Skip to content

Evidence request lists

Saudi Arabia PDPL

Evidence request list. 37 controls, 37 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Breach

SAUDIPDPL-8
Breach Notification, Sanctions, Enforcement

Per Saudi PDPL: breach notification to SDAIA + affected subjects + enforcement awareness including penalties.

Artefacts an auditor will ask for
  • SA PDPL evidence for SAUDIPDPL-8
Where this commonly fails
  • SDAIA notification + DPO + breach partial

Collection, Notice and Lawful Basis

SA-PDPL-01
Notice and transparency requirements

Notice and transparency requirements. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Collection & Consent.

Artefacts an auditor will ask for
  • privacy notice document
  • layered notice templates
  • notice delivery logs
  • language localization records
Where this commonly fails
  • notice not provided at collection point
  • missing Arabic language version
  • incomplete purpose disclosure
SA-PDPL-02
Consent management and withdrawal

Consent management and withdrawal. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Collection & Consent.

Artefacts an auditor will ask for
  • consent capture records
  • consent withdrawal workflow
  • consent registry
  • preference center logs
Where this commonly fails
  • no granular consent options
  • withdrawal mechanism harder than opt-in
  • stale consent records
SA-PDPL-03
Lawful basis for processing

Lawful basis for processing. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Collection & Consent.

Artefacts an auditor will ask for
  • lawful basis register
  • processing inventory
  • legitimate interest assessments
  • legal basis decision logs
Where this commonly fails
  • lawful basis not documented per activity
  • basis switching without notice
  • missing LIA records
SA-PDPL-04
Purpose limitation and specification

Purpose limitation and specification. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Collection & Consent.

Artefacts an auditor will ask for
  • purpose specification register
  • compatibility assessments
  • secondary use approvals
  • processing scope documentation
Where this commonly fails
  • vague purpose statements
  • scope creep without reassessment
  • no compatibility checks
SA-PDPL-05
Data minimization requirements

Data minimization requirements. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Collection & Consent.

Artefacts an auditor will ask for
  • data minimization assessments
  • field-level necessity reviews
  • data inventory mapping
  • retention schedules
Where this commonly fails
  • over-collection of fields
  • no periodic minimization review
  • missing necessity justification

Consent

SAUDIPDPL-2
Consent, Notice, Sensitive Data

Per Saudi PDPL: consent + notice + sensitive data. Requirements include (a) Consent requirements + (b) Privacy notices + (c) Sensitive personal data safeguards + (d) Special protection for health + biometric + criminal records.

Artefacts an auditor will ask for
  • SA PDPL evidence for SAUDIPDPL-2
Where this commonly fails
  • SDAIA notification + DPO + breach partial

Cross-Border

SAUDIPDPL-6
Cross-Border Transfer

Per Saudi PDPL: cross-border transfer restrictions with adequacy + safeguards + consent + national security exceptions.

Artefacts an auditor will ask for
  • SA PDPL evidence for SAUDIPDPL-6
Where this commonly fails
  • SDAIA notification + DPO + breach partial

Data Subject Rights

SA-PDPL-06
Right of access to personal data

Right of access to personal data. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • DSAR procedure
  • access request log
  • identity verification records
  • response templates
Where this commonly fails
  • no defined SLA
  • weak identity verification
  • incomplete data returned
SA-PDPL-07
Right to rectification of inaccurate data

Right to rectification of inaccurate data. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • rectification request log
  • data correction workflow
  • downstream propagation records
  • accuracy review reports
Where this commonly fails
  • corrections not propagated to processors
  • no audit trail of edits
  • delayed response
SA-PDPL-08
Right to erasure and deletion

Right to erasure and deletion. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • deletion request log
  • erasure workflow
  • secure disposal records
  • backup deletion procedures
Where this commonly fails
  • backups not purged
  • third party copies not deleted
  • no deletion confirmation
SA-PDPL-09
Right to data portability

Right to data portability. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • portability request log
  • export format documentation
  • machine-readable export procedure
  • delivery confirmation
Where this commonly fails
  • proprietary export formats only
  • no automated portability
  • scope misalignment
SA-PDPL-10
Right to restrict processing

Right to restrict processing. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • restriction request log
  • processing flag registry
  • system access controls
  • restriction lifting procedure
Where this commonly fails
  • no system-level restriction flag
  • automated processing continues
  • restriction not auditable
SA-PDPL-11
Right to object to processing

Right to object to processing. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • objection request log
  • marketing suppression list
  • objection response templates
  • balancing test records
Where this commonly fails
  • objection not honored across systems
  • no suppression sync
  • missing balancing analysis
SA-PDPL-12
Automated decision-making protections

Automated decision-making protections. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Subject Rights.

