The 72 Hour Clock: A PDPL Breach Response Your Board Trusts

The clock is a legal instrument, not an IT metric
Under Article 20 of the Personal Data Protection Law (PDPL), issued pursuant to Royal Decree No. M/19 dated 9/2/1443H and amended by Royal Decree No. M/148 dated 5/9/1444H, a data controller must notify the competent authority upon becoming aware of a personal data breach. Article 24 of the Implementing Regulations fixes that period at 72 hours from awareness. The Saudi Data and Artificial Intelligence Authority (SDAIA) is the competent authority. The National Data Management Office (NDMO) sits within SDAIA's own organizational structure rather than existing as a separate body. Any future reallocation of operational oversight for incidents is therefore best understood as an internal shift within SDAIA, not a transfer to an outside entity. Notification is submitted, in either case, through the National Data Governance Platform.
Two features of this framework distinguish it from its international counterparts, and both frequently catch boards unprepared.
First, neither the Implementing Regulations nor SDAIA's procedural guide on data breach incidents establishes a materiality threshold. The trigger is an incident that may harm personal data or conflict with the rights and interests of data subjects irrespective of the number of records involved. Directors accustomed to regimes with volume based thresholds should not assume a small incident is an unreportable one.
Second, notification to affected data subjects is a distinct obligation, owed without undue delay where the incident may damage their personal data or conflict with their rights and interests. The PDPL framework does not carry the exemptions familiar from other jurisdictions for instance, exemptions where the data was encrypted or where notification would require disproportionate effort.
Where "awareness" is actually decided
The window runs from awareness, and awareness is an organisational fact rather than a technical one. This is where the deadline is most commonly lost.
A common failure mode is procedural rather than malicious: a service desk ticket sits unescalated over a weekend; a processor informs the controller several days after detecting an anomaly; a forensic team is instructed to establish certainty before the Personal Data Protection Officer is told. Each of these consumes the window before the legal obligation is even recognised internally.
Boards should require three things in writing: a documented definition of what constitutes awareness within the organisation, a named escalation path with deputies for absence, and contractual undertakings obliging processors to notify the controller promptly. The last point deserves emphasis the notification duty rests with the controller regardless of where in the supply chain the incident originated.
Parallel clocks run simultaneously
PDPL notification does not displace other reporting duties. Entities within the scope of the National Cybersecurity Authority's (NCA) frameworks carry separate incident reporting obligations. Regulated financial institutions carry reporting duties to the Saudi Central Bank. Listed issuers must assess whether the incident constitutes a material development requiring disclosure under the CMA's Rules on the Offer of Securities and Continuing Obligations. An incident response plan addressing SDAIA alone is structurally incomplete.
The stakes, stated precisely
Article 36 of the PDPL establishes specialised committees empowered to consider violations of the Law and its Implementing Regulations. These committees may impose a warning or a fine not exceeding SAR 5 million per violation, and penalties may be increased in cases of repeat offence.
Article 35 operates on a separate track. Disclosure or publication of sensitive data in violation of the Law, with the intention of harming the data subject or achieving a personal benefit, is punishable by imprisonment for a period not exceeding two years, a fine not exceeding SAR 3 million, or both. The Public Prosecution is responsible for investigation and prosecution before the competent court, and fines may be doubled for repeat offences. Courts may also order confiscation of proceeds obtained through the violation and publication of the judgment at the violator's expense.
The distinction matters at board level. A failure to notify within the 72-hour window sits in the administrative track under Article 36. Article 35 addresses culpable disclosure by individuals the exposure that becomes relevant in insider-driven incidents.
The three-stage discipline
SDAIA's procedural guide frames breach response in three stages: containment and assessment; notification to SDAIA and, where required, to data subjects; and documentation. The third stage is the one most frequently under resourced and the one that determines defensibility. Controllers are expected to retain records of incidents, submissions made to SDAIA, and corrective actions taken. Where a controller cannot evidence when it became aware and what it did next, it is arguing from a weak position.
What the board should settle before an incident
- Complete registration on the National Data Governance Platform in advance; registration is not an activity to attempt mid incident.
- Pre-authorise expenditure for external counsel and forensic support, and appoint both on retainer.
- Decide, in advance, who signs the notification and who deputises.
- Prepare bilingual notification templates for SDAIA and for data subjects.
- Rehearse against a scenario involving a processor-side breach discovered on a weekend.
- Ensure the Personal Data Protection Officer has a direct reporting line to the board or audit committee.
Draft versus enacted
SDAIA opened a third public consultation on 27 April 2025 concerning proposed amendments to the Implementing Regulations, including a revised framework for the Personal Data Protection Officer role. These remain unenacted draft amendments. Boards should plan against the Regulations currently in force while monitoring for enactment, and should verify the present status before relying on any proposed provision.
Structural alignment
The 72 hour clock is not a test of an organisation's incident response technology. It is a test of whether decision rights, escalation paths, and documentation discipline were settled before the incident occurred. A board-level diagnostic of breach readiness — examining escalation architecture, processor contracts, platform registration, and evidentiary records — is a proportionate response to a deadline measured in hours.


