The Personal Data Protection Law is Saudi Arabia’s first comprehensive data privacy law, issued pursuant to Royal Decree No. M/19 dated 09/02/1443 AH (16 September 2021), as amended by Royal Decree No. M/148 dated 5/9/1444H (27 March 2023). The law came into effect on 14 September 2023 with a one-year grace period for compliance ending on 14 September 2024. It establishes principles similar to GDPR including lawfulness, transparency, purpose limitation, data minimization, and security. The law provides penalties including imprisonment for up to two years and/or fines up to SAR 3 million ($800,000) for disclosing sensitive personal data, and fines up to SAR 5 million ($1.3 million) for other violations. Data protection laws in Saudi Arabia – Data Protection Laws of the World The Saudi Data & Artificial Intelligence Authority (SDAIA) serves as the initial supervisory authority with eventual transfer to the National Data Management Office planned.
Health Data Management Policy (under Ayushman Bharat Digital Mission)
ABDM participants must comply with the Health Data Management Policy. Healthcare laws include the Clinical Establishments Act, National Medical Commission Act provisions requiring physician confidentiality,