← Blog

Saudi PDPL AI Audit Evidence: What SDAIA Asks For After 48 Enforcement Decisions

The Saudi Data and Artificial Intelligence Authority moved from grace period to enforcement when the PDPL transition window closed on 14 September 2024, and its specialised committees have since issued 48 decisions against organisations found in violation. The common failures were legal basis, unauthorised disclosure, and absent technical safeguards. This walks the evidence an organisation running AI in the Kingdom should be able to produce against each.

ByParminder Singh· Founder & CEO, DeepInspect Inc.
Compliance & Regulationcomplianceregulationai-governanceai-complianceauditdata-privacy
Saudi PDPL AI Audit Evidence: What SDAIA Asks For After 48 Enforcement Decisions

The Saudi Personal Data Protection Law came into force on 14 September 2023, with the Implementing Regulations published by the Saudi Data and Artificial Intelligence Authority on 7 September 2023, one week ahead. A transition period ran to 14 September 2024. Since it closed, SDAIA's specialised committees have issued 48 decisions against organisations found in violation.

The decisions cluster around four failures: processing without a valid legal basis, unauthorised disclosure, absent technical and organisational safeguards, and marketing without consent. Three of those four describe things that happen routinely when an employee pastes customer data into a hosted model, which is the reason this piece exists.

I want to walk the evidence each obligation asks for, because the regulator here supervises both data protection and the national AI agenda, and an organisation that cannot document its AI processing is answering to the same authority on both counts.

Legal basis: the first thing an inspector asks

The PDPL requires a lawful basis for each processing activity. Consent is one route, and the amended law added legitimate interest for non-sensitive data, alongside contractual necessity and legal obligation.

The evidence is a mapping from processing activity to basis, and AI deployments break it in a specific way. An organisation documents its basis for holding customer records and then routes those records through a summarisation tool nobody assessed. The processing activity changed, and the basis document did not. What a reviewer wants is a record showing which data categories reached which external processor, tested against the basis registered for that activity.

Legitimate interest carries its own artifact. Relying on it requires a balancing assessment, and an assessment written for internal analytics does not extend to transferring the same data to a third-party model provider outside the Kingdom.

Records of processing activities

Controllers must maintain records of processing activities and produce them to SDAIA on request. The Implementing Regulations set the content, including purposes, categories of data subjects and personal data, recipients, cross-border transfers, and retention periods.

For AI, the recipients and cross-border fields are where a RoPA assembled from interviews diverges from reality. Interviews produce the providers people remember. Observed egress produces the providers in use, and reconciling the two is the discovery exercise most organisations have never run. That gap is shadow AI discovery arriving under a records obligation.

Impact assessments

The Implementing Regulations require an assessment of the impact of processing personal data for products and services offered to the public, and for processing that carries heightened risk to data subjects. A new AI system introduced into a customer-facing process falls squarely inside that trigger.

The artifact is a dated assessment naming the data categories, the model provider, the transfer route, the safeguards, and the residual risk. Dated before deployment. An assessment produced after an inspector asks demonstrates only that the inspection worked.

Cross-border transfer

The Kingdom's regime on transferring personal data outside its borders was issued alongside the Implementing Regulations and amended in 2024, permitting transfer for specified purposes subject to conditions including a risk assessment where an adequate level of protection is not established.

This obligation is where AI deployments differ from ordinary SaaS. A hosted model endpoint sits in a foreign region by default, and the transfer happens per request rather than per contract. Evidence of compliance is a destination record showing which endpoints in which regions received which data classes, which is a per-request artifact rather than a procurement document.

Breach notification within 72 hours

Controllers must notify SDAIA within 72 hours of becoming aware of a personal data breach that may cause harm to the data or to the data subject, and inform affected individuals without delay. The clock runs continuously, including weekends.

Meeting it requires knowing what was in the payload. An organisation that discovers an agent has been sending prompts to an unapproved endpoint for six weeks needs the data classes and the volume before it can characterise harm, and it needs them inside three days. Reconstructing that from application logs is not a three-day job in most stacks.

