WhatsApp Us

Saudi PDPL · the technical side of a website or app

PDPL compliance for websites: what your Saudi site or app must change

PDPL compliance for websites comes down to a short list of technical changes: a clear privacy notice, consent that is real, a way to handle access and deletion requests, a deliberate hosting and transfer decision, a breach log that supports notifying the regulator, and forms and analytics that collect less. BtechWaleTech is three freelance developers in India who build those changes for Saudi businesses, alongside your lawyer. Fixes to an existing site start from US$150. SDAIA publishes the law and its regulations on the National Data Governance Platform.

  • Fixes on an existing site fromUS$150, 1–2 weeks
  • Request and breach workflows fromUS$600, 2–4 weeks
  • Rebuild inside a custom app fromUS$900, 6–12 weeks
  • RegulatorSDAIA, via the National Data Governance Platform
  • Breach notice window72 hours from awareness, per the Implementing Regulation
  • Request response window30 days, extendable in set cases
  • Privacy notice placement
  • Consent and cookie banner
  • Data request workflow
  • Hosting and transfer map
  • Breach log with timestamps
  • Form and analytics minimisation
  • Your counsel signs off

Three freelance developers in India · build work only, legal sign-off stays with your lawyer · WhatsApp 7 days a week

  • 72Hours to notify the authority after learning of a breach
  • 30Days to act on a data subject request
  • 5Rights listed in Article 4 of the law
  • 2Working days to our itemised quote

The short answer

What does PDPL compliance for websites require technically?

PDPL compliance for websites usually means six technical changes: a privacy notice linked wherever data is collected, consent that keeps non-essential tracking off until accepted, a workflow that answers access, correction and deletion requests within 30 days, documented hosting and transfer choices, a breach log supporting 72-hour notification, and leaner forms and analytics. With BtechWaleTech, fixes start from US$150 and workflows from US$600.

Rebuilding anyway? See what a Saudi website costs or ecommerce development in Saudi Arabia, and build privacy in from day one.

Last updated

Six website changes the PDPL usually drives
Privacy noticeWritten by your lawyer, linked at every form, checkout and sign-up
ConsentNon-essential tags off until the visitor agrees; choice recorded
Data requestsAccess, copy, correction and deletion handled within 30 days
Hosting and transfersWhere data sits and which tools send it abroad, mapped and decided
Breach logTimestamped incident record to support the 72-hour notice
MinimisationFewer form fields, trimmed analytics, shorter retention
Starting priceFixes from US$150; workflows from US$600

What we change on your site or app

Engineering work that supports your PDPL obligations

Your lawyer decides what the law requires of your business. We turn those decisions into code, screens and logs, and show you where each one lives.

Data and tag audit

A list of every form, cookie, pixel, script, plugin and third-party service on your site, what personal data each one touches, and where it sends it. This is the starting point for everything else.

Consent and cookie banner

A banner in Arabic and English that blocks analytics and advertising tags until the visitor accepts, stores the choice with a timestamp, and lets people change their mind. Part of fixes from US$150.

Data subject request workflow

A request form, identity check, internal queue with a 30-day timer, export in a readable format, and deletion that reaches backups and connected tools. From US$600.

Breach and incident log

An internal log that records when an incident was noticed, what data was involved and what was done, so your team can prepare the notice within the deadline.

Hosting and transfer review

A map of where your database, backups, email and analytics physically run, plus a plan if you decide to host inside the Kingdom.

Form and analytics minimisation

Remove fields you do not use, stop sending form contents to ad pixels, and set retention so old records are deleted on schedule.

App privacy updates

Consent screens, account deletion and store privacy labels for Flutter or React Native apps.

Privacy by design in new builds

The same controls designed into a new website or store instead of patched on later.

Why choose us

Banner plugin, law firm, or a developer who builds the controls?

You will likely need legal advice and engineering. This table shows what each route covers on its own.

Banner plugin, law firm, or a developer who builds the controls?
Area Cookie banner plugin only Law firm or consultant only BtechWaleTech with your counsel
Legal interpretation None Yes No; we follow your counsel's written decisions
Privacy notice text Template text Drafted for your business Placed and linked everywhere data is collected
Blocking tags before consent Only if configured correctly Advice only Built and tested tag by tag
Data request handling No Process design Form, queue, 30-day timer, export and deletion built
Breach log No Response plan Timestamped log and alerting built in
Hosting and transfers No Legal assessment Technical map, migration if you choose one
Arabic and English Varies Usually Bilingual screens; you approve the Arabic
Starting cost Low monthly fee Quotes vary widely From US$150 for fixes

We are developers, not lawyers: we do not certify a site as compliant, and the final judgement on your obligations belongs to your own legal counsel.

