Your Thermal Receipt Is a PDPL Liability You Never Signed Up For
Every thermal receipt carrying a customer name or phone number is personal data you no longer control, and enforcement activity is growing. Penalties under the PDPL can reach SAR 5 million.

Every thermal receipt that leaves your store carrying a customer's name, phone number, or loyalty ID is a piece of personal data you no longer control. It sits in a pocket, a shopping bag, a restaurant table, or on the pavement. The Personal Data Protection Law applies to that data from the moment it is collected, and it does not stop applying because the data now lives on a slip of paper you printed.
SDAIA has issued 48 enforcement decisions since the grace period ended in September 2024. Fines reach SAR 5 million. Repeat violations reach SAR 10 million. The 72-hour breach notification requirement means the clock starts the moment a customer's data is exposed, whether or not you are aware of it.
What counts as personal data on a thermal receipt
Saudi Arabia's Personal Data Protection Law (PDPL, Law No. M/19) defines personal data as any information relating to an identified or identifiable natural person. A thermal receipt triggers PDPL obligations the moment it prints any of the following:
A customer's name
A phone number
A loyalty programme identifier tied to an individual
The data minimization principle in PDPL requires organizations to collect and process only the personal data necessary for the stated purpose. Printing a customer's name on a slip of paper they may drop in the street is not data minimization. It is the opposite.
The breach exposure no one discusses
A thermal receipt is physically insecure by design. There is no access control. There is no encryption. There is no deletion mechanism. Once printed, the data on that receipt is available to anyone who picks it up, including competitors, data aggregators, and people whose interest in a customer's purchase history is not benign.
PDPL's breach notification requirement, 72 hours to notify SDAIA and 5 days to notify affected individuals, assumes the organization knows a breach has occurred. With thermal receipts, it usually does not. A customer drops a receipt. A table gets cleared. A slip blows off the counter. None of these events trigger internal incident response, yet under PDPL they may qualify as unauthorized disclosure of personal data.
The gap between what PDPL requires and what thermal receipt operations actually deliver is not a technicality. It is a compliance posture built on the assumption that regulators will not look, auditors will not ask, and customers will not complain.
That assumption is getting harder to defend.
The Saudi store pattern
Saudi food and beverage and retail operations typically enroll customers in loyalty programmes at the point of sale. The enrollment capture, usually a name and a phone number, then prints on every subsequent receipt as the customer identifier. The same data collected to build the customer relationship is the data exposed on every transaction slip.
SDAIA is now licensing accredited PDPL auditors. The auditing phase has begun, not just the enforcement phase. Merchants who have not addressed personal data exposure at the point of sale are running out of time to argue that they did not know.
What Wateer does instead
Wateer issues every receipt digitally. No personal data printed on paper, no uncontrolled copies leaving the premises, and every transaction tied to a verified digital record with a full audit trail. You inherit PDPL compliance at the receipt layer from the moment you integrate.
Sources & References
Related reading
Want to see Wateer on your system?
Talk to Sales