Saudi PDPL and Candidate Data: A Practical Guide for HR Teams in 2026
The Kingdom of Saudi Arabia's Personal Data Protection Law (PDPL), issued by Royal Decree M/19 of 1443H and amended in March 2023, became fully enforceable on 14 September 2024 after a one-year grace period. The implementing regulations issued by the Saudi Data and Artificial Intelligence Authority (SDAIA) give it operational teeth.
For HR teams hiring in the Kingdom — whether you are a Riyadh-based bank, a Jeddah retailer, or a multinational opening an office in NEOM — candidate data is squarely within scope. Voice recordings from AI-assisted interviews, transcripts, scorecards, and even shortlists are all personal data under the law.
This piece is a practical guide to what compliant candidate data handling looks like under the Saudi PDPL in 2026.
The KSA PDPL is not a copy of the GDPR. It borrows the vocabulary but applies it inside a regulatory and cultural context that differs in several specific ways HR teams need to understand.
Who is in scope
The PDPL applies to the processing of personal data of individuals located in Saudi Arabia, regardless of where the controller or processor is based. That extraterritorial reach is important: a UK-headquartered recruitment agency screening candidates in Riyadh is in scope. So is a UAE-based consultancy that processes Saudi candidate data on behalf of a Kingdom-based client.
Two roles are defined:
- Controller — the entity that decides why and how personal data is processed. For most hiring scenarios, this is the employer.
- Processor — the entity that processes data on behalf of the controller. An AI interview vendor is typically a processor.
Both have direct obligations under the law, but the controller carries the primary accountability.
The six things HR has to get right
1. Lawful basis for processing
Under Article 6 of the PDPL and SDAIA's implementing regulations, processing personal data generally requires the data subject's consent unless one of a small set of alternative bases applies (legitimate interest, contractual necessity, legal obligation, vital interests, or public interest).
For candidate interviews, consent is the cleanest and most defensible basis. Two pitfalls to avoid:
- Bundled consent. A single "I accept" button covering job application, marketing, and AI screening will not survive scrutiny. Each purpose needs its own opt-in.
- Pre-ticked boxes. Consent must be a positive action by the candidate.
The consent record should capture: the timestamp, the specific purposes consented to, the data categories, the retention period, and the candidate's identity. A well-built interview platform produces this record automatically.
2. Transparency notice before any AI processing
The PDPL requires controllers to inform data subjects about the collection and processing of their personal data. SDAIA's regulations specify the minimum content of a privacy notice: identity of the controller, purpose, legal basis, recipients, retention period, cross-border transfer information, and the data subject's rights.
In a hiring context, this notice has to be presented before the candidate begins the AI interview, not buried in a footer. A short, plain-Arabic and plain-English summary at the start of the session — followed by a longer notice the candidate can read in full — is the pattern that holds up.
3. Data minimisation in interview design
Article 24 imposes a data minimisation principle: collect only what is necessary for the stated purpose. For AI interviews, this has concrete implications:
- Do not ask competency questions that probe protected characteristics (religion, ethnic origin, family status) unless there is a clear, lawful, role-specific reason.
- Do not retain audio when a transcript and scorecard would suffice for the stated purpose.
- Do not enrich candidate data from external sources without a separate lawful basis.
The principle works in HR's favour: a tighter scope of data reduces both compliance burden and breach exposure.
4. Cross-border data transfer
This is where the KSA PDPL diverges most sharply from neighbouring frameworks. The implementing regulations restrict transfers of personal data outside the Kingdom and require either an adequacy decision by the competent authority, appropriate safeguards (such as binding corporate rules or contractual mechanisms approved by SDAIA), or an explicit derogation.
For AI hiring vendors, this matters in three places:
- Where the model inference runs. If transcription or scoring happens in a data centre outside Saudi Arabia, you need a documented safeguard.
- Where the audio is stored. Long-term storage in a non-KSA region needs the same.
- Who has access. Support engineers in another country accessing candidate data is a transfer event.
Ask vendors for a written data-flow diagram and the corresponding safeguard for each cross-border step. If a vendor cannot produce one, that is a sourcing risk.
5. Data subject rights
Candidates have rights to access, correction, deletion, and to be informed of their data. They also have the right to request a copy of their personal data in a readable format. The implementing regulations set response timelines — typically 30 days, extendable in limited circumstances.
For HR teams, this means having an operational workflow ready before you start collecting candidate data. Specifically:
- A named point of contact (often the data protection officer) that candidates can email.
- A way to search across systems — ATS, interview platform, scorecards, internal notes — to assemble a complete response.
- A deletion process that removes the candidate from all systems when a valid erasure request is made.
A platform that exposes candidate-level data export and deletion through an API or admin UI shortens this from a multi-day manual exercise to a few minutes.
6. Breach notification
The PDPL requires controllers to notify SDAIA of personal data breaches within a defined window and, in higher-risk cases, to notify affected individuals. The thresholds and timelines are specified in the implementing regulations.
Practical implications for HR:
- Maintain an incident log for any candidate-data event, even ones below the notification threshold.
- Ensure your interview vendor has a contractually-defined breach notification timeline to you that is shorter than the regulator's deadline to you.
- Rehearse the workflow at least once a year.
A KSA-specific checklist for AI interview procurement
When evaluating an AI interview platform for use in the Kingdom, the following questions should produce written answers before contract signature:
- Where is candidate audio stored, and in which region?
- Where does the speech-to-text and AI scoring run?
- What is the cross-border transfer safeguard for each non-KSA processing step?
- How is candidate consent captured, and can the consent record be exported?
- How long is data retained by default, and can retention be configured per role?
- What is the breach notification timeline from vendor to controller?
- Can the platform produce a complete data-subject access response on demand?
- Is the rubric documented and reviewable, and has the vendor performed bias testing on outcomes?
A vendor that handles all of these credibly — and produces evidence rather than marketing copy — is a credible KSA partner.
What good looks like in practice
A defensible Saudi hiring workflow with AI assistance generally has these properties:
- Candidate sees a clear, plain-language consent screen in Arabic and English before any AI processing.
- The interview runs against a documented, role-specific question set.
- A scorecard is produced with every claim linked to a verbatim candidate quote.
- A named human recruiter reviews the scorecard and records a decision with a written rationale.
- All data is stored in a region disclosed to the candidate, with the relevant cross-border safeguard documented.
- Retention is bounded — typically 90 to 180 days after the role closes, unless the candidate opts in to a talent pool with a separate consent.
- Deletion and access requests are handled within the regulatory window via a documented workflow.
The pattern does not slow hiring down. In practice, it speeds it up: the structured rubric and evidence reduce recruiter review time, and the consent and audit trail eliminate the back-and-forth that drags out compliance sign-off.
Where to go next
If you are setting up AI-assisted hiring in the Kingdom and want to see what a compliant flow looks like end to end, the Voxxhire demo walks through the candidate consent, interview, and scorecard in under three minutes.
For a deeper look at how to design the underlying interview itself so that it produces defensible evidence, see bias audits for AI hiring and our piece on structured graduate hiring funnels.
For an example of an early-stage company using AI-assisted interviews under similar data-handling discipline, see the Exara AI design partner case study.
This article is general guidance for HR leaders considering AI-assisted interviews under the Saudi PDPL. It is not legal advice. Always consult qualified KSA data protection and employment counsel before deploying any AI hiring system in production.