PDPL Compliance for Saudi Hospitals | Medinous

PDPL Compliance for Saudi Hospitals: What You Must Know

PDPL compliance for a Saudi hospital means enforcing Saudi Arabia’s Personal Data Protection Law in software: consent as the default lawful basis for processing patient data, breach notification to SDAIA within 72 hours, restrictions on moving data outside the Kingdom, and audit evidence to prove all of it. Since September 2024 the law has been fully in force and actively enforced, with administrative penalties reaching SAR 5 million per violation.

QUICK ANSWER

Under Saudi Arabia’s PDPL, enforced by SDAIA: consent is the default lawful basis and health data is sensitive data with enhanced protection; breaches must be notified within 72 hours; cross-border transfers are restricted and governed by separate regulation; penalties reach SAR 5 million per violation, with criminal sanctions for intentional disclosure. PDPL sits alongside NPHIES and ZATCA, so privacy is one thread in a wider KSA compliance fabric. The same control patterns extend across the Gulf, Africa and the Caribbean.


This guide is part of our pillar on Patient Privacy and Data Security: The Controls Every Hospital Management System Must Enforce. PDPL is where the six technical controls in that guide meet the law — this article covers the Saudi obligations and the wider regional picture in detail.


Sep 2024

PDPL fully in force after the grace period; now actively enforced.

72 hrs

Window to notify SDAIA of a personal data breach.

SAR 5M

Maximum administrative penalty per violation, doubling for repeat offences.

48

SDAIA enforcement decisions issued as the law moved into active enforcement.

WHY THIS MATTERS NOW: PDPL is no longer a future obligation. SDAIA is issuing decisions, and organisations have days, not weeks, to respond to an enforcement notice. Compliance is a state a hospital maintains with evidence, every day, not a certificate earned once.

What PDPL is, and Who it Applies to

The Personal Data Protection Law was enacted by Royal Decree M/19 in 2021, amended in 2023, and came fully into force on 14 September 2023 with a one-year grace period that expired on 14 September 2024. It is enforced by the Saudi Data and Artificial Intelligence Authority (SDAIA) through its national data-governance platform. One of its defining features is reach: it applies to any entity, inside or outside the Kingdom, that processes the personal data of individuals located in Saudi Arabia. For a hospital, that means every patient record it holds is in scope.

Crucially, health data is not ordinary personal data under the law — it is sensitive data, which carries enhanced protection. That single classification raises the bar for how a hospital must handle consent, access, storage, and disclosure of clinical information, and it is why data protection cannot be treated as a back-office IT concern in a Saudi healthcare setting.

What PDPL Requires of a Hospital

The obligations translate directly into how a hospital management system must behave. These are the requirements a CIO, compliance lead, or medical director needs to be able to evidence.

  • Consent as the default lawful basis. Patient data is processed on a defined lawful basis; for sensitive health data consent carries enhanced protection. The system must capture, version, and evidence it.
  • 72-hour breach notification. Personal data breaches must be reported to SDAIA within 72 hours, so the incident-response runbook has to be wired to a fixed clock.
  • Data subject rights. Patients have rights of access, correction, deletion, and portability the hospital must service.
  • Cross-border transfer restrictions. Moving patient data outside the Kingdom is governed by separate regulation and mechanisms such as standard contractual clauses, making residency a design decision.
  • Penalties with teeth. Administrative penalties reach SAR 5 million per violation, doubling for repeat offences, with criminal sanctions for intentional disclosure of sensitive data.

Behind each of these sits a technical control. Consent needs a capture-and-enforce layer; breach notification needs monitoring and a rehearsed runbook; data subject rights need the record to be findable and exportable; transfer restrictions need hosting decisions made deliberately. This is exactly why we treat privacy as a stack of enforceable controls in the pillar guide rather than as a policy document.

Consent and the Burden of Proof

Under PDPL, consent is not a formality collected once at registration. It is the lawful basis on which processing rests, and the burden of proving it sits with the hospital. That means the system has to record what a patient agreed to, when, and for what purpose — and be able to produce that evidence on demand. A scanned form in a folder is documentation; it is not enforceable consent.

