TwinEthos homeAPI access

Law

Saudi Arabia PDPL Implementing Regulation: decisions based on automated processing

Saudi Data and AI Authority (SDAIA), the competent authority · SA · 3 provisions encoded · verified against the official source as of 2026-10-03.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: dgp.sdaia.gov.sa.

Trust and provenance 2 official sources · last verified 4 Oct 2026 · not reviewed by a lawyer · 3 of 3 provisions audit-grade · release 2026.10.05

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 3
Verification
Sources last verified 4 Oct 2026; each provision states how.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
None of the 3 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 3.
Audit standard
3 of 3 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
4 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.05 (5 Oct 2026): 3 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force AI-adjacent law

Tell people whether decisions will be based entirely on automated processing (Saudi PDPL Implementing Regulation Art. 4(5)(c))

Implementing Regulation of the PDPL, Art. 4(5), including (c) (information on decisions based entirely on automated processing) · official text · In force: applies since 14 Sep 2024 · SA

Under Art. 4(5) of the Implementing Regulation of Saudi Arabia's Personal Data Protection Law, a controller whose activities include, on a large scale or repeatedly, making decisions based on automated processing of personal data must take the necessary measures to tell the data subject what Art. 4(1) requires and, in addition, whether decisions will be based entirely on automated processing of personal data ((c)), with the means of collecting and processing sensitive data and the measures taken to protect personal data ((a)-(b)). The Arabic text is authoritative; the Regulation applies from the Law's entry into force (Art. 38), which SDAIA states was 2023-09-14, with a one-year grace period to 2024-09-14. Detect a privacy notice that never says whether decisions are automated.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 14 Sep 2024
Official source
Implementing Regulation of the PDPL, Art. 4(5), including (c) (information on decisions based entirely on automated processing) · captured 3 Oct 2026 · anchor hash (SHA-256) ef21ff27bdee… · 3 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Notices outside the repository
  • Statements using other words (for example 'algorithmic assessment')
  • Only meaningful where the controller makes decisions based on automated processing; the notice may be hosted outside the repository, or given at collection in the app (Art. 4(1)).

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision
  • Controllers (public entities, natural persons and private legal persons that set the purpose and manner of processing) that make decisions about individuals based on automated processing of their personal data, for processing in the Kingdom and processing outside it of data on individuals residing in the Kingdom (Law Art. 2(1), read, not stored). The Regulation applies from the Law's entry into force (Art. 38), 2023-09-14 as SDAIA states it, with SDAIA's one-year grace period to 2024-09-14. Arabic text authoritative.
  • Not covered:
    • An individual processing personal data for purposes not exceeding personal or family use, within their family or limited social circle (Regulation Art. 2(1)-(2))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Keep an automated-decisions section in the privacy policy, generated or checked against the decision paths in code.

A section of the privacy policy that lists the kinds of decisions computer programs make solely, the kinds they substantially and directly help make (scores, rankings, recommendations a person then decides on), and the kinds of personal information each uses. Keep a small inventory in the repository (decision name, model or rule, inputs, solely automated or assisted) and a CI check that every decision service calling a model or scoring rule appears in the inventory and in the policy, so a new decision path cannot ship without its policy entry.

Where it goes: 11 CI/CD pipeline, 12 repository artifacts, 14 user-facing text.

What this provision adds:

  • State in the information given to data subjects whether decisions will be based entirely on automated processing of their personal data, with the means used to collect and process sensitive data and to protect personal data.

Example (APP privacy policy), before:

# Privacy policy
We collect your name, contact details and transaction history to provide our services.

After:

# Privacy policy
We collect your name, contact details and transaction history to provide our services.

## Automated decisions
Decisions made solely by a computer program: instant approval or decline of credit limit increases
(uses your income, repayment history and current balances).
Decisions a computer program substantially helps us make: fraud reviews, where a model scores each
transaction (uses transaction amount, merchant, device and location) before a staff member decides.