Artefacts an auditor will ask for
  • ADM inventory
  • human review procedure
  • logic disclosure documents
  • impact assessment records
Where this commonly fails
  • no human review path
  • opaque decision logic
  • no notification to subjects

Governance

SAUDIPDPL-7
DPO, Registration, Governance

Per Saudi PDPL + IR: DPO designation + Registration with SDAIA where required + governance.

Artefacts an auditor will ask for
  • SA PDPL evidence for SAUDIPDPL-7
Where this commonly fails
  • SDAIA notification + DPO + breach partial

Governance and Accountability

SA-PDPL-19
Data protection officer designation

Data protection officer designation. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Governance.

Artefacts an auditor will ask for
  • DPO appointment letter
  • DPO job description
  • DPO contact disclosure
  • independence documentation
Where this commonly fails
  • DPO not registered with SDAIA
  • conflicting duties
  • insufficient authority
SA-PDPL-20
Records of processing activities

Records of processing activities. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Governance.

Artefacts an auditor will ask for
  • ROPA registry
  • processing activity templates
  • annual review records
  • controller and processor inventories
Where this commonly fails
  • incomplete inventory
  • outdated entries
  • missing processor mapping
SA-PDPL-21
Data protection impact assessments

Data protection impact assessments. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Governance.

Artefacts an auditor will ask for
  • DPIA templates
  • DPIA register
  • consultation records
  • mitigation plans
Where this commonly fails
  • DPIA not triggered for high-risk activities
  • no consultation with DPO
  • outdated assessments
SA-PDPL-22
Privacy by design and default

Privacy by design and default. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Governance.

Artefacts an auditor will ask for
  • privacy by design checklist
  • default settings review
  • design review records
  • engineering guidelines
Where this commonly fails
  • privacy not in SDLC
  • permissive defaults
  • no privacy gates
SA-PDPL-23
Data processing agreements

Data processing agreements. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Governance.

Artefacts an auditor will ask for
  • data processing agreements
  • vendor inventory
  • processor audit reports
  • subprocessor approvals
Where this commonly fails
  • missing DPA clauses
  • no subprocessor list
  • no audit rights
SA-PDPL-24
Cross-border transfer safeguards

Cross-border transfer safeguards. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Governance.

Artefacts an auditor will ask for
  • transfer impact assessments
  • adequacy decisions register
  • standard contractual clauses
  • SDAIA approval records
Where this commonly fails
  • transfers without TIA
  • no SDAIA approval where required
  • missing safeguard documentation

High-Risk

SAUDIPDPL-4
Sensitive Data, Children, DPIA

Per Saudi PDPL: heightened safeguards including children + DPIA + privacy by design.

Artefacts an auditor will ask for
  • SA PDPL evidence for SAUDIPDPL-4
Where this commonly fails
  • SDAIA notification + DPO + breach partial

Monitoring, Cooperation and Enforcement

SA-PDPL-25
Compliance monitoring and auditing

Compliance monitoring and auditing. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Accountability & Compliance.

Artefacts an auditor will ask for
  • audit plan
  • audit reports
  • compliance dashboards
  • corrective action tracking
Where this commonly fails
  • audits not risk-based
  • findings not closed
  • no executive reporting
SA-PDPL-26
Training and awareness programs

Training and awareness programs. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Accountability & Compliance.

Artefacts an auditor will ask for
  • training curriculum
  • completion records
  • role-based modules
  • phishing simulation results
Where this commonly fails
  • one-size training
  • low completion
  • no role-based content
SA-PDPL-27
Regulatory reporting and cooperation

Regulatory reporting and cooperation. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Accountability & Compliance.

