The most common misreading of PDPL we hear in the Kingdom is that registration is something public entities do. It is not. For a large part of the private sector it is mandatory, and it is the first thing an auditor will ask about.
Who has to register
Registration on SDAIA's National Data Governance Platform applies to three groups:
Public entities, which is the part everyone remembers
Controllers whose core activity involves processing personal data, which covers banks, insurers, telcos, healthcare groups, retailers with loyalty programmes and most digital businesses
Anyone processing sensitive data at all, whatever their size or sector
There is no small-organisation derogation. Registration certificates run for five years, which means renewal dates are already a governance item for early registrants.
One platform, three obligations
The reason registration matters more than it looks is that the National Data Governance Platform is not a one-off filing. It is where three separate obligations meet.
What lives on the platform | Why it matters |
|---|---|
Your registration record | Proves you are a known controller with a valid certificate |
Your DPO's details | Shows who is accountable and reachable |
Your breach notifications | The 72-hour filing route to SDAIA runs through it |

Registration is the paper trail that every other PDPL control hangs from.
The audit question
If nobody in your organisation can say who registered the entity, when, and with which DPO named, that is a finding before any other control is looked at. It also has an operational cost. A team that has never logged into the platform will be learning it during a 72-hour breach window rather than before one.
In plain language
If you process personal data as part of your core business, or any sensitive data, you should be registered with SDAIA. Know who did it, when it expires, and that the DPO named is still in post.
The DPO gap is visible in hiring data
When we built our own view of privacy leadership in the Kingdom, we found very few people holding a privacy or data protection title at organisations of 200 staff or more. The DPO function barely exists yet in many large employers. That is the registration gap, showing up in the org chart.
A short checklist
Confirm the registration. Certificate number, date issued, date of expiry.
Confirm the DPO. Named, in post, reachable, and matching what the platform shows.
Rehearse the filing. Make sure the incident team knows how to file a breach notification on the platform before they need to.
Record the basis. Keep a short note on why you are or are not in scope, signed off by legal.
Next step. Our PDPL briefing pack covers registration, cross-border transfers, the breach clock and the four behaviours SDAIA's committees penalised. Download the briefing pack →
For any comments or information please reach out to info@astragar.com







