Compliance software · Saudi Arabia

PDPL and cyber security compliance software for Saudi businesses

Saudi Arabia's Personal Data Protection Law is now enforced by SDAIA, the NCA's Essential Cybersecurity Controls bind government and critical-sector suppliers, and SAMA sets the bar for finance. AI Pazz Govnex gives a Saudi company one place to run the controls, risks and evidence all three expect.

In short

Organisations processing personal data in Saudi Arabia must follow the Personal Data Protection Law (PDPL), in force since September 2023 and enforced from September 2024 by SDAIA — including breach notification within 72 hours. Government entities, critical national infrastructure and their suppliers must also meet the NCA's Essential Cybersecurity Controls. Govnex keeps both as control sets with owners and evidence.

Reviewed . A plain-language guide, not legal advice — check the regulator's site for the current position.

The laws and rules that apply in Saudi Arabia

What each asks of a business, who it applies to, what happens if you fall short — and whether Govnex holds it as a ready-made control set.

Saudi PDPL

Personal Data Protection Law (PDPL) and its Implementing Regulations

Track it with your own controls
Regulator
Saudi Data and AI Authority (SDAIA)
Who it applies to
Every organisation processing the personal data of people in Saudi Arabia, including from abroad.
If you fall short
Fines of up to SAR 5 million, which may be doubled for repeat violations; disclosing sensitive data can bring imprisonment.
What it asks of you
  • A lawful basis, a privacy policy and records of processing
  • Data subject rights of access, correction and destruction
  • Notify SDAIA of a personal data breach within 72 hours, and affected people where it may harm them
  • A Data Protection Officer in the cases the regulations specify, and registration on SDAIA's national platform where required
  • Conditions on transfers outside the Kingdom, under the transfer regulations

Source: sdaia.gov.sa

NCA ECC

NCA Essential Cybersecurity Controls (ECC)

Track it with your own controls
Regulator
National Cybersecurity Authority (NCA)
Who it applies to
Government organisations, critical national infrastructure operators and the private companies that serve them.
If you fall short
Enforced through the NCA and procurement conditions.
What it asks of you
  • Cybersecurity governance, defence, resilience and third-party controls across the ECC domains
  • Periodic self-assessment and reporting of compliance to the NCA
  • Related NCA control sets — for cloud (CCC), data (DCC) and critical systems — where they apply

Source: nca.gov.sa

SAMA CSF

SAMA Cyber Security Framework

Track it with your own controls
Regulator
Saudi Central Bank (SAMA)
Who it applies to
Banks, insurers, finance companies and other SAMA-regulated entities.
If you fall short
Supervisory action by SAMA.
What it asks of you
  • Cyber security leadership and governance, risk management and operations
  • Third-party cyber security and maturity self-assessment

Source: sama.gov.sa

Standards Saudi Arabia buyers ask for

How AI Pazz Govnex helps in Saudi Arabia

What you needHow Govnex does itModule
PDPL obligationsAdd the PDPL and its regulations as your own control set, assign owners and collect evidence.
NCA ECC self-assessmentTrack each ECC control with its owner, evidence and status, and report compliance to management.
72-hour breach notificationEach breach an issue with an owner, deadline and closing actions.
Records of processing and transfersA register of personal data, purposes, owners and cross-border transfers.
Cyber and third-party riskRisk registers with treatments and owners for cyber and supplier risk.

Your first 90 days

  1. 1Confirm whether you must register on SDAIA's platform and appoint a DPO.
  2. 2Add the PDPL and — if you serve government or CNI — the NCA ECC as control sets.
  3. 3Map the personal data you hold and any transfers outside the Kingdom.
  4. 4Put your 72-hour breach process in place.
  5. 5Run a self-assessment against the ECC and report your position.

Start with what applies to you

Adopt the control sets that fit, add your own for the rest, and give every control an owner. The first months are free.

Start free

Compliance in Saudi Arabia: questions and answers

When did Saudi Arabia's PDPL take effect?
It came into force on 14 September 2023, with a one-year grace period — organisations were expected to comply from 14 September 2024. SDAIA supervises it.
How quickly must a data breach be reported in Saudi Arabia?
The implementing regulations require notifying SDAIA within 72 hours of becoming aware of a breach, and notifying affected people without undue delay where it may harm them.
Who must follow the NCA Essential Cybersecurity Controls?
Government organisations, operators of critical national infrastructure, and the private companies that provide them with services — so many Saudi SMEs meet the ECC through their customers.
Can data stay in the Kingdom?
Dedicated Hosting runs your own deployment with data and files stored in the Azure region you choose — speak to the AI Pazz team about in-Kingdom options.
Are the PDPL and ECC in the Govnex Library?
Not yet as ready-made sets — add them as your own controls and track them exactly like a Library standard. ISO 27001, NIST CSF and ISO 22301 are ready-made.
What else does Govnex include?
Policies, risk registers, issues, internal audits, regulatory change, a data register and ESG & EHS.