Pricing

What PDPL website work costs, in US dollars

Technical PDPL fixes on an existing website, such as the audit, consent banner, notice links and form clean-up, start from US$150 and usually take 1–2 weeks. Data request and breach-log workflows, which connect your forms, database and email or WhatsApp tools, start from US$600 over 2–4 weeks. When privacy controls sit inside a larger custom platform or portal, that work starts from US$900. The quote depends on how many tools hold personal data, whether you run an app as well as a site, and whether you decide to move hosting. Legal fees for your counsel are separate and paid by you.

Starting prices in INR and USD
ServiceIndia (INR)Worldwide (USD)Typical timelineWhat is included
Static website from ₹10,000 from US$150 1 to 2 weeks Up to 100 pages, Responsive design, Contact form and enquiry setup, Basic SEO tags and sitemap
SEO website (299+ pages) from ₹20,000 from US$300 3 to 5 weeks 299+ SEO pages, Keyword and page planning, Schema, sitemap, and internal linking, Design to deployment included
Ecommerce store from ₹50,000 from US$750 4 to 8 weeks Product and category pages, Payment gateway setup, Order and inventory basics, Performance tuning
Android & iOS app from ₹40,000 from US$600 6 to 10 weeks Android and iOS app (Flutter or React Native), Login, forms and push notifications, Admin panel and API connection, Google Play and App Store publishing
Custom web app or software from ₹60,000 from US$900 6 to 12 weeks Custom features and APIs, User accounts and roles, Admin panel, Deployment and handover
AI automation from ₹40,000 from US$600 2 to 4 weeks Workflow mapping, Tool and CRM integrations, AI agent or automation build, Testing and handover
Monthly SEO from ₹10,000/mo from US$150/mo Ongoing, monthly Technical fixes, On-page and content work, Local SEO and listings, Search Console reporting
Maintenance and support from ₹8,000/mo from US$120/mo Ongoing, monthly Content updates, Bug fixes, Backups and security checks, Speed and uptime checks

All prices are starting points, quoted in INR for India and USD for international clients, not fixed quotes. Final cost depends on the number of pages, features, integrations, content, and timelines. Share your requirement and you get an itemised estimate with nothing hidden. See full pricing.

What is the PDPL, and does it apply to your website?

The PDPL is Saudi Arabia's Personal Data Protection Law, and if your website or app collects names, phone numbers, emails, addresses, IDs or tracking data about people in the Kingdom, you should assume it applies and ask your lawyer to confirm the details. The Saudi Data and AI Authority (SDAIA) administers it through the National Data Governance Platform.

The law says it takes effect 720 days after publication (Article 43), and it has an Implementing Regulation and a separate regulation on transferring personal data outside the Kingdom. Enforcement has applied since September 2024. For a website owner, the practical question is not whether the law exists but which parts of your site handle personal data, and whether each part behaves the way the law and your privacy notice say it does.

PDPL compliance for websites is therefore mostly an inventory job followed by a handful of fixes. Contact forms, WhatsApp buttons, booking tools, checkout, newsletter sign-ups, analytics, ad pixels, chat widgets and embedded maps all touch personal data in some way.

  • Contact and quote forms: names, phones, emails, messages.
  • Checkout and accounts: addresses, order history, sometimes national ID.
  • Analytics and ad pixels: device identifiers, behaviour, sometimes form data.
  • Chat, booking and CRM tools: conversations and appointment details.

What must a Saudi website change for PDPL compliance?

Most sites need six changes: a privacy notice, working consent, a request workflow, a hosting and transfer decision, a breach log, and less data collected. The rest of this guide takes each one in turn, from the developer's side.

The order matters. Start with an audit, because you cannot write an accurate notice or consent banner until you know what the site actually collects. Many owners are surprised by what turns up: an old plugin still sending form data somewhere, an ad pixel capturing email addresses, or a test database copied to a developer's laptop years ago.

