PDPL structure overview
PDPL is the first comprehensive Saudi privacy framework. Substantively similar to GDPR with Saudi-specific elements: explicit consent default (limited reliance on legitimate interest), mandatory data subject notice + consent, prior approval for cross-border transfers in some contexts, SDAIA as the regulator.
Data subject rights under PDPL
Per PDPL Art 4, Saudi data subjects have rights to: be informed about purpose + parties, access their data, request correction, request destruction, request transfer of their data (portability), object to processing. Koydo's data subject request flow handles all 6 rights.
Children + adolescent provisions
PDPL requires explicit consent for processing minor data; specific operational requirements still being refined by SDAIA implementation guidance. Koydo's default: COPPA-equivalent verifiable parental consent for all Saudi learners under 18, conservative posture pending SDAIA final guidance.
Cross-border data transfer
Per PDPL Art 29-31, transferring Saudi personal data outside Saudi Arabia requires: an adequate country determination, OR equivalent contractual protections, OR specific approval, OR exception for important state interest. Koydo's Saudi → US transfers use standard contractual clauses + specific approval as needed for processing scope.
Breach notification to SDAIA
Per PDPL Art 12 + implementing regulations, controllers must notify SDAIA + affected data subjects of incidents causing harm. Koydo's commitment: notify Saudi controllers within 48 hours of confirmed material breach so they can meet their SDAIA notification obligations.
How Saudi institutions engage
Saudi-based corporate Arabic cohorts (MENA-based multinationals, Saudi-based companies) typically engage via institutional contracts with Arabic-language DPA + PDPL addendum. Saudi government + state-affiliated institutions have additional procurement requirements (preferential local supplier rules) that Koydo addresses via partner arrangements where applicable.