Patient Records in the NPHIES Era: A Governance Roadmap for Saudi Healthcare Providers

July 15, 2026
Undigitized Records: Your Biggest Saudi PDPL Liability

Undigitized Records: Your Biggest Saudi PDPL Liability

August 3, 2026

PDPL Enforcement Has Arrived: Building a Defensible Records Retention and Destruction Program

July 21, 2026

For two years, Saudi organizations discussed the Personal Data Protection Law as something to prepare for. That phase is over. The PDPL — issued under Royal Decree No. M/19 in September 2021, amended in March 2023, and in force since 14 September 2023 — completed its compliance grace period on 14 September 2024. Since then, the Saudi Data and Artificial Intelligence Authority (SDAIA) has moved into active enforcement: its specialized committees issued 48 decisions against violating organizations in the first full enforcement cycle, covering unlawful collection and processing, insufficient security controls, unauthorized disclosure, and unconsented marketing communications.

The lesson in those decisions is not that fines exist — penalties can reach SAR 5 million per violation, with the possibility of doubled fines for repeat offenses. The lesson is that compliance is now evidence-based. When SDAIA asks a question, organizations are expected to answer with documentation, within short timeframes. The organizations that struggle are not necessarily careless; they simply cannot prove what they did, when, and why.

Nowhere is that more visible than in how organizations retain and destroy records.

Over-retention is the new risk

Most Saudi enterprises inherited a simple records philosophy: keep everything, forever, just in case. Warehouses and basement archives across Riyadh, Jeddah, and Dammam hold decades of contracts, HR files, customer forms, and correspondence — much of it containing personal data.

The PDPL turns that habit into exposure. The law’s data-minimization and purpose-limitation principles mean personal data should be retained only as long as a defined purpose requires, subject to legal retention obligations. A filing room full of customer records with no continuing purpose is not a safety net; it is an unmanaged repository of regulated data — a larger attack surface in a breach, a larger disclosure burden in a dispute, and a standing question with no good answer in a regulatory inquiry.

At the same time, under-retention is equally dangerous. Sector rules, tax and commercial obligations, and litigation-preservation duties require certain records to be kept for defined periods. Destroy them early — or destroy them without documentation — and the organization faces a different kind of liability.

The way through is not intuition. It is a defensible retention schedule.

What “defensible” actually means

A defensible program has four characteristics that a regulator, auditor, or court would recognize.

1. A written, approved retention schedule. Every record category is mapped to a retention period with a stated legal or business basis, approved by legal and executive leadership, and reviewed on a defined cycle. Under the PDPL’s Implementing Regulations, controllers must also maintain records of their processing activities — and a retention schedule is the backbone of that documentation.

2. Consistent application. A schedule applied selectively is worse than no schedule, because it suggests decisions were made for convenience. Consistency requires knowing what you hold — which for most organizations begins with a physical and digital records inventory.

3. Documented, secure destruction. When a retention period expires, destruction should follow written authorization, a legal-hold check, secure chain of custody, and certified destruction — whether shredding of physical records or verified erasure of media. The certificate of destruction is your proof, years later, that disposal was lawful, deliberate, and complete.

4. Controlled processors. The PDPL holds controllers accountable for the vendors that process personal data on their behalf. Contracts with storage, scanning, and destruction providers should specify security measures, confidentiality, breach-notification support (SDAIA must be notified within 72 hours of qualifying breaches), and audit rights. Vendor selection is a compliance decision.

The 90-day starting plan

Organizations that have not yet operationalized retention can make real progress in a quarter.

Weeks 1–4: Inventory. Identify record repositories — offices, warehouses, shared drives, legacy systems. Estimate volumes and identify categories containing personal data. Assign an accountable owner.

Weeks 5–8: Draft the schedule. Start with the ten highest-volume record categories. For each, determine the governing retention requirement and the business purpose, and set a destruction trigger. Have legal counsel validate the schedule against your sector’s obligations.

Weeks 9–12: Execute the first defensible destruction. Select a clearly expired, low-controversy category. Run the full process — authorization, legal-hold check, secure destruction, certification — and document it end to end. This first cycle builds the institutional muscle and produces your first evidence artifacts.

In parallel, confirm whether your organization must register on SDAIA’s National Data Governance Platform under the Rules Governing the National Register of Controllers, and whether a Data Protection Officer appointment applies to you. SDAIA also ran a public consultation on amendments to the Implementing Regulations in 2025, so assign someone to track regulatory updates — the framework is still maturing.

Storage is part of the compliance story

Records still within their retention period need protection proportionate to their sensitivity. Purpose-built records centres — with fire prevention systems, environmental controls, restricted and logged access, and audited retrieval — provide demonstrably stronger safeguards than office storerooms, at a lower cost per file than commercial office space. When SDAIA’s enforcement decisions cite “insufficient technical and organizational controls,” physical records are part of that equation, not an exception to it.

Turn your archive from liability into evidence

Tejoury has been the Kingdom’s records management partner since 2007, providing secure storage, digitization, and certified destruction from purpose-built facilities across Saudi Arabia and Bahrain. We help compliance, legal, and operations teams build retention programs that hold up to scrutiny — and produce the documentation to prove it.

Book a retention and destruction compliance review with Tejoury.

This article provides general information, not legal advice.

Related

Schedule a call with us!








    Thank you for considering Tejoury PDPL Enforcement Has Arrived: Building a Defensible Records Retention and Destruction Program. We are excited about the possibility of working with you and addressing your requirements. Our team is prepared to reach out to you at your preferred time for a meaningful conversation about how we can assist you.

    Schedule a call with us!








      Thank you for considering Tejoury. We are excited about the possibility of working with you and addressing your requirements. Our team is prepared to reach out to you at your preferred time for a meaningful conversation about how we can assist you.