All series
ACTIVE4 of 26

Saudi PDPL Governance and Audit Series

A 26-part working guide to the Personal Data Protection Law of Saudi Arabia. Roles, records, lawful basis, cross-border transfers, and audit readiness.

Organized across five arcs: Foundations (01 to 06), Operations (07 to 12), Audit and Metrics (13 to 18), Incidents and Risk (19 to 22), and Leadership and Culture (23 to 26). Four parts published; the rest are drafting in sequence.
01/26

PDPL in Saudi Arabia, what actually changed for organizations

The regulatory shift and what actually lands on the operations team, not the legal one.

May 5, 2026
02/26

Controller vs Processor, stop guessing your role

The two roles that decide who owns what. Getting this wrong makes everything else wrong.

May 26, 2026
03/26

Your PDPL data map in 60 minutes, first step that unlocks everything

A one-hour exercise that gives you the foundation for records, retention, and everything downstream.

Jun 16, 2026
04/26

Data Subject rights, what people can ask for and how fast you must respond

The requests you'll receive and the timelines that decide whether you comply or get fined.

Jul 7, 2026
05/26

Consent under PDPL, when you need it and when you do not

Consent is one lawful basis among several. Knowing when it applies keeps you from asking the wrong questions.

Coming Soon
···
06/26

Privacy policy and collection notices, what must be disclosed before collecting

The disclosures that turn a data collection action into a lawful one.

Coming Soon
···
07/26

Purpose limitation and data minimization, how to pass an audit with simple proofs

Two principles auditors keep coming back to, and evidence that satisfies without theatre.

Coming Soon
···
08/26

Retention and destruction, how to justify keeping data and how to delete it safely

Deciding how long to hold personal data and executing deletion cleanly.

Coming Soon
···
09/26

Security measures under PDPL, what auditors expect to see

The security controls PDPL calls for, and what an auditor actually looks for.

Coming Soon
···
10/26

Access control for personal data, a practical least privilege model

Least privilege applied specifically to personal data, without breaking day-to-day work.

Coming Soon
···
11/26

Vendor due diligence under PDPL, what must be in your processor contract

The clauses your processor contracts need and the diligence that supports them.

Coming Soon
···
12/26

Cross-border data transfers, when data can leave Saudi Arabia and when it cannot

The transfer mechanisms that are permitted, and the steps to prove you used them.

Coming Soon
···
13/26

Records of processing, the audit artifact that saves weeks of effort

The ledger that turns audit conversations from interrogation into review.

Coming Soon
···
14/26

PDPL lifecycle, from policy to operations to evidence

The end-to-end flow of a PDPL program, and where each phase touches your organization.

Coming Soon
···
15/26

PDPL audit planning, scope, and what complete coverage means

Defining audit scope so the exercise is meaningful, not decorative.

Coming Soon
···
16/26

Self-assessment and maturity scoring that actually works

A scoring model that reflects real state instead of aspirational targets.

Coming Soon
···
17/26

PDPL KPIs, how to measure compliance without fake metrics

Metrics that hold up under scrutiny, and ones that quietly mislead leadership.

Coming Soon
···
18/26

Updating the audit checklist, turning PDPL obligations into test steps

Translating regulatory text into checklist items an auditor can execute.

Coming Soon
···
19/26

Personal data breach response in Saudi Arabia, what to notify and when

The reporting obligations and timing rules for a personal data breach in the Kingdom.

Coming Soon
···
20/26

DPIA under PDPL, when you need it and how to do it properly

Data protection impact assessments as a working tool, not a filing exercise.

Coming Soon
···
21/26

Sensitive and health data, what extra care really means

The heightened requirements for sensitive categories and how to apply them in practice.

Coming Soon
···
22/26

Complaints handling and inspections, what happens when someone escalates

The complaint pipeline, from receipt to regulator involvement, and how to be ready.

Coming Soon
···
23/26

DPO and privacy governance, building a model that works in real org charts

Placing the DPO function so it has authority without duplicating existing roles.

Coming Soon
···
24/26

Board reporting for PDPL, metrics leaders actually understand

Board-level reporting that surfaces exposure without drowning the audience in acronyms.

Coming Soon
···
25/26

Penalties and liability under PDPL, what leaders must know

The enforcement landscape, and where personal liability sits.

Coming Soon
···
26/26

Building a privacy culture that survives audits and staff changes

The organizational habits that keep compliance intact when the team behind it turns over.

Coming Soon
···

Get the next article when it's published

No promotions. Just the next piece.