For most organizations in the Kingdom, the first wave of PDPL work produced documents: a privacy policy, a privacy notice, a data protection manual, a consent banner. Those documents were necessary. They are also not what a regulator is looking for when it asks how you comply.
The grace period for the Personal Data Protection Law ended on 14 September 2024. In January 2026, SDAIA confirmed it had issued 48 enforcement decisions during 2025. The era of preparing for PDPL is over. The question now is whether what you have on file would hold up if someone outside your organization read it closely.
What the enforcement record tells us
SDAIA has not published individual decisions or penalty amounts, but it did disclose the four categories the decisions fell into. Each one maps directly to a kind of evidence an organization should be able to produce on request.
Collecting data without a valid legal basis. The question is not whether you have a privacy policy, but whether you can show, for each processing activity, which lawful basis applies and why.
Unauthorized disclosure. Sharing personal data with third parties, group companies, or vendors without a documented justification and the right safeguards.
Failing to implement protective measures. Note the word implement. A security policy describes controls. Evidence shows they are actually in place and working.
Unsolicited marketing. Sending marketing messages without valid consent, and without being able to show when and how that consent was given.
A policy says what you intend to do. Evidence shows what you actually did, when, and who was responsible.
Policy on paper versus evidence on file
The gap between the two is where most PDPL programs are exposed. The left column is usually in good shape; the right is scattered across inboxes, spreadsheets, and memories.
What we say
- "We process data lawfully"
- "We share data only when necessary"
- "We protect data with appropriate controls"
- "We respect marketing preferences"
What we can show
- A current record of processing with a basis for each activity
- Signed data sharing terms and a disclosure log
- Access reviews, test results, and incident records
- Timestamped consent and opt-out records
The six things a review will ask to see
Most PDPL programs come down to six building blocks. Each one needs to exist, and each one needs evidence that it is working, not just written down.
Record of processing
Every processing activity with its purpose, lawful basis, data, recipients, retention, and owner, kept current.
Impact assessments
Completed before high-risk or sensitive processing starts, with the risks found and the actions taken.
Technical and organizational measures
Access controls, encryption, and procedures that are implemented and tested, not only described.
Role-based training
Training matched to what each role handles, with completion records and refreshers.
Data protection officer
A named, empowered DPO where required, with a clear mandate and reporting line.
Everyday awareness
Ongoing reminders and guidance, so privacy shows up in daily decisions, not once a year.
The record of processing is the backbone. The law requires it to be kept for the life of the processing and five years after, and it answers most of a reviewer's first questions on its own. Impact assessments show you considered the risk before you started, not after something went wrong.
Technical and organizational measures are where enforcement has already focused: the word that matters is implemented. Access reviews, test results, and incident records prove it. Training and awareness are different things: training builds the skills a role needs, awareness keeps privacy in mind day to day. Both leave records. And a DPO, where one is required, gives the whole program an accountable owner.
Evidence survives scrutiny when it is dated, owned, traceable, and current.
From documents to daily practice
Most organizations already have much of this on paper. The real work is operationalizing it: making each element part of how the business runs, so evidence is produced as a by-product of normal work rather than assembled when a review is announced.
In practice, that means connecting privacy to the processes that already exist. The record of processing is updated through change management and procurement, not in an annual exercise. Impact assessments are triggered automatically when a new project or system is proposed. Technical and organizational measures have owners, and are monitored and reported like any other control. Training is tied to onboarding and role changes, awareness runs throughout the year, and the DPO reports to leadership on a regular rhythm.
When privacy is built into how work gets done, compliance stops being a project with an end date. It becomes a capability the organization keeps, and one it can demonstrate at any time.
This article is for general information and is not legal advice. WISE Advisory helps organizations across the GCC build PDPL programs that produce evidence, not just documents. To discuss your readiness, reach us at info@wise-advisory.com.