Overview
Personal Data Processing Activities Record Guideline – Second: Contents of Personal Data Processing Activities Records specify the minimum mandatory information that Controllers must include when preparing Records of Processing Activities under the Saudi Personal Data Protection Law (PDPL).
This section defines the core data elements that ensure transparency, accountability, and regulatory oversight, covering controller details, processing purposes, data categories, retention, disclosures, cross-border transfers, and security measures.
SDAIA's Official Text
The text below reproduces official PDPL law, regulation, or guideline issued by the Saudi Data & AI Authority, verified against the original SDAIA source. No changes or reinterpretation applied.
Second: Contents of Personal Data Processing Activities Records
Records of personal data processing activities shall, as a minimum, include the following:
- Controller's name and relevant contact details.
- Information of the Data Protection Officer (DPO), wherever the appointment of a DPO is required.
- Purposes of personal data processing.
- Description of the personal data categories being processed, and data subjects categories.
- Retention period for personal data and, where possible, specific retention periods for each category of personal data.
- Categories of recipient entities to whom the personal data has been or will be disclosed.
- Description of operations of personal data transfer outside the Kingdom, including the legal basis for the transfer and the recipient entities.
- Description of the procedures and organizational, administrative, and technical measures in place that ensure the security of personal data, where possible.
Plain-Language Explanation
The explanation below is provided to help you understand the SDAIA’s legal text and does not replace or override the official PDPL law, regulation, or guideline.
1. Controller and Contact Information
This requirement explains that RoPA must identify the Controller by name and include relevant contact details. This ensures clear accountability and enables communication with the Competent Authority (SDAIA) and Data Subjects when necessary.