Saudi Arabia's PDPL Enforcement Wave: What HR Technology Teams Must Do Now
By Tim Kreling, Co-Founder, OVI
Saudi Arabia's data protection authority is no longer issuing warnings. In January 2026, the Saudi Data & AI Authority (SDAIA) announced 48 enforcement decisions covering violations identified during 2025 — the largest single enforcement action since the Personal Data Protection Law (PDPL) took full effect on 14 September 2024 (SPA; Fyntralink).
For HR technology teams operating in Saudi Arabia — or processing data of individuals residing in the Kingdom — the message is unambiguous: the grace period is over, and the compliance gaps most common in HR tech stacks are exactly the ones SDAIA is targeting.
The Penalty Framework
The financial exposure is substantial. Administrative fines reach up to SAR 5,000,000 (approximately $1.33 million USD) per violation, doubling to SAR 10,000,000 for repeat offenses. Intentional disclosure of sensitive personal data carries criminal penalties of up to two years' imprisonment and an additional SAR 3,000,000 fine (Securiti.ai; Clyde & Co).
The 48 decisions concentrated on four violation categories: processing without a valid legal basis, unauthorized disclosure, inadequate technical and organizational safeguards, and unsolicited marketing without consent (Fyntralink; Out2Sol).
Every one of these categories intersects directly with how HR technology platforms handle candidate and employee data.
Four Compliance Traps for HR Technology Teams
1. Automated Decision-Making Without Explicit Consent
The PDPL requires explicit consent before any hiring decision made solely by automated processing — including CV screening algorithms and AI interview scoring systems. This is the sharpest compliance gap in most HR tech stacks. If your ATS ranks candidates, filters applications, or scores assessments without human review and documented consent, you are exposed (Evalufy; Clyde & Co).
Unlike GDPR, where employers frequently rely on legitimate-interests as a lawful basis for processing, the PDPL's automated-decision provisions demand explicit opt-in consent — a materially higher bar that many international platforms have not yet built into their workflows.
2. Expatriate Data as Sensitive Personal Data
Saudi Arabia's workforce is heavily expatriate-dependent. Under the PDPL, data relating to an individual's national origin qualifies as sensitive personal data. This means expatriate employee records — which inherently identify nationality, visa status, and residency — require heightened protections and explicit consent for processing (ComplianceHub Wiki; Securiti.ai).
The legitimate-interests lawful basis that many international HR vendors use as a default processing ground under GDPR is unavailable for sensitive data under the PDPL. This eliminates the path most global HRIS and ATS platforms rely on without modification.
3. The Five-Day Response Window
When SDAIA issues a violation notification, the responding entity has only five calendar days to submit a response — through an Arabic-language portal that requires a pre-authorized, certified in-Kingdom representative (Clyde & Co; ComplianceHub Wiki).
No casual email response. No extension request from a regional headquarters in Dubai or London. Organizations without a designated Saudi data protection representative and pre-registered portal access will almost certainly miss this window — converting a manageable compliance issue into a compounding penalty situation.
4. Extraterritorial Reach
The PDPL applies to any entity processing personal data of individuals residing in the Kingdom, regardless of where the processing entity is headquartered. UK recruitment agencies, EU SaaS vendors, and US ATS platforms sourcing or screening Saudi-based candidates are all within scope (ComplianceHub Wiki; Clyde & Co).
This is not theoretical. The 48 enforcement decisions signal that SDAIA has operational capacity and institutional willingness to pursue violations — a posture that parallels early GDPR enforcement by European regulators.
What to Demand from Your HR Technology Vendors
Major enterprise vendors — SAP SuccessFactors, Workday, and Oracle HCM — all operate in the Saudi market. SAP has issued KSA-specific PDPL compliance guidance in 2026, including data residency configurations and consent management modules (SAP PDPL compliance guide).
However, vendor readiness is uneven. HR technology leaders should be asking every platform vendor:
- Consent architecture: Does the platform capture and store explicit, granular consent for automated processing — not just a blanket privacy notice checkbox?
- Sensitive data classification: Can the system flag and apply heightened controls to nationality, visa, and residency data automatically?
- Data residency: Where is candidate and employee data stored, and does the vendor offer in-Kingdom or GCC-region hosting?
