transfer personal data outside the Kingdom only for one of four enumerated purposes (international-agreement obligation, Kingdom interests, a Data Subject's own contractual obligation, or a Regulations-specified purpose), and only where the transfer does not prejudice national security or Kingdom vital interests, an adequate level of protection at least equivalent to the Law's own applies per a Competent Authority assessment, and the transfer is limited to the minimum data needed.

The standalone Regulation on Personal Data Transfer Outside the Kingdom operationalizes this with defined "Appropriate Safeguards" the competent authority may impose where an exemption from the adequacy requirement is granted, and an "Operational Processes" basis for data tied to a controller's own internal operations.

No provision compelling in-Kingdom data storage as a default rule was found; this is a multi-factor national-security-and-adequacy gate rather than either a blanket ban or an open transfer policy, more restrictive in structure than the UAE's or Jordan's equivalent provisions in this batch.

The original sdaia.gov.sa path for the Regulation 404s; it is now served from SDAIA's Digital Government Platform, and the "Appropriate Safeguards" and "Operational Processes" quotations above are confirmed against that working URL.

What it requires

Enforcement supervision

Personal Data Protection Law, enforcement and penalties

Royal Decree No. M/19, Arts. 35-36official statute text, SDAIA document library

In force since 14 September 2023. Binds public and private bodies.

What this law does

Art. 35 imposes criminal penalties, imprisonment up to two years or a fine up to SAR 3,000,000, or both, doubled on recidivism, on any individual who discloses or publishes Sensitive Data (including identifying biometric data) with intent to harm the Data Subject or gain personal benefit, prosecuted by the Public Prosecution before the competent court. Art. 36 sets administrative fines up to SAR 5,000,000, doubled on repeat violation, for other violations.

No civil private-right-of-action provision letting a Data Subject sue a Controller directly for damages was found in the sections read; this is treated as not established rather than a confirmed negative pending a full read of any general civil-liability article.

What it requires

Sensitive categories

Personal Data Protection Law, sensitive data and biometric processing

Royal Decree No. M/19, Art. 1(11); Implementing Regulations Arts. 8, 11(2)(a)official statute and Implementing Regulations text, SDAIA document library

In force since 14 September 2023. Binds public and private bodies.

What this law does

Art. 1(11) folds "biometric... Data for the purpose of identifying the person" directly into the Sensitive Data definition, with no standalone "Biometric Data" term and no worked-example list, unlike the UAE, Oman, and ADGM statutes. Implementing Regulations Art. 11(2)(a) requires explicit consent whenever processing involves Sensitive Data, reaching identifying biometric data by the Art. 1(11) definition. No modality-specific (voice or face) language was found.

Implementing Regulations Art. 8 requires the Controller to destroy Personal Data on enumerated grounds (purpose fulfilled, consent withdrawn), notifying every party the data was disclosed to and destroying all system copies; this is the general destruction duty applying to biometric data as Sensitive Data, with no biometric-specific retention ceiling found.

What it requires

Scraping law3 instruments, 3 in force

Research summary (218 words)

Saudi Arabia has no scraping-specific statute, so general law governs each dimension separately, and confirmed findings exist for only two of the eight research dimensions. The Anti-Cyber Crime Law (Royal Decree No. M/17, 8 Rabi I 1428H, 26 March 2007), which would ordinarily govern unauthorized access to a computer system, has no primary text located, so no computer_misuse finding is recorded.

The Copyright Law (Royal Decree No. M/41, 2003, as amended 2018) creates no text-and-data-mining or other exception reaching automated collection or model training beyond its Art. 15 exceptions (personal use, quotation, education, and similar narrow uses), and protects a database only as a compilation where its selection or arrangement is creative, conferring no sui generis database right.

The Personal Data Protection Law (Royal Decree No. M/19, 2021) does not exempt publicly available personal data from its scope, but Arts. 10 and 15 both list a Data Subject's personal data already being publicly available, or having been collected from a publicly available source, as one of several grounds on which a Controller may collect, repurpose, or disclose it without the Data Subject's consent; data collected on this ground remains subject to the Law's other duties (purpose limitation, security, breach notification, data subject rights).

No terms-of-service enforceability doctrine, unfair-competition or trespass doctrine, or robots.txt legal-weight provision has been located.

Copyright and text and data mining (TDM)

Copyright Law, exceptions article and absence of a text-and-data-mining exception

Royal Decree No. M/41, Art. 15 exceptions, no text-and-data-mining exception (2 Rajab 1424H, 30 August 2003)official Copyright Law text, WIPO Lex consolidated version

In force. Binds public and private bodies.

