Skip to content

Saudi PDPL for Marketers: What 48 Enforcement Decisions in 2025 Mean for Email, SMS and WhatsApp Campaigns

Saudi PDPL for Marketers: What 48 Enforcement Decisions in 2025 Mean for Email, SMS and WhatsApp Campaigns
  • Reading time 13 min
  • Summarize with AI
  • Oct. 2, 2026

Saudi regulators now penalise marketers who message people without consent. In 2025, committees at the Saudi Data and AI Authority (SDAIA) issued 48 decisions under the Personal Data Protection Law (PDPL), and advertising messages sent without consent were one of four named violation types. For email, SMS and WhatsApp, compliance means documented opt-in, an opt-out as easy as the sign-up, a named sender and a lawful route for data stored abroad.

This is our plain-language reading of the official texts, not legal advice. Confirm your setup with qualified Saudi counsel and check the regulator’s own text on SDAIA’s data governance platform.

What did SDAIA’s 48 decisions in 2025 cover?

SDAIA’s violation committees issued 48 decisions in 2025 confirming PDPL breaches and imposing penalties under Article 36 of the Law. The Saudi Press Agency announcement of 16 January 2026 named four violation types: unlawful collection and processing, disclosure without legal basis, weak protection measures, and advertising or marketing messages sent without consent.

The SPA release did not name the companies, the sectors or the fine amounts. Any article that quotes a specific fined brand is guessing. What the record does show is where the committees looked, and three of the four categories touch daily campaign work: building lists, sharing them with vendors and sending messages.

The IAPP’s analysis, published on 25 February 2026, adds that a notable number of the cases involved promotional messages sent without prior consent. It describes the practice as widespread in retail, telecommunications and financial services. That is the IAPP’s reading. SDAIA published no breakdown by violation type, so the exact share of marketing cases is unknown outside the committees.

For a marketing lead the takeaway is narrow. Consent for messages has moved out of the privacy policy and into the enforcement record. It is one of the few violations the regulator chose to name in public.

PDPL timeline: in force since 2023, penalties since September 2024

The PDPL took effect on 14 September 2023, according to SDAIA’s own guide to the law, and organisations received a one-year grace period that ended on 14 September 2024. SDAIA said it would apply no penalties during that year. The 48 decisions therefore cover the first full calendar year in which fines were available.

Date Milestone Source
9/2/1443H (September 2021) Law issued by Royal Decree No. M/19 Law text, SDAIA
5/9/1444H (March 2023) Law amended by Royal Decree No. M/148 Implementing Regulation, Article 1
14 September 2023 PDPL in force SDAIA guide to the PDPL
August 2024 Transfer Regulation version 2.0 published SDAIA
14 September 2024 Grace period ends, penalties apply SDAIA guide to the PDPL
2025 48 violation decisions issued SPA, 16 January 2026

The dates for entry into force and the grace period come from SDAIA’s Guide to the Saudi Personal Data Protection Law. SDAIA also ran a public consultation on draft amendments to the Implementing Regulation from 27 April to 27 May 2025, according to a Bird & Bird summary. When we checked SDAIA’s platform on 1 October 2026, the published text still carried the original wording, so the article numbers below follow that version.

What the Implementing Regulation requires for marketing messages

Article 25 of the Law requires the recipient’s consent and a clear opt-out before you use their phone number or email address for advertising. Articles 28 and 29 of the Implementing Regulation add the detail: consent given freely and documented, the sender named without hiding identity, and an opt-out as simple as the opt-in.

Read together with Article 11 (consent) and Article 12 (withdrawal), the Implementing Regulation sets these duties for advertising and direct marketing:

  • Consent quality. Freely given, no misleading methods, and the recipient chooses which materials they accept (Article 28(2)).
  • Purpose and proof. Purposes explained before or at the time of asking, a separate consent for each purpose, and a record showing time and method (Article 11(1)).
  • Named sender. State the sender’s name without hiding identity (Article 28(3)(a)) and the sending entity without anonymisation (Article 29(2)).
  • Opt-out. As simple as the opt-in, free of charge, honoured immediately (Article 28(3)(b) to (d)).
  • Evidence. Keep material evidence of each recipient’s consent (Article 28(3)(e)).

Two limits sit in the Law itself. Article 26 allows marketing use only of data collected directly from the person, with consent, and never of sensitive data, which includes health data. For clinics and labs, that closes the door on patient records as a marketing list, which is why our healthcare SEO strategy guide builds demand from search instead.

Article 28(1) as published still ties the consent duty to cases with no prior interaction. Do not build a plan on that gap. Article 25 of the Law contains no such carve-out.

Channel by channel: what PDPL requires and the practical fix

Every outbound channel needs the same three things under the PDPL: recorded consent tied to a purpose, a named sender, and an opt-out that works as easily as the sign-up. SMS adds telecom rules from the CST, and tracking pixels add a transfer question. The table maps each channel to its rule and a fix.

