PDPL compliance
Article by article, not a badge.
Checked against the Implementing Regulations published by SDAIA.
Last updated 13 September 2026
1. What this page covers
The Kingdom’s personal data regime has two instruments: the Personal Data Protection Law, and the Implementing Regulations that sit under it. The competent authority is the Saudi Data and Artificial Intelligence Authority (SDAIA).
Every article cited on this page is from the Implementing Regulations, checked against SDAIA’s published text. The Law’s own article numbers are different, and are not cited here.
2. Controller and processor
The restaurant group is the controller. It decides which stations are recorded, who receives alerts, and how long records are kept. Proof Manager is the processor, acting on those instructions under a written processing agreement.
That split decides who answers a rights request. A request about branch footage goes to the group; we support them in answering it. Several obligations — the national register in Article 34, for instance — sit with the controller, not with us.
Article 17 governs our side of it. It requires the controller to choose a processor that gives sufficient guarantees, and to put the purpose, the categories of data, the term, and breach notification in writing. Our processing agreement is built around those four.
3. Article by article
4. Design choices that reduce the obligation
The cheapest way to comply is to hold less.
5. What your legal team can ask us for
A data processing agreement, a short PDPL note, the processing register for your account, and a branch notice you can post at the station.
6. This is not legal advice
This page describes how the product is built and what we are prepared to commit to contractually. It is a summary, not a substitute for the Law or the Regulations, and your own counsel should confirm what applies to you as controller. The official texts are published by SDAIA.
Rights requests reach the controller first. Anything addressed to us goes to hello@proofmanager.co.
PDPL compliance
Article by article, not a badge.
Checked against the Implementing Regulations published by SDAIA.
Last updated 13 September 2026
1. What this page covers
The Kingdom’s personal data regime has two instruments: the Personal Data Protection Law, and the Implementing Regulations that sit under it. The competent authority is the Saudi Data and Artificial Intelligence Authority (SDAIA).
Every article cited on this page is from the Implementing Regulations, checked against SDAIA’s published text. The Law’s own article numbers are different, and are not cited here.
2. Controller and processor
The restaurant group is the controller. It decides which stations are recorded, who receives alerts, and how long records are kept. Proof Manager is the processor, acting on those instructions under a written processing agreement.
That split decides who answers a rights request. A request about branch footage goes to the group; we support them in answering it. Several obligations — the national register in Article 34, for instance — sit with the controller, not with us.
Article 17 governs our side of it. It requires the controller to choose a processor that gives sufficient guarantees, and to put the purpose, the categories of data, the term, and breach notification in writing. Our processing agreement is built around those four.
3. Article by article
4. Design choices that reduce the obligation
The cheapest way to comply is to hold less.
5. What your legal team can ask us for
A data processing agreement, a short PDPL note, the processing register for your account, and a branch notice you can post at the station.
6. This is not legal advice
This page describes how the product is built and what we are prepared to commit to contractually. It is a summary, not a substitute for the Law or the Regulations, and your own counsel should confirm what applies to you as controller. The official texts are published by SDAIA.
Rights requests reach the controller first. Anything addressed to us goes to hello@proofmanager.co.