Compliance Colleague · Tools

Breach-notification clock

Saudi Arabia, UAE (onshore, DIFC, ADGM), Kuwait, Oman, Qatar and Bahrain · table updated 2026-09-30

Enter when your team discovered the breach. The deadlines come from the Gulf breach-notification table, which cites the law and source for each one. Everything runs in your browser; nothing you enter is sent anywhere.

Notify Saudi Data & AI Authority (SDAIA)
72 hours after discovery: enter a time above
Notify affected data subjects
Not fixed / see source
Without undue delay (no hour count).

Conditions: Only where the incident may cause harm to the data or data subjects, or conflicts with their rights or interests. Late information must be sent as soon as possible, with reasons. NCA and SAMA duties apply on top where relevant.

Law: Personal Data Protection Law (Royal Decree M/19, amended by M/148), Art. 20; Implementing Regulation Art. 24. SDAIA: laws and regulations (official English translation), checked 2026-09-23 (Official text (SDAIA's English translation; Arabic is binding)).

Need the detail behind a deadline, or several regimes at once? Compliance Colleague answers with the article cited, across 30+ standards and laws. Try it free, no card required →

Not legal advice. A research aid only: it applies the fixed hour counts in the table and does not decide whether a breach is notifiable or when your clock started. Confirm against the official text and take local legal advice.