Control: The privacy policy does not describe the decisions computer programs make or help make with personal information. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Rule id sa-pdpl-regs.automated-decision-notice · review status: primary source derived

Binding law — in force AI-adjacent law

Assess in writing the impacts and risks of making decisions based on automated processing (Saudi PDPL Implementing Regulation Art. 25(1)(c))

Implementing Regulation of the PDPL, Art. 25(1), including (c) (impact assessment where the controller's activity includes decisions based on automated processing) · official text · In force: applies since 14 Sep 2024 · SA

Under Art. 25(1)(c) of the Implementing Regulation of Saudi Arabia's Personal Data Protection Law, a controller must prepare a written and documented assessment of the potential impacts and risks to data subjects of processing their personal data where its activity includes, on a large scale or repeatedly, making decisions based on automated processing of personal data (among other cases). The Arabic text is authoritative; the Regulation applies from the Law's entry into force (Art. 38), which SDAIA states was 2023-09-14, with a one-year grace period to 2024-09-14. Detect the absence of an impact assessment for the automated decision system.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 4 Oct 2026 · release 2026.10.05
Lane
Binding law — in force In force: applies since 14 Sep 2024
Official source
Implementing Regulation of the PDPL, Art. 25(1), including (c) (impact assessment where the controller's activity includes decisions based on automated processing) · captured 3 Oct 2026 · anchor hash (SHA-256) a44e679a28a5… · 3 more anchors in the data release
Verification
Quoted text found word for word in the captured official document (4 Oct 2026). Source last verified 4 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.05, data as of 4 Oct 2026, schema 0.3.10.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Model registries kept outside the repository (an MLOps platform)
  • An inventory entry that links an assessment never written
  • Assessments kept in a privacy-management tool outside the repository

Who it applies to

  • Duty falls on: controller
  • Systems covered: automated decision
  • Controllers (public entities, natural persons and private legal persons that set the purpose and manner of processing) that make decisions about individuals based on automated processing of their personal data, for processing in the Kingdom and processing outside it of data on individuals residing in the Kingdom (Law Art. 2(1), read, not stored). The Regulation applies from the Law's entry into force (Art. 38), 2023-09-14 as SDAIA states it, with SDAIA's one-year grace period to 2024-09-14. Arabic text authoritative.
  • Not covered:
    • An individual processing personal data for purposes not exceeding personal or family use, within their family or limited social circle (Regulation Art. 2(1)-(2))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Organizational artifact to keep (not verifiable from code); the guard is the record, its owner and its upkeep.

Document an impact assessment for each AI system covering its consequences for individuals, groups, and society, and revisit it when the system changes.

A per-system impact assessment, distinct from the organizational risk register, that looks outward: intended use and context, who is affected (individuals, groups including vulnerable ones, society), foreseeable benefits and harms (rights, safety, fairness, access, wider societal effects), reasonably foreseeable misuse, mitigations, residual impact, and sign-off. The AI system owner maintains it within the AI management system and revisits it before release and on any material change of model, data, or use. Keep it next to the model card and have a release check confirm a current assessment exists for each deployed system.

Where it goes: 12 repository artifacts, 11 CI/CD pipeline.

What this provision adds:

  • Prepare the written impact assessment before or when decisions based on automated processing start, covering the risks to data subjects of that processing.

Example (Impact assessment record (docs/impact/)), before:

# Resume screener
Risk: low. Approved.

After:

# AI system impact assessment: resume screener (v3, 2026-09-01)
- Intended use: rank applications for recruiter review; no automatic rejection
- Affected: applicants; groups at risk: career-gap, non-native-language applicants
- Harms: unfair exclusion, opaque ranking; societal: narrowing of hiring pools
- Mitigations: subgroup ranking audit each release; recruiter sees all applicants
- Residual impact: medium, accepted by Head of Talent (signed 2026-09-03)
- Revisit: on model, feature, or use change

Control: AI system deployed without an AI system impact assessment. The same guard addresses 4 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Rule id sa-pdpl-regs.impact-assessment-for-automated-decisions · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.