  • 1. Audit: list every place personal data enters, is stored or leaves the site.
  • 2. Notice: place the privacy notice your lawyer writes where people give data.
  • 3. Consent: keep non-essential tracking off until the visitor agrees.
  • 4. Requests: let people access, copy, correct and delete their data within 30 days.
  • 5. Hosting and transfers: decide where data lives and which transfers abroad you accept.
  • 6. Breach log: record incidents so the 72-hour notice is possible.
  • 7. Minimise: collect less, keep it for less time, share it with fewer tools.

Each item is a piece of engineering with a clear finish line. None of them needs a full website rebuild unless your platform is so old it cannot be changed safely.

What should a PDPL privacy notice cover, and where does it go on the site?

Article 12 of the PDPL requires a privacy policy made available to people before their data is collected, covering the purpose, what data is collected, how it is collected, stored, processed and destroyed, and the person's rights. Your lawyer writes that text; our job is to put it where it will actually be seen.

The Implementing Regulation adds detail on what people must be told, including the organisation's identity and contact details, the data protection officer's contact where one is appointed, the purpose and legal basis, retention periods, rights and how to exercise them, and how to withdraw consent. SDAIA also publishes a guide on preparing privacy policies in its knowledge centre.

On a website that means a permanent footer link in both languages, a short line with a link next to every form and checkout, the notice shown during app sign-up, and a version date so you can prove which text a person saw. When the notice changes, the site keeps the old versions.

Short notice at the form

One or two sentences under each form saying what the data is for, with a link to the full notice. Visitors read this; they rarely open the full page.

Version history

Each notice version stored with its date, and consent records point to the version shown. That is a small database table that saves a lot of argument later.

The law does not use the word "cookie", and SDAIA's handbook we reviewed does not single cookies out. But tracking that processes personal data is still processing, and the Implementing Regulation requires consent to be freely given, specific, clear and documented where consent is your legal basis. The practical, low-risk build is a banner that keeps non-essential tags off until the visitor agrees.

A real consent banner does three things a cosmetic one does not. It actually blocks analytics and advertising scripts before a choice is made. It records the choice with a timestamp and the notice version. And it lets people withdraw as easily as they agreed, through a link that stays on every page.

For Google tags, Google's consent mode defines four signals, ad_storage, analytics_storage, ad_user_data and ad_personalization, and a basic mode in which tags stay blocked until the visitor interacts with the banner. We wire the banner to those signals and to any non-Google pixels separately.

  • Necessary: session, cart, security and language cookies; on without consent.
  • Analytics: off until accepted, unless your counsel decides otherwise.
  • Advertising and remarketing: off until accepted.
  • Embedded videos and maps: loaded on click where they set tracking cookies.

Explicit consent is required for some data, including sensitive data and credit data, per Article 11 of the Implementing Regulation. If your forms collect health, religious or financial details, flag that to your lawyer before we design the screen.

How should a website handle PDPL data subject requests?

Give people a simple way to ask, check who they are, track the request against a 30-day clock, and answer with data they can read. The Implementing Regulation sets 30 days to carry out a request, with a further 30 days in cases that need unusual effort, so an email inbox and good intentions are not enough once volume grows.

Article 4 of the law lists the rights: to be informed, to access personal data, to receive it in a readable and clear format, to have it corrected, completed or updated, and to have data destroyed when it is no longer needed. Each maps to a feature. Access and copy need an export. Correction needs an edit path. Destruction needs deletion that reaches the database, the CRM, the email tool and, on schedule, backups.

Identity checks matter because a request is also an attack surface. A one-time code to the phone or email already on the account is usually proportionate; asking for a national ID copy often is not.

What we build

A bilingual request form, OTP verification, an admin queue with the due date shown, one-click export to a readable file, a deletion job across connected tools, and a log of every step.

What stays manual

Deciding whether an exception applies to a request. That is a legal call, so the queue has a 'needs legal review' status rather than an automatic refusal.

Does PDPL require Saudi hosting? Cross-border transfer and data location

The PDPL does not simply ban hosting abroad; it regulates transfers outside the Kingdom. Article 29 allows transfers in set circumstances where they do not harm national security and where the level of protection is not reduced, and SDAIA has issued a separate regulation on transfers plus standard contractual clauses and a transfer risk-assessment guideline. Your lawyer decides whether your current setup fits.

The technical job is to make the transfers visible. A typical Saudi website sends personal data to several countries without anyone deciding it: the host, the backup location, the email service, the analytics platform, the chat widget, the CRM. We produce a one-page map of each flow, the provider, the region and the data involved.

