The Saudi PDPL and the customer support team: what changes in practice

Customer conversations are personal data. Five obligations on the support team since September 2024.

The support team handles the most sensitive personal data every day: names, numbers, addresses, order details and complaints. The Personal Data Protection Law has been fully enforceable since 14 September 2024, and it applies to anyone processing the data of residents of the Kingdom, wherever they are.

Five practical obligations

  1. Where it is held: personal data stays inside the Kingdom unless a legal exception applies. The first question for any support-platform provider is the name of the country where conversations are stored.
  2. The sub-processor: the platform provider is a processor acting on your behalf, and a data processing agreement defining roles and instructions is required.
  3. Access and logging: who can read the conversations? Fine-grained roles and an audit log are not a luxury.
  4. Data subject rights: a request to access, correct or delete reaches the support team first. Export and erasure tools need to be within its reach.
  5. Breach notification: the notification window is fixed, and the provider needs to commit to it in writing.

The personal phone is the biggest gap

When customer conversations live on an employee's personal phone, the business does not own the data, cannot protect it, and cannot delete it on request. Moving them to a platform that holds them inside the Kingdom is the first step, not the last.

Fines reach SAR 5 million and double for repeat offences. But the main reason to comply is not the fine; it is that customers have started asking.

Try Hadir Chat on your store

Create a workspace in a minute. No card, no commitment.