This is where consent management becomes an operational discipline rather than a compliance checkbox. Consent needs to be granular, versioned, and enforced at the point of access, so a record is only shared for a purpose the patient actually agreed to. We cover how to build that properly in Consent Management: Handling Patient Data the Right Way.

THE DEMONSTRABILITY TEST: When SDAIA investigates, the question is not only whether a control existed but whether the hospital can prove who accessed sensitive data and when. A tamper-evident audit trail is often the line between a manageable finding and a finding of negligence — which is why encryption and audit trails underpin PDPL compliance in practice.

FREE DOWNLOAD — THE HOSPITAL DATA PRIVACY HANDBOOK

The six controls, the multi-market compliance map, and a practical build sequence — in one guide for hospital IT and compliance leaders across the Gulf, Africa and the Caribbean. . Download at medinous.com/brochures

PDPL Sits Alongside NPHIES and ZATCA

A Saudi hospital does not manage PDPL in isolation. It already carries NPHIES interoperability and claims obligations and ZATCA e-invoicing requirements. Patient data privacy is one thread in that wider compliance fabric, and the smart approach is to let the same underlying controls serve all three. The access model, the audit trail, and the residency decision that satisfy PDPL are the same infrastructure that supports NPHIES exchange and ZATCA invoicing securely.

This is the practical argument for building privacy into the platform rather than bolting it on before an audit: compliance configured after deployment is fragile and duplicated across three separate obligations, while compliance engineered into the core is enforced once and reused. It also means new mandates land more gently, because the foundation is already in place.


“Compliance configured after deployment is fragile. Compliance engineered into the platform is enforced once and serves PDPL, NPHIES and ZATCA together.”


A Practical PDPL Readiness Checklist

For a hospital assessing where it stands, the following is a working checklist. It maps the legal obligations onto the technical and organisational steps that actually satisfy them.

✓  Register and assign clear accountability for data protection, including a responsible owner.

✓  Map where patient data is collected, stored, and transferred, including every integration and vendor.

✓  Enforce consent as a lawful basis, captured, versioned, and evidenced in the system.

✓  Encrypt patient data at rest (AES-256) and in transit (TLS 1.3), backups included.

✓  Maintain tamper-evident audit logs of all access to sensitive data.

✓  Wire a breach-response runbook to the 72-hour SDAIA notification clock, and rehearse it.

✓  Confirm hosting satisfies data-residency and cross-border transfer rules.

✓  Service data subject rights — access, correction, deletion, portability — through the system.

✓  Review third-party and vendor access under the same standard the hospital holds itself to.

Beyond KSA: The Same Pattern Across Our Markets

Medinous operates across the Gulf, Africa and the Caribbean, and while the statute changes by market, the operational requirements converge: consent-first processing, tight breach-notification windows, cross-border transfer rules, and real penalties. A hospital group that builds for the strictest regime is close to compliant everywhere. The table below is a practical orientation to the primary regime in each market as of 2026 — it is not legal advice, and hospitals should confirm current obligations with local counsel.

MarketPrimary lawRegulatorStatus (2026)
Saudi ArabiaPDPL (Royal Decree M/19, 2021)SDAIAFully enforced since Sep 2024; 72-hour breach notice; fines to SAR 5M.
BahrainPDPL (Law No. 30 of 2018)PDPAIn force since 2019; GDPR-aligned; consent and breach duties.
QatarPDPPL (Law No. 13 of 2016)NCGAA / CDPPIn force since 2017; among the first GCC data-protection laws.
KuwaitCITRA Data Privacy Regulation (2024)CITRASector regulation; a general national law is anticipated.
KenyaData Protection Act 2019 + Digital Health Act 2023ODPCActive enforcement; health data dual-regulated; 72-hour notice.
NigeriaData Protection Act 2023 (NDPA)NDPCActive enforcement; annual compliance audit returns; DPO required.
GhanaData Protection Act 2012 (Act 843)DPCNationwide enforcement began Jan 2026; registration mandatory.
BotswanaData Protection Act (amended 2024)Info. & Data Protection CommissionAmended Act in force from Jan 2024.
UgandaData Protection and Privacy Act 2019PDPO / NITA-UIn force; registration and consent obligations.
CaribbeanNational DPAs (GDPR-aligned, varies)National authoritiesRegimes advancing toward unified regional exchange.