Channel What the rules require Practical fix (our recommendation)
Email Consent before advertising, sender named, free opt-out as easy as opt-in, evidence kept (Law Art. 25; Regulation Art. 28, 29) Unticked box per purpose at sign-up, brand name in the From field, one-click unsubscribe, consent log with timestamp and form wording
SMS All of the above, plus a registered sender name with the -AD suffix, express consent outside contracts and privacy policies, stop within 24 hours, no sends from 10:00 pm to 9:00 am (CST regulations) Register a separate -AD sender, use only CST-authorised providers, send the opt-in and opt-out confirmation text, schedule inside the allowed hours
WhatsApp Consent and opt-out under Law Art. 25; WhatsApp’s own policy requires opt-in from each recipient and honouring opt-outs made on or off WhatsApp A WhatsApp-specific checkbox, a STOP keyword wired to suppression, approved templates only, no uploaded third-party lists
Retargeting pixels and analytics Privacy policy must name cookie data, the collection method, purpose and legal basis (SDAIA Privacy Policy Guideline); data sent abroad falls under the Transfer Regulation Consent banner that separates analytics from advertising, tags gated on consent, no pixels on pages that reveal health conditions
Lead forms Purpose explained at collection, separate consent per purpose (Regulation Art. 11); no sensitive data for marketing (Law Art. 26) Two checkboxes: “contact me about this request” and “send me offers”; no medical questions on marketing forms
Bought or scraped lists Marketing use limited to data collected directly from the person (Law Art. 26); harvesting software banned for SMS (CST) Delete them. Rebuild through your own site, stores and events

The WhatsApp row draws on the WhatsApp Business Messaging Policy, last updated 23 September 2026. Not sure your forms and pixels would survive a complaint? Review my Saudi lead forms and tracking setup.

SMS has a second rulebook from the CST

Promotional SMS also falls under the Communications, Space and Technology Commission’s Regulations for Curbing SPAM Messages and Calls, approved by Decision 493/1444 on 17 October 2022. They require registered sender names, an -AD suffix on advertising senders, express consent with proof, and a stop within 24 hours of a request.

The CST regulations (the document still carries the commission’s former CITC name) go further than the PDPL text in several places:

  • Consent contained in privacy policies and service contracts does not count, and the sender must provide proof (clause 4.6.6.1).
  • The suffix -AD is added to every sender name classified as advertising (clause 4.3.10).
  • Promotional and awareness messages are banned from 10:00 pm to 9:00 am daily, and from 1:00 am to 12:00 pm during Ramadan, KSA time (clause 4.6.8).
  • Promotional SMS cannot be sent from a mobile phone number (clause 4.6.9).
  • Senders must confirm each opt-in and opt-out with a notification (clause 4.6.6.4).

Operators must also block promotional messages by default and let each subscriber allow specific senders (clause 4.4.8.2). Under that clause, your -AD sender starts blocked for any subscriber who has not allowed it, so consent capture has a deliverability payoff as well as a legal one. Where the CST allows 24 hours and the Implementing Regulation says “immediately”, build for immediately.

Can you use a CRM or email platform hosted outside Saudi Arabia?

Yes, with a legal route. Article 29 of the Law allows transfers abroad for listed purposes if national security is unharmed, protection abroad is adequate and only the minimum data moves. Without an adequacy finding, the Transfer Regulation points you to safeguards such as standard contractual clauses, plus a documented risk assessment.

The Regulation on Personal Data Transfer outside the Kingdom (version 2.0, August 2024) works in three layers:

  • Adequacy list. Article 3 says SDAIA will publish a list of countries with adequate protection, reviewed every four years. We found no published list on SDAIA’s platform on 1 October 2026.
  • Safeguards. Article 4 names standard contractual clauses, binding common rules and accreditation certificates, with exemption cases such as transfers that deliver a service directly to the person.
  • Risk assessment. Article 7 requires one before any Article 4 transfer, covering purpose, legal basis, safeguards, data minimisation, likely harms and mitigations.

Start by listing every tool that receives Saudi contacts: the email platform, CRM, SMS gateway, WhatsApp provider and analytics. We also treat customer-list uploads to ad platforms as transfers, because the platform matches the list back to identifiable people. Inventory each one, sign SDAIA’s clauses where the vendor allows it, and file the assessment before the next campaign.

Not a dedicated one. Neither the Law nor the Implementing Regulation contains a cookie article. SDAIA’s Privacy Policy Guideline of August 2024 does require privacy policies to name cookie data as a category, and to list cookies and website analytics as indirect collection methods with a stated purpose and legal basis.

The guideline lists the legal bases a controller can cite, including consent and the controller’s legitimate interests. It also recommends linking a cookie policy from the privacy policy. It stops short of mandating a banner.

For marketing pixels we treat consent as the safer basis, for three reasons. Legitimate interest under Article 6(4) of the Law is unavailable for sensitive data. It also fails when processing conflicts with the person’s interests. And retargeting data almost always leaves the Kingdom, which brings the transfer rules above into play.

Two setups create avoidable exposure. The first is a pixel firing on every page, including booking confirmations and test-result pages. The second is a privacy policy copied from a European template that never mentions Saudi law or the transfer route. A tag manager with consent gating and a policy rewrite address both.

What do PDPL penalties look like?

