Who the standard applies to
- Saudi-licensed entities within the regulator's perimeter
- Government bodies, GREs and critical-sector operators
- Service providers processing Saudi resident data
- Foreign processors falling under extra-territorial scope
Defining the right scope is the single biggest determinant of KSA PDPL success. Too narrow and the certificate is meaningless; too broad and the programme stalls under its own weight.
Delivered by an ISO/IEC 27001, 27701 & 9001 certified organisation
Icon grid titled "Scope dimensions" with 5 categories: Legal entities and business units in scope, Geographies and data residency boundaries, Cloud accounts, data centres and end-user computing estates, Third parties processing in-scope data on your behalf, Products, services or customer segments included.
Checklist titled "Scoping pitfalls to avoid" with 4 items, every item marked complete: Excluding shared services (HR, payroll, identity) that handle in-scope data.; Treating SaaS platforms as out-of-scope when they process production data.; Omitting DR, backup and recovery sites from the boundary.; Forgetting to include the security operations function itself..
A two-week scoping sprint with your sponsor, IT, security, legal and audit produces a written scope statement, an asset and data-flow map, and a signed-off boundary diagram. This becomes the anchor for the entire KSA PDPL programme.