THE SHARED PATTERN

Across all these markets the requirements converge: a lawful basis (usually consent) enforced in software, breach notification against a fixed clock, cross-border transfer rules that dictate hosting, and demonstrable audit evidence. Build for the strictest and you are close to compliant everywhere.

The residency piece deserves particular attention for multi-country groups. PDPL restricts cross-border transfer; Kenya’s cloud guidance encourages localisation for sensitive data; other markets set their own terms. The way to satisfy all of them without weakening security is in-country or sovereign hosting, a point we develop in Cloud vs On-Premise HIS: Which Is More Secure?

Key Takeaways

PDPL has been fully enforced since September 2024, with SDAIA actively issuing decisions.

→  Consent is the default lawful basis; health data carries enhanced protection as sensitive data.

→  The burden of proving consent sits with the hospital — it must be captured, versioned and evidenced.

→  Breaches must be notified to SDAIA within 72 hours; penalties reach SAR 5M per violation.

→  Cross-border transfers are restricted, making data residency a design decision.

→  PDPL sits alongside NPHIES and ZATCA — the same controls serve all three.

→  Across the Gulf, Africa and the Caribbean the obligations converge; build for the strictest.

Frequently Asked Questions

What is PDPL and who enforces it in Saudi Arabia?

The Personal Data Protection Law (PDPL), enacted by Royal Decree M/19, is Saudi Arabia’s data-protection law, enforced by the Saudi Data and Artificial Intelligence Authority (SDAIA). It has been fully in force since September 2024 and applies to any entity processing the personal data of individuals in the Kingdom, including hospitals.

How quickly must a Saudi hospital report a data breach under PDPL?

Within 72 hours. Personal data breaches must be notified to SDAIA within that window, which is why a hospital’s incident-response runbook needs to be mapped to a fixed clock and tested before an incident occurs.

Does PDPL require patient consent for processing health data?

Consent is the default lawful basis under PDPL, and health data is treated as sensitive data with enhanced protection. Hospitals should capture explicit, purpose-scoped, versioned, and withdrawable consent, enforce it at the point of access, and be able to evidence it. Penalties reach SAR 5 million per violation.

How does PDPL relate to NPHIES and ZATCA?

They are separate obligations that a Saudi hospital manages together. NPHIES governs health-information exchange and claims, ZATCA governs e-invoicing, and PDPL governs personal data protection. Building privacy into the platform means the same access, audit, and residency controls support all three rather than being solved three times.

Do these rules apply outside Saudi Arabia?

Yes. Bahrain, Qatar and Kuwait have their own Gulf regimes; Kenya, Nigeria, Ghana, Botswana and Uganda enforce African data-protection laws; and Caribbean states are advancing GDPR-aligned regimes. The statutes differ but the operational pattern is the same: consent-first processing, breach notification, transfer restrictions and audit evidence.

See how Medinous configures PDPL, NPHIES and market-specific compliance before go-live. Book a demo.

  • Clinic Management System
  • Digital Healthcare
  • Elеctronic Mеdical Rеcords Softwarе
  • Emerging Technologies In Healthcare
  • healthcare management software
  • Healthcare Technology
  • Hospital Information System
  • Hospital Management
  • hospital management software
  • Hospital Management Software in Saudi Arabia
  • Hospital Management System
  • Hospital Software Systems
  • MRA E-invoicing
  • MRA E-invoicing compliant hospital software
  • MRA E-invoicing hospital management software
  • nphies
  • NPHIES Integrated Hospital Management System
  • NPHIES integration
  • zatca
  • ZATCA e invoicing
hospital information system software

Revolutionize your hospital operations

Get a demo