Saudi Arabia's data protection law for marketers: consent, leads and WhatsApp

Saudi Arabia's Personal Data Protection Law has been enforced since its grace period ended in September 2024, and it reaches agencies outside the Kingdom. Here is what it asks of lead forms, marketing messages and data sent to the UAE.

3 October 20263 min readBy the Wiro team, Dubai
A padlock with the WhatsApp and Gmail logos and a note on consent, beside Article 28 of the Saudi data protection implementing regulation
Screen: SDAIA. Logos: WhatsApp, Gmail.

If you run lead forms, email or WhatsApp campaigns for a Saudi client, the Personal Data Protection Law applies to you, even from Dubai. Article 2 covers processing of data on people residing in the Kingdom by any party outside it. The law came into force on 14 September 2023, businesses had until 14 September 2024 to comply, and in April 2025 the Saudi Data and AI Authority, SDAIA, said its committees were imposing penalties now that the grace period was over.

Sensitive data

The law treats as sensitive: racial or ethnic origin, religious, intellectual or political belief, criminal and security data, biometric or genetic data used for identification, health data, and data on people of unknown parentage. Keep these out of marketing forms entirely. Article 26 excludes sensitive data from marketing use.

The marketing rules

  • Using someone's personal contact details, such as their email address, for advertising needs their prior consent and a clear way to opt out (Article 25 of the law).
  • Marketing use is allowed only for data collected directly from the person, with consent (Article 26).
  • Consent must be freely given, documented and separate for each purpose (Article 11 of the Implementing Regulation). Explicit consent is needed for sensitive data, credit data and fully automated decisions.
  • Before sending advertising where there has been no prior interaction, get consent, show the sender's name, and make opting out as easy as opting in, free and immediate (Article 28).
  • Direct marketing, physical or electronic, needs that consent, an easy opt-out and the sender's identity, and must stop without undue delay once consent is withdrawn (Article 29).

Rights, requests and breaches

  • People can be informed, access their data, get a copy in a readable format, correct it and have it destroyed, and they can withdraw consent at any time.
  • Requests must be answered within 30 days, extendable by 30.
  • A breach that could cause harm must be reported to SDAIA within 72 hours, and the people affected told without undue delay. The duty depends on the risk of harm; it does not apply to every incident.

Officers and registration

SDAIA's rules require a data protection officer where core activities involve regular, systematic monitoring or sensitive data, and its own examples include "marketing companies processing personal data for marketing purposes" and the use of cookies. Registration on the national data governance platform is required for public entities, entities whose main activity is processing personal data, those processing sensitive data, and individuals processing beyond personal use. The platform has a track for entities outside the Kingdom.

Sending data to the UAE

Transfers outside the Kingdom are governed by a separate regulation. Where data goes abroad under one of its exemptions, standard contractual clauses or binding common rules apply, and a risk assessment is required, as it is for continuous or widespread transfers of sensitive data.

Penalties

Violations carry a warning or a fine of up to SAR 5 million, which can be doubled for a repeat offence. Disclosing sensitive data to harm someone or for personal gain is a separate offence, decided by a court, carrying up to two years in prison and a fine of up to SAR 3 million. People can also claim compensation.

For agencies running Saudi campaigns

  • The brand is usually the controller and the agency the processor, so put a processing contract in place.
  • Show the privacy notice on the lead form, and collect a separate, logged consent for marketing.
  • Leave sensitive data fields out of forms.
  • Name the sender in every WhatsApp message and email, and offer a free, one-step opt-out.
  • If leads are stored in the UAE or elsewhere, document the transfer and its risk assessment.
  • Check whether your agency's own officer and registration duties apply.

Our guide to UAE data protection for agencies covers the rules on the other side of the border.