Artefacts an auditor will ask for
  • SDAIA correspondence log
  • regulatory reports
  • registration records
  • cooperation procedures
Where this commonly fails
  • delayed responses to SDAIA
  • missing registrations
  • incomplete reports
SA-PDPL-28
Complaints handling and resolution

Complaints handling and resolution. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Accountability & Compliance.

Artefacts an auditor will ask for
  • complaints procedure
  • complaints register
  • resolution tracking
  • escalation pathways
Where this commonly fails
  • no SLA on complaints
  • missing escalation to SDAIA
  • no root-cause analysis
SA-PDPL-29
Enforcement and penalties awareness

Enforcement and penalties awareness. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Accountability & Compliance.

Artefacts an auditor will ask for
  • enforcement risk register
  • penalty schedule reference
  • executive briefings
  • compliance scorecard
Where this commonly fails
  • no awareness of penalties
  • no board reporting
  • missing remediation prioritization

Rights

SAUDIPDPL-3
Data Subject Rights

Per Saudi PDPL: data subject rights including access + rectification + erasure + portability + restriction.

Artefacts an auditor will ask for
  • SA PDPL evidence for SAUDIPDPL-3
Where this commonly fails
  • SDAIA notification + DPO + breach partial

Scope

SAUDIPDPL-1
Scope, Lawful Basis, Definitions

Per Saudi Arabia PDPL (Royal Decree M/19 of 2021 + Amendment 2023 + Implementing Regulations 2023): scope. Requirements include (a) determine applicability + (b) Lawful Basis for Processing per the Law + (c) align with SDAIA (Saudi Data and AI Authority) guidance + (d) document applicability.

Artefacts an auditor will ask for
  • SA PDPL evidence for SAUDIPDPL-1
Where this commonly fails
  • SDAIA notification + DPO + breach partial

Security

SAUDIPDPL-5
Security of Processing

Per Saudi PDPL + NCA: security per Essential Cybersecurity Controls + appropriate to risk.

Artefacts an auditor will ask for
  • SA PDPL evidence for SAUDIPDPL-5
Where this commonly fails
  • SDAIA notification + DPO + breach partial

Security of Processing

SA-PDPL-13
Encryption of personal data

Encryption of personal data. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Security.

Artefacts an auditor will ask for
  • encryption policy
  • key management procedures
  • encryption inventory
  • algorithm review records
Where this commonly fails
  • data at rest unencrypted
  • weak key management
  • legacy algorithms in use
SA-PDPL-14
Pseudonymization techniques

Pseudonymization techniques. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Security.

Artefacts an auditor will ask for
  • pseudonymization procedure
  • key separation documentation
  • re-identification risk assessment
  • tokenization registry
Where this commonly fails
  • reversible mapping accessible
  • no risk assessment
  • weak separation of keys
SA-PDPL-15
Access control for personal data

Access control for personal data. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Security.

Artefacts an auditor will ask for
  • access control matrix
  • RBAC documentation
  • access review reports
  • privileged access logs
Where this commonly fails
  • over-privileged accounts
  • stale access not removed
  • no periodic review
SA-PDPL-16
Data breach notification requirements

Data breach notification requirements. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Security.

Artefacts an auditor will ask for
  • breach notification procedure
  • SDAIA notification templates
  • breach register
  • data subject notification log
Where this commonly fails
  • 72-hour window missed
  • incomplete breach details
  • subjects not notified when required
SA-PDPL-17
Security incident response procedures

Security incident response procedures. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Security.

Artefacts an auditor will ask for
  • incident response plan
  • Playbooks
  • incident log
  • post-incident reviews
Where this commonly fails
  • no tabletop exercises
  • outdated runbooks
  • missing escalation paths
SA-PDPL-18
Regular security testing and assessment

Regular security testing and assessment. Control from Saudi Arabia PDPL framework, domain: Saudi Arabia PDPL: Data Security.

Artefacts an auditor will ask for
  • penetration test reports
  • vulnerability scan results
  • remediation tracking
  • test schedule
Where this commonly fails
  • infrequent testing
  • remediation backlog
  • scope gaps
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Saudi Arabia PDPL framework page.