This article is for educational guidance only. SDAIA's enforcement practices, penalty amounts, and PDPL implementing regulations may change. Businesses should confirm current obligations directly through SDAIA and qualified data protection counsel.

48 PDPL enforcement decisions confirmed by SDAIA under Article 36
For the first eighteen months after Saudi Arabia's Personal Data Protection Law (PDPL) took effect, most companies treated it as a documentation exercise: a policy to draft, a clause to add to a contract, a box to check before an audit. On 16 January 2026, the Saudi Data and Artificial Intelligence Authority (SDAIA) made clear that phase is over. In an official statement carried by the Saudi Press Agency, SDAIA confirmed that its Committees for Reviewing Violations had issued 48 enforcement decisions against organizations found in breach of the PDPL over the preceding year.
This is not a projection or a warning from a law firm newsletter — it is SDAIA's own confirmed enforcement record, the first public numbers of their kind since the law's compliance grace period ended in September 2024. For compliance officers and business owners in the Kingdom, it changes the PDPL from a theoretical risk into a documented one. This guide breaks down what SDAIA actually found, what it can cost a business under Article 36, and the specific steps to take before your organization becomes decision number 49.
What SDAIA Just Confirmed
According to SDAIA's 16 January 2026 announcement, the 48 decisions were issued by its specialized Committees for Reviewing Violations, acting under the authority granted by Article 36 of the PDPL. The announcement did not name the organizations involved or disclose the specific penalty applied in each case, but it was explicit about the pattern behind the violations and the intent behind publishing the figure: to consolidate responsible data-handling practices, strengthen compliance with the law's requirements, and build public confidence in how personal data is handled across the Kingdom's digital economy.
Source: SDAIA announcement via Saudi Press Agency, 16 January 2026
Two things stand out for businesses reading this for the first time. First, this covers only the decisions SDAIA has chosen to disclose in aggregate — it does not include warnings, corrective orders, or cases still under review, so the real volume of enforcement activity is almost certainly higher than 48. Second, the announcement frames this as an annual disclosure, which means every review cycle from here forward will produce a public benchmark that regulators, insurers, and business partners can point to when asking how a company's data practices compare.
The Four Violation Categories Behind the 48 Decisions
SDAIA grouped the confirmed violations into four categories. None of them describe a novel or unusual scenario — they describe day-to-day data handling that most Saudi businesses perform without a documented legal basis or a consent record to support it.
|
Violation category |
What it typically looks like in practice |
|
Unlawful collection or processing |
Collecting personal data (customer forms, HR records, CCTV, loyalty programs) without a documented legal basis under the PDPL, or processing it beyond the purpose it was collected for |
|
Unauthorized disclosure |
Sharing personal data with a third party, affiliate, or overseas parent company without the data subject's consent or a valid legal exception |
|
Failure to implement safeguards |
Missing or inadequate organizational, administrative, and technical measures — no access controls, no breach-response process, no documented risk assessment |
|
Marketing without consent |
Sending promotional SMS, email, or app notifications without prior, specific consent — flagged as “widespread” in retail, telecom, and financial services |
Source: SDAIA announcement via Saudi Press Agency, 16 January 2026

The four violation categories behind SDAIA's 48 PDPL enforcement decisions
If your organization cannot immediately point to the documented legal basis for its three or four largest personal-data processing activities, you are exposed to the first category above — and it is the one SDAIA lists first.
How Much a PDPL Violation Can Cost You
Article 36 of the PDPL gives SDAIA's review committees the power to issue warnings and financial penalties. Under the law, an administrative fine can reach SAR 5,000,000 per violation, and the penalty can be increased — doubled, in the case of repeat violations within the applicable period — where the committee finds the breach was serious or the organization failed to remedy an earlier finding.
|
Penalty tier |
Basis |
|
Warning |
First-instance or lower-severity violations, at the committee's discretion |
|
Administrative fine — up to SAR 5,000,000 |
Confirmed violation of PDPL obligations under Article 36 |
|
Increased fine for repeat violations |
Applied where the same organization is found in breach again within the relevant period |
|
Remedial order |
Requirement to correct the underlying practice, independent of any fine issued |
Sources: Article 36 of the Personal Data Protection Law, as summarized in law firm coverage including A&O Shearman and Al Tamimi & Company; enforcement figures per the SDAIA/SPA announcement of 16 January 2026.
SDAIA has not disclosed individual penalty amounts from the 48 decisions, which means businesses cannot yet benchmark “typical” fines against a real case. That absence of transparency should be read as a reason for more caution, not less — the ceiling in the law is the number a committee is legally entitled to apply, and the four violation categories above show the committees are actively using their authority rather than treating it as symbolic.
From Warning to Repeat Offense: How Enforcement Escalates
-
Initial finding. A complaint, an audit, or a data breach notification brings a practice to SDAIA's attention. This is often triggered by an individual exercising their data subject rights and receiving no response.
-
Review by committee. The Committees for Reviewing Violations assess the evidence against the four categories above and decide whether the case merits a warning, a fine, or a remedial order.
-
Decision and (in aggregate) disclosure. The organization receives its ruling directly; SDAIA may later reference the case, without naming it, in aggregate enforcement statistics of the kind published in January 2026.
-
Remediation window. Where a remedial order is issued, the organization must correct the practice within the period specified. Failure to do so, or a fresh violation, is what triggers the increased, repeat-violation penalty tier.
-
Repeat violation. A second confirmed breach within the relevant period exposes the organization to the higher penalty tier under Article 36, alongside continued regulatory attention.
PDPL Enforcement Readiness Checklist
-
Map every personal-data processing activity in the business and document its specific legal basis under the PDPL — not a general privacy policy, but a basis for each activity.
-
Confirm that any sharing of personal data with third parties, affiliates, or a parent company outside the Kingdom has documented consent or a valid legal exception, including for cross-border transfers.
-
Review marketing and customer-communication workflows for prior, specific consent before any promotional SMS, email, or push notification is sent.
-
Verify that organizational, administrative, and technical safeguards are documented — access controls, a breach-response plan, and a current risk assessment, not just a policy on file.
-
Confirm your Data Protection Officer is appointed (where required) and registered on SDAIA's National Data Governance Platform.
-
Establish a process to respond to data subject rights requests (access, correction, deletion) within the timeframes the PDPL requires, so an unanswered request does not become the trigger for a review.
-
Log every data-handling decision and remediation step in writing, so that if a review does occur, the organization can demonstrate active compliance rather than starting its response from zero.

Seven checks to complete before your next SDAIA review
Turning this checklist into documented practice is what SCI's Data Protection and Privacy Compliance course walks through step by step — from mapping a legal basis for each processing activity to running a Data Protection Impact Assessment — for teams that would rather follow structured guidance than build the process from scratch.
Conclusion
SDAIA's 48 enforcement decisions are the clearest signal yet that the PDPL's compliance grace period is over in practice, not just on paper. The violations behind those decisions are not exotic — they are the everyday data handling most Saudi businesses do without a documented legal basis, a consent record, or a safeguard in place. The penalty structure under Article 36 gives committees room to escalate quickly for repeat or serious findings, and the annual disclosure pattern SDAIA has now established means next year's number, and the story behind it, will be watched closely. Businesses that treat this as a prompt to audit their own data practices now — rather than a statistic about someone else's fine — are the ones least likely to appear in next year's total.


