ZATCA and PDPL: Why Compliance With One Is Not Compliance With Both
Yes, you need both. ZATCA is tax, PDPL is privacy. They overlap on receipts, which is why getting both right at once is harder than either alone.

Two regulators, one point of contact
ZATCA, the Zakat, Tax and Customs Authority, operates Saudi Arabia's mandatory e-invoicing framework through Fatoora. The Personal Data Protection Law (PDPL) is a separate regime, enforced by SDAIA. Different mandates, different oversight, different enforcement teams. For merchants, though, the two converge on a single document: the receipt.
What ZATCA asks of you
ZATCA's e-invoicing requirements apply to every VAT-registered business in the Kingdom. Phase 2, the integration phase, is live. Every B2B and B2C transaction must produce an electronic invoice in a prescribed format, digitally signed, carrying a QR code, and integrated with the Fatoora platform. A paper receipt with no compliant digital equivalent is a violation.
What PDPL asks of you
PDPL has no interest in your tax position. Its concern is personal data: names, phone numbers, email addresses, purchase history, loyalty identifiers. Any receipt or transaction record containing personal data falls under PDPL rules on consent, retention, cross-border transfer, and breach notification.
Where the two meet
A typical Saudi receipt carries both categories of data at once. The amount, the tax line, and the QR code belong to ZATCA. The customer name, phone number, loyalty ID, and purchase history belong to PDPL. The same piece of paper, or the same digital record, is simultaneously a tax artefact and a personal data record.
Compliance with one therefore says nothing about compliance with the other. You can issue flawless ZATCA e-invoices while running a PDPL liability underneath: data stored without consent, transferred outside the Kingdom, held with no retention policy. You can also handle customer data impeccably on receipts that fail ZATCA requirements and expose you to tax penalties.
The integration gap
Most point-of-sale vendors cover ZATCA compliance. In the Saudi market it is the minimum expectation. Far fewer handle PDPL with the same rigour. The pattern is predictable: a merchant buys a ZATCA-compliant POS, assumes the matter is settled, and learns during an audit that the way customer data is collected and stored breaches PDPL.
The better approach treats both obligations together from day one. That is how Wateer is built. Every digital receipt carries QR validation and is PDPL-compliant by default. One vendor, one contract, one audit surface.
A short comparison
Regulator: ZATCA oversees e-invoicing; SDAIA enforces PDPL.
Subject matter: ZATCA governs the tax content of the invoice. PDPL governs the personal data attached to it.
Scope: ZATCA applies to VAT-registered businesses. PDPL applies to anyone processing personal data.
Core duties: ZATCA requires a prescribed format, digital signature, QR code, and platform integration. PDPL requires lawful consent, defined retention, controlled transfer, and breach notification.
Overlap: the receipt itself, which satisfies or fails both regimes independently.
The answer
Yes, you need both. Neither is optional and neither substitutes for the other. If your business operates in the Kingdom and touches customer data, you are within scope of both frameworks, and both carry consequences. The only real decision is whether you treat them as two separate compliance projects or as one integrated layer of infrastructure.
Sources & References
Related reading
Want to see Wateer on your system?
Talk to Sales