Saudi Arabia PDPL
What is Saudi Arabia PDPL?
Saudi Arabia Personal Data Protection Law. It comprises 8 controls organised across 8 domains, and applies in Saudi Arabia.
How Saudi Arabia PDPL maps to other frameworks
All 8 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains Saudi Arabia PDPL groups its controls into
Frameworks that share controls with Saudi Arabia PDPL
Each of these has at least one control mapped to a control in Saudi Arabia PDPL. The number is how many Saudi Arabia PDPL controls are shared, counted from the mapping graph.
Virginia CDPA
13 shared controlsUruguay DPL
13 shared controlsTexas Data Privacy Act
13 shared controlsTaiwan PDPA
13 shared controlsUK GDPR (UK General Data Protection Regulation)
9 shared controlsUK AI Regulation Framework
8 shared controlsFTC GLBA Safeguards Rule (16 CFR Part 314)
8 shared controlsTrinidad and Tobago Data Protection Act 2011
7 shared controlsWhere Saudi Arabia PDPL overlaps with the standards you already hold
What Saudi Arabia PDPL means in your sector
What Saudi Arabia PDPL means for your job
Questions people ask about Saudi Arabia PDPL
What is Saudi Arabia PDPL?
How many controls does Saudi Arabia PDPL have?
Where does Saudi Arabia PDPL apply?
How do I get started with Saudi Arabia PDPL compliance?
Query Saudi Arabia PDPL programmatically
Saudi Arabia PDPL, its 8 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
Saudi Arabia PDPL API reference and MCP config →What Saudi Arabia PDPL requires, control by control
Each page carries the requirement text for one Saudi Arabia PDPL control and what an assessor expects to see as evidence.
- SA-PDPL-09 Right to data portability
- SA-PDPL-13 Encryption of personal data
- SA-PDPL-15 Access control for personal data
- SA-PDPL-16 Data breach notification requirements
- SA-PDPL-17 Security incident response procedures
- SA-PDPL-18 Regular security testing and assessment
- SA-PDPL-19 Data protection officer designation
- SA-PDPL-20 Records of processing activities
- SA-PDPL-21 Data protection impact assessments
- SA-PDPL-22 Privacy by design and default
How ready are you for Saudi Arabia PDPL?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.