- Audit trail: Can you produce a documented record of every automated decision, the data inputs used, and the consent basis — within five days?
- In-Kingdom representation: Does the vendor provide or support appointment of a certified Saudi data protection representative?
What HR Technology Teams Must Do Now
The following actions are immediately relevant for any organization processing HR data in or from Saudi Arabia:
Audit every automated hiring decision point. Map where AI or algorithmic processing influences candidate outcomes — screening, scoring, ranking, rejection. Each point requires documented explicit consent under the PDPL.
Reclassify expatriate data handling. Review how nationality and residency data flows through your HR systems. Apply sensitive-data protections and ensure processing is grounded in explicit consent, not legitimate interests.
Conduct a Privacy Impact Assessment (PIA). PIAs are mandatory before deploying AI for large-scale systematic monitoring or automated decision-making. Most HR tool deployments have not completed this step (Evalufy; SDAIA AI regulation framework).
Appoint or verify your in-Kingdom representative. Ensure you have a certified, Arabic-fluent representative with active SDAIA portal access. Test the response workflow before you need it.
Review vendor PDPL commitments. Request written confirmation from every HR technology vendor on consent capture, data residency, automated-decision transparency, and sensitive-data handling specific to Saudi PDPL — not just generic GDPR documentation.
Establish a five-day incident response protocol. Build a documented response workflow that can produce a substantive Arabic-language submission within the SDAIA portal deadline.
SDAIA's Expanding Mandate
The 48 enforcement decisions are a beginning, not a culmination. SDAIA's mandate extends beyond data protection into broader AI governance — the authority is actively developing regulatory frameworks for AI systems deployed in the Kingdom, with particular attention to automated decision-making in employment and recruitment (SDAIA AI regulation framework).
For HR technology teams, this means today's PDPL compliance work is also the foundation for tomorrow's AI regulation requirements. Organizations that build transparent consent architectures, documented audit trails, and human-in-the-loop decision frameworks now will be materially better positioned as SDAIA's AI governance rules take shape.
Among AI-native ATS platforms designed for GCC hiring workflows, OVI exemplifies this approach — operating with a human-in-the-loop architecture where AI provides decision-support through audio-only screening while final hiring decisions remain with the recruiter, with no biometric or voice-characteristic analysis. OVI's compliance posture aligns with Saudi PDPL requirements alongside GDPR and UAE PDPL frameworks, with documented consent flows and audit trails built into the platform (ovi-me.com/standards).
What is Saudi Arabia's PDPL and when did enforcement begin?
The Personal Data Protection Law (PDPL) is Saudi Arabia's comprehensive data privacy regulation, enforced by the Saudi Data & AI Authority (SDAIA). Full enforcement began on 14 September 2024 after a transitional grace period. In January 2026, SDAIA announced 48 enforcement decisions — the first major wave of penalties — signaling active, operational enforcement capacity.
What are the penalties for PDPL violations?
Administrative fines reach up to SAR 5,000,000 (approximately $1.33 million USD) per violation, doubling to SAR 10,000,000 for repeat offenses. Intentional disclosure of sensitive personal data can result in criminal penalties including up to two years' imprisonment and an additional SAR 3,000,000 fine.
Does the PDPL apply to companies outside Saudi Arabia?
Yes. The PDPL has extraterritorial reach — any entity processing personal data of individuals residing in the Kingdom is within scope, regardless of where the company is headquartered. This includes UK recruitment agencies, EU HR SaaS vendors, and US applicant tracking systems processing Saudi-based candidate data.
How does the PDPL affect AI-powered hiring tools?
The PDPL requires explicit consent before any hiring decision made solely by automated processing. This covers CV screening algorithms, AI interview scoring, and automated candidate ranking. Organizations must conduct a Privacy Impact Assessment before deploying AI for automated decision-making in hiring, and must maintain documented audit trails for every automated decision.
What makes Saudi PDPL compliance different from GDPR compliance?
Key differences include: the legitimate-interests lawful basis is unavailable for sensitive data (eliminating the default path most EU vendors rely on), the response window for violations is only five calendar days (versus GDPR's more flexible timeline), responses must go through an Arabic-language portal via a certified in-Kingdom representative, and expatriate data — inherently identifying nationality — qualifies as sensitive personal data requiring heightened protections.