If you decide to keep data in the Kingdom, local cloud regions exist. Google Cloud's Dammam region, for example, is accessed by KSA-based customers through its local partner CNTXT, according to Google Cloud's documentation. Moving the database is a planned migration with downtime measured in minutes, but third-party tools may still send data abroad, so the map matters more than the host.

  • Database and file storage: which provider, which region.
  • Backups: often a different region from the main server.
  • Email and SMS: where messages and contact lists are processed.
  • Analytics, pixels and chat widgets: usually outside the Kingdom.

How do you log a breach so you can notify SDAIA within 72 hours?

Keep a timestamped incident log and alerting that tells a named person quickly. Article 24 of the Implementing Regulation requires the controller to notify the competent authority within 72 hours of becoming aware of a personal data breach, and to tell affected people without undue delay where the breach may harm them. The clock starts at awareness, so detection and logging are part of compliance.

SDAIA's National Data Governance Platform lists a service for notifying personal data breaches. The notice itself is your team's and your lawyer's job. What the website can do is make sure you notice incidents, record what happened, and have the facts ready: what data, how many records, when it started, what you did.

We add alerts for the signals that usually come first: repeated failed logins on admin accounts, unusual bulk exports, new admin users, changes to payment or form scripts, and database access from unfamiliar locations.

  • Time the incident was noticed and by whom.
  • Systems and categories of personal data involved.
  • Estimated number of people affected.
  • Containment steps taken, with times.
  • Who decided on notification, and when the notice was sent.

The log is internal and access-controlled. We build the tooling; decisions on notifying the authority and individuals stay with you and your counsel.

Form and analytics minimisation: collecting less on your website

Collect only what you use, keep it only as long as you need it, and send it to as few tools as possible. SDAIA publishes guidelines on determining the minimum personal data and on destroying data, and minimisation is also the cheapest compliance measure: data you never collect cannot leak.

On forms, that means asking whether each field earns its place. A quote form rarely needs a date of birth; a newsletter rarely needs a phone number. Optional fields should look optional. Free-text boxes invite people to share things you did not ask for, so a short hint helps.

On analytics, check what each tag actually sends. Some pixels capture form values or URLs containing emails. Per Google's documentation, Google Analytics 4 does not log or store IP addresses, but that does not cover every other script on your pages. We test each tag with a network inspector and remove what does not need to be there.

  • Remove unused form fields and old plugins.
  • Stop passing form contents or emails into ad pixels.
  • Set retention: delete stale enquiries and abandoned accounts on a schedule.
  • Mask personal data in logs and error reports.
  • Restrict staff access by role, and log exports.

Records of processing and the DPO: what the website contributes

Article 31 of the PDPL requires controllers to keep a record of processing activities, and the Implementing Regulation lists what it holds, including purposes, categories of data, retention periods, recipients, transfers outside the Kingdom and security measures. The website audit gives you most of the raw material for the website part of that record.

SDAIA's handbook notes that not every organisation must appoint a data protection officer; the Implementing Regulation sets the cases, and SDAIA publishes rules on appointing one. Whether you need a DPO is a question for your lawyer. If you have one, their contact details belong in the privacy notice and the request workflow should route to them.

We hand over the technical inventory in a format your DPO or lawyer can drop straight into the record: each system, the data it holds, where it runs, who can access it and how long records are kept.

PDPL compliance for online stores, booking sites and apps

Stores, booking sites and apps hold more personal data than brochure sites, so PDPL compliance for websites of this kind goes deeper: account deletion, order data retention, and marketing consent separate from order messages.

The Implementing Regulation requires a way for people to stop receiving marketing that is as easy as signing up (Article 29). So an unsubscribe link in every email, a STOP option on WhatsApp broadcasts, and an account setting for marketing preferences. Order confirmations and delivery updates are a different purpose and should not be tied to marketing consent.

Apps need an in-app account deletion path and accurate privacy labels on Google Play and the App Store. Marketplaces share buyer data with vendors, which needs tight limits; our multi vendor marketplace development page covers vendor access in detail. Store owners on Zid can see our note on integrations in the Zid store developer guide.

  • Marketing opt-in separate from order updates, with easy opt-out.
  • Account deletion in the site and the app.
  • Retention rules for orders, balanced against tax record-keeping your accountant advises.
  • Vendor, courier and support-tool access limited to what each needs.

What happens if a website ignores the PDPL?

