GDPR

What Is PDPL? A Guide to Personal Data Protection Laws

  • Data Protection
  • Data Governance
  • Privacy

PDPL stands for Personal Data Protection Law. Like PDPA, it is a name several legislatures have arrived at independently, so the acronym alone does not tell you which law is meant. In most international contexts PDPL refers to Saudi Arabia’s law, which is the largest and most actively enforced of the group. Bahrain, Oman, Jordan, the UAE and Vietnam also have statutes called the PDPL, and they differ in scope, in regulator, and in how far along enforcement has got.

This guide covers each of them: what the law requires, who enforces it, what the penalties are, and where the differences are large enough to matter.

Last reviewed: September 2026.

What does PDPL stand for?

Personal Data Protection Law. Several jurisdictions use the term for their principal data protection statute:

Jurisdiction Statute In force Regulator
Saudi Arabia Royal Decree M/19 (2021), amended by M/148 (2023) 14 September 2023; enforced from 14 September 2024 Saudi Data and AI Authority (SDAIA)
Bahrain Law No. 30 of 2018 1 August 2019 Personal Data Protection Authority, under the Ministry of Justice and Islamic Affairs
Oman Royal Decree No. 6/2022 13 February 2023; Executive Regulations from February 2024 Ministry of Transport, Communications and Information Technology
Jordan Law No. 24 of 2023 - Ministry of Digital Economy and Entrepreneurship
UAE Federal Decree-Law No. 45 of 2021 2 January 2022 UAE Data Office
Vietnam Law No. 91/2025/QH15 1 January 2026 Ministry of Public Security

Qatar is usually included in the same family, though its statute is Law No. 13 of 2016 Concerning Personal Data Privacy, abbreviated PDPPL rather than PDPL. Qatar was the first GCC state to issue a personal data protection law.

If you are searching for PDPL and finding results about Saudi Arabia, that is not an error in the results. The Saudi law generates by far the most search interest, and the term is used there most consistently.

Saudi Arabia’s PDPL

The Saudi PDPL is the Kingdom’s first comprehensive data protection statute, and it has moved from paper to enforcement faster than most first-generation laws in the region.

The timeline

The law was issued by Royal Decree No. M/19 of 9/2/1443H, corresponding to 16 September 2021, approving Council of Ministers Resolution No. 98. It was substantially amended by Royal Decree No. M/148 of 5/9/1444H, corresponding to 27 March 2023. The amended law entered into force on 14 September 2023 with a one-year grace period, which expired on 14 September 2024. Since that date the PDPL has been fully enforceable.

Two supporting instruments carry much of the operational detail: the Implementing Regulation, and a separate Regulation on the Transfer of Personal Data Outside the Kingdom.

Who enforces it

The Saudi Data and Artificial Intelligence Authority. SDAIA was designated as supervisory authority for an initial period, with the possibility of supervision transferring to the National Data Management Office later. For now, SDAIA is the body that registers controllers, receives breach notifications and issues enforcement decisions.

What the PDPL requires

The core obligations will be familiar to anyone who has worked with the GDPR, with some notable differences:

  • Consent as the default basis. The Saudi law leans more heavily on consent than the GDPR does, though the 2023 amendment introduced legitimate interests as a basis for non-sensitive data.
  • Controller registration. Controllers are required to register on SDAIA’s national platform. This is a step with no GDPR equivalent, and it is frequently missed by organisations that assume a GDPR programme covers them.
  • A data protection officer where core activities involve large-scale processing of sensitive personal data, large-scale systematic monitoring, or where SDAIA determines one is needed on a risk basis.
  • Breach notification within 72 hours to SDAIA from becoming aware, with a detailed account of the breach and the remediation steps taken. Where the breach poses significant risk to individuals, they must be informed promptly and given DPO contact details.
  • Restrictions on cross-border transfer, governed by the separate transfer regulation and supported by risk assessment guidance issued in 2025.
  • Extraterritorial reach. The law applies to organisations outside the Kingdom that process the personal data of individuals resident in Saudi Arabia.

Penalties

The Saudi PDPL has a two-tier penalty structure that is worth understanding precisely, because the two tiers are often conflated in summaries.

Article 35 creates a criminal offence. Disclosing or publishing sensitive personal data in breach of the law, with intent to harm the data subject or to achieve personal benefit, carries imprisonment of up to two years and a fine of up to SAR 3 million.

