SDAIA's enforcement committees had issued 48 decisions confirming violations of the Personal Data Protection Law by the middle of January 2026. The recurring findings are not exotic. Processing without a valid legal basis. Disclosure that nobody authorised. Technical and organisational measures that were never implemented. Marketing sent to people who had not agreed to receive it.
Companies read that and reach for the obvious response, which is to appoint someone. A data protection officer gets named, usually in a memo, usually the head of IT or the head of legal, and the file gets closed. We have now reviewed enough of these appointments to say two things about them. A good number of the companies making them were never required to appoint anyone. And a good number of the appointments themselves do not comply with the rules they were made to satisfy.
Both problems come from the same place: nobody read the rules.
The trigger is narrower than most companies assume
The Rules for Appointing a Personal Data Protection Officer sit under Article 30(2) of the PDPL and Article 32(4) of the Implementing Regulations. SDAIA published them in August 2024. Article 5 sets out when appointment is mandatory, and it is a closed list of three cases:
- the controller is a public entity providing services that involve processing personal data on a large scale
- the controller's core activities involve regular and systematic monitoring of data subjects
- the controller's core activities involve processing sensitive personal data
Read what is absent. There is no revenue threshold. There is no headcount threshold. There is no test based on the size of the company at all. "Large scale" is assessed on the number of data subjects, the volume of data, the types of data, the geographic scope, and the variety of categories of data subject. Every one of those measures the data, not the business.
That cuts in two directions, and both matter commercially.
A small company can be squarely caught. A twenty person firm running behavioural analytics, location tracking, or continuous employee monitoring is doing regular and systematic monitoring as a core activity. So is a clinic, because health data is sensitive personal data and processing it is the point of the clinic. Neither of them gets out of Article 5 by being small.
A large company may not be caught at all. A manufacturer or a contractor with several thousand staff, processing payroll, HR files and a customer contact list, is not monitoring data subjects and is not handling sensitive data as a core activity. On the face of Article 5, no appointment is required.
The instinct at that point is to appoint anyway, to be safe. Understand what that costs. Once you appoint, the rest of the Rules attach: the qualification requirements, the reporting line, the resourcing duty, the independence protection. A voluntary appointment that fails those tests is worse than no appointment, because you have created the obligation and then breached it. If you are outside Article 5, the defensible position is a documented determination that you are outside it, reviewed when your processing changes. Not a memo naming a volunteer.
What the role cannot be
Article 9(7) is the provision that quietly invalidates most of the appointments we see. It does two things. It sets the DPO's organisational reporting line to the data management office or its equivalent. And it prohibits the controller from assigning the DPO conflicting duties, or tasks that affect the independence of the role. The controller must also provide adequate resources and support.
Now put the standard Saudi appointment against that. The head of IT owns the systems, the access controls, the retention configuration and the vendor stack. The head of legal owns the contracts, the consent language and the disclosure decisions. The DPO's function is to review those decisions and report on them. Appoint either of them and the reviewer is the person who made the thing being reviewed.
That is not a comment on anybody's integrity. It is a structural defect, and it is the kind an assessor finds in an hour by drawing your org chart. The same logic applies to the CFO, the chief information security officer, and the head of HR in a company whose sensitive data is mostly employee data. Whoever owns the largest processing decision in the business is the one person who cannot hold the role.
Article 4 adds a duty most controllers skip entirely. It is the controller, not the candidate, who must verify that the person has an appropriate academic qualification and genuine expertise in personal data protection, competence in risk management including the handling of breach incidents, sufficient knowledge of the regulatory requirements, and integrity with no conviction for crimes against honour. That is a verification you should be able to evidence. In practice we ask a simple question: where is the file that shows you checked? There usually isn't one.
Then there is what the role actually carries. Under Article 8 the DPO advises across all aspects of data protection, develops the internal policies and procedures, runs awareness and training, reviews the incident response plan, prepares periodic compliance reports, and tracks regulatory change. The Arabic text is also explicit that the DPO is the direct point of contact with SDAIA and is responsible for implementing its decisions and instructions, and that data subject requests come to them.
Sit with that last part for a moment. When a committee notification arrives, the response window is measured in days, and the named point of contact is the person who has to move. If that person has a day job running the function under review, no delegated authority, and no standing file, the deadline is going to pass. The resourcing duty in Article 9(7) is not administrative housekeeping. It is what makes the role able to function when it is finally needed.