The law sets real penalties, which is why it is worth doing properly rather than adding a banner and hoping. Article 36 allows warnings or fines of up to 5 million riyals for violations, which can be doubled for repeat offences, and Article 35 sets up to two years' imprisonment and fines of up to 3 million riyals for disclosing sensitive data with intent to harm.

We mention penalties only for context. The more common cost of ignoring PDPL compliance for websites is practical: a customer asks for their data and nobody knows where it is; a breach goes unnoticed for weeks; an enterprise client's procurement team sends a questionnaire you cannot answer. Each of those is avoided by the same engineering.

None of this is legal advice. Your lawyer will judge your exposure; we build the controls that make their advice real on your site.

How much does PDPL website compliance cost?

With us, technical fixes on an existing site start from US$150, request and breach workflows from US$600, and privacy controls inside a larger custom platform from US$900. Consultancies and agencies quote very differently, and much of the gap is whether legal work, engineering or both are included.

The cost drivers are easy to list. The number of tools holding personal data sets the audit size. A site with an app, a CRM and an email platform needs deletion and export across all of them. An old CMS with abandoned plugins may need a platform update before any fix is safe. And a hosting move adds a migration.

  • Number of forms, tools and integrations that hold personal data.
  • Website only, or website plus mobile app.
  • Automated request handling versus a guided manual process.
  • Hosting move inside the Kingdom, or staying put with documented transfers.
  • Age and condition of the CMS or codebase.

We quote in USD, itemised, in about two working days. Legal review is separate and paid to your own counsel.

Working with a team in India on PDPL fixes for a Saudi site

The time difference is small: India is two and a half hours ahead of Saudi Arabia, so most of your Sunday-to-Thursday day overlaps with ours, and we answer WhatsApp every day. Calls are on Google Meet or Zoom, and each one ends with a written list of decisions.

Because this work touches personal data, access is set up carefully. We work in staging copies with personal data masked wherever possible, use accounts you create with limited roles, and never keep copies of your database. If you decide on in-Kingdom hosting, the production environment sits in your cloud account in that region.

Quotes and invoices are in US dollars from India, paid by Wise, bank wire or PayPal. There is no Saudi office or on-site visit. We sign your NDA, and your lawyer's written decisions become the acceptance criteria for our work.

Your first two weeks

Days 1–3: kickoff call, limited access granted, audit of forms, tags and tools. Days 4–6: audit report and transfer map sent to you and your lawyer. Days 7–10: consent banner and notice links built on staging, request form drafted, and a list of decisions your counsel needs to make.

What we will not do

Draft legal text, interpret the law for your business, register you with SDAIA, act as your DPO or certify compliance. We will tell you when a question needs your lawyer.

Worked example: a hypothetical fitness studio with a booking site and app

Picture a Riyadh fitness studio group with three branches, a booking website, a Flutter app, a CRM and WhatsApp reminders. This is a made-up scenario showing how PDPL website work would run, not a past project.

The audit finds seven tools holding member data, an ad pixel receiving email addresses from the sign-up form, health questions stored in plain text next to bookings, and backups in a region nobody chose. The lawyer decides the health questions need explicit consent and a shorter retention period, and that analytics can wait for consent.

The build: a bilingual consent banner wired to consent mode, the pixel stripped of form data, health answers moved to a separate, access-restricted table with explicit consent recorded, a request form with OTP and a 30-day queue, account deletion in the app, marketing opt-out on WhatsApp, and an incident log with admin-login alerts. Quoted from US$150 for the site fixes and from US$600 for the request and incident workflows, with app changes scoped alongside.

PDPL compliance checklist for websites and apps

Use this list as a working checklist with your lawyer and developer. Each line is something you can open the site and verify, which is the point: compliance you cannot see on the page usually is not there.

  • Inventory of every form, tag, plugin and tool that touches personal data.
  • Privacy notice written by counsel, linked in the footer and beside every form, in Arabic and English.
  • Consent banner that blocks non-essential tags until accepted, with withdrawal on every page.
  • Consent records with timestamp and notice version.
  • Data request form, identity check and a queue that shows the 30-day due date.
  • Export and deletion that reach every connected tool.
  • Transfer map of providers and regions, reviewed by counsel.
  • Incident log, admin alerts and a named person for the 72-hour decision.
  • Unused fields removed, retention schedules running, logs masked.
  • Marketing opt-out as easy as opt-in; app account deletion working.

After launch, re-run the tag check whenever marketing adds a new pixel. Most sites drift out of shape within months because someone pastes a new script into the header.

