WaqiSecWaqiSec

Saudi PDPL Data Breach Notification: The 72-Hour Rule and a Step-by-Step Response Procedure

WaqiSec Compliance Team · Last reviewed:

SHORT ANSWER

Under the Saudi PDPL and Article 24 of its Implementing Regulations, a controller must notify the Saudi Data & AI Authority (SDAIA) within 72 hours of becoming aware of a personal data breach, if the breach may harm the data or the individuals, or conflict with their rights or interests. Notification is made through the National Data Governance Platform. Information not available within 72 hours must follow as soon as possible, with reasons for the delay. Affected individuals must be told without undue delay when the breach could harm them, and the controller must keep records of the notification and the corrective measures.

Legal basisPDPL (Article 20) and Implementing Regulations Article 24
TriggerBreach that may harm the personal data or data subjects, or conflict with their rights or interests
Deadline72 hours from becoming aware (not from when the breach happened)
WhereSDAIA's National Data Governance Platform — Personal Data Breach Notification service
IndividualsNotified without undue delay, in clear and simple language, when the breach could harm them
ProcessorsMust notify the controller without undue delay (per the controller–processor agreement)
SDAIA guidancePersonal Data Breach Incidents Procedural Guide (October 2024)
PenaltyUp to SAR 5 million, doubled for repeat violations

When must a personal data breach be reported?

Not every incident must be reported. Under Article 24 of the Implementing Regulations, you must notify SDAIA when a breach may cause harm to the personal data or to the data subjects, or conflicts with their rights or interests. Examples include a leaked customer database, a mis-sent file containing ID numbers, or ransomware that exposed employee records.

What the SDAIA notification must contain

  1. A description of the incident: when and how it happened, and when you discovered it.
  2. The categories of data subjects affected and their actual or approximate number.
  3. The types of personal data involved.
  4. The risks and likely consequences, and the measures taken or proposed to limit them.
  5. Whether the affected individuals have been notified.
  6. Contact details for the controller and its DPO, or another contact person.

Notification is submitted through SDAIA's National Data Governance Platform using the personal data breach notification service. According to Baker McKenzie, a Saudi national ID or Iqama is needed to use it. Prepare in advance who in your organization will file, especially if your team works from outside Saudi Arabia.

Notifying affected individuals

When the breach could harm them, tell affected individuals without undue delay, in clear and simple language. The message should include:

Use their usual contact channel, such as SMS or email. For large breaches, SDAIA's guide allows public notice through your website or social media.

Records you must keep

Keep copies of the reports you submit to SDAIA, and document the corrective measures you took with supporting records. The regulations do not set a specific retention period for breach records, but keeping an internal breach register for all incidents is good practice. It shows how you assessed each one, including those you decided not to report.

Processors and suppliers

Your contracts with processors (cloud providers, outsourced support, payroll providers and similar) must require them to notify you of a breach without undue delay. The regulations do not set a fixed number of hours, so define one in the contract (for example, 24 hours) to protect your own 72-hour window.

NCA, SAMA and other regulators

PDPL notification does not replace reporting duties under other rules:

Step-by-step breach response procedure

SDAIA's October 2024 procedural guide organizes breach handling into three stages: notify SDAIA, contain the incident (including notifying individuals), and document. A practical internal procedure looks like this:

  1. Detect and escalate (hour 0): anyone who spots a possible breach reports it to a named breach lead immediately.
  2. Contain (hours 0–24): stop the leak by revoking access, isolating systems, changing credentials and recalling mis-sent data.
  3. Assess (hours 0–48): what data, how many people, how sensitive, and whether it could cause harm. Record the decision either way.
  4. Notify SDAIA (by hour 72): submit through the National Data Governance Platform, and follow up with missing details as soon as possible.
  5. Notify individuals (without undue delay): clear message, risks, protective advice and a contact point.
  6. Notify other regulators where applicable (NCA, SAMA, CST).
  7. Document and learn: keep the reports and evidence of corrective measures, then fix the root cause.

Breach readiness checklist

Frequently Asked Questions

How long do I have to report a data breach in Saudi Arabia?

72 hours from becoming aware of the breach, if it may cause harm to the personal data or the individuals or conflict with their rights or interests. Missing information can follow as soon as possible with reasons for the delay.

Do I have to report every data breach to SDAIA?

No. Notification is required when the breach may harm the personal data or data subjects, or conflict with their rights or interests. Keep a record of how you assessed incidents you did not report.

Where do I report a breach to SDAIA?

Through SDAIA's National Data Governance Platform, using the personal data breach notification service.

What must a breach notification to SDAIA include?

A description of the incident and when it was discovered, affected categories and approximate number of individuals, the types of data, likely consequences and measures taken, whether individuals were notified, and contact details for the controller and DPO.

Do I have to tell affected customers?

Yes, without undue delay and in clear, simple language, when the breach could harm them, including the risks, the measures taken and advice on protecting themselves.

What is the penalty for not reporting a breach?

Violations of the PDPL can lead to a warning or fines of up to SAR 5 million, doubled for repeat violations.

Related guides

Sources

  1. Umm Al-Qura — PDPL Implementing Regulations (Arabic, Art. 24)
  2. SDAIA — Personal Data Breach Incidents Procedural Guide (Oct 2024)
  3. Baker McKenzie — Saudi Arabia publishes guidance on data breach notification
  4. DLA Piper — Breach notification: Saudi Arabia
  5. Clyde & Co — Saudi Arabia issues Implementing Regulations
  6. Addleshaw Goddard — Impact of the Regulations on the Saudi PDPL
  7. CMS — Data protection and cybersecurity laws in Saudi Arabia
  8. Saudi Press Agency — SDAIA enforcement decisions (Jan 2026)

This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.

💬