Saudi PDPL Data Breach Notification: The 72-Hour Rule and a Step-by-Step Response Procedure
Under the Saudi PDPL and Article 24 of its Implementing Regulations, a controller must notify the Saudi Data & AI Authority (SDAIA) within 72 hours of becoming aware of a personal data breach, if the breach may harm the data or the individuals, or conflict with their rights or interests. Notification is made through the National Data Governance Platform. Information not available within 72 hours must follow as soon as possible, with reasons for the delay. Affected individuals must be told without undue delay when the breach could harm them, and the controller must keep records of the notification and the corrective measures.
| Legal basis | PDPL (Article 20) and Implementing Regulations Article 24 |
|---|---|
| Trigger | Breach that may harm the personal data or data subjects, or conflict with their rights or interests |
| Deadline | 72 hours from becoming aware (not from when the breach happened) |
| Where | SDAIA's National Data Governance Platform — Personal Data Breach Notification service |
| Individuals | Notified without undue delay, in clear and simple language, when the breach could harm them |
| Processors | Must notify the controller without undue delay (per the controller–processor agreement) |
| SDAIA guidance | Personal Data Breach Incidents Procedural Guide (October 2024) |
| Penalty | Up to SAR 5 million, doubled for repeat violations |
When must a personal data breach be reported?
Not every incident must be reported. Under Article 24 of the Implementing Regulations, you must notify SDAIA when a breach may cause harm to the personal data or to the data subjects, or conflicts with their rights or interests. Examples include a leaked customer database, a mis-sent file containing ID numbers, or ransomware that exposed employee records.
- The clock: 72 hours from the moment you become aware of the breach. These are calendar hours, not business days, and they do not run from when the breach first happened.
- Partial information is acceptable at first: anything you cannot provide within 72 hours must be submitted as soon as possible, together with the reasons for the delay.
What the SDAIA notification must contain
- A description of the incident: when and how it happened, and when you discovered it.
- The categories of data subjects affected and their actual or approximate number.
- The types of personal data involved.
- The risks and likely consequences, and the measures taken or proposed to limit them.
- Whether the affected individuals have been notified.
- Contact details for the controller and its DPO, or another contact person.
Notification is submitted through SDAIA's National Data Governance Platform using the personal data breach notification service. According to Baker McKenzie, a Saudi national ID or Iqama is needed to use it. Prepare in advance who in your organization will file, especially if your team works from outside Saudi Arabia.
Notifying affected individuals
When the breach could harm them, tell affected individuals without undue delay, in clear and simple language. The message should include:
- a description of the incident;
- the possible risks and the measures taken to prevent or reduce them;
- contact details for the controller and its DPO (if any);
- advice on how they can protect themselves (for example, changing passwords or watching for phishing).
Use their usual contact channel, such as SMS or email. For large breaches, SDAIA's guide allows public notice through your website or social media.
Records you must keep
Keep copies of the reports you submit to SDAIA, and document the corrective measures you took with supporting records. The regulations do not set a specific retention period for breach records, but keeping an internal breach register for all incidents is good practice. It shows how you assessed each one, including those you decided not to report.
Processors and suppliers
Your contracts with processors (cloud providers, outsourced support, payroll providers and similar) must require them to notify you of a breach without undue delay. The regulations do not set a fixed number of hours, so define one in the contract (for example, 24 hours) to protect your own 72-hour window.
NCA, SAMA and other regulators
PDPL notification does not replace reporting duties under other rules:
- NCA-regulated entities must also report cybersecurity incidents to the National Cybersecurity Authority.
- SAMA-regulated financial institutions must inform SAMA immediately of medium- or high-rated cyber incidents under the SAMA Cyber Security Framework.
- Telecom and cloud providers have separate reporting duties to the Communications, Space & Technology Commission.
Step-by-step breach response procedure
SDAIA's October 2024 procedural guide organizes breach handling into three stages: notify SDAIA, contain the incident (including notifying individuals), and document. A practical internal procedure looks like this:
- Detect and escalate (hour 0): anyone who spots a possible breach reports it to a named breach lead immediately.
- Contain (hours 0–24): stop the leak by revoking access, isolating systems, changing credentials and recalling mis-sent data.
- Assess (hours 0–48): what data, how many people, how sensitive, and whether it could cause harm. Record the decision either way.
- Notify SDAIA (by hour 72): submit through the National Data Governance Platform, and follow up with missing details as soon as possible.
- Notify individuals (without undue delay): clear message, risks, protective advice and a contact point.
- Notify other regulators where applicable (NCA, SAMA, CST).
- Document and learn: keep the reports and evidence of corrective measures, then fix the root cause.
Breach readiness checklist
- Written breach response procedure, approved by management
- Named breach lead and backup, with 24/7 contact details
- Harm assessment criteria to decide whether an incident is reportable
- Access to SDAIA's National Data Governance Platform arranged in advance
- Pre-drafted SDAIA notification and individual notification templates (Arabic and English)
- Processor contracts with a defined breach notification time
- Internal breach register covering all incidents
- Mapping of other reporting duties (NCA, SAMA, CST)
- Annual tabletop exercise to test the procedure
Frequently Asked Questions
How long do I have to report a data breach in Saudi Arabia?
72 hours from becoming aware of the breach, if it may cause harm to the personal data or the individuals or conflict with their rights or interests. Missing information can follow as soon as possible with reasons for the delay.
Do I have to report every data breach to SDAIA?
No. Notification is required when the breach may harm the personal data or data subjects, or conflict with their rights or interests. Keep a record of how you assessed incidents you did not report.
Where do I report a breach to SDAIA?
Through SDAIA's National Data Governance Platform, using the personal data breach notification service.
What must a breach notification to SDAIA include?
A description of the incident and when it was discovered, affected categories and approximate number of individuals, the types of data, likely consequences and measures taken, whether individuals were notified, and contact details for the controller and DPO.
Do I have to tell affected customers?
Yes, without undue delay and in clear, simple language, when the breach could harm them, including the risks, the measures taken and advice on protecting themselves.
What is the penalty for not reporting a breach?
Violations of the PDPL can lead to a warning or fines of up to SAR 5 million, doubled for repeat violations.
Related guides
Sources
- Umm Al-Qura — PDPL Implementing Regulations (Arabic, Art. 24)
- SDAIA — Personal Data Breach Incidents Procedural Guide (Oct 2024)
- Baker McKenzie — Saudi Arabia publishes guidance on data breach notification
- DLA Piper — Breach notification: Saudi Arabia
- Clyde & Co — Saudi Arabia issues Implementing Regulations
- Addleshaw Goddard — Impact of the Regulations on the Saudi PDPL
- CMS — Data protection and cybersecurity laws in Saudi Arabia
- Saudi Press Agency — SDAIA enforcement decisions (Jan 2026)
This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.