Keeping a website PDPL-ready after the fixes

PDPL compliance for websites is not a one-off project, because websites change weekly. New campaigns bring new pixels, new forms appear for events, and plugins update. A light monthly check keeps the controls working.

After our work you get two months of free maintenance, during which we re-check tags after changes and keep the request and incident tools running. After that, maintenance starts from US$120/mo a month. If you also want search growth, monthly SEO starts from US$150/mo; privacy and SEO work well together, because a lean, fast site with fewer scripts also scores better on Core Web Vitals.

For AI search, clear public pages about how you handle data, in plain Arabic and English, help assistants answer customers' privacy questions accurately. Our SEO services for Saudi businesses cover that content side.

Law to code

PDPL requirements and the website change each one drives

Article numbers refer to the PDPL (law) or the Implementing Regulation (IR), as published by SDAIA. Your counsel confirms how each applies to you.

PDPL requirements and the website change each one drives
RequirementSourceWebsite or app changeStarts from
Privacy policy available before collection Law, Art. 12Notice linked in footer and beside every form, versionedUS$150
Consent freely given, specific, documented IR, Art. 11Banner blocks tags until consent; choices loggedUS$150
Rights to access, copy, correct, destroy Law, Art. 4Request form, export, edit and deletion jobsUS$600
Act on requests within 30 days IR, Art. 3Queue with due dates and remindersUS$600
Breach notice within 72 hours IR, Art. 24Incident log, admin alerts, named ownerUS$600
Easy opt-out from marketing IR, Art. 29Unsubscribe links, WhatsApp STOP, preference pageUS$150
Records of processing Law, Art. 31Technical inventory handed to your DPO or counselUS$150
Transfers outside the Kingdom Law, Art. 29Provider and region map; optional in-Kingdom hostingUS$900

Data subject requests

How each type of request is handled on the site

The 30-day window comes from the Implementing Regulation. Identity checks should be proportionate to the data involved.

How each type of request is handled on the site
RequestWhat the person getsHow we build itWatch out for
Be informed Clear notice of purpose and useShort notices at forms, full notice pageNotice out of date with real tools
Access Confirmation of what you holdAdmin search across connected toolsData scattered in email and sheets
Copy in readable format A file they can openOne-click export to a readable fileIncluding other people's data by mistake
Correction or update Accurate recordsSelf-service edit or admin edit with logChanges not reaching the CRM
Destruction Data removed when no longer neededDeletion job across tools; backups on scheduleLegal retention duties your accountant flags
Withdraw consent Tracking or marketing stopsPreference link on every page and messageTags that ignore the new choice

Timeline

A typical PDPL website project, phase by phase

For a business website with a few integrations. Stores and apps add time to the request and deletion phase.

A typical PDPL website project, phase by phase
PhaseWorkTypical timeOutput
Audit Forms, tags, plugins, tools, hosting regions2–4 daysData inventory and transfer map
Counsel review Your lawyer decides notice, consent and transfersDepends on counselWritten decisions
Quick fixes Banner, notice links, form clean-up, tag removal3–5 daysChanges on staging
Workflows Request queue, export, deletion, incident log1–3 weeksWorking tools with logs
Testing Tag behaviour before and after consent, request drills2–3 daysTest notes and screenshots
Launch and handover Go live, walkthrough, inventory handed over1–2 daysRunbook and recording

Across Saudi Arabia

Where Saudi businesses ask about PDPL and their websites

The law applies nationwide and our work is remote. What differs is the kind of personal data each business collects.

  • Riyadh

    Government suppliers, fintech start-ups and B2B software firms in the capital often face privacy questionnaires from larger clients and need their website and app controls documented.

  • Jeddah

    Retail, fashion and hospitality brands here run heavy marketing tags and loyalty sign-ups, so consent banners and marketing opt-out are usually the first fixes.

  • Dammam

    Industrial, logistics and trading businesses in Dammam hold customer and driver data in several tools, which makes the data inventory and transfer map the most useful step.

  • Al Khobar

    Clinics, beauty centres and fitness studios in Khobar collect health-related details on booking forms, which may need explicit consent and tighter access.

  • Dhahran

    Engineering and services suppliers around Dhahran often answer strict vendor security reviews, so breach logging and access control on their portals matter.

  • Mecca

    Hotels, transport and travel services serving visitors handle passport and booking details, so retention rules and careful hosting choices come up quickly.

