The hardest PDPL questions, answered one at a time
No 40-page guide. Short, straight answers to what the market actually asks.
HR Data Hard to Destroy? Here’s the Fix
The retention and disposal policy every auditor asks for, without the guesswork.
Which Encryption Level Does a SDAIA Auditor Accept?
The standard isn’t "the highest one." It’s whatever matches your data classification.
Is an NDA Enough? No, and Here’s Why
The difference between an NDA and a DPA, and why every third party processing your data needs the latter.
Using Cloudflare or AI Models Outside the Kingdom?
Every external data path needs a documented transfer impact assessment, not a decision put off for later.
There’s No Such Thing as a "PDPL Certificate." What’s the Alternative?
What stops an auditor’s question is an evidence-backed readiness report, not a questionnaire you filled out yourself.
If SDAIA Calls Tomorrow, Who Answers? And Can They Prove the Number?
The breach notice needs an actual or approximate count of affected people, not a guess.
Does Your Marketing Team Actually Know Who Consented?
The most commonly published SDAIA violation: direct marketing without explicit consent.
3 Things SDAIA Has Published as Violations That Aren’t What You’d Guess
None of them were a headline-grabbing breach. All of them were missed operational steps.
Do You Need One Person, or a Whole Department?
A DPO can be an internal employee or an external contractor, with no nationality or certification requirement.
The 72-Hour Clock: What It Actually Means
The clock starts at detection, not once the assessment is finished.
NCA or SDAIA? Same Incident, Two Separate Tracks
NCA notification is a separate track from SDAIA, and legal accountability sits with the controller, not just cybersecurity.
Is There a "PDPL Certificate"? The Nuance Nobody Explains
There is an accreditation regime for audit bodies themselves, a completely different thing from a per-company "compliance certificate."
Why the Fine Number Won’t Help You Plan
SDAIA doesn’t publish fine amounts or entity names, so there’s no real number to calculate from.
Is Appointing a DPO Even Required for You?
Three conditions determine whether it’s mandatory. Not every organization needs one, but more than you’d think do.
"We Already Have DLP": 4 Reasons It Doesn’t Cover PDPL Alone
DLP protects what you already know to look for. PDPL requires proving who the data belongs to and honoring their rights.
NDI’s January Evidence Window: What It Actually Asks For
The window opens once a year, for a few weeks. Preparation needs to start long before it does.
RoPA: The 8 Statutory Fields, Not Auto-Generated
The record is kept throughout processing plus 5 years after, and it’s filled in by departments, not guessed by software.
Why We Never Say "100% Compliant"
Any percentage invites the question "prove it," and there’s no defined exam anyone can answer with.
Does PD-Fort Scan Employee Laptops? The Honest Answer
The mechanism is file upload, not remote device scanning, and the difference matters before you sign anything.
Consent Withdrawal: What Actually Happens Next
The recording and the flag happen immediately. Automatically halting processing inside your own systems is a different thing entirely.
Data Subject Requests by Email: What’s Automated, What Isn’t
The structured intake portal is ready today. Turning a free-form email into a case automatically is a gap we state plainly.
Exactly Which Cloud Storage Do We Connect To?
Two connectors today, no more. An accurate short list beats a long inaccurate one every time.
Worried the Scan Itself Creates New Compliance Risk?
A real objection we’ve heard: "if we discover something, we become responsible for it." The gap between knowing and acting deserves an honest answer.