All news
October 20, 2024

PDPL Consent Management — What Every Saudi Merchant Must Do by 2027

SDAIA issued 48 enforcement decisions in 2025. PDPL Articles 5–7 set strict consent rules for Saudi merchants. Here is what valid consent looks like — and how Wateer handles it automatically.

The grace period ended. SDAIA enforcement began. In 2025, 48 formal decisions were issued against organizations that got consent wrong.

If your business collects a customer's name, phone number, or purchase history — and most merchants do — you are subject to PDPL's consent requirements under Articles 5 through 7. Here is what valid consent actually requires, and what the gaps look like in practice.

What Articles 5–7 Require

Three conditions. All three must be met.

**Article 5 — Lawful basis.** Processing personal data requires either explicit consent or a recognized lawful basis: performance of a contract, compliance with a legal obligation, protection of vital interests, or legitimate interest (narrowly interpreted). Most merchant data collection — loyalty databases, CRM records, customer contact lists — relies on consent as the primary basis.

**Article 6 — Consent conditions.** Valid consent under PDPL must be:

  • **Specific** — collected for a defined, stated purpose
  • **Informed** — the data subject understands exactly what they are agreeing to
  • **Unambiguous** — a clear affirmative act, not inferred from silence or a pre-ticked box
  • **Freely given** — not conditioned on receiving a service

A loyalty enrollment form that says "by signing up you agree to receive offers" does not meet this standard. Neither does a verbal consent at the register with no record kept.

**Article 7 — Withdrawal.** Customers must be able to withdraw consent at any time. Withdrawal must be as simple as giving consent. Once withdrawn, processing must stop — there is no carve-out for "existing relationship management."

The Enforcement Reality

PDPL became enforceable in September 2024. The penalty framework is active:

  • **Fines up to SAR 5 million** for a first violation
  • **SAR 10 million** for repeat offenders
  • **72-hour breach notification** — if personal data is exposed, SDAIA must be notified within 3 business days
  • **48 formal enforcement decisions issued in 2025** — not warnings, decisions with real consequences

SDAIA is now licensing accredited PDPL auditors. Merchants are about to face structured audits, not paperwork spot-checks.

What Merchants Get Wrong

Common gaps found in Saudi retail:

**No consent records.** Verbal agreements at the register, unsigned loyalty forms, WhatsApp opt-ins without saved confirmation — none of these create an auditable record.

**Blanket consent language.** "We may use your data for marketing purposes" is not purpose-specific. PDPL requires disclosure per purpose, not a catch-all clause.

**No withdrawal mechanism.** If a customer cannot easily opt out of data processing, the consent was never valid under Article 7.

**Retention after purpose expires.** Keeping customer data after the stated purpose ends — or after consent is withdrawn — is a violation.

How Wateer Handles Consent Automatically

**No PII on paper.** Thermal receipts print personal data on a physical document that can end up anywhere. Wateer delivers receipts digitally, to the customer's device, via WhatsApp or SMS.

**Consent at the delivery layer.** The first time a customer receives a Wateer receipt, the consent flow is built into the channel. The record is timestamped and stored.

**Audit-ready.** If SDAIA requests documentation of consent collection processes, Wateer merchants have a timestamped digital record — not a drawer of signed forms.

The merchant who switched to digital receipts closed a PDPL exposure that most of their competitors have not noticed yet.

---

Want to see Wateer on your stack?

Talk to Sales