Outsourcing is allowed, and often the cleaner answer
Article 4(2) is explicit that the DPO may be an employee or an external contractor. Where the role is outsourced, Article 6(1)(b) requires a written agreement.
For a mid-sized controller this is frequently the better structure, and not merely on cost. Independence comes built in, because an external DPO has no internal career to protect and no adjacent function to defend. Specialist knowledge is easier to buy than to develop, particularly the breach handling competence Article 4 requires, which most companies cannot build internally because they do not have enough incidents to learn from. And the reporting line stops being awkward, because an outside appointee can report where the Rules say without anybody being asked to review their own manager.
The agreement is where these arrangements succeed or fail. It has to secure real access to systems, records and people rather than a monthly call. It needs a defined escalation route that does not run through the function being reviewed. It needs enough contracted time to actually discharge Article 8, which is a standing role and not an annual report. And it should name who responds when SDAIA makes contact, with the authority to do it inside the window.
An external DPO on a nominal retainer, reachable by email, with no access and no authority, fails Article 9(7) exactly as a conflicted internal appointment does. The form is different. The defect is the same.
Somebody is now licensed to check this
Until this year, the question of who tests a controller's compliance had no clear answer. On 17 February 2026 SDAIA issued two sets of rules that change it: one governing licences to issue accreditation certificates to controllers and processors, and one governing licences to carry out audit and inspection of personal data processing activities. The audit licence is open to private and public sector bodies.
The reported terms, which we would confirm against the Arabic texts before relying on them, are that licences run for three years with renewal at least 90 business days before expiry, and that a body issuing accreditation certificates needs minimum capital of SAR 10 million, at least ten full time evaluators, and accreditation from the Saudi Accreditation Center.
One reported consequence deserves a direct check by anyone who has bought assurance in this area. Accreditation certificates and audit reports issued by unlicensed bodies are not recognised for PDPL purposes. If your company procured a privacy certification during 2025 from a consultancy that is not on SDAIA's licensed list, you may be holding a document with no regulatory standing. That is worth ten minutes and a phone call.
The wider point is about direction of travel. A licensed assessor market exists because SDAIA intends compliance to be tested by people with standing to test it, against evidence rather than intention. The governance questions travel first because they are the cheapest to check: is there a DPO, does Article 5 require one, who do they report to, what else do they do, who verified them, what resources do they have. An assessor answers all six from your org chart and your appointment file. Neither of those is something you can assemble the week the request arrives, which is the same problem we described in moving from an annual audit to continuous assurance.
Six questions worth answering this quarter
Are you actually caught? Test your processing against the three cases in Article 5 and write down the answer with reasons. Revisit it when the processing changes, not annually out of habit.
If you are, who does the DPO report to? If the line runs into IT, legal, or whichever function owns your largest processing activity, the appointment has a defect on the face of Article 9(7).
What else is on their plate? Conflicting duties invalidate the appointment as surely as the wrong reporting line. A DPO who also approves the vendor contracts is not independent of the vendor contracts.
Can you evidence the Article 4 verification? Qualification, expertise, risk and breach competence, regulatory knowledge, integrity. There should be a file.
If outsourced, does the agreement give them access and authority? Contracted time, systems access, an escalation route outside the reviewed function, and named authority to answer SDAIA inside the window.
Is the assessor you are paying licensed? And is the certificate you already bought worth anything.
The point
Data protection compliance in the Kingdom has stopped being a drafting exercise. Enforcement is running, the sanctions include publication of the penalty alongside fines that reach SAR 5 million and double on repeat, and there is now a licensed profession whose job is to check the work. What gets checked first is not your encryption. It is your governance: who is accountable, whether they are independent, and whether you can show it.
Most of the companies we help are in one of two positions. Either they appointed a DPO who cannot lawfully hold the role, or they never asked whether Article 5 applied to them and have no record of the question being considered. Both are fixable in weeks, and both get considerably more expensive once somebody with a licence is asking.
Alpha Advisory works with controllers on exactly this: testing whether the appointment obligation bites, designing a DPO role that survives an independence challenge, serving as external DPO where that is the cleaner structure, and building the appointment and processing records that an assessor will ask to see. It is the same discipline as any other third-party and governance exposure, which is that the control either exists as evidence or it does not exist. If SDAIA wrote to you on Sunday, who would answer, and what could they show? Speak with a Specialist.

