• Sectors we work in banner(2)

    Quick Reads

Safeguarding Data Privacy: Saudi Arabia's New Rules for Personal Data Protection Officers

min read

Following the implementation of the Kingdom of Saudi Arabia’s (KSA) new Personal Data Protection Law (PDPL), the Saudi Data & AI Authority (SDAIA) has issued new rules for appointing Personal Data Protection Officers (DPOs). This represents a significant step in reinforcing data protection and privacy in Saudi Arabia. These rules are designed to align with international best practices and to ensure that entities processing personal data are doing so in a manner that respects individual rights and complies with the PDPL.

The requirement for certain data controllers to appoint a DPO is in line with similar requirements in other jurisdictions, such as the European Union's General Data Protection Regulation (GDPR). The criteria set forth for determining what constitutes large-scale processing and regular and systematic monitoring are crucial for controllers to understand whether they fall under the obligation to appoint a DPO.

DPO Requirements

The emphasis on the qualifications of the DPO, including academic background, experience, and knowledge of data protection and risk management, underscores the importance of the role. The DPO is not just a nominal position but is expected to have a substantive impact on the controller's data protection practices.

The flexibility in allowing the DPO to be either an employee or an external contractor provides controllers with the ability to choose the best arrangement for their operations. However, regardless of the employment status, the DPO's contact details must be made available to both the SDAIA and data subjects, a measure intended to enhance transparency and accountability.

The detailed roles and tasks of the DPO, including policy advising, contributing to data breach response plans, and monitoring regulatory updates, show that the DPO is expected to be actively involved in all aspects of data protection within their organisations.

The requirement for controllers to support the DPO with necessary resources and ensure their independence is also critical. It is envisaged that this will assist with preventing conflicts of interest and will also ensure that the DPO can perform their duties without undue influence from the controller.

Looking Ahead

The encouragement of training and professional development for DPOs is a forward-thinking approach that recognises the evolving nature of data protection laws and practices in the Kingdom. These new rules represent a comprehensive approach to data protection governance, ensuring that entities in KSA are held to a high standard when it comes to handling personal data.

Organisations should consider undertaking a review of their data policies and procedures to ensure that they are in compliance with KSA legislation.

Our thinking

  • IBA Annual Conference 2026

    Jean-Baptiste Beauvoir-Planson

    Events

  • In-House Insights: Next Gen Drinks Reception

    Events

    min read
  • The UAE's New Civil Code: Implications for Construction Contracts

    Maher Al Nashar

    Events

    min read
  • Claudine Morgan, Hannah Gornall and Ellen Roberts write in New Law Journal about the implications of a landmark anti-SLAPP judgment

    Claudine Morgan

    In the Press

    min read
  • India-UAE BIT 2024: What to Expect When You’re Investing

    Thomas R. Snider

    Insights

    min read
  • Charles Russell Speechlys advises long standing client SPS on its acquisition of Cleardata

    Hamish Perry

    News

    min read
  • The Increased Expedited Procedure Threshold under the 2026 ICC Rules: What Does It Mean for Mid-Value Construction Disputes in the UAE?

    Glenn Bull

    Insights

    min read
  • Darren Bailey sits on the judging panel for City AM's Football Power List

    Darren Bailey

    In the Press

    min read
  • Charles Russell Speechlys LLP, as Liquidator of Awal Bank BSC(c) (In Liquidation), welcomes Bahraini Court judgment upholding liquidator’s rejection of US$2.8 billion of claims and confirming debts owing to Awal Bank of US$2.56 billion

    Patrick Gearon FCIArb

    News

    min read
  • New 2026 ICC Rules of Arbitration: what’s changed and what it means

    Thomas R. Snider

    Insights

    min read
  • The Dubai Conflicts of Jurisdiction Tribunal Continues to Define the Boundaries of DIFC and Onshore Dubai Court Jurisdiction in Arbitral Award Recognition and Enforcement

    Thomas R. Snider

    Insights

    min read
  • Disputes Over Donuts: Spotlight on the ICC Arbitration Rules 2026

    Thomas R. Snider

    Podcasts

  • The New UAE Civil Code: A Series Overview

    Glenn Bull

    Insights

    min read
  • Charles Russell Speechlys appoints corporate and private equity specialist in London

    David Collins

    News

    min read
  • Charles Russell Speechlys has advised the founders of legal technology business, Obviously, on its sale to AIM listed RWS, a global AI solutions company

    Mark Howard

    News

    min read
  • New Swiss succession law on the transfer of businesses

    Grégoire Uldry

    Insights

    min read
  • Paula Boast MBE comments on the UK-GCC free trade agreement in Gulf Daily News

    Paula Boast MBE

    In the Press

    min read
  • Extra Time: Evolution of Technology in Sport

    Anna Sowerby

    Podcasts

  • Mark Bailey reflects on the UK's planned Cyber Security Bill in Security Brief and Ecommerce News

    Mark Bailey

    In the Press

    min read
  • Functional Food and Drink in 2025: Why Gut Health and Cognitive Performance are Driving UK M&A

    Imogen Brown

    Insights

    min read
Back to top