Saudi Arabia's Personal Data Protection Law (PDPL) has been in force since 2023 and enforced by SDAIA since September 2024, and it applies to every business that holds a customer's name, phone number or ID, not only to banks and hospitals. It asks for things most estates have never written down: a record of what personal data is held and why, a privacy notice that says so, consent or another lawful basis for each use, a retention period, a way for people to ask what you hold on them, and a report to the regulator within seventy-two hours of a breach.
We map it onto the blueprint: which systems hold personal data, where they are hosted and whether that is inside the Kingdom, who can reach them, how long records are kept and how they are deleted. Transfers outside Saudi Arabia are listed and justified or stopped. The result is a register and a set of settings rather than a binder, and it is checked again at every quarterly review. We are engineers, not lawyers: the policy wording is yours or your counsel's; the systems that make it true are ours.