PDPL is a product constraint, not a certificate
If an app or admin processes personal data of people in the Kingdom, the Personal Data Protection Law applies. Privacy notices, a lawful basis, subject rights. We are not a law firm.

PDPL Saudi Arabia applies to personal data of people in the Kingdom, including processing from outside. If the product has an app and an admin on that data, the constraint is in the schema, the notice, the rights path, and the export button. Fluids is not a law firm. Fluids is not certified. Counsel answers legal questions. This note is how we already build.
What the Law actually applies to
SDAIA’s own page: the Law applies to any processing of personal data involving individuals within the Kingdom, by any means. It also covers processing of personal data related to individuals in the Kingdom by any entity outside the Kingdom. Article 2 of the Personal Data Protection Law says the same thing. A Flutter binary in a Gulf user’s pocket is not a loophole. A server abroad is not a loophole.
Personal data, in Article 1, is any data that may lead to identifying an individual — name, ID number, address, phone, records, bank details, photos, video. Processing is collecting, storing, using, disclosing, transmitting, sharing, erasing, destroying. A booking is personal data. An employee performance file is personal data. We will not upgrade either into a hospital system.
Sensitive data is a higher class
Health data is sensitive: a health condition, or health services received. Article 1. Booking a clinic visit, as Naqrah.app is published, is personal data. It is not an EHR. Extra care for health data lives in the healthcare note. We do not wear HIPAA.
Four product consequences
- A privacy policy, available before collection. Article 12.
- A notice at collection: legal basis, purpose, mandatory versus optional, who collects, who sees it, whether it leaves the Kingdom, rights. Article 13. The App Store nutrition label is not this notice.
- A lawful basis. Consent is the default. It is not the only basis. Article 5 and Article 6.
- Subject rights the product can actually do. Article 4.
Consent may be withdrawn at any time. It may not be the price of a service unless the service is the processing. Article 7. Legitimate interest exists and does not cover sensitive data. We will not pick a basis for you. That is counsel’s job.
One schema, two faces, RLS as the gate
Flutter is the mobile default. Swift when the product belongs on Apple. React admin. One Supabase project. Hiding a menu is not access control. Anyone with the publishable key can call the API. Row-level security is the gate. The secret key never ships in the IPA, the AAB, or the React bundle.
The admin is where rights get exercised. Informed, access, a readable copy, correction, destruction when no longer needed, withdraw consent. Those are routes, jobs, and policies. Identity check before you hand someone someone else’s file.
Export is a dangerous admin action
Delete a user. Change a role. Unlock an archive. Export personal data. Confirmation. A reason. An audit line. A CSV of every performance file, or every clinic booking, is disclosure. Treat it as such. An admin that cannot answer who exported this, and when, is not finished.
CareerFolio: locked year, secure share
CareerFolio is web. Say web. Bilingual performance portfolios for Ministry of Education employees. A finished year is finalized with a rating, then locked as a permanent read-only archive. A reviewer gets a secure read-only share link. That is a state on the row plus a policy, not a greyed-out button. The work page already names Supabase and row-level security. A government reviewer may only read a locked year.
Leaving the Kingdom is a separate question
Article 29 and the Transfer Regulation govern disclosure outside the Kingdom. Hosting and subprocessors are product decisions. We will not tell you where you must host. We will not revive the old line that every transfer needs SDAIA’s prior written approval — the 2023 amendments changed that general condition. SDAIA’s breach guide: notify the Authority within 72 hours of becoming aware, if the incident is expected to harm personal data or conflict with rights. We are not a notification desk. We are not certified.
What we will not put in this page
- A Fluids PDPL certification.
- Legal advice. A lawful-basis opinion for your product.
- Nafath as a Fluids case study.
- GDPR articles pasted as if they were PDPL.
- A claim that data must live in the Kingdom.
- Hospital counts, student counts, a named app written in Swift.
If the product processes personal data of people in the Kingdom, say so in Frame. Write to us with the rows, not with a badge.
Tell us what you’re building.
Write to us with the product you want built. You will get a considered reply from the people who would do the work.
Start a conversation