Skip to content
Trust & compliance

PDPL Compliance

How Nexora helps you meet your obligations under Saudi Arabia's Personal Data Protection Law - built in, not bolted on.

Last updated: 6 July 2026

What the PDPL is

The Personal Data Protection Law (PDPL) is Saudi Arabia's data protection law, issued by Royal Decree No. M/19 of 1443H and overseen by the Saudi Data & AI Authority (SDAIA). It sets out how organisations may collect and handle the personal data of people in the Kingdom - including rules on consent, purpose limitation, data-subject rights, cross-border transfers and breach notification.

Nexora was built for this region from day one, so PDPL wasn't an afterthought bolted on later - the controls you need are part of the product.

This page explains how Nexora supports your compliance. It isn't legal advice - your obligations depend on your business, and you should confirm them with your own legal or privacy advisers.

Who does what

Under the PDPL, the organisation that decides why and how personal data is processed is the controller. A vendor that processes that data on the controller's instructions is the processor.

When you use Nexora to engage your audience, you are the controller and Nexora is your processor. You decide who to contact and what to send; we provide the platform and process the data on your instructions, under a Data Processing Agreement.

Data residency in the Kingdom

For teams whose regulatory posture requires personal data to stay inside the Kingdom, the Local Data Storage add-on keeps data in-region on infrastructure aligned with regional regulator guidance. You switch it on - there's no six-month procurement cycle to get there.

Data-subject rights

The PDPL gives individuals rights over their data - to be informed, to access, to request correction, and to request deletion. Nexora helps you act on these:

  • Look up and export the data held about a person.
  • Correct or update a profile across the platform.
  • Delete a person's data and suppress future messaging.
  • Honour a consent withdrawal everywhere at once.

Records, security & breach response

Full audit logs record every change, send and consent event, so you can demonstrate what happened and when. Data is encrypted in transit and at rest, access is restricted on a need-to-know basis, and sensitive-data guardrails keep regulated data classes out of the wrong flows. If a security incident affecting personal data occurs, we'll notify affected customers without undue delay so you can meet your own notification duties.

Data Processing Agreement

We offer a Data Processing Agreement (DPA) that sets out how we handle personal data as your processor, including sub-processors, security measures and support for data-subject requests. Request it from your account team or through the contact page, and we'll get it to you quickly.

A shared responsibility

Compliance is a partnership. Nexora provides the tooling, controls and residency options; you decide who to contact, obtain the consent your use requires, set your retention rules, and respond to the people you engage. We're here to make your side of that easier.

Want the full picture? The Trust Center covers our security and privacy controls, and our Privacy Policy explains how we handle data as a controller.

Talk to us

Have a PDPL question, or need our DPA or compliance brief? Email techsupport@usenexora.com or reach out through the contact page. Real people, real answers.

Ready to reach every customer, everywhere?

Get set up with our team and see Nexora on your own data - in Arabic or English.