The short version
PDPL applies to your shop. Not only to banks and hospitals, but to anyone who collects other people's personal data in Saudi Arabia, including the barbershop holding 200 mobile numbers in a loyalty app. Saudi Arabia's Personal Data Protection Law has been fully enforceable since 14 September 2024, and SDAIA, the Saudi Data and Artificial Intelligence Authority, is the regulator behind it.
The useful news is that a first name and a mobile number is close to the smallest data set a business can hold. Your obligations are real but short. Tell people what you collect and why, collect only what you need, keep it only while you need it, honor requests to see or delete it, and know who else touches it. That is most of the work.
One thing this article is not: legal advice. I'm a founder who built a Saudi loyalty product, not a licensed Saudi lawyer. Every specific figure below is one to confirm on sdaia.gov.sa or in the consolidated text on laws.boe.gov.sa before you paste it into a policy. If a filing, a contract, or money depends on the answer, pay a licensed Saudi lawyer for an hour.
You're responsible for the list, not your vendor
PDPL splits the roles. You decide why the data is collected and what happens to it, which makes you the controller. Your loyalty software processes that data on your instructions, which makes it the processor. The distinction matters because the accountability lands on you. If a customer complains, the regulator asks your shop, not your app.
That is why the written agreement matters. A processor should hand you a data processing agreement without you having to chase it, and it should say what they do with the data, who can see it, where it is stored, and what happens when you leave. Waya publishes ours at trywaya.com/dpa, alongside trywaya.com/privacy, trywaya.com/terms, and trywaya.com/acceptable-use. Read the equivalent pages from any vendor before you upload a customer list.
No vendor can make you compliant, and one that claims otherwise is selling comfort. Waya does not hold a PDPL certification and does not claim one. What software can do is make the correct behavior the default: fewer fields on the form, a consent that is actually recorded, and a delete button that works.
Consent at the moment someone joins
Consent is the main legal basis in PDPL for a small business collecting a phone number. A 2023 amendment to the law added a legitimate-interest basis, which is narrower than it sounds. It does not cover sensitive data, and it expects you to document an assessment justifying it. For a stamp card, plain consent is simpler and far easier to defend.
Consent only counts if the person understood what they agreed to, which is a design problem more than a legal one. On Waya, joining is a QR scan, one screen asking for a first name and a mobile number, then one tap to add the pass to Apple Wallet or Google Wallet. Directly above that button sits a single line saying that adding the card means agreeing to the terms and privacy policy and receiving updates about rewards.
Adding the card is the approval, so there is no checkbox to hunt for. Behind it, Waya writes an append-only record: which consent was accepted, a short hash of the exact policy text as it read at that moment, the timestamp, the IP, and the browser. Those rows are never edited or deleted, and the owner and staff can read them. If someone asks in a year what a customer agreed to last March, you have an answer with a date attached.
Withdrawal has to be possible too. A wallet pass has a built-in off switch, because the customer can delete the pass and the lock-screen messages stop. On your side, you delete their record from the dashboard when they ask. Both routes belong in your privacy text, in the language your customers read.
Data minimization, or the two-field test
PDPL expects you to collect the minimum the purpose needs, so run the test field by field. A stamp card needs a name so the greeting is not robotic, and a mobile number as the identity key that finds the right card when your cashier scans it. That is the purpose met with two fields.
Now argue for the third. A birthday buys you one message a year. Gender buys you a segment you may never send to. Neither is illegal to collect, but both increase the amount of personal data you are answerable for, and both cost you signups because the form got longer. Waya can add a birthday, gender, and custom fields to the join screen; the default is not to.
Some fields do not belong on a loyalty form at all. Don't ask for a national ID or Iqama number in exchange for a free coffee, and skip home addresses. Treat health, religion, biometrics, and financial details as a separate tier that PDPL guards more tightly, and keep a loyalty card well away from them.
Retention: write the number down
PDPL expects personal data to be destroyed once the purpose it was collected for has ended. This is the obligation most shops quietly skip, because nothing forces the issue day to day. A phone number sitting in a dashboard four years after that person's last visit is not serving a purpose; it is just sitting there.
So pick a number and publish it. Something like: if a customer records no visit and no redemption for 24 months, the record is deleted. Suppose you enroll 400 customers over two years and 90 of them stop coming within the first six months. Under a 24-month rule, that is 90 records you delete on a specific date instead of holding indefinitely, and a sentence you can point to if anyone asks.
The Waya dashboard makes finding them easy, because it flags which regulars have gone quiet. It does not purge them on a schedule for you, and you should know that before you promise a retention period in writing. Deleting a customer removes their card and any pending wallet messages for your shop, while your own sales history stays intact, so your reporting numbers don't shift.
