3 Things SDAIA Has Published as Violations That Aren’t What You’d Guess

The official list as published

SDAIA published violation categories in June 2026, without fine amounts or named entities. But the categories themselves are clear: direct marketing without explicit consent, a missed data-subject-request response, a missed 72-hour breach notice, inadequate protection measures, and a DPO not appointed when required.

Why this is worth paying attention to

Every item on that list is an operational step that was missed or never existed in the first place, not a major security incident. The real risk isn’t "will we get breached." It’s simply whether these day-to-day procedures are actually running.

SDAIA doesn’t publish the fine amount or the entity’s name, so calculating your exposure from an undisclosed number isn’t possible. What you can actually calculate is whether these five operational steps are running today.

See where your own data actually stands → free scan