What the PDPL is
The Personal Data Protection Law (PDPL) is Saudi Arabia's data protection law, issued by Royal Decree No. M/19 of 1443H and overseen by the Saudi Data & AI Authority (SDAIA). It sets out how organisations may collect and handle the personal data of people in the Kingdom - including rules on consent, purpose limitation, data-subject rights, cross-border transfers and breach notification.
Nexora was built for this region from day one, so PDPL wasn't an afterthought bolted on later - the controls you need are part of the product.
Who does what
Under the PDPL, the organisation that decides why and how personal data is processed is the controller. A vendor that processes that data on the controller's instructions is the processor.
When you use Nexora to engage your audience, you are the controller and Nexora is your processor. You decide who to contact and what to send; we provide the platform and process the data on your instructions, under a Data Processing Agreement.
Consent, captured properly
The PDPL expects consent to be specific and revocable. Nexora captures and stores consent separately for each channel a person uses, so an SMS opt-in isn't treated as a WhatsApp opt-in. Opt-outs (STOP / UNSUBSCRIBE) are honoured instantly across the platform, and every consent event is timestamped and logged.
Data residency in the Kingdom
For teams whose regulatory posture requires personal data to stay inside the Kingdom, the Local Data Storage add-on keeps data in-region on infrastructure aligned with regional regulator guidance. You switch it on - there's no six-month procurement cycle to get there.
Data-subject rights
The PDPL gives individuals rights over their data - to be informed, to access, to request correction, and to request deletion. Nexora helps you act on these:
- Look up and export the data held about a person.
- Correct or update a profile across the platform.
- Delete a person's data and suppress future messaging.
- Honour a consent withdrawal everywhere at once.
Records, security & breach response
Full audit logs record every change, send and consent event, so you can demonstrate what happened and when. Data is encrypted in transit and at rest, access is restricted on a need-to-know basis, and sensitive-data guardrails keep regulated data classes out of the wrong flows. If a security incident affecting personal data occurs, we'll notify affected customers without undue delay so you can meet your own notification duties.
Data Processing Agreement
We offer a Data Processing Agreement (DPA) that sets out how we handle personal data as your processor, including sub-processors, security measures and support for data-subject requests. Request it from your account team or through the contact page, and we'll get it to you quickly.
Talk to us
Have a PDPL question, or need our DPA or compliance brief? Email techsupport@usenexora.com or reach out through the contact page. Real people, real answers.