All news
September 15, 2025

SDAIA's First Year of Enforcement, in Numbers

SDAIA's enforcement of Saudi Arabia's PDPL entered its second year in September 2025. Here's what happened in year one: decisions issued, industries targeted, fines assessed, and what merchants should expect next.

**48.** That is how many formal enforcement decisions SDAIA issued in the first year of active PDPL enforcement. Not warnings. Not advisory notices. Decisions — with financial and operational consequences.

The grace period ended in September 2024. Twelve months later, the enforcement landscape looks different from what many merchants expected. Here is what year one actually produced.

What Happened in Year One

SDAIA's enforcement authority under PDPL covers both reactive investigations (complaints from data subjects) and proactive inspections of organizations that handle personal data at scale. In year one, both channels were active.

**Decisions issued:** 48 formal enforcement decisions in year one of PDPL enforcement.

**Industries hit:** [SOURCE NEEDED — verify sector breakdown from SDAIA press releases. Expected to include: retail/F&B, healthcare, financial services, telecommunications. Add verified figures and source links before publishing.]

**Fine range:** The penalty framework sets a maximum of SAR 5 million for a first violation and SAR 10 million for repeat offenders. [SOURCE NEEDED — verify the actual aggregate fines assessed in year one, if SDAIA has published this figure.]

**Public decisions:** [SOURCE NEEDED — verify how many decisions have been made public vs. confidential. SDAIA has authority to publish enforcement decisions under PDPL. Add verified count and links to any published decisions.]

Patterns in the Enforcement Data

What can be read from year one activity:

**Consent and collection violations lead.** The most common violations in initial enforcement cycles involve organizations that collected personal data without a valid legal basis — missing or inadequate consent documentation, blanket consent language, and no mechanism for data subjects to withdraw consent. [SOURCE NEEDED — verify this pattern from official SDAIA communications.]

**Breach notification failures.** PDPL's 72-hour notification requirement — inform SDAIA within 72 hours of discovering a personal data breach — has been cited in multiple enforcement actions. [SOURCE NEEDED — verify count from official sources.]

**Cross-border transfers without legal basis.** Organizations routing Saudi personal data to international servers without an adequacy determination or documented explicit consent are in active scope. [SOURCE NEEDED — verify whether cross-border transfers have been specifically cited in year-one decisions.]

**SMEs are not exempt.** Early enforcement was not limited to large organizations. SDAIA's mandate covers any organization that processes personal data of Saudi residents, regardless of size.

What Merchants Should Expect in Year Two

Three developments signal that year two will be more intensive than year one.

**Accredited PDPL auditors.** SDAIA is licensing a network of accredited auditors to conduct structured compliance assessments. This shifts enforcement from reactive (responding to complaints) to proactive (initiating audits). Merchants who have not documented their data practices are exposed to scheduled audit risk, not just complaint-driven investigation.

**Rising complaint volume.** As public awareness of PDPL rights increases, data subject complaints are expected to increase correspondingly. Each complaint is a potential enforcement trigger.

**Repeat offender escalation.** Organizations that received advisory guidance or first-violation decisions in year one face the SAR 10 million penalty tier for any subsequent violation. Year two is where the stakes double for anyone who did not fix the issue the first time.

What to Do Right Now

If you are unsure of your PDPL posture, three areas have the highest enforcement priority based on year-one patterns:

1. **Consent documentation.** Review every point at which you collect customer data. Does each collection have a specific, documented consent? Is the consent withdrawal mechanism functional? See [PDPL Consent Management — What Every Saudi Merchant Must Do by 2027](/en/articles/pdpl-consent-management-what-every-saudi-merchant-must-do-by-2027) for the requirements.

2. **Cross-border transfer audit.** Map where your transaction data goes. If your POS or CRM routes customer data to international servers, that is a cross-border transfer requiring a legal basis. See [Cross-Border Data Transfer Under PDPL](/en/articles/pdpl-cross-border-data-transfer-pos-saudi-arabia) for the framework.

3. **Breach notification readiness.** The 72-hour clock starts when you discover a breach — not when you have investigated it. If your team does not have a documented response procedure that gets to SDAIA notification within 72 hours, that gap needs to close before the next incident.

SDAIA's year one was a foundation. Year two is built on it.

---

#

Want to see Wateer on your stack?

Talk to Sales