Skip to main content
Version: 1.0.0-beta

PDPL Compliance

AIIA supports the Saudi Personal Data Protection Law (PDPL) — the primary data privacy regulation issued by SDAIA governing the collection, processing, and storage of personal data.

Framework Details

PropertyValue
CodePDPL
NamePersonal Data Protection Law
Name (AR)نظام حماية البيانات الشخصية
Issuing BodySDAIA
CountrySaudi Arabia
CategoryRegulatory

PDPL Domains

DomainKey Requirements
Data CollectionLawful basis, consent management, purpose limitation
Data ProcessingMinimization, accuracy, processing records
Data Subject RightsAccess, rectification, erasure, portability
Data TransferCross-border transfer restrictions, adequacy decisions
Data SecurityTechnical and organizational measures
Breach NotificationNotification to SDAIA and data subjects
Data Protection OfficerDPO appointment and responsibilities

Using PDPL in AIIA

Enable and Map

  1. Navigate to Compliance → Frameworks → PDPL
  2. Enable the framework
  3. Map your data protection controls to PDPL requirements
  4. Assess compliance status for each requirement

Privacy Impact Assessment

Create questionnaires aligned with PDPL requirements:

  • Data inventory and classification
  • Consent mechanisms assessment
  • Data subject rights processes
  • Cross-border transfer analysis

Evidence Collection

For each PDPL requirement, attach evidence:

  • Privacy policies and notices
  • Consent records
  • Data processing agreements
  • Technical security measures documentation

Cross-Framework Mapping

PDPL requirements overlap with:

  • GDPR — many shared concepts (consent, subject rights, breach notification)
  • NCA ECC — data security controls overlap
  • ISO 27001 — information security management controls

Bilingual Support

All PDPL requirements are available in Arabic and English, matching the official regulation language.