PDPL Readiness Checklist
Review lawful basis, rights and security. Article 36 permits a warning or fine up to SAR 5 million for covered violations.
1. Lawful basis & notice
- Identify a lawful basis for every processing activity.
- Publish a PDPL-aligned privacy notice (purpose, data, retention, rights, contact).
- Where cookie processing relies on consent, obtain it before processing without preselected choices.
2. Consent & rights
- Consent is specific, informed, and withdrawable.
- Obtain marketing consent and provide a clear opt-out.
- A working process to handle data-subject requests (access, correction, deletion).
3. Records & governance
- Maintain a Record of Processing Activities (RoPA).
- Assess DPO appointment under the effective rules; do not treat a proposed amendment as binding.
- Ability to respond to SDAIA inquiries within the statutory window.
4. Security
- Technical + organizational safeguards proportionate to risk.
- Data classification applied before storage/hosting.
- Prepare SDAIA notification within 72 hours of awareness where a breach may harm personal data or subjects, or conflict with their rights or interests.
5. Cross-border transfers
- Verify any destination adequacy decision directly; this review did not locate a published list.
- Select the transfer route and safeguard with its conditions; SCCs, Binding Common Rules and accreditation are not interchangeable for every case.
- Complete risk assessment before Article 4 transfers and continuous or large-scale sensitive-data transfers.
6. Vendors
- Processor agreements with PDPL clauses.
- Sub-processor controls and locations documented.
Sources: SDAIA PDPL; Implementing Regulation Article 24; Transfer Regulation Version 2 (August 2024), Articles 4 and 7. Official links are in the hosting guide.