Your Thermal Receipt Is a PDPL Liability
Every thermal receipt with a customer name or phone number is uncontrolled personal data. SDAIA has issued 48 enforcement decisions. Fines reach SAR 5M.
Every thermal receipt that leaves your store carrying a customer's name, phone number, or loyalty ID is a piece of personal data you no longer control. It is in a pocket, a bag, a restaurant table, or a pavement. PDPL applies to that data the moment it is collected — and it does not stop applying because the data is now on a piece of paper you printed.
SDAIA has issued 48 enforcement decisions since the grace period ended in September 2024. Fines reach SAR 5 million. Repeat violations reach SAR 10 million. The 72-hour breach notification requirement means the moment a customer's data is exposed, the clock starts — whether you know about it or not.
What counts as personal data on a thermal receipt
Saudi Arabia's Personal Data Protection Law (PDPL, Law No. M/19) defines personal data as any information that relates to an identified or identifiable natural person. A thermal receipt that prints any of the following triggers PDPL obligations:
- Customer name (common in loyalty program enrollment)
- Phone number (used as loyalty ID, for VAT receipt delivery)
- Email address
- Loyalty account number linked to a profile
- Purchase history items that, in combination, could identify a person
The data minimization principle in PDPL requires organizations to collect and process only the personal data necessary for the stated purpose. Printing a customer's name on a thermal receipt that they may drop in the street is not data minimization. It is the opposite.
The breach exposure that no one discusses
A thermal receipt is physically insecure by design. There is no access control. There is no encryption. There is no deletion mechanism. Once printed, the data on that receipt is accessible to anyone who picks it up — including competitors, data aggregators, and people whose interest in a customer's purchase history is not benign.
PDPL's breach notification requirement — 72 hours to notify SDAIA, 5 days to notify affected individuals — requires that organizations know when a breach has occurred. With thermal receipts, organizations generally do not know. A customer drops a receipt. A table gets bussed. A receipt blows off a counter. These are not events that trigger internal incident response, but under PDPL they may qualify as unauthorized personal data disclosure.
The gap between what PDPL requires and what thermal receipt operations actually deliver is not a technicality. It is a compliance posture that assumes regulators will not look, auditors will not ask, and customers will not complain.
That posture is getting harder to maintain.
The Saudi store pattern
Saudi F&B and retail operations typically enroll customers in loyalty programs at POS. The enrollment capture — name and phone — then prints on subsequent receipts as the customer identifier. The very data collected to build the customer relationship is the data being exposed on every transaction slip.
SDAIA is now licensing accredited PDPL auditors. The auditing phase — not just the enforcement decisions phase — is beginning. Merchants who have not addressed their personal data exposure at POS are running out of the window in which "we didn't know" is a plausible position.
What Wateer does instead
Wateer issues every receipt digitally — no personal data printed on paper, no uncontrolled copies leaving the premises, every transaction tied to a verified digital record with a full audit trail. You inherit PDPL compliance at the receipt layer the moment you integrate.
← Previous: The Minutes You Lose to Thermal Receipts Every Day
Want to see Wateer on your stack?
Talk to Sales