PDPL Enforcement in Saudi Arabia: What SDAIA's 48 Decisions Mean for Your Business

This article is for educational guidance only. SDAIA's enforcement practices, penalty amounts, and PDPL implementing regulations may change. Businesses should confirm current obligations directly through SDAIA and qualified data protection counsel. 48 PDPL enforcement decisions confirmed by SDAIA under Article...

  • October 01, 2026
  • 8Mins
Saudi professional reviews a privacy compliance checklist beside a security dashboard and Riyadh skyline.

This article is for educational guidance only. SDAIA's enforcement practices, penalty amounts, and PDPL implementing regulations may change. Businesses should confirm current obligations directly through SDAIA and qualified data protection counsel.

Cover: 48 PDPL enforcement decisions confirmed by SDAIA, with fines up to SAR 5 million.

48 PDPL enforcement decisions confirmed by SDAIA under Article 36

For the first eighteen months after Saudi Arabia's Personal Data Protection Law (PDPL) took effect, most companies treated it as a documentation exercise: a policy to draft, a clause to add to a contract, a box to check before an audit. On 16 January 2026, the Saudi Data and Artificial Intelligence Authority (SDAIA) made clear that phase is over. In an official statement carried by the Saudi Press Agency, SDAIA confirmed that its Committees for Reviewing Violations had issued 48 enforcement decisions against organizations found in breach of the PDPL over the preceding year.

This is not a projection or a warning from a law firm newsletter — it is SDAIA's own confirmed enforcement record, the first public numbers of their kind since the law's compliance grace period ended in September 2024. For compliance officers and business owners in the Kingdom, it changes the PDPL from a theoretical risk into a documented one. This guide breaks down what SDAIA actually found, what it can cost a business under Article 36, and the specific steps to take before your organization becomes decision number 49.

What SDAIA Just Confirmed

According to SDAIA's 16 January 2026 announcement, the 48 decisions were issued by its specialized Committees for Reviewing Violations, acting under the authority granted by Article 36 of the PDPL. The announcement did not name the organizations involved or disclose the specific penalty applied in each case, but it was explicit about the pattern behind the violations and the intent behind publishing the figure: to consolidate responsible data-handling practices, strengthen compliance with the law's requirements, and build public confidence in how personal data is handled across the Kingdom's digital economy.

Source: SDAIA announcement via Saudi Press Agency, 16 January 2026

Two things stand out for businesses reading this for the first time. First, this covers only the decisions SDAIA has chosen to disclose in aggregate — it does not include warnings, corrective orders, or cases still under review, so the real volume of enforcement activity is almost certainly higher than 48. Second, the announcement frames this as an annual disclosure, which means every review cycle from here forward will produce a public benchmark that regulators, insurers, and business partners can point to when asking how a company's data practices compare.

The Four Violation Categories Behind the 48 Decisions

SDAIA grouped the confirmed violations into four categories. None of them describe a novel or unusual scenario — they describe day-to-day data handling that most Saudi businesses perform without a documented legal basis or a consent record to support it.

Violation category

What it typically looks like in practice

Unlawful collection or processing

Collecting personal data (customer forms, HR records, CCTV, loyalty programs) without a documented legal basis under the PDPL, or processing it beyond the purpose it was collected for

Unauthorized disclosure

Sharing personal data with a third party, affiliate, or overseas parent company without the data subject's consent or a valid legal exception

Failure to implement safeguards

Missing or inadequate organizational, administrative, and technical measures — no access controls, no breach-response process, no documented risk assessment

Marketing without consent

Sending promotional SMS, email, or app notifications without prior, specific consent — flagged as “widespread” in retail, telecom, and financial services

Source: SDAIA announcement via Saudi Press Agency, 16 January 2026

Four PDPL violations: unlawful processing, unauthorized disclosure, missing safeguards, and marketing without consent.

The four violation categories behind SDAIA's 48 PDPL enforcement decisions

If your organization cannot immediately point to the documented legal basis for its three or four largest personal-data processing activities, you are exposed to the first category above — and it is the one SDAIA lists first.

How Much a PDPL Violation Can Cost You

Article 36 of the PDPL gives SDAIA's review committees the power to issue warnings and financial penalties. Under the law, an administrative fine can reach SAR 5,000,000 per violation, and the penalty can be increased — doubled, in the case of repeat violations within the applicable period — where the committee finds the breach was serious or the organization failed to remedy an earlier finding.

