Data Privacy Notice Template for Saudi Arabia
Generate a bespoke document
What is a Data Privacy Notice?
The Data Privacy Notice is a mandatory document required under Saudi Arabia's Personal Data Protection Law (PDPL) for organizations processing personal data within the Kingdom or relating to residents of Saudi Arabia. This document must be provided to data subjects before or at the time of collecting their personal data, explaining how their information will be handled, their rights under the law, and the organization's data protection practices. The notice should be available in both Arabic and English, reflecting Saudi Arabia's legal requirements, and must be updated whenever there are significant changes to data processing activities. It serves as a primary tool for transparency and establishing trust with data subjects while demonstrating compliance with Saudi Arabian privacy regulations.
Trusted by high-performance teams
About the Data Privacy Notice
A Data Privacy Notice is your organization's formal commitment to transparency under Saudi Arabia's Personal Data Protection Law (PDPL). This critical document communicates to individuals how you collect, use, store, and protect their personal data, while establishing your legal basis for processing and outlining their rights as data subjects.
When do you need this document?
You must provide a Data Privacy Notice before or at the point of collecting any personal data from individuals in Saudi Arabia. This requirement applies whether you're collecting data through websites, mobile applications, employment processes, customer registration forms, or any other means. Organizations operating in Saudi Arabia, processing data of Saudi residents, or transferring data to the Kingdom must implement comprehensive privacy notices. The notice is also essential when onboarding new employees, registering customers for services, conducting marketing campaigns, or engaging third-party processors who handle personal data on your behalf.
Key legal considerations
Your Data Privacy Notice must clearly specify the legal basis for processing under PDPL, whether it's consent, legitimate interest, contractual necessity, or legal obligation. The document should comprehensively detail what personal data you collect, including basic identification information, sensitive personal data, and any special categories requiring additional protection. You must explain data retention periods, storage locations, and security measures implemented to protect personal information. The notice should address data subject rights including access, rectification, erasure, and data portability, along with procedures for exercising these rights. Cross-border data transfer provisions are crucial, particularly when sharing data with international entities or cloud service providers outside Saudi Arabia.
Legal requirements in Saudi Arabia
Under the PDPL and its implementing regulations, your Data Privacy Notice must be available in both Arabic and English to ensure accessibility for all data subjects. The Saudi Data & Artificial Intelligence Authority requires organizations to maintain current notices that accurately reflect processing activities and promptly notify individuals of any material changes. The document must comply with specific formatting and content requirements outlined in PDPL implementing regulations, including mandatory sections for data subject rights, complaint procedures, and contact information for your Data Protection Officer. Organizations must ensure the notice is easily accessible, prominently displayed on websites, and provided in clear, understandable language. The Cloud Computing Regulatory Framework may impose additional requirements if you're using cloud services for data storage or processing, particularly regarding data localization and sovereignty provisions.
GOVERNING LAW
Applicable law
This Data Privacy Notice is drafted to comply with Saudi Arabia law. Key legislation includes:
PDPL Implementing Regulations: Detailed regulations that supplement the PDPL, providing specific requirements and procedures for compliance with the main law
Anti-Cyber Crime Law (Royal Decree No. M/17): Addresses cybersecurity and data protection aspects, including penalties for unauthorized access to data and breach of privacy
Cloud Computing Regulatory Framework (CCRF): Regulations by the Communications and Information Technology Commission (CITC) governing cloud computing services and data storage, including data protection requirements
National Data Governance Regulations: Framework establishing requirements for data classification, protection, and sharing within Saudi Arabia
Essential Cybersecurity Controls (ECC): Guidelines issued by the National Cybersecurity Authority (NCA) that include requirements for protecting personal data and maintaining information security
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

