Saudi PDPL and Health Data: Obligations for Clinics

Health data is sensitive data under Saudi Arabia's PDPL. Breach notice in 72 hours, transfer rules, fines and 2026 draft amendments: a guide for clinics.

Saudi Arabia's Personal Data Protection Law (PDPL) is now fully part of the compliance landscape for every clinic, laboratory and hospital in the Kingdom. Health data sits at the top of the law's risk scale. The Saudi Data and Artificial Intelligence Authority (SDAIA) is still refining the implementing rules, with consultations in 2025 and again in 2026. This guide sets out the obligations that matter most to healthcare providers, based on the law, its regulations and published legal analyses.

Health data is "sensitive data"

The PDPL came into force on 14 September 2023, after amendments approved earlier that year, together with its Implementing Regulation and its rules on cross-border transfers. The amended law lists health data as sensitive data, along with genetic and biometric data, data revealing ethnic origin or beliefs, and criminal or security data.

For a clinic this means that the core of its activity, including consultation notes, diagnoses, imaging, lab results and prescriptions, falls into the strictest category. Sensitive data attracts heavier duties and harsher penalties when it is misused.

Core obligations for healthcare providers

Lawful basis and transparency

Process patient data only for a defined purpose, tell patients how their data is used through a clear privacy notice, and collect no more than you need. Keep records of your processing activities.

Risk assessment

Published legal summaries note that controllers must carry out risk assessments for certain processing, including the processing of sensitive personal data, apparently even when it is not large-scale. For most clinics this means documenting how patient data flows through the EMR, the billing system, imaging archives, messaging tools and any cloud or AI service.

Data protection officer

Commentary on enforcement since 2024 lists failure to appoint a data protection officer, where one is required, among the violations SDAIA has flagged. Hospitals and groups that process sensitive data at scale should treat the appointment as a priority.

Security and breach notification

Controllers must take organisational and technical measures to keep data safe. If a breach may cause harm, the controller must notify SDAIA through the National Data Governance Portal within 72 hours of becoming aware of it. Affected individuals must be informed without undue delay. Prepare a written incident procedure before you need it.

Sending data outside the Kingdom

Cloud hosting, teleradiology, foreign laboratories and AI tools can all involve a transfer abroad. SDAIA amended the transfer regulation in September 2024 to bring it closer to international standards. Where the destination has not been recognised as adequate, transfers rely on safeguards such as standard contractual clauses, binding common rules or accreditation certificates. When this was reported, no list of adequate countries had been published.

In practice, a clinic that pastes patient notes into a foreign online service is likely making a cross-border transfer of sensitive data. It needs a legal basis and safeguards for that, or a tool that keeps the data on site.

Penalties

Law-firm summaries describe a tiered system:

ViolationMaximum sanction
Disclosing or publishing sensitive data with intent to harm or for personal benefitup to 2 years' imprisonment and/or a fine of up to SAR 3 million
Other violations of the lawfine of up to SAR 5 million, which can be doubled for repeat offences

Commentators stress that the SAR 5 million ceiling also covers procedural failures, not only large leaks.

What is changing: 2025 and 2026 consultations

The rules are still evolving:

  • On 27 April 2025, SDAIA opened a third public consultation on draft amendments to the Implementing Regulations. The drafts covered privacy notices, record-keeping, complaints, the DPO's role and controller registration.
  • In October 2026, Al Tamimi & Co. reported a new SDAIA consultation. Among other things, it proposes a requirement for controllers to store personal data within Saudi Arabia, while still allowing transfers that comply with the PDPL. It also proposes a 20-business-day deadline to answer SDAIA requests and a 90-day window for data subject complaints. DataGuidance reported a comment period running until 5 November 2026.

These 2026 measures are proposals, not law. Clinics should follow the final text before redesigning their infrastructure.

Key takeaways

  • Treat every patient record as sensitive data under the PDPL and document why and how you process it.
  • Map your data flows, including cloud, messaging, imaging and AI tools, and run a risk assessment.
  • Appoint or designate a data protection lead and write a breach procedure built around the 72-hour notice to SDAIA.
  • Check every foreign service that sees patient data for transfer safeguards. Prefer tools that keep data inside the clinic.
  • Watch the 2026 draft amendments, especially the proposed in-Kingdom storage requirement.

This article is general information, not legal advice. Consult qualified counsel for your situation.

Frequently asked questions

Is health data sensitive under the Saudi PDPL?

Yes. The amended PDPL lists health data as sensitive data, with genetic, biometric and certain other categories, which brings stricter obligations and higher penalties.

How quickly must a clinic report a data breach in Saudi Arabia?

Where a breach may cause harm, the controller must notify SDAIA through the National Data Governance Portal within 72 hours of becoming aware of it, and inform affected individuals without undue delay.

Must patient data be stored inside Saudi Arabia?

A 2026 SDAIA consultation proposes an in-Kingdom storage requirement, but it was still a draft in October 2026. Current rules allow transfers abroad with safeguards.

Sources

  1. Latham & Watkins — Saudi Arabia's data protection law enters into force
  2. Baker McKenzie — Saudi Arabia: New amendments have been introduced to the Personal Data Protection Law
  3. DLA Piper — Data Protection in Saudi Arabia
  4. Clyde & Co — Saudi Arabia PDPL: third public consultation (2025)
  5. Al Tamimi & Co — SDAIA opens public consultation on proposed amendments to the PDPL Implementing Regulation
  6. DataGuidance — Saudi Arabia jurisdiction overview
Dictate your reports, nothing leaves your computer

Nabady Whisper transcribes your voice offline in English, French or Arabic, with report templates for every specialty.

General information, checked at the publication date; it is neither medical nor legal advice.

Share LinkedIn WhatsApp X