Penalty tier

Basis

Warning

First-instance or lower-severity violations, at the committee's discretion

Administrative fine — up to SAR 5,000,000

Confirmed violation of PDPL obligations under Article 36

Increased fine for repeat violations

Applied where the same organization is found in breach again within the relevant period

Remedial order

Requirement to correct the underlying practice, independent of any fine issued

Sources: Article 36 of the Personal Data Protection Law, as summarized in law firm coverage including A&O Shearman and Al Tamimi & Company; enforcement figures per the SDAIA/SPA announcement of 16 January 2026.

SDAIA has not disclosed individual penalty amounts from the 48 decisions, which means businesses cannot yet benchmark “typical” fines against a real case. That absence of transparency should be read as a reason for more caution, not less — the ceiling in the law is the number a committee is legally entitled to apply, and the four violation categories above show the committees are actively using their authority rather than treating it as symbolic.

From Warning to Repeat Offense: How Enforcement Escalates

  1. Initial finding. A complaint, an audit, or a data breach notification brings a practice to SDAIA's attention. This is often triggered by an individual exercising their data subject rights and receiving no response.

  2. Review by committee. The Committees for Reviewing Violations assess the evidence against the four categories above and decide whether the case merits a warning, a fine, or a remedial order.

  3. Decision and (in aggregate) disclosure. The organization receives its ruling directly; SDAIA may later reference the case, without naming it, in aggregate enforcement statistics of the kind published in January 2026.

  4. Remediation window. Where a remedial order is issued, the organization must correct the practice within the period specified. Failure to do so, or a fresh violation, is what triggers the increased, repeat-violation penalty tier.

  5. Repeat violation. A second confirmed breach within the relevant period exposes the organization to the higher penalty tier under Article 36, alongside continued regulatory attention.

PDPL Enforcement Readiness Checklist

  • Map every personal-data processing activity in the business and document its specific legal basis under the PDPL — not a general privacy policy, but a basis for each activity.

  • Confirm that any sharing of personal data with third parties, affiliates, or a parent company outside the Kingdom has documented consent or a valid legal exception, including for cross-border transfers.

  • Review marketing and customer-communication workflows for prior, specific consent before any promotional SMS, email, or push notification is sent.

  • Verify that organizational, administrative, and technical safeguards are documented — access controls, a breach-response plan, and a current risk assessment, not just a policy on file.

  • Confirm your Data Protection Officer is appointed (where required) and registered on SDAIA's National Data Governance Platform.

  • Establish a process to respond to data subject rights requests (access, correction, deletion) within the timeframes the PDPL requires, so an unanswered request does not become the trigger for a review.

  • Log every data-handling decision and remediation step in writing, so that if a review does occur, the organization can demonstrate active compliance rather than starting its response from zero.

Seven-point PDPL readiness checklist covering legal basis, consent, safeguards, DPO, rights, and compliance logs.

Seven checks to complete before your next SDAIA review

Turning this checklist into documented practice is what SCI's Data Protection and Privacy Compliance course walks through step by step — from mapping a legal basis for each processing activity to running a Data Protection Impact Assessment — for teams that would rather follow structured guidance than build the process from scratch.

Conclusion

SDAIA's 48 enforcement decisions are the clearest signal yet that the PDPL's compliance grace period is over in practice, not just on paper. The violations behind those decisions are not exotic — they are the everyday data handling most Saudi businesses do without a documented legal basis, a consent record, or a safeguard in place. The penalty structure under Article 36 gives committees room to escalate quickly for repeat or serious findings, and the annual disclosure pattern SDAIA has now established means next year's number, and the story behind it, will be watched closely. Businesses that treat this as a prompt to audit their own data practices now — rather than a statistic about someone else's fine — are the ones least likely to appear in next year's total.

 

Frequently Asked Questions

Find quick answers to frequently asked questions. Can't find what you're looking for?

SDAIA confirmed that its Committees for Reviewing Violations issued 48 enforcement decisions against organizations found in breach of the PDPL during the preceding year, publicized via the Saudi Press Agency on 16 January 2026.

Four categories: unlawful collection or processing of personal data, unauthorized disclosure to third parties, failure to implement adequate safeguards, and sending marketing communications without consent.

Under Article 36, an administrative fine can reach SAR 5,000,000 per violation, with an increased penalty where the organization is found in repeat violation within the relevant period.

No. The 16 January 2026 announcement gave the aggregate number of decisions and the categories of violation, but did not name the organizations involved or disclose individual penalty amounts.