Most breaches, unsolicited marketing included, fall under Article 36: a warning or a fine up to SAR 5 million, which can double for a repeat violation to a ceiling of SAR 10 million. Disclosing or publishing sensitive data to harm someone or for personal gain is a crime under Article 35, carrying up to two years in prison.

Penalty Applies to Who decides Law article
Warning or fine up to SAR 5,000,000; up to double for repeat violations Any private person or entity breaching the Law or Regulations, outside Article 35 SDAIA committee (minimum three members), appealable to court 36
Prison up to 2 years and/or fine up to SAR 3,000,000; fine doubled at most for recidivism Disclosing or publishing sensitive data with intent to harm or for personal benefit Public Prosecution and the competent court 35
Confiscation of proceeds Money obtained through violations Competent court 38(1)
Published summary of the decision at the violator’s cost Any penalty decision, once final Committee or court 38(2)
Compensation for material or moral damage Anyone harmed by a violation Competent court 40

Figures come from the Arabic Law text on SDAIA’s platform. The January 2026 release confirms the committees used Article 36 in 2025, but no individual amounts were disclosed.

Our read

Treat every Saudi contact as opt-in only, whatever the prior-interaction wording in Article 28 says. Article 25 of the Law has no carve-out for existing customers, the CST ignores consent buried in contracts, and the committees named unsolicited marketing as a headline violation. The cheapest compliance programme is a consent log you can export in one click.

We also think bought lists are finished in Saudi Arabia. Article 26 limits marketing to data you collected directly, and that single sentence removes most of the grey market for SMS and WhatsApp numbers.

That shifts budget toward channels where people come to you first. Search and AI answers are the obvious ones, and our Google AI Overviews optimisation guide covers how pages earn citations. One VOCTOS client, Delta Medical Labs, a Saudi medical lab, reached more than 1 million monthly organic visits during an engagement that began in March 2026. It also holds 1,186 keywords ranking #1 in Saudi Arabia. Organic visitors arrive by choice, with no list involved.

None of this makes email, SMS or WhatsApp less useful. It makes them channels for people who already said yes.

FAQ

Do I need consent to email existing customers in Saudi Arabia?

Plan on yes. Article 28(1) of the Implementing Regulation, as published, ties the consent duty to recipients with no prior interaction. Article 25 of the Law, however, requires the recipient’s consent for advertising sent to personal addresses, with no exception for customers. Ask existing customers at checkout or in account settings, and log every answer.

Can I buy a phone list for a Saudi SMS or WhatsApp campaign?

No safe version exists. Article 26 of the Law allows marketing use of personal data only when it was collected directly from the person, with consent, and never for sensitive data. The CST also bans numbers gathered by harvesting software, and WhatsApp’s own policy requires opt-in from every recipient you message.

Does PDPL apply if our company is based outside Saudi Arabia?

Yes, when you process data about people living in the Kingdom. Article 2 of the Law covers processing carried out in Saudi Arabia and processing of residents’ data by any entity outside it. A Dubai or London team emailing Saudi residents is in scope, and its tools abroad also trigger the transfer rules.

Someone asked us to stop messaging. How fast do we have to act?

Immediately. Article 28(3)(c) of the Implementing Regulation requires an immediate halt on request, and Article 12 says processing stops without undue delay once consent is withdrawn. For SMS, the CST sets an outer limit of 24 hours and requires a confirmation message. Automate suppression instead of relying on weekly manual exports.

Will SDAIA publish the names of companies it fines?

It has not so far. The January 2026 announcement gave the count and violation types but no company names or amounts. Article 38 of the Law does allow a committee or court to order a summary of a final decision published in local newspapers at the violator’s expense, so public naming remains a live option.

Where this leaves your next Saudi campaign

A narrower question matters more than the odds of a fine: can you show, for any number or address on your list, when and how that person said yes? The 48 decisions of 2025 tell you the committees ask exactly that question, and the Implementing Regulation tells you what an acceptable answer looks like.

If you can export that proof today, spend the next sprint on the opt-out path, the -AD sender and the transfer clauses with your vendors, then keep sending. If you cannot, pause cold sends and fix the capture points first: forms, checkout, WhatsApp click-to-chat and store sign-ups. Every contact gathered from then on should carry its own consent record.

Either way, the work is mostly plumbing. Consent logs, suppression lists and vendor clauses rarely appear in a campaign brief. They decide whether the campaign survives its first complaint.

Want a pipeline that does not depend on lists at all? Help me grow a Saudi audience that comes to us first.

Everything else we have run on Compliance & Regulations

Written by whoever ran the work, not a content team

5 articles
All articles
Previous articleNext article
Did you like the article?
Share:
  • Fake Reviews in Saudi Arabia and the UAE (2026): What Google, the Law and Platforms Say, and How to Respond in Arabic and English

  • Healthcare Advertising in Saudi Arabia and the UAE: SFDA, DHA, Google and ChatGPT Rules in One Checklist (2026)

  • DHA Social Media Advertising Standards 2026: Banned Claims, Influencer Rules and a Content Checklist

  • ChatGPT Ads Manager Now Lists Saudi Arabia and the UAE: What Gulf Advertisers Can Run (October 2026)