Skip to content
PDPL (Saudi & UAE Personal Data Protection Laws)
compliance

PDPL (Saudi & UAE Personal Data Protection Laws)

PDPL is the common shorthand for two laws: Saudi Arabia's Personal Data Protection Law, enforced by SDAIA, and the UAE's federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021). Both regulate how organisations collect, use, store, share and transfer individuals' personal data.

The Saudi PDPL was issued by Royal Decree in 2021, amended in 2023, and came into force in September 2023 with a grace period for organisations to comply; the Saudi Data and AI Authority (SDAIA) supervises it and has issued implementing regulations. The UAE's federal PDPL was issued as Federal Decree-Law No. 45 of 2021 and is overseen by the UAE Data Office; the DIFC and ADGM free zones run their own separate data protection regimes. Both laws share the familiar structure of GDPR: a lawful basis for processing, purpose limitation, data-subject rights (access, correction, deletion), breach notification, and conditions on transferring data outside the country.

For an AI deployment the law is concrete, not abstract. A WhatsApp agent collects names, phone numbers, addresses and sometimes health or financial details; a voice agent records calls; a medical scribe processes sensitive health data, which both laws treat with stricter conditions. The questions that follow are practical: what is the lawful basis and is the customer told, where are transcripts and audio stored, which vendor's servers see the data and in which country, how long is it retained, and how does a customer ask for deletion. Cross-border transfer rules in Saudi Arabia in particular affect which model providers and hosting regions can be used.

Nano AI designs its data handling to align with Saudi PDPL, UAE PDPL and GDPR: data minimisation in what the agent stores, retention limits, documented processors, and human handoff for requests that touch a customer's rights. When you ask any AI vendor about PDPL, do not accept 'we are compliant' as an answer; ask for the data flow diagram, the list of sub-processors and their regions, the retention schedule, and the process for a deletion request. If they cannot produce those four items, the compliance claim is not yet real.

Chat on WhatsApp