Overview
Saudi Personal Data Protection Law (KSA PDPL) Article 30 explains the powers of the Competent Authority, SDAIA, and outlines how supervisory oversight is carried out across all sectors in the Kingdom.
It also sets the rules for when controllers must appoint a Data Protection Officer (DPO) and clarifies what responsibilities apply to that role. The Article grants SDAIA authority to investigate, request documents, enforce compliance, and supervise data protection practices. It also authorizes SDAIA to issue rules, coordinate with external entities, and operate national monitoring tools.
This Article forms the foundation of Saudi Arabia’s national data protection supervision model. It provides controllers with clear expectations on when a DPO is required, what support they must provide to SDAIA, and the mechanisms SDAIA uses to maintain regulatory oversight under the Personal Data Protection Law (PDPL).
SDAIA's Official PDPL Text
The text below reproduces official PDPL law, regulation, or guideline issued by the Saudi Data & AI Authority, verified against the original SDAIA source. No changes or reinterpretation applied.
Article 30
- Without prejudice to the provisions of this Law and the powers of the Saudi Central Bank pursuant to applicable legal provisions, the Competent Authority shall be the entity in charge of overseeing the implementation of this Law and the Regulations.
- The Regulations shall identify the situations where the Controller shall appoint one or more persons as personal data protection officer(s). and shall set the responsibilities of any such person in accordance with the provisions of this Law.
- The Controller shall cooperate with the Competent Authority in performing its duties to supervise the implementation of the provisions of this Law and the Regulations, and shall take such steps as necessary in connection with the related matters referred to the Controller by the Competent Authority.
- The Competent Authority, in order to carry out its duties related to supervising the implementation of the provisions of the Law and Regulations, may:
- Request the necessary documents or information from the Controller to ensure its compliance with the provisions of the Law and Regulations.
- Request the cooperation of any other party for the purposes of support in accomplishing supervisory duties and enforcement of the provisions of the Law and Regulations.
- Specify the appropriate tools and mechanisms for monitoring Controllers’ compliance with the provisions of the Law and the Regulations, including maintaining a national register of Controllers for this purpose.
- Provide services related to Personal Data protection through the national register referred to in Subparagraph (c) of this Paragraph or through any other means deemed appropriate. The Competent Authority may collect a fee for the Personal Data protection services it may provide.
- The Competent Authority may, at its discretion, delegate to other authorities the accomplishment of some of its duties that are related to supervision or enforcement of the provisions of the Law and Regulations.
Plain-Language PDPL Explanation
The explanation below is provided to help you understand the SDAIA’s legal text and does not replace or override the official PDPL law, regulation, or guideline.