Binding law — in force AI-adjacent law
Tell people whether decisions will be based entirely on automated processing (Saudi PDPL Implementing Regulation Art. 4(5)(c))
Under Art. 4(5) of the Implementing Regulation of Saudi Arabia's Personal Data Protection Law, a controller whose activities include, on a large scale or repeatedly, making decisions based on automated processing of personal data must take the necessary measures to tell the data subject what Art. 4(1) requires and, in addition, whether decisions will be based entirely on automated processing of personal data ((c)), with the means of collecting and processing sensitive data and the measures taken to protect personal data ((a)-(b)). The Arabic text is authoritative; the Regulation applies from the Law's entry into force (Art. 38), which SDAIA states was 2023-09-14, with a one-year grace period to 2024-09-14. Detect a privacy notice that never says whether decisions are automated.
Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
- Lane
- Binding law — in force In force: applies since 14 Sep 2024
- Official source
- Implementing Regulation of the PDPL, Art. 4(5), including (c) (information on decisions based entirely on automated processing) · captured 3 Oct 2026 · anchor hash (SHA-256)
ef21ff27bdee…· 3 more anchors in the data release - Verification
- Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
- Data release
- Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
- Legal review
- Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
- Audit standard
- Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
- Notices outside the repository
- Statements using other words (for example 'algorithmic assessment')
- Only meaningful where the controller makes decisions based on automated processing; the notice may be hosted outside the repository, or given at collection in the app (Art. 4(1)).
Who it applies to
- Duty falls on: controller
- Systems covered: automated decision
- Controllers (public entities, natural persons and private legal persons that set the purpose and manner of processing) that make decisions about individuals based on automated processing of their personal data, for processing in the Kingdom and processing outside it of data on individuals residing in the Kingdom (Law Art. 2(1), read, not stored). The Regulation applies from the Law's entry into force (Art. 38), 2023-09-14 as SDAIA states it, with SDAIA's one-year grace period to 2024-09-14. Arabic text authoritative.
- Not covered:
- An individual processing personal data for purposes not exceeding personal or family use, within their family or limited social circle (Regulation Art. 2(1)-(2))
- Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Keep an automated-decisions section in the privacy policy, generated or checked against the decision paths in code.
A section of the privacy policy that lists the kinds of decisions computer programs make solely, the kinds they substantially and directly help make (scores, rankings, recommendations a person then decides on), and the kinds of personal information each uses. Keep a small inventory in the repository (decision name, model or rule, inputs, solely automated or assisted) and a CI check that every decision service calling a model or scoring rule appears in the inventory and in the policy, so a new decision path cannot ship without its policy entry.
Where it goes: 11 CI/CD pipeline, 12 repository artifacts, 14 user-facing text.
What this provision adds:
- State in the information given to data subjects whether decisions will be based entirely on automated processing of their personal data, with the means used to collect and process sensitive data and to protect personal data.
Example (APP privacy policy), before:
# Privacy policy
We collect your name, contact details and transaction history to provide our services.After:
# Privacy policy
We collect your name, contact details and transaction history to provide our services.
## Automated decisions
Decisions made solely by a computer program: instant approval or decline of credit limit increases
(uses your income, repayment history and current balances).
Decisions a computer program substantially helps us make: fraud reviews, where a model scores each
transaction (uses transaction amount, merchant, device and location) before a staff member decides.Control: The privacy policy does not describe the decisions computer programs make or help make with personal information. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.
Rule id sa-pdpl-regs.automated-decision-notice · review status: primary source derived