What this law does

Article 15 lists eleven enumerated uses of a copyrighted work that are lawful without the copyright owner's permission. The first of them is personal use, excluding computer software and audio-visual works; others include quotation with attribution and educational use.

None of the eleven reaches reproduction for training an AI or machine-learning model, and no text-and-data-mining opt-out or opt-in mechanism was found elsewhere in the sections located, so training a model on scraped Saudi-copyrighted text rests on none of the Law's own exceptions.

What it requires

Database right

Copyright Law, database compilations and absence of a sui generis right

Royal Decree No. M/41, Art. 3(5) database compilations, no sui generis right (2 Rajab 1424H, 30 August 2003)official Copyright Law text, WIPO Lex consolidated version

In force. Binds public and private bodies.

What this law does

Article 3(5) protects a database, whether mechanically readable or readable in any other manner, as a derived work only where it is creative as to the selection or arrangement of its contents, the same creativity-based standard the article applies to encyclopedias, anthologies, and folklore compilations.

No separate sui generis or producer's database right, of the kind the European Union's Database Directive creates, was found in the sections located; a non-creative, merely comprehensive database compiled by a scraper's target falls outside this protection.

What it requires

Personal data

Personal Data Protection Law, publicly available source ground

Royal Decree No. M/19, Arts. 10, 15 publicly available source ground (9/2/1443H, 16 September 2021)official Personal Data Protection Law text, SDAIA document library

In force. Binds public and private bodies.

What this law does

The Personal Data Protection Law does not exempt publicly available personal data from its scope. Article 10 lists the Personal Data already being publicly available, or having been collected from a publicly available source, as one of several grounds on which a Controller may collect it from a source other than the Data Subject or repurpose it without the Data Subject's consent. Article 15 lists the same ground for disclosing Personal Data.

Personal data scraped from a publicly available Saudi source therefore does not need the Data Subject's consent on this specific ground, but it remains subject to the Law's other duties, including purpose limitation, accuracy, security, breach notification, and the Data Subject's rights. Article 43 provides that the Law comes into force 720 days after its Official Gazette publication date; no source located states that publication date, so this Law's specific commencement day is not confirmed.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (236 words)

Saudi Arabia's Copyright Law (Royal Decree No. M/41, 2 Rajab 1424H, 30 August 2003, as amended by Council of Ministers Decision No. 536 of 19 Shawwal 1439H, 3 July 2018) permits quoting passages from a published work in another work, including journalistic summaries abstracted from newspapers and periodicals, without the copyright owner's permission, subject to source and author attribution and to the quotation being consistent with established conventions and within the limits justified by its purpose (Art. 15(2)).

The Law creates related rights for performers, producers of audio recordings, and broadcasting organizations, but none of the provisions located create a press-publisher neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 establishes, and no compelled platform-to-publisher bargaining regime was located.

No reported Saudi decision addressing hyperlinking, framing, hot-news misappropriation, or a text-and-data-mining opt-out has been located, and the Law's exceptions article carries no machine-readable reservation mechanism.

A new Copyright Law (reported citation: Royal Decree No. M/169 of 14/08/1447H, 13 February 2026), approved by the Council of Ministers on 27 January 2026 and published in the Official Gazette Umm Al-Qura, has been reported by commentary to introduce an exception permitting reproduction of lawfully published works for developing AI products and algorithms, taking effect approximately 180 days after Gazette publication; no primary Official Gazette or Bureau of Experts text confirming this exception's wording has been located, so no instrument is recorded for it here.

Snippet reproduction

Copyright Law, quotation and journalistic-summary exception

Royal Decree No. M/41 Art. 15(2) quotation and journalistic-summary exception (2 Rajab 1424H, 30 August 2003), amended by Council of Ministers Decision No. 536 (19 Shawwal 1439H, 3 July 2018)official Copyright Law text, WIPO Lex consolidated version

In force. Binds public and private bodies.

What this law does

Article 15(2) permits quoting passages from a copyrighted work, in its original language or in translation, in another work without the copyright owner's permission, and states this also applies to journalistic summaries abstracted from newspapers and periodicals, provided the quotation is consistent with established conventions and within the limits justified by its purpose, and that the source and the author's name are mentioned.

Related rights for performers, producers of audio recordings, and broadcasting organizations exist elsewhere in the Law (Arts. 9, 18-19), but none of the provisions located create a press-publisher neighbouring right or a compelled platform-to-publisher bargaining regime reaching a news aggregator. No text-and-data-mining opt-out mechanism and no reported case on hyperlinking, framing, or hot-news misappropriation was located.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.