Saudi Arabia’s Personal Data Protection Law is now firmly in its operational phase.

For organisations processing personal data connected with Saudi Arabia, compliance is no longer limited to reviewing privacy notices, contractual terms or internal policies. SDAIA’s National Data Governance Platform creates an additional operational layer through registration, regulatory e-services and the assessment of whether a Personal Data Protection Officer must be appointed.

The National Register framework is therefore relevant not only as an administrative requirement, but as part of the broader governance infrastructure through which controllers interact with the Saudi data-protection regime.

The original version of this Insight was published shortly before the end of the PDPL transition period in September 2024. Since then, the registration framework has developed further, including an operational process for entities established outside the Kingdom.

For organisations operating across several jurisdictions, the practical question is now:

Does the organisation need to register, who should act as its representative on the Platform, and does its processing require appointment of a DPO?

Saudi PDPL compliance now includes an operational registration layer

The Saudi Personal Data Protection Law came into force on 14 September 2023.

The one-year compliance transition period that accompanied its introduction has now expired. Organisations within scope should therefore approach the PDPL as an operational compliance framework rather than as a future implementation project.

The framework includes:

  • the PDPL itself;
  • its Implementing Regulations;
  • the Regulation on Personal Data Transfer Outside the Kingdom;
  • rules and guidance issued by the Saudi Data & AI Authority (SDAIA); and
  • the services and registration processes made available through the National Data Governance Platform.

The National Register sits within this broader framework.

Its purpose is to support SDAIA in identifying relevant controllers, monitoring compliance and providing data-protection services through the Platform.

Who falls within the PDPL?

Article 2 PDPL gives the law a broad territorial reach.

It applies to processing of personal data that takes place in Saudi Arabia.

It also applies where personal data relating to individuals residing in Saudi Arabia is processed by a party located outside the Kingdom.

This means that an organisation does not need to be incorporated or physically established in Saudi Arabia for its processing to fall within the PDPL.

A multinational organisation may therefore need to assess the Saudi framework where, for example:

  • a foreign group company processes personal data relating to individuals residing in Saudi Arabia;
  • a service provider outside Saudi Arabia accesses Saudi customer or employee information;
  • a global cloud or HR system processes personal data relating to individuals in the Kingdom; or
  • a non-Saudi entity provides services involving the processing of Saudi-resident personal data.

The PDPL excludes processing by an individual where the activity remains within personal or family use, subject to the conditions of the law and Implementing Regulations.

Who must register in the National Register?

The Rules Governing the National Register of Controllers Within the Kingdom identify the circumstances in which controllers covered by those Rules must register on the National Data Governance Platform.

Registration is required where:

  1. the Controller is a public entity;
  2. the Controller’s main activity is based on personal data processing;
  3. the Controller processes sensitive personal data; or
  4. an individual processes personal data for purposes exceeding personal or family use.

The assessment should therefore begin with the organisation’s actual processing activities rather than with its size alone.

A business may need to consider:

  • whether personal-data processing forms part of its main activity;
  • whether sensitive personal data is processed;
  • whether processing occurs within Saudi Arabia;
  • whether Saudi-resident individuals are involved; and
  • which entity within a multinational group determines the purposes and manner of the relevant processing.

Registration for entities outside Saudi Arabia

One important development since the original 2024 publication is that SDAIA now provides a dedicated registration process for entities established outside the Kingdom.

The National Data Governance Platform includes a registration route for external entities.

The current process requires, among other steps, the appointment of an authorised representative and completion of the relevant external-entity registration procedure through the Platform.

The process also includes an assessment of whether appointment of a DPO is mandatory.

Once the required registration process has been completed and approved, the Platform provides for issuance of a National Personal Data Protection Register Certificate.

For international organisations, this means the registration analysis should no longer stop at the conclusion that the entity is located outside Saudi Arabia.

Instead, organisations should assess:

  • whether the PDPL applies to the relevant processing;
  • whether the external-entity registration process is applicable;
  • who will act as the authorised representative;
  • whether a DPO must be appointed; and
  • how responsibility for maintaining the Platform account will be managed internally.

The role of the entity representative

The National Register framework uses the concept of a representative to manage the controller’s registration procedures on the Platform.

For relevant entities, the representative is responsible for completing the registration process and maintaining required entity information.

The representative may also be involved in:

  • completing the entity’s profile;
  • providing DPO information where a DPO has been appointed;
  • reviewing compliance-assessment results and available Platform services;
  • using Platform services where applicable; and
  • keeping registration information current.

The representative should therefore not be treated merely as a technical account administrator.

Organisations should determine who owns the Platform relationship, who is responsible for regulatory communications and how changes to corporate or processing information will be reflected in the registration.

When is a Personal Data Protection Officer mandatory?