  • Medina

    Hospitality and tour operators collect guest details through booking forms and WhatsApp, where minimisation and clear notices at each form help most.

  • Buraidah

    Agricultural traders and growing online sellers in Qassim often start with simple WordPress sites, where plugin clean-up and a real consent banner go a long way.

  • Abha

    Tourism, hotels and event businesses in Asir run seasonal booking forms, and seasonal data should be deleted on schedule rather than kept indefinitely.

  • Taif

    Hotels, schools and family-run retailers in Taif collect parent, guest or customer contacts, and benefit from a simple request form and a clean mailing list.

  • Tabuk

    New tourism and real estate projects in the north-west collect leads through ads and landing pages, where pixel behaviour needs checking before consent.

  • Al Ahsa

    Schools, clinics and family businesses in Al Ahsa often keep enquiries in spreadsheets and inboxes, which makes access and deletion requests hard without a workflow.

  • Jubail

    Contractors and industrial service firms in Jubail manage worker and client records in portals where role-based access and export logging matter.

  • Najran

    Local retailers and service providers in Najran moving online can build privacy controls in from the start, which is far cheaper than retrofitting them later.

How it works

How a PDPL website project runs with us

  1. Kickoff and access

    A short call on your site, app and tools. You create limited accounts for us; we agree how personal data will be masked in staging.

  2. Audit and map

    We list every form, tag, plugin and tool that touches personal data, where each runs, and send you and your lawyer the inventory and transfer map.

  3. Counsel decisions

    Your lawyer decides notice wording, consent approach, transfers and retention. Their written answers become our checklist and acceptance criteria.

  4. Quick fixes first

    Consent banner, notice links, form clean-up and tag removal go live early, because they reduce exposure fastest and need little new code.

  5. Workflows and logs

    Request queue, export and deletion across tools, incident log and admin alerts are built on staging, tested with drills, then launched.

  6. Handover and upkeep

    Runbook, recorded walkthrough and technical inventory handed over, followed by two months of free maintenance and tag re-checks after changes.

Questions

PDPL compliance for websites: common questions

What is PDPL compliance for websites?

It is the set of changes that make a website or app handle personal data the way Saudi Arabia's Personal Data Protection Law and your privacy notice say it should. Technically that usually means a visible privacy notice, working consent, a data request workflow, documented hosting and transfers, a breach log, and collecting less data. Your lawyer confirms the legal requirements for your business.

Does the PDPL apply to my small business website?

If your site collects personal data such as names, phone numbers, emails or tracking data from people in Saudi Arabia, you should assume the law is relevant and ask your lawyer to confirm how it applies. Even a simple contact form and an analytics tag handle personal data. The fixes for a small site are usually modest and quick.

Who enforces the PDPL?

The Saudi Data and AI Authority, SDAIA, administers the Personal Data Protection Law through its National Data Governance Platform. That platform publishes the law, the Implementing Regulation, the regulation on transfers outside the Kingdom and guidance documents, and it provides services such as a national register and personal data breach notification.

Does PDPL require a cookie consent banner?

The law does not mention cookies by name, and the SDAIA handbook we reviewed does not single them out. However, tracking that processes personal data is processing, and where you rely on consent the Implementing Regulation requires it to be freely given, specific and documented. The low-risk approach is a banner that blocks non-essential tags until the visitor agrees.

What must a PDPL privacy notice include?

Article 12 of the law requires a policy covering the purpose, the data collected, how it is collected, stored, processed and destroyed, and people's rights. The Implementing Regulation adds items such as your identity and contact details, any DPO contact, legal basis, retention periods and how to withdraw consent. Your lawyer writes it; we place and version it on the site.

How quickly must I answer a data subject request?

The Implementing Regulation sets 30 days to carry out a request, with a possible further 30 days where the request needs unusual effort. A request queue with visible due dates, identity checks and one-click export makes that practical. Without a workflow, requests tend to sit in someone's inbox until the deadline has passed.

What rights do people have under the PDPL?

Article 4 of the law lists the right to be informed about collection and its purpose, to access personal data held about them, to receive it in a readable and clear format, to have it corrected, completed or updated, and to have it destroyed when it is no longer needed. The Implementing Regulation also covers withdrawing consent and stopping marketing.

How long do I have to report a data breach under PDPL?

