WISE Advisory/Insights/Privacy & PDPL
Insight

Evidence that survives a regulator's read.

Moving from privacy policies on paper to the exhibit-backed evidence a PDPL review actually expects.

WISE AdvisoryPrivacy & PDPL7 min read
Illustration of a PDPL evidence file connected to RoPA, DPIA, technical and organizational measures, training, DPO, and awareness

For most organizations in the Kingdom, the first wave of PDPL work produced documents: a privacy policy, a privacy notice, a data protection manual, a consent banner. Those documents were necessary. They are also not what a regulator is looking for when it asks how you comply.

The grace period for the Personal Data Protection Law ended on 14 September 2024. In January 2026, SDAIA confirmed it had issued 48 enforcement decisions during 2025. The era of preparing for PDPL is over. The question now is whether what you have on file would hold up if someone outside your organization read it closely.

48
Enforcement decisions SDAIA reported for 2025
SAR 5M
Maximum fine per violation, doubled for repeat offenses
72 hrs
To notify SDAIA of a qualifying personal data breach

What the enforcement record tells us

SDAIA has not published individual decisions or penalty amounts, but it did disclose the four categories the decisions fell into. Each one maps directly to a kind of evidence an organization should be able to produce on request.

Collecting data without a valid legal basis. The question is not whether you have a privacy policy, but whether you can show, for each processing activity, which lawful basis applies and why.

Unauthorized disclosure. Sharing personal data with third parties, group companies, or vendors without a documented justification and the right safeguards.

Failing to implement protective measures. Note the word implement. A security policy describes controls. Evidence shows they are actually in place and working.

Unsolicited marketing. Sending marketing messages without valid consent, and without being able to show when and how that consent was given.

A policy says what you intend to do. Evidence shows what you actually did, when, and who was responsible.

Policy on paper versus evidence on file

The gap between the two is where most PDPL programs are exposed. The left column is usually in good shape; the right is scattered across inboxes, spreadsheets, and memories.

Policy on paper

What we say

  • "We process data lawfully"
  • "We share data only when necessary"
  • "We protect data with appropriate controls"
  • "We respect marketing preferences"
Evidence on file

What we can show

  • A current record of processing with a basis for each activity
  • Signed data sharing terms and a disclosure log
  • Access reviews, test results, and incident records
  • Timestamped consent and opt-out records

The six things a review will ask to see

Most PDPL programs come down to six building blocks. Each one needs to exist, and each one needs evidence that it is working, not just written down.

01 · RoPA

Record of processing

Every processing activity with its purpose, lawful basis, data, recipients, retention, and owner, kept current.

02 · DPIA

Impact assessments

Completed before high-risk or sensitive processing starts, with the risks found and the actions taken.

03 · TOMs

Technical and organizational measures

Access controls, encryption, and procedures that are implemented and tested, not only described.

04 · Training

Role-based training

Training matched to what each role handles, with completion records and refreshers.

05 · DPO

Data protection officer

A named, empowered DPO where required, with a clear mandate and reporting line.

06 · Awareness

Everyday awareness

Ongoing reminders and guidance, so privacy shows up in daily decisions, not once a year.

The record of processing is the backbone. The law requires it to be kept for the life of the processing and five years after, and it answers most of a reviewer's first questions on its own. Impact assessments show you considered the risk before you started, not after something went wrong.

Technical and organizational measures are where enforcement has already focused: the word that matters is implemented. Access reviews, test results, and incident records prove it. Training and awareness are different things: training builds the skills a role needs, awareness keeps privacy in mind day to day. Both leave records. And a DPO, where one is required, gives the whole program an accountable owner.

Evidence survives scrutiny when it is dated, owned, traceable, and current.

From documents to daily practice

Most organizations already have much of this on paper. The real work is operationalizing it: making each element part of how the business runs, so evidence is produced as a by-product of normal work rather than assembled when a review is announced.

In practice, that means connecting privacy to the processes that already exist. The record of processing is updated through change management and procurement, not in an annual exercise. Impact assessments are triggered automatically when a new project or system is proposed. Technical and organizational measures have owners, and are monitored and reported like any other control. Training is tied to onboarding and role changes, awareness runs throughout the year, and the DPO reports to leadership on a regular rhythm.

When privacy is built into how work gets done, compliance stops being a project with an end date. It becomes a capability the organization keeps, and one it can demonstrate at any time.


This article is for general information and is not legal advice. WISE Advisory helps organizations across the GCC build PDPL programs that produce evidence, not just documents. To discuss your readiness, reach us at info@wise-advisory.com.

Have a problem worth solving well?

Tell us what you're working on. We'll listen, share how we could help, and be open about whether we're the right fit.