The three requests that actually arrive
In practice you will get three: what do you have on me, fix this, and delete me. PDPL gives people the right to be informed, to access and obtain a copy of their data, to correct it, and to have it destroyed, and it sets a window for you to respond. Confirm the current window on sdaia.gov.sa before you quote a number in your own policy, because those timelines live in the implementing regulation and it has been revised more than once.
Give the request a named route. One WhatsApp number or one email address, written in your privacy text, that a real person reads. "Contact the shop" is not a route if nobody owns the inbox, and an unanswered request is how a minor question becomes a complaint to the regulator.
Then there is the case nobody plans for. SDAIA's implementing regulation requires a controller to notify the authority within 72 hours of becoming aware of a personal data breach, and to inform affected people without undue delay. The published ceilings for violations run into the millions of riyals, up to 5,000,000 SAR for general breaches of the law and doubled for a repeat offense, with a separate criminal track for deliberately disclosing sensitive data. Those are ceilings for the worst cases, not the invoice waiting for a salon with 200 phone numbers, and they are figures to verify at the source rather than take from a blog post.
Questions to ask any loyalty vendor
Start with storage and access. Where is my customer data stored, and in which country? Who inside your company can see my customer list, and is that access logged? Ask both by email so the answer exists in writing; for Waya, write to [email protected] and we will answer the hosting-region question in writing rather than approximate it here.
Then ask about the exit and the audit trail. What happens to my list if I stop paying, and can I export it myself? Is consent recorded with a timestamp, and can I see that record? A vendor who cannot produce the moment a customer said yes is asking you to carry their risk.
Next, onward sharing. Do you sell, share, or market to my customers yourself? Do you send SMS, and if so, which gateway receives the phone number? That last question matters more than it sounds, because every third party your numbers pass through is another place they can leak. Waya sends nothing by SMS, since updates ride Apple Wallet and Google Wallet as pass updates and lock-screen messages, so the number stays where you put it.
Finish with the two that filter out bad answers. Will you notify me within 72 hours of a breach, and can I read your data processing agreement today without asking a salesperson? Then ask whether they are certified compliant with PDPL. Anyone who says yes without qualification is overselling, because compliance is a state you maintain, not a badge a vendor hands you.
What to do this week
Three things, in order. Open your join form and delete any field you can't justify in one sentence. Paste a plain privacy notice onto the join page covering what you collect, why, how long you keep it, and how to reach you; Waya ships a starter privacy and terms template in Arabic and English that you can edit, written as sensible defaults for a Saudi small business rather than as legal advice. Third, write your retention number down and put a calendar reminder on the date you will act on it.
All three fit inside the free plan. It's 0 SAR forever for up to 100 customers, 100 wallet messages a month, one stamp card, and one branch, with no credit card. Past that, Growth is 85 SAR a month and Premium is 149 SAR a month, and the meter on paid plans is wallet messages rather than customers. More than 100 shops across Saudi Arabia run on this today, with over 5,000 cards living in customers' wallets.
Frequently asked questions
Does PDPL apply to my small shop?
Yes. PDPL applies to anyone processing personal data in Saudi Arabia, including a single-branch shop holding customer names and mobile numbers. There is no small-business exemption that lets you skip consent, minimization, or retention. Your workload is smaller because you collect so little, but the duties are not waived.
Do I need consent to send loyalty messages to my customers?
Yes, and the cleanest way is to state at signup that joining means receiving updates about rewards, then record that the person agreed. SDAIA's enforcement decisions in the first year of enforcement covered marketing messages sent without a valid basis, so this is not theoretical. On Waya, adding the card is the recorded approval, and the record keeps a timestamp plus a hash of the policy text shown at that moment.
How long can I keep a customer's phone number?
Only as long as the purpose you collected it for still exists, which for a loyalty card means while that person is still your customer. PDPL expects destruction once the purpose ends and does not hand every business a single universal number. Choose a defensible rule, such as deleting after 24 months with no visit and no redemption, publish it in your privacy text, and act on it.
If my loyalty app leaks the data, is it my problem or the vendor's?
Both, but the accountability for your customer list sits with you as the controller, while your vendor is the processor and answers to you under a data processing agreement. That is why the DPA and the breach-notification commitment matter before you upload a single number. SDAIA's implementing regulation requires notification to the authority within 72 hours of becoming aware of a breach; confirm the current wording on sdaia.gov.sa.
Do I have to register with SDAIA to run a loyalty card?
Check sdaia.gov.sa for the current answer rather than trusting any blog post, including this one. SDAIA operates a national register for data controllers, and the question of which businesses must register, and by when, is exactly the detail that has moved since the law came into force. If a filing deadline is attached to your situation, that is the point to bring in a licensed Saudi lawyer.