# Patient Records, Consent, and PDPL: What Saudi Healthcare Providers Are Getting Wrong About Data Retention
Saudi healthcare providers face a structural compliance problem: existing medical record retention schedules — some requiring indefinite storage — directly conflict with the PDPL's data minimization and storage limitation obligations, which became fully enforceable in September 2024. SDAIA issued 48 enforcement decisions in the past year alone, and healthcare organizations sit at the highest-risk end of the spectrum because health data is classified as sensitive personal data, attracting stricter obligations and criminal penalties for unauthorized disclosure. Getting data retention right is no longer a governance aspiration — it is an active legal requirement.
—
Why Is Healthcare Data Especially Exposed Under the PDPL?
The PDPL draws a clear distinction between ordinary personal data and sensitive personal data. Health data — including clinical records, lab results, diagnostic imaging, pharmaceutical trial data, and insurance claims — falls explicitly within the sensitive category, alongside biometric, genetic, and other high-risk data types.
That classification has cascading consequences. Sensitive data requires:
- Explicit, informed consent before collection, with narrow exceptions for emergency treatment and public health purposes.
- Enhanced technical and organisational security controls proportionate to the risk.
- Stricter accountability for any third-party sharing, including Health Information Exchange partners, insurers, and cloud platform providers.
For most Saudi healthcare organisations, sensitive data is not an edge case — it is the core of everything they process. That is why the PDPL has particular force in this sector.
—
What Does the PDPL Actually Require on Retention and Minimization?
Two principles sit at the heart of the conflict.
Data minimization requires controllers to collect only the personal data strictly necessary to achieve the defined processing purpose. Holding records beyond that purpose — even if technically possible — is a violation.
Storage limitation, operationalised through Article 18, requires that once personal data has fulfilled its intended collection purpose, it must be permanently destroyed. Controllers must also maintain records of their own processing activities for five years following the termination of that processing activity, or until the purpose of collection ends — whichever is longer.
The obligation to destroy is not passive. Controllers must ensure destruction across all systems, backups, and archived copies, and must notify any third parties with whom the data was shared — unless a separate legal or judicial retention obligation applies.
—
Where Do Existing Retention Schedules Conflict With the PDPL?
This is where Saudi healthcare providers face the most immediate compliance exposure.
Under current Ministry of Health rules, records held by governmental institutions must be retained indefinitely. Private healthcare providers may store records for ten years, after which destruction is permitted once a summary is prepared. The Saudi Health Information Exchange policy sets retention of managed protected health information as indefinite.
Against the PDPL's storage limitation principle, these schedules create a direct structural conflict. Indefinite retention cannot, by definition, be reconciled with a requirement to destroy data once its purpose is fulfilled. The practical result is that many organisations are holding patient data they have no current legal basis to retain — and doing so at scale, across EHRs, insurance systems, and legacy physical archives.
The resolution requires a sector-level policy conversation between SDAIA, the MoH, and relevant regulators. But in the meantime, healthcare providers cannot simply wait. They need to document the legal basis for every retention category, identify data held beyond any defensible purpose, and build disposal workflows that can execute when retention periods end.
—
What Triggers a Mandatory Disposal Obligation?
Under the PDPL, controllers are required to destroy personal data when any of the following conditions is met:
- The data subject requests deletion and no overriding legal basis for retention exists.
- The data is no longer necessary for the purpose for which it was collected.
- The data subject withdraws consent and consent was the sole legal basis for processing.
- The controller becomes aware that data is being processed in violation of the PDPL.
Each of these triggers requires an operational response — not just a policy acknowledgement. Healthcare organisations need workflows that can identify which records are affected, execute verified destruction, update processing records, and notify third-party recipients. That is a significant operational capability gap for most organisations currently relying on manual archive management.
—
What Should a Compliant Data Disposal Workflow Look Like?
A defensible disposal programme in healthcare has five components.
1. A complete processing inventory. You cannot manage what you have not mapped. Every data category — clinical records, consent forms, billing data, referral letters, trial data — needs to be documented with its legal basis, purpose, and retention period. This is also a PDPL requirement in itself: controllers must maintain records of processing activities.
2. Retention schedules aligned to legal basis. Each data category needs a retention period tied to a specific legal justification — whether that is the MoH's ten-year rule for private providers, a contractual obligation, or a judicial hold. Where no current legal basis exists, the default obligation is destruction.
3. Triggered review and destruction processes. Retention periods should trigger automatic review workflows, not manual reminders. When a period expires, the process should verify whether any exception applies and, if not, execute destruction.
4. Verified, auditable destruction. Destruction must be verifiable — across live systems, backups, and physical records. For physical patient files and legacy paper archives, secured information destruction with a documented chain of custody and certificates of destruction is the minimum standard. SDAIA enforcement decisions have specifically targeted failures to implement adequate technical and organisational safeguards.
5. Third-party notification. Where data has been shared with insurers, HIE platforms, laboratories, or other processors, destruction obligations cascade. Controllers must notify those parties and obtain confirmation that data has been removed from their systems too.
—
How Should Healthcare Organisations Approach Their Physical and Digital Archives?
Many Saudi healthcare providers carry decades of physical patient records alongside growing volumes of digital data. Both require governance — and both create PDPL exposure if retention is not actively managed.
For physical archives, archival management that applies structured retention schedules, access controls, and documented destruction workflows is foundational. Unmanaged physical archives are not a legacy problem — they are an active compliance liability.
For digital transformation initiatives — EHR migrations, cloud adoption, HIE integrations — digitization solutions need to be designed with retention logic built in from the start, not retrofitted after deployment. Converting paper records to digital formats without embedding retention and disposal rules simply moves the problem into a new system.
Where organisations are uncertain about how to structure their compliance framework, consultation and advisory services can help map processing activities, identify retention conflicts, and build the governance architecture that SDAIA will expect to see in the event of an audit or complaint.
—
What Are the Real Penalties for Getting This Wrong?
SDAIA's enforcement posture has hardened. In the past year, 48 decisions were issued against organisations for violations including processing without a valid legal basis, unauthorized disclosure, and failure to implement adequate safeguards.
For substantive violations, fines reach up to SAR 5 million (approximately USD 1.33 million). Repeat violations double that ceiling to SAR 10 million. For the unauthorized disclosure of sensitive personal data — which health records categorically are — penalties can include imprisonment of up to two years in addition to financial sanctions.
These are not theoretical risks. Healthcare organisations that cannot demonstrate a documented legal basis for every data category they hold, or that cannot produce evidence of compliant disposal, are exposed.
—
The Strategic Takeaway
The PDPL's data minimization and storage limitation requirements are not in conflict with good healthcare delivery — they are in conflict with poor data governance. The organisations that will navigate this well are those that treat retention schedules as active compliance instruments, build destruction workflows with the same rigour as data collection processes, and invest in the records infrastructure to make both defensible.
If your organisation is ready to assess its current position and build a compliant retention framework, contact us to speak with a specialist.





