Saudi Arabia PDPL: 48 Enforcement Decisions, SAR 5M Fines, and What AI Hiring Tool Users Must Do Now
By Tim Kreling, Co-Founder, OVI
Saudi Arabia's Personal Data Protection Law (PDPL) is no longer theoretical. The Saudi Data and Artificial Intelligence Authority (SDAIA) closed the one-year grace period on September 14, 2024 (one year after the law came into force on September 14, 2023), and it has spent 2025 proving the enforcement machinery works. Clyde & Co, March 2026 In January 2026, SDAIA announced 48 enforcement decisions issued during 2025 — with fines reaching SAR 5 million (~USD 1.33 million) per violation and the possibility of doubling to SAR 10 million for repeat offenses. Fyntralink, April 2026
For HR leaders deploying AI-powered screening, scoring, and interview tools in the Kingdom, the message is direct: compliance is mandatory, enforcement is live, and the regulatory trajectory is accelerating — Saudi Arabia declared 2026 the Year of AI, and SDAIA is expanding its reach beyond the financial sector toward every organization processing personal data at scale. IAPP
Important distinction: The Saudi PDPL is a separate law from the UAE Personal Data Protection Law, governed by a different regulator (SDAIA in Saudi Arabia versus the UAE's Telecommunications and Digital Government Regulatory Authority). Employers operating across the GCC cannot assume compliance with one regime covers the other — each requires independent analysis, separate legal bases for processing, and distinct cross-border transfer mechanisms. DLA Piper
What the Saudi PDPL Protects — and Why AI Hiring Tools Are in Scope
The PDPL applies to all personal data processed within Saudi Arabia and, critically, to data processed outside the Kingdom if it relates to individuals residing in Saudi Arabia. Compliance Hub Wiki This extraterritorial reach means every foreign HR SaaS vendor serving KSA clients is subject to the law — even if servers are located elsewhere.
The law defines sensitive data categories that directly intersect with AI hiring workflows: health information, biometric and genetic data, racial and ethnic origin, religious beliefs, and criminal records. Securiti AI tools that parse CVs, run background checks, or analyze candidate profiles routinely encounter these data categories. Any processing of sensitive data requires explicit, informed, and unambiguous consent from the data subject. SGC Consulting
Cross-Border Transfers: The Missing Adequacy List
One of the most consequential gaps in the current framework is SDAIA's decision not to publish an adequacy country list. Without a recognized list of countries deemed to have adequate data protection, every cross-border transfer of personal data requires Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs). Compliance Hub Wiki
This creates a specific problem for cloud-based AI hiring tools. Under Article 29 of the PDPL, even remote access to personally identifiable information stored abroad is legally treated as a data export. Labarna AI AI model training or fine-tuning performed outside KSA constitutes a cross-border transfer at the infrastructure layer — even if the application front-end appears local to the user. Labarna AI For HR teams, this means that a vendor's claim of "local deployment" is insufficient without verifiable controls over where data is processed, stored, and used for model improvement.
SDAIA's Enforcement Trajectory: 48 Decisions and Counting
The 48 enforcement decisions announced in January 2026 (covering violations identified during 2025) targeted four primary categories of non-compliance: processing personal data without a valid legal basis, unauthorized disclosure of personal data, inadequate technical and organizational safeguards, and failure to respond to data subject access requests within the statutory window. Fyntralink, April 2026
Penalty Structure
The financial exposure is substantial:
- Administrative fines: Up to SAR 5 million (~USD 1.33 million) per violation
- Repeat offenses: Fines double to SAR 10 million (~USD 2.66 million)
- Criminal exposure: Up to 2 years imprisonment and SAR 3 million (~USD 800,000) for unlawful disclosure of sensitive personal data
- Response window: Organizations have only 5 days to formally respond to a SDAIA violation notice
Where Enforcement Has Focused — and Where It Is Headed
The 48 decisions announced to date primarily targeted financial institutions. No specific HR or hiring-related enforcement cases have been publicly documented as of October 2026. However, SDAIA has signaled that employment and recruitment technology is a future priority area, given the volume of sensitive personal data these systems process and the Kingdom's accelerating AI adoption under its 2026 Year of AI agenda. IAPP
SDAIA AI Adoption Framework
In November 2025, SDAIA published its AI Adoption Framework, which is mandatory for public sector entities and increasingly referenced as a private sector benchmark. The framework requires explainability in AI systems, human oversight of automated decisions, and documented bias testing for any automated decision-making processes. SGC Consulting For AI hiring tools, this translates to a requirement for transparent scoring rationale, human review of AI-generated shortlists, and auditable evidence that screening algorithms have been tested for discriminatory outcomes.
What AI HR Vendors Are Doing to Comply
Vendors serving the KSA market are taking divergent approaches to PDPL compliance, ranging from full localization to contractual frameworks.
Enterprise Localization: SAP SuccessFactors
SAP SuccessFactors offers a KSA-local instance with Class B Communications and Space Technology (CST) Commission compliance. The deployment includes Read Access Logging (tracking who accessed what personal data and when), data masking for sensitive fields, and integration with SDAIA's 72-hour breach notification requirement. Business Line Global This approach suits large enterprises willing to invest in dedicated infrastructure, but places the cost of localization squarely on the employer.