Safeguards

Absent technical and organisational safeguards appeared repeatedly across the 48 decisions. Applied to AI traffic, the standard controls do not reach the payload.

Network data-loss prevention sits underneath TLS to a provider API. Document classification examines a file, while a prompt assembles fragments from several systems and ships them as one HTTPS request. The inspectable safeguard is a per-request classification decision and the policy outcome that followed it, held for a period long enough to cover an inspection window.

[@portabletext/react] Unknown block type "code", specify a component for it in the `components.types` prop

What sits outside the request path

Four rows read No or Partial, and the reasons should be stated rather than glossed.

Appointing a data protection officer where required, registering on SDAIA's national platform, running the consent-capture surfaces, and producing the impact assessment itself are governance and legal work. Retention and disposal inside your own stores is a data-governance programme reaching well past AI traffic. Marketing consent, which drove a share of the 48 decisions, is a campaign-systems problem.

My candid view: the penalty structure is what makes this regime worth taking seriously ahead of the paperwork. Administrative fines reach SAR 5 million for general violations and double for repeat offences, and disclosure of sensitive personal data with intent to harm carries up to two years imprisonment and a fine up to SAR 3 million. Criminal exposure attached to a disclosure changes how a security team should think about an employee pasting patient records into a general-purpose model, because that action is a disclosure to a foreign processor and nobody assessed it.

DeepInspect

This is the record layer behind the rows marked Yes. DeepInspect sits inline between your users or agents and the LLM APIs they call, as a stateless proxy the calling application has no custody over. It evaluates identity, request classification, and destination on every call, enforces per-role and per-route policy with a fail-closed default, and writes a signed, tamper-evident per-decision record.

For a PDPL deployment that record supplies the recipient and cross-border fields of the RoPA from observed traffic rather than from interviews, the region-level transfer evidence, the classification decision that evidences safeguards, and the data-class and volume figures a 72-hour notification assessment depends on. The DPO appointment, the platform registration, and the impact assessment stay with your privacy function. Book a technical deep dive at deepinspect.ai.

Frequently asked questions

Who enforces the Saudi PDPL?

The Saudi Data and Artificial Intelligence Authority, which supervises the law and its Implementing Regulations and operates specialised committees that determine violations. SDAIA also holds the Kingdom's national data and AI mandate, which means the same authority sees your data protection posture and your AI deployment.

When did enforcement actually begin?

The law came into force on 14 September 2023 with a transition period that closed on 14 September 2024. Since that date every organisation processing the personal data of individuals in the Kingdom, public or private, domestic or foreign, has been required to comply, and SDAIA's committees have issued 48 decisions confirming violations.

What are the penalties?

Administrative fines reach SAR 5 million for general violations, doubling for repeat offences. Disclosure of sensitive personal data with intent to harm or for personal benefit carries criminal exposure of up to two years imprisonment and a fine of up to SAR 3 million, with penalties doubling on repeat.

How fast must a breach be reported?

Within 72 hours of becoming aware of a personal data breach that may cause harm to the personal data or the data subject, with affected individuals informed without delay. The 72 hours run continuously, including weekends and public holidays.

Does sending a prompt to a foreign model provider count as a cross-border transfer?

Where the request carries personal data to an endpoint outside the Kingdom, the transfer rules apply to that request. The regime issued alongside the Implementing Regulations and amended in 2024 permits transfer for specified purposes subject to conditions, including a risk assessment where an adequate level of protection has not been established for the destination.

Does the PDPL contain AI-specific provisions?

The law regulates personal data rather than AI systems, and SDAIA publishes separate AI ethics principles and generative AI guidance. In practice the two converge, since an AI system processing personal data of individuals in the Kingdom is subject to the full PDPL and answers to the same authority that sets the AI guidance. The same convergence appears in the Korea AI Basic Act controls mapping.