Article 36 provides administrative enforcement. Specialised committees can impose fines of up to SAR 5 million per violation, and the fine may be doubled for a repeat offence.

The enforcement record has substance behind it. Reporting in early 2026 indicated SDAIA had issued 48 violation decisions, covering processing without a valid legal basis, unauthorised disclosure, inadequate technical and organisational safeguards, and marketing without consent. That mix is instructive: the most common failures are foundational rather than exotic.

Bahrain’s PDPL

Bahrain moved early. Law No. 30 of 2018 was enacted on 12 July 2018 and came into force on 1 August 2019, making it the first comprehensive standalone data protection statute in the Gulf Cooperation Council. It is supplemented by ten ministerial resolutions issued in March 2022 covering transfers, security measures and notification procedures.

Bahrain’s approach to the DPO role differs from every other law discussed here, and the difference is unusual enough to flag. The Authority maintains a register of data protection officers, and an individual must be listed on that register to be accredited. Most controllers may appoint a DPO voluntarily, but licensed financial institutions are required to. A controller may appoint either an internal or an external DPO, subject to conditions.

If your organisation operates across both Bahrain and Saudi Arabia, the DPO analysis has to be done twice. A person who satisfies the Saudi requirement does not automatically satisfy the Bahraini accreditation requirement.

Oman’s PDPL

Oman’s Personal Data Protection Law was issued under Royal Decree No. 6/2022 and came into force on 13 February 2023, replacing the earlier data protection provisions in the Electronic Transactions Law. Executive Regulations followed in February 2024, supplying the operational detail.

The Omani law is consent-forward: the general rule is that a controller or processor must obtain the data subject’s consent before processing. It grants a set of data subject rights including withdrawal of consent, correction, updating, deletion, and notification of any breach affecting their data. The Ministry of Transport, Communications and Information Technology administers it.

Jordan’s PDPL

Jordan enacted Personal Data Protection Law No. 24 of 2023, administered through the Ministry of Digital Economy and Entrepreneurship. It brought Jordan into line with the wider regional trend of comprehensive, GDPR-influenced legislation and sits alongside comparable laws in Egypt (Law No. 151 of 2020) and Turkiye (Law No. 6698, the KVKK).

The UAE

The UAE issued Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, which took effect on 2 January 2022, alongside Federal Decree-Law No. 44 of 2021 establishing the UAE Data Office as the federal regulator.

There is an important caveat. The executive regulations that would supply the detail on timelines and penalties have not been published, which leaves parts of the federal regime unresolved in practice.

The UAE also has a layered structure that the federal law does not displace. The DIFC operates under its own Data Protection Law No. 5 of 2020, and the ADGM has its own regime. If your entity is established in a financial free zone, the free zone law is likely the one that governs you, not the federal decree-law. This trips up a lot of first-time entrants.

Vietnam’s PDPL

Vietnam is the newest entrant and the only one of the group outside the Middle East.

Law No. 91/2025/QH15 was passed by the National Assembly on 26 June 2025 and took effect on 1 January 2026. It replaced a decree-level framework with statutory law. Decree No. 356/2025/ND-CP, promulgated on 31 December 2025 and effective on the same date as the law, provides the implementing detail and formally replaced Decree No. 13/2023/ND-CP.

Two features distinguish it from the other PDPLs.

Enforcement sits with the Ministry of Public Security rather than an independent data protection authority. That is a structural difference with practical consequences for how enforcement is conducted.

The law recognises three roles, not two. Alongside the personal data controller and the personal data processor, it expressly recognises a personal data controller and processor as a distinct category. Anyone mapping a GDPR programme onto Vietnam needs to work through this carefully, because the third role does not correspond neatly to GDPR joint controllership. I have written a fuller treatment in controller and processor roles under Vietnam's PDPL.

Scale-based exemptions. Micro-enterprises and household businesses are exempt. Small enterprises and start-ups have a five-year grace period from 1 January 2026, but the exemption falls away if they act as data processing service providers, process sensitive personal data, or process large volumes of data.

