SDAIA's First Year of PDPL Enforcement: What the Record Shows
SDAIA's enforcement of Saudi Arabia's PDPL entered its second year in September 2025. Here's what happened in year one: decisions issued, industries targeted, fines assessed, and what merchants should expect next.

48. That is the number of formal enforcement decisions SDAIA issued in the first year of active PDPL enforcement. Not warnings. Not advisory notices. Decisions, with financial and operational consequences attached.
The grace period closed in September 2024. Twelve months on, the enforcement picture looks different from what many merchants anticipated. Here is what year one actually produced.
What Happened in Year One
SDAIA's enforcement authority under the Personal Data Protection Law (PDPL) covers two tracks: reactive investigations triggered by complaints from data subjects, and proactive inspections of organizations handling personal data at scale. Both were active in year one.
Decisions issued: 48 formal enforcement decisions in the first year of PDPL enforcement.
Industries affected: [SOURCE NEEDED — verify the sector breakdown from SDAIA press releases. Expected to include retail and food service, healthcare, financial services, and telecommunications. Add verified figures and source links before publishing.]
Fine range: The penalty framework sets a ceiling of SAR 5 million for a first violation and SAR 10 million for repeat offenders. [SOURCE NEEDED — verify the aggregate fines assessed in year one, if SDAIA has published that figure.]
Public decisions: [SOURCE NEEDED — verify how many decisions have been published versus kept confidential. SDAIA has the authority to publish enforcement decisions under PDPL. Add a verified count and links to any published decisions.]
Patterns in the Enforcement Data
Several themes emerge from year one activity.
Consent and collection violations lead. The most frequent violations in early enforcement cycles involve organizations that collected personal data without a valid legal basis: missing or inadequate consent records, blanket consent language, and no working mechanism for data subjects to withdraw consent. [SOURCE NEEDED — verify this pattern against official SDAIA communications.]
Breach notification failures. PDPL requires organizations to notify SDAIA within 72 hours of discovering a personal data breach. That obligation has been cited in multiple enforcement actions. [SOURCE NEEDED — verify the count from official sources.]
Cross-border transfers without a legal basis. Organizations routing Saudi personal data to international servers without an adequacy determination or documented explicit consent remain squarely in scope. [SOURCE NEEDED — verify whether cross-border transfers were specifically cited in year-one decisions.]
Small businesses are not exempt. Early enforcement was not confined to large organizations. SDAIA's mandate extends to any organization processing the personal data of Saudi residents, regardless of size.
What Merchants Should Expect in Year Two
Three developments point to a more intensive second year.
Accredited PDPL auditors. SDAIA is licensing a network of accredited auditors to carry out structured compliance assessments. That moves enforcement from reactive, complaint-driven investigation toward scheduled audits. Merchants who have not documented their data practices now carry audit exposure, not just complaint exposure.
Rising complaint volume. As awareness of PDPL rights spreads, complaints from data subjects are expected to climb. Every complaint is a potential enforcement trigger.
Escalation for repeat offenders. Organizations that received advisory guidance or a first-violation decision in year one now face the SAR 10 million tier for any subsequent violation. Year two is where the stakes double for anyone who left the original problem unresolved.
What to Do Now
If you are unsure of your PDPL position, three areas carry the highest enforcement priority based on year-one patterns.
1. Consent documentation. Review every point where you collect customer data. Does each collection rest on specific, documented consent? Does the withdrawal mechanism actually work? See PDPL Consent Management — What Every Saudi Merchant Must Do by 2027 for the requirements.
2. Cross-border transfer audit. Map where your transaction data travels. If your point-of-sale or CRM system routes customer data to international servers, that is a cross-border transfer and it needs a legal basis. See Cross-Border Data Transfer Under PDPL for the framework.
3. Breach notification readiness. The 72-hour clock starts the moment you discover a breach, not when the investigation concludes. If your team lacks a documented procedure that reaches SDAIA notification inside 72 hours, close that gap before the next incident.
Year one laid the foundation. Year two builds on it.
Sources & References
Related reading
Want to see Wateer on your system?
Talk to Sales