Introduction: PDPL Breach Notification — Why It Matters
Saudi Arabia’s Personal Data Protection Law (PDPL) sets a defined process for qualifying personal-data breaches. The PDPL breach notification requirement can require a Controller to notify the competent authority within 72 hours of becoming aware of an incident when it may harm personal data, a Data Subject, or their rights and interests.
PDPL Breach Notification: The 72-Hour Rule
Under Article 24, a Controller must notify the competent authority within no more than 72 hours of becoming aware of a personal-data breach if the incident potentially causes harm to personal data or a Data Subject, or conflicts with their rights or interests.
SDAIA’s official notification service confirms the deadline and provides an online process through the National Data Governance Platform. Rapid incident assessment is therefore essential once a potentially reportable breach is discovered.
What must the notification include?
A PDPL breach notification should provide the authority with enough information to understand the incident and its impact:
- Breach date, time, circumstances, and discovery time.
- Data categories and types involved.
- Actual or approximate numbers of affected Data Subjects.
- Actual or potential risks and impacts.
- Measures taken to contain or mitigate risks.
- Future measures planned to prevent recurrence.
- Whether Data Subjects have been notified.
- Relevant Controller or Data Protection Officer contact details.
If some information is unavailable within 72 hours, it can be submitted as soon as possible with reasons for the delay.
When Must Data Subjects Be Notified?
Regulatory notification and individual notification are separate obligations. A Controller must notify Data Subjects without undue delay when a breach may damage their personal data or conflict with their rights or interests.
The notice should explain the breach, potential risks, measures taken, contact details, and recommendations that can help individuals reduce the impact.
PDPL Breach Reporting: What Businesses Should Do First
A documented response process can help organizations meet the deadline while maintaining accuracy. Businesses should:
- Activate the incident-response team and record when the incident became known.
- Contain the incident while preserving logs, records, and evidence.
- Identify affected data categories and Data Subjects.
- Assess potential harm and risks to individuals.
- Prepare required notifications and identify missing information.
- Document corrective measures and retain supporting evidence.
CyberNexora’s Learn & Protect resources and Laws & Government coverage provide related security and regulatory guidance.
Regulatory and Compliance Risks
Article 24 requires Controllers to retain copies of submitted reports and document corrective measures and relevant supporting evidence. The 72-hour rule is not necessarily the only reporting duty: other requirements issued by Saudi Arabia’s National Cybersecurity Authority or applicable laws and regulations may also apply.
For broader incident coverage, readers can follow CyberNexora’s Cyber Incidents section.
How Organizations Can Prepare for a 72-Hour Deadline
A breach-response plan should include:
- Assigned security, privacy, legal, and compliance responsibilities.
- A clear escalation path for suspected breaches.
- A method for recording incident discovery times.
- Current personal-data inventories and processing records.
- Notification templates and evidence-preservation procedures.
- Regular testing of the response process.
Testing these procedures before an incident can reduce response delays.
Official Reporting Process
SDAIA provides a Personal Data Breach Notification service through the National Data Governance Platform. Organizations can log in, select the service, complete the notification form, and submit it.
The SDAIA Personal Data Protection Law and Implementing Regulation should be used as the primary regulatory reference when assessing reporting duties.
Key Takeaways
- Qualifying personal-data breaches may trigger a 72-hour notification deadline.
- The period starts when the Controller becomes aware of the incident.
- Notifications should cover the breach, affected data, risks, mitigation, and contacts.
- Data Subjects may also need notification without undue delay.
- Controllers must document corrective actions and retain evidence.
- Other Saudi reporting requirements may also apply.
Conclusion: PDPL Breach Notification and What Happens Next
The Saudi PDPL breach notification framework gives organizations a defined timeline for qualifying personal-data incidents. The 72-hour requirement makes early detection, escalation, and accurate records essential to privacy compliance.
Organizations should review and test their breach-response procedures before an incident occurs. Readers can monitor CyberNexora’s Cyber Incidents coverage for relevant developments.
Frequently Asked Questions(FAQs)
PDPL requires notifying the UAE Data Office within 72 hours of a breach that may affect the privacy, confidentiality, or security of personal data.
The UAE Data Office, and affected data subjects where the breach poses a significant risk to them.
The nature of the breach, data categories affected, likely consequences, and the measures taken to address it.
Yes. CBUAE-licensed banks and fintechs must report significant cyber incidents within 24 hours.
With a documented, tested breach response plan. A security assessment (offered free initially by providers including CyberNexora helps validate readiness.