How the PDPLs differ from each other

Treating “the PDPL” as one thing is the most common mistake in this area. The laws diverge on points that determine what you actually have to build:

Topic Saudi Arabia Bahrain Oman UAE (federal) Vietnam
Enforcement maturity Active, with published decisions Established, lower volume Regulations in force since 2024 Awaiting executive regulations New as of 2026
Controller registration Required with SDAIA Notification regime Per Executive Regulations Not yet operative See Decree 356
DPO Required in specified cases Register-based accreditation; mandatory for licensed financial institutions Per Executive Regulations Required in specified cases Required, with scale-based exemptions
Breach notification 72 hours to SDAIA Per ministerial resolutions Data subject must be notified Pending regulations Per the law and Decree 356
Maximum administrative fine SAR 5 million, doubling for repeat Set by the law and resolutions Per the law Pending regulations Administrative and criminal exposure

PDPL, PDPA and GDPR

Three acronyms, easily confused:

  • GDPR is the EU’s General Data Protection Regulation, and it is the template most of these laws borrow from.
  • PDPA is Personal Data Protection Act, used by Singapore, Malaysia, Thailand, Taiwan and Sri Lanka. I have covered that family in what is PDPA.
  • PDPL is Personal Data Protection Law, used by Saudi Arabia, Bahrain, Oman, Jordan, the UAE and Vietnam.

The shared inheritance from the GDPR means the concepts travel. Controllers, processors, lawful bases, data subject rights, breach notification and cross-border transfer restrictions appear in all of them. What does not travel is the detail: the notification windows, the registration requirements, the DPO thresholds and the contract content. Those have to be checked jurisdiction by jurisdiction. The wider picture, including how these laws relate to the GDPR, US state law and Australia, is in data protection laws around the world.

If you are starting from a GDPR programme, the productive way to approach a PDPL is to treat your existing controls as the baseline and then work through a gap list per country. The gaps are usually in the same four places: registration with the regulator, DPO qualification and appointment, the breach clock, and cross-border transfer paperwork. Getting the underlying controller and processor analysis right first makes all four easier, and a shared data governance framework is what stops the country-specific overlays from turning into separate programmes.

If your footprint extends into Southeast Asia as well as the Gulf, the wider regional picture is in APAC privacy laws.

Frequently asked questions

What does PDPL stand for?

Personal Data Protection Law. Saudi Arabia, Bahrain, Oman, Jordan, the UAE and Vietnam each have a statute by that name.

Which country’s PDPL do people usually mean?

Saudi Arabia’s, in most international contexts. It has the largest scope of application and the most active enforcement record.

When did the Saudi PDPL come into force?

It entered into force on 14 September 2023, with a one-year grace period. Full enforcement began on 14 September 2024.

What are the penalties under the Saudi PDPL?

Article 35 provides for imprisonment of up to two years and a fine of up to SAR 3 million for disclosing or publishing sensitive personal data with intent to harm or for personal benefit. Article 36 allows administrative fines of up to SAR 5 million per violation, which may be doubled for repeat offences.

Does the Saudi PDPL require a DPO?

Yes, where core activities involve large-scale processing of sensitive personal data or large-scale systematic monitoring, or where SDAIA determines one is needed on a risk assessment.

Is PDPL the same as PDPA?

No. They are different acronyms for different laws in different countries. PDPL refers to Saudi Arabia, Bahrain, Oman, Jordan, the UAE and Vietnam. PDPA refers to Singapore, Malaysia, Thailand, Taiwan and Sri Lanka.

Which was the first PDPL in the Gulf?

Qatar issued the first personal data protection law in the GCC, Law No. 13 of 2016. Bahrain’s Law No. 30 of 2018 was the first comprehensive standalone data protection statute in the bloc.

Does the Saudi PDPL apply to companies outside Saudi Arabia?

Yes. The law reaches organisations outside the Kingdom that process the personal data of individuals resident there.


Sources

  • Saudi Arabia Personal Data Protection Law, Royal Decree No. M/19 of 9/2/1443H, as amended by Royal Decree No. M/148 of 5/9/1444H; Implementing Regulation and Regulation on the Transfer of Personal Data Outside the Kingdom, issued by SDAIA
  • Bahrain Law No. 30 of 2018 with respect to Personal Data Protection, and the ministerial resolutions issued in March 2022
  • Oman Royal Decree No. 6/2022 promulgating the Personal Data Protection Law, and its Executive Regulations
  • Jordan Personal Data Protection Law No. 24 of 2023
  • Qatar Law No. 13 of 2016 Concerning Personal Data Privacy
  • UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and Federal Decree-Law No. 44 of 2021
  • Vietnam Law No. 91/2025/QH15 on Personal Data Protection, and Decree No. 356/2025/ND-CP