← Back to Blogs

Information Security & Data Protection

ISO 27001 and Saudi Arabia’s PDPL: What Organisations Need to Do in 2026

For years, the question organisations in Saudi Arabia asked about data protection compliance was: when will enforcement actually start? That question has been answered.

Between 2025 and 2026, Saudi Arabia’s Data and Artificial Intelligence Authority (SDAIA) issued 48 formal enforcement decisions against organisations found to have violated the Personal Data Protection Law (PDPL). The violations covered collecting personal data without a lawful basis, failing to implement adequate technical security controls, and disclosing personal data without authorisation. The era of grace periods is over. Organisations that have not yet built a structured approach to information security compliance in Saudi Arabia are already operating in the enforcement window and the evidence shows that regulators are using it.

This guide explains what the PDPL requires, how it intersects with the National Cybersecurity Authority’s (NCA) framework, and why ISO 27001 certification in Saudi Arabia has become the most practical and defensible way to demonstrate compliance across all applicable regulatory obligations simultaneously.

What the PDPL Actually Requires and What It Will Cost You to Ignore It

The Personal Data Protection Law (PDPL) came into full force in September 2024 and is enforced by SDAIA. It applies to any organisation that collects, processes, stores, or transfers the personal data of Saudi residents, regardless of where the organisation is headquartered. A UK company with Saudi customers, a Pakistani IT firm servicing Saudi clients, and a Riyadh-based hospital all fall within scope.

The PDPL’s core obligations include: a lawful basis for every processing activity, explicit consent for sensitive personal data (health, financial, biometric), the right of data subjects to access and correct their data, Data Protection Impact Assessments for high-risk processing, and breach notification to SDAIA within 72 hours of becoming aware of any incident involving personal data. That 72-hour clock applies with no materiality threshold, even a small breach triggers the obligation.

The financial stakes:
PDPL violations carry fines of up to SAR 5 million per breach, doubling to SAR 10 million for repeat offences. Intentional violations involving sensitive personal data can result in criminal proceedings and imprisonment of up to two years. Beyond fines, SDAIA has authority to suspend an organisation’s data processing activities entirely, which for digital-first businesses is an existential operational risk.

The NCA Layer: When Cybersecurity Obligations Go Beyond the PDPL

Saudi Arabia’s regulatory landscape for information security does not stop at the PDPL. The National Cybersecurity Authority (NCA) administers its own mandatory framework, the Essential Cybersecurity Controls (ECC-2:2024) covering government entities, critical national infrastructure operators, and, since 2025, the broader private sector under NCNICC-1:2025.

Under NCNICC-1:2025, private sector organisations are categorised into Category A (large entities) and Category B (SMEs). Category A organisations must implement governance, defence, and resilience controls including an independent cybersecurity unit, access management, risk management, monitoring, incident response, and third-party security requirements. The penalties for NCA non-compliance are significantly higher than PDPL fines, reaching up to SAR 25 million, plus licence suspension and mandatory public disclosure of violations.

For financial institutions, a third layer applies: the SAMA Cybersecurity Framework, which mandates specific controls for banks, insurance companies, and fintech firms licensed by the Saudi Central Bank. A Saudi bank, in practice, must simultaneously satisfy SAMA requirements, NCA ECC controls, and PDPL obligations, three overlapping frameworks administered by three different regulators.

This regulatory overlap is exactly where ISO 27001 becomes strategically valuable.

How Saudi Arabia’s Cybersecurity Frameworks Map to ISO 27001

The four major regulatory frameworks that apply to organisations in Saudi Arabia all draw substantially from ISO 27001 and NIST CSF principles. Building an ISO 27001 Information Security Management System (ISMS) provides the governance foundation; Saudi-specific regulatory evidence is then layered on top, rather than building three or four separate compliance programmes from scratch.

 

Framework Administered by Applies to ISO 27001 relationship
PDPL SDAIA All organisations processing personal data of Saudi residents ISO 27001 Annex A controls directly satisfy PDPL’s technical and organisational safeguard requirements
NCA ECC-2:2024 National Cybersecurity Authority (NCA) Government entities, critical national infrastructure, and private sector under NCNICC-1:2025 ISO 27001 ISMS provides the governance foundation; NCA controls layer on top as evidence
SAMA Cybersecurity Framework Saudi Central Bank (SAMA) Banks, insurance companies, fintech, and financial institutions ISO 27001 certification is accepted as partial evidence of SAMA CSF compliance
NCNICC-1:2025 National Cybersecurity Authority (NCA) All private sector organisations – Category A (large) and Category B (SME) Building an ISO 27001 ISMS satisfies the governance, risk, and control architecture NCNICC-1 requires

This is not a coincidence. NCA ECC-2:2024 was explicitly designed to align with international security standards. SDAIA’s enforcement guidance references ‘appropriate technical and organisational security measures’, language drawn directly from ISO 27001 Annex A terminology. Organisations with a certified ISMS are demonstrably better positioned in regulatory investigations than those with ad hoc security controls, because they have independent, third-party verified evidence of their security posture.