Article 24 of the Implementing Regulation requires the controller to notify the competent authority within 72 hours of becoming aware of a personal data breach, and to tell affected people without undue delay where the breach may harm them. We build incident logging and alerts so you notice problems quickly and have the facts ready for your team and lawyer.

Does PDPL require my website to be hosted in Saudi Arabia?

The law regulates transfers of personal data outside the Kingdom rather than simply banning foreign hosting. Article 29 and a separate SDAIA regulation set the conditions, and SDAIA publishes standard contractual clauses and a transfer risk-assessment guideline. Your lawyer decides whether your setup fits; we map every provider and region and can move hosting into the Kingdom if you choose.

Can I use Google Analytics under PDPL?

Many Saudi sites do, with safeguards your lawyer approves. Google's documentation says Google Analytics 4 does not log or store IP addresses, and consent mode lets analytics wait for the visitor's choice. The bigger risks are usually other pixels that send form data or emails. We test every tag and configure consent so analytics behaves the way your notice says.

What are the penalties for breaking the PDPL?

Article 36 of the law allows warnings or fines of up to 5 million riyals, which can be doubled for repeat violations. Article 35 sets up to two years' imprisonment and fines of up to 3 million riyals for disclosing sensitive data with intent to harm. Your lawyer can explain your specific exposure; we focus on the technical controls.

Do I need a data protection officer for my website?

Not always. SDAIA's handbook says not every organisation must appoint a DPO, and the Implementing Regulation defines when one is required; SDAIA also publishes appointment rules. Ask your lawyer whether your processing triggers it. If you do appoint one, their contact goes in the privacy notice and the request workflow routes to them.

How much does PDPL website compliance cost?

With BtechWaleTech, technical fixes on an existing website start from US$150, data request and breach-log workflows from US$600, and privacy controls inside a larger custom platform from US$900. The price depends on how many tools hold personal data, whether an app is involved and whether hosting moves. Legal review is separate and paid to your own counsel.

How long does it take to make a website PDPL-ready?

The audit takes a few days, quick fixes such as the consent banner and notice links about a week, and request and incident workflows one to three weeks. The biggest variable is how quickly your lawyer can make decisions on notice wording, consent and transfers. Starting the audit early gives your counsel accurate facts to work from.

Can you guarantee my website is PDPL compliant?

No, and nobody honest can. Compliance depends on how your whole business processes personal data, not just the website, and the legal judgement belongs to your own counsel. What we can do is build the technical controls your lawyer specifies, show where each one lives, and test that they behave as described in your privacy notice.

Is a cookie banner plugin enough for PDPL?

Rarely on its own. Many banners look correct but still load analytics and ad tags before the visitor chooses, or ignore a withdrawal. A banner also does nothing for data requests, breach logging, transfers or minimisation. A plugin can be part of the answer if it is configured and tested tag by tag.

How does PDPL affect my online store or booking system?

Stores and booking systems hold addresses, order histories and sometimes health or ID details, so they need account deletion, retention rules, marketing consent kept separate from order messages, and an opt-out as easy as the opt-in. Tax record-keeping your accountant advises may require keeping some order data, so deletion rules must balance both.

What about PDPL for mobile apps?

Apps need the same controls plus a few of their own: consent screens before tracking SDKs start, in-app account deletion, accurate privacy labels on Google Play and the App Store, and careful handling of device permissions. We update Flutter and React Native apps and keep the app and website consistent with one privacy notice.

Can a developer in India work on a Saudi website's personal data?

Yes, with care, and your lawyer should confirm the arrangement fits your transfer decisions. We work in staging copies with personal data masked where possible, use limited accounts you create and control, and never keep copies of your database. Production systems stay in your cloud account, including any in-Kingdom hosting you choose.

Will PDPL changes hurt my SEO or marketing?

Usually less than people fear. Consent affects how much analytics data you see, and consent mode helps fill some gaps. Removing unused scripts often makes pages faster, which helps Core Web Vitals. Marketing lists built on clear opt-in tend to perform better, and a plain privacy page can help AI assistants answer customer questions accurately.

What happens after the PDPL fixes are live?

You get two months of free maintenance, including tag re-checks after marketing changes and upkeep of the request and incident tools. After that, maintenance starts from US$120/mo a month. We recommend a quick tag review whenever a new pixel, form or plugin is added, because that is how most sites drift.

Next step

Send your site link and let us map its personal data

Share your website or app link on WhatsApp. We reply with the audit scope and an itemised USD quote in about two working days, and your lawyer keeps the final say on every legal decision.