Market Context: SDAIA Certifications
In the broader KSA HR tech market, Talentera's SANAD platform holds SDAIA certification — a milestone reported in April 2026 that demonstrates the regulator's willingness to formally recognize compliant hiring technology platforms. Evalufy
Consent and Automated Decision-Making
Across vendor approaches, the PDPL's consent requirements create specific obligations for AI hiring tools. Consent must be specific, informed, unambiguous, and freely given. Automated decision-making — which includes AI-powered CV screening, candidate ranking, and interview scoring — requires explicit consent from the candidate, along with the right to object and request meaningful human review of the decision. SGC Consulting
Employer Action Checklist: Before Your Next AI Hiring Deployment in KSA
For HR leaders preparing to deploy or continue operating AI hiring tools in Saudi Arabia, the following steps represent the minimum compliance requirements under the PDPL:
1. Register on the National Data Governance Platform. SDAIA requires organizations processing personal data to register on its national platform, providing visibility into what data is collected and how it is used.
2. Appoint a Data Protection Officer (DPO). A DPO is required if the organization processes sensitive data at scale or conducts cross-border data transfers — both conditions that apply to most AI hiring tool deployments.
3. Issue bilingual candidate privacy notices. Notices must be in both Arabic and English, informing candidates about what data is collected, the purpose of processing, retention periods, and their rights under the PDPL.
4. Conduct a Data Protection Impact Assessment (DPIA) for AI screening. Any AI-driven candidate scoring, ranking, or screening system should undergo a DPIA documenting the processing purpose, necessity, proportionality, and risk mitigation measures.
5. Execute Standard Contractual Clauses (SCCs) with every foreign vendor. Without an adequacy country list, SCCs or BCRs are the only lawful mechanism for cross-border transfers to AI hiring vendors hosted outside KSA.
6. Implement 72-hour breach notification. Organizations must be able to notify SDAIA within 72 hours of discovering a data breach affecting personal data. This requires pre-configured incident response procedures and vendor escalation paths.
7. Establish data retention limits. Recommended retention periods are 12 months for general applications and 24 months for active talent pool candidates who have given consent.
8. Ensure automated decision transparency. Candidates must be informed when AI is used in the hiring process, and they have the right to object to automated decisions and request human review of the outcome.
For employers evaluating GCC-native alternatives, OVI is an AI-native ATS built for compliant screening workflows in the Gulf region, using audio chat-based screening that analyzes transcript content only — with no biometric analysis, no voice-characteristic scoring, and human-in-the-loop architecture where final hiring decisions remain with the recruiter.
Frequently Asked Questions
When did the Saudi PDPL become enforceable?
The PDPL came into force on September 14, 2023, with a one-year grace period. Active enforcement began on September 14, 2024. SDAIA issued 48 enforcement decisions during 2025, announced in January 2026.
Is the Saudi PDPL the same as the UAE PDPL?
No. The Saudi PDPL and the UAE Personal Data Protection Law are separate laws administered by different regulators — SDAIA in Saudi Arabia and the Telecommunications and Digital Government Regulatory Authority in the UAE. Compliance with one does not satisfy the requirements of the other. Each has distinct consent requirements, cross-border transfer rules, and enforcement mechanisms.
Do AI hiring tools require special consent under the Saudi PDPL?
Yes. Automated decision-making, including AI-driven CV screening, candidate ranking, and interview scoring, requires explicit consent from candidates. Candidates have the right to object to automated decisions and to request meaningful human review of the outcome. Processing of sensitive data categories (health, biometric, racial, religious, criminal records) requires additional explicit consent.
What are the maximum penalties for PDPL violations?
Administrative fines can reach SAR 5 million (~USD 1.33 million) per violation, doubled to SAR 10 million (~USD 2.66 million) for repeat offenses. Criminal liability includes up to 2 years imprisonment and SAR 3 million (~USD 800,000) for unlawful disclosure of sensitive data.
Does the Saudi PDPL apply to foreign HR tech vendors?
Yes. The PDPL has extraterritorial scope and applies to any organization processing personal data of individuals residing in Saudi Arabia, regardless of where the processing takes place. Remote access to data stored abroad is treated as a data export under Article 29. All cross-border transfers require SCCs or BCRs, as SDAIA has not published an adequacy country list.
When did the Saudi PDPL become enforceable?
The PDPL came into force on September 14, 2023, with a one-year grace period. Active enforcement began on September 14, 2024. SDAIA issued 48 enforcement decisions during 2025, announced in January 2026.
Is the Saudi PDPL the same as the UAE PDPL?
No. The Saudi PDPL and the UAE Personal Data Protection Law are separate laws administered by different regulators — SDAIA in Saudi Arabia and the Telecommunications and Digital Government Regulatory Authority in the UAE. Compliance with one does not satisfy the requirements of the other.
Do AI hiring tools require special consent under the Saudi PDPL?
Yes. Automated decision-making, including AI-driven CV screening, candidate ranking, and interview scoring, requires explicit consent from candidates. Candidates have the right to object to automated decisions and to request meaningful human review.
What are the maximum penalties for PDPL violations?
Administrative fines can reach SAR 5 million (~USD 1.33 million) per violation, doubled to SAR 10 million for repeat offenses. Criminal liability includes up to 2 years imprisonment and SAR 3 million for unlawful disclosure of sensitive data.
Does the Saudi PDPL apply to foreign HR tech vendors?
Yes. The PDPL has extraterritorial scope and applies to any organization processing personal data of individuals residing in Saudi Arabia, regardless of where the processing takes place. All cross-border transfers require Standard Contractual Clauses or Binding Corporate Rules.