Saudi Arabia's Cybersecurity Frameworks

What Enforcement Looks Like in Practice

The 48 SDAIA enforcement decisions issued in 2025–2026 provide a clear picture of what organisations are getting wrong. The most common violations were:

  • Processing personal data without a lawful basis:
    Organisations collecting customer data for marketing or profiling without documented consent or a recognised processing ground.
  • Insufficient technical security controls:
    SDAIA enforcement has specifically targeted organisations where basic controls, access management, encryption, audit logging — were absent or inadequately implemented.
  • Failure to notify breaches within 72 hours:
    Organisations discovering security incidents and taking days or weeks to report, often because they had no incident response plan that assigned clear responsibility for regulatory notification.
  • Unauthorised cross-border data transfers:
    Sending personal data to overseas processors without SDAIA-approved safeguards in place, a common gap for multinational organisations with centralised IT infrastructure.

Organizations are penalized not for sophisticated attacks but for lacking documented controls and processes that could prevent violations or aid in proper responses. ISO 27001’s requirement for documentation, including risk registers and incident response procedures, transforms security practices into verifiable evidence. In the healthcare sector, Saudi organizations must comply with various regulations while achieving ISO 27001 certification, which ensures proper documentation of information assets, risk assessments, access controls for patient records, and breach notification testing, aligning with SDAIA and NCA enforcement inspection requirements.

The practical lesson from these enforcement actions is consistent with what experienced practitioners see in internal audit work: organisations are not being penalised for sophisticated attacks or unavoidable breaches. They are being penalised for the absence of documented controls and processes that would have either prevented the violation or enabled them to respond correctly when it occurred.

ISO 27001’s strength is precisely that it mandates documentation, a risk register, an asset inventory, an incident response procedure, access control policies, that transforms invisible security practices into auditable, verifiable evidence.

Sector perspective – Healthcare:
Saudi healthcare organisations processing patient data face overlapping obligations under PDPL (sensitive personal data rules), the Saudi Health Information Exchange Policies (SeHE), and NCA ECC. A hospital group that has achieved ISO 27001 certification has documented its information asset inventory, conducted a formal risk assessment, implemented access controls for patient records, and tested its breach notification procedure. Each of these maps directly to the SDAIA and NCA controls being tested in enforcement inspections.

What Your Organisation Needs to Do in 2026

The following six actions address PDPL compliance, NCA ECC requirements, and ISMS certification in an integrated sequence, building toward ISO 27001 certification while satisfying immediate regulatory obligations at each stage:

 

# Action Why it matters in Saudi Arabia
1 Conduct a data mapping and PDPL gap assessment SDAIA enforcement has specifically targeted organisations with insufficient security controls. You cannot demonstrate compliance with what you have not mapped.
2 Implement an Information Security Management System (ISMS) aligned with ISO 27001 ISO 27001 Annex A controls directly address PDPL technical safeguard requirements and the NCA ECC control domains. One system serves multiple regulatory obligations simultaneously.
3 Appoint a Data Protection Officer (DPO) if processing sensitive personal data at scale PDPL requires DPO appointment for entities handling sensitive categories, health data, financial data, biometric data at scale. SDAIA expects evidence of DPO function, not just a job title.
4 Establish a 72-hour breach notification procedure Under PDPL Article 24, organisations must notify SDAIA within 72 hours of becoming aware of a breach. No materiality threshold, any breach involving personal data triggers the obligation.
5 Achieve ISO 27001 certification from an accredited certification body SDAIA will consider whether an organisation has implemented an internationally recognised ISMS when determining sanction severity. Certification is documented evidence of commitment.
6 Conduct annual ISMS internal audits and management reviews NCA ECC-2:2024 requires regular independent cybersecurity audits. ISO 27001’s internal audit programme satisfies this in a documented, verifiable way.

 

How Long Does ISO 27001 Certification Take in Saudi Arabia?

For most single-site organisations new to formal information security management, the implementation timeline to certification runs between four and nine months. The main variables are the size of the organisation, the complexity of the IT environment, and whether experienced internal resource is available to lead the implementation or whether external consulting support is required.

Organisations that invest in ISO 27001 training at the outset through a formal Lead Implementer course, consistently move faster than those who attempt to interpret the standard from the text alone. A 5-day PECB or Exemplar Global certified Lead Implementer course gives the implementation lead the clause-by-clause competence needed to make informed decisions about scope, risk treatment, and control selection from day one, rather than discovering misinterpretations at the Stage 1 audit.

Build Your ISMS Before the Next Enforcement Wave

The 48 enforcement decisions issued in 2025–2026 are not the ceiling, they are the baseline. SDAIA has signalled that enforcement will intensify, particularly against organisations in healthcare, financial services, and technology, where personal data volumes are highest and the risk of harm from inadequate controls is greatest. Organisations that act now, building a documented ISMS and achieving ISO 27001 certification, do so with time on their side. Those that wait do so with the next SDAIA inspection cycle approaching.

HSEQ Professionals delivers PECB-accredited ISO 27001 training and ISMS implementation support across Saudi Arabia and online globally. Our ISO management systems consulting team can conduct your PDPL and NCA gap assessment, design your ISMS architecture, and prepare your organisation for third-party certification in a timeline that reflects the regulatory urgency your organisation is facing.

Contact our team to discuss your ISO 27001 implementation timeline and get a realistic assessment of where your organisation currently stands against PDPL and NCA requirements.