Article 32 of the PDPL Implementing Regulations and SDAIA’s Rules for Appointing a Personal Data Protection Officer establish the circumstances in which a controller must appoint one or more individuals responsible for personal-data protection.

A DPO must be appointed where:

  • a public entity provides services involving processing of personal data on a large scale;
  • the controller’s core activities are based on processing operations that, by their nature, require regular and systematic monitoring of data subjects; or
  • the controller’s core activities are based on processing sensitive personal data.

The DPO analysis should therefore focus on the controller’s actual core processing activities.

Supporting or ancillary processing does not automatically become a core activity merely because it involves personal data.

For example, ordinary employee-data processing by an internal HR function will not necessarily have the same character as a business whose principal service depends on systematic monitoring or sensitive-data processing.

What does SDAIA expect from the DPO?

The DPO role is not simply a title assigned to an existing member of staff.

SDAIA’s current DPO rules require controllers to consider whether the proposed DPO has the knowledge and experience necessary to perform the role.

The requirements include, among other matters:

  • appropriate academic qualifications and experience in personal-data protection;
  • sufficient knowledge of risk-management practices, including management of personal-data breaches;
  • sufficient knowledge of applicable data-protection regulatory requirements and organisational measures; and
  • appropriate standards of honesty and integrity.

The DPO may be:

  • an executive;
  • another employee of the controller; or
  • an external contractor.

The appointment must be documented appropriately.

Where an external contractor is appointed, the engagement should be documented contractually.

The controller must also provide a clear and accessible means through which data subjects can communicate with the DPO.

Can the entity representative also act as DPO?

Potentially, yes.

The National Register rules expressly contemplate circumstances in which the controller’s representative may also be appointed as the Personal Data Protection Officer.

However, the fact that the same individual can perform both functions does not mean that every representative is automatically suitable to act as DPO.

The controller should separately assess:

  • whether appointment of a DPO is mandatory;
  • whether the proposed individual satisfies the DPO requirements;
  • whether the individual has sufficient independence and organisational access to perform the role effectively;
  • whether adequate resources are available; and
  • whether the combined roles create practical or organisational conflicts.

The legal ability to combine roles should therefore be distinguished from the governance question of whether doing so is appropriate for the organisation.

What does the National Data Governance Platform support?

Registration also provides access to the broader regulatory infrastructure maintained through the National Data Governance Platform.

The Platform currently supports a number of data-protection processes and e-services.

These include, among others:

  • personal-data breach notification;
  • data-protection impact-assessment functionality;
  • compliance-related assessments and services; and
  • other regulatory tools made available by SDAIA.

For example, the breach-notification service allows controllers to notify SDAIA of qualifying personal-data breaches within the applicable 72-hour period.

This makes ownership of the Platform account operationally important.

Organisations should ensure that responsibility for using the Platform is connected to their incident-response procedures, privacy governance and regulatory escalation process.

Practical implementation steps

For organisations assessing their Saudi data-protection position, a practical sequence is:

  1. Confirm PDPL applicability

    Determine whether the relevant processing takes place in Saudi Arabia or relates to individuals residing in the Kingdom.

  2. Identify the controller

    Determine which entity determines the purposes and manner of the relevant processing.

  3. Assess registration

    Apply the relevant National Register criteria and, where appropriate, the process applicable to an entity established outside the Kingdom.

  4. Appoint the Platform representative

    Establish who will be responsible for the registration process and ongoing Platform administration.

  5. Assess the DPO requirement

    Review the organisation’s core processing activities against the mandatory DPO criteria.

  6. Assess DPO suitability

    If a DPO is required or voluntarily appointed, verify qualifications, knowledge, documentation and organisational arrangements.

  7. Connect the Platform to operational compliance

    Ensure that breach notification, compliance assessments and other relevant services are incorporated into the organisation’s privacy-governance processes.

  8. Maintain the information

    Registration should remain aligned with changes to the organisation, its representative, DPO and relevant processing arrangements.

Registration is part of the compliance architecture, not a substitute for it

The National Register is an important part of Saudi Arabia’s increasingly operational data-protection framework.

But registration alone does not establish PDPL compliance.

Controllers must still assess the wider requirements applicable to their processing, including:

  • lawful processing;
  • transparency;
  • data-subject rights;
  • processor governance;
  • security;
  • breach management;
  • data-protection impact assessments where required;
  • records of processing activities;
  • international transfers; and
  • other sector-specific or processing-specific requirements.

For multinational organisations, the National Register also needs to sit within a broader governance model.

The organisation should know which entity owns the Saudi processing activity, who manages the regulatory interface, whether a DPO is required and how Saudi obligations connect with the wider privacy framework used across the group.

The most effective approach is therefore not to treat registration as a standalone filing exercise, but as one operational component of the organisation’s Saudi data-protection programme.