Skip to content

Compliance

Saudi PDPL and Call Recordings: What Contact Centers Must Know

How Saudi Arabia's PDPL applies to call recordings and transcripts: notice, legal basis, retention, rights, transfers and breaches, plus a practical checklist.

Ranen teamUpdated 7 October 20268 min read

Every recorded call in a Saudi contact center creates personal data: the caller's voice, their words, their number and often an account or ID number. Under the Personal Data Protection Law (PDPL), that recording and every transcript or summary derived from it needs a legal basis, a defined purpose, a retention limit, adequate security and a process for rights requests.

This guide applies the PDPL and its Implementing Regulations to recordings and transcripts, then turns the obligations into a checklist. It is general information, not legal advice. Confirm your position with qualified counsel and the current official text published by SDAIA.

Key takeaways

The PDPL is enforceable since 14 September 2024. Tell callers at the start that the call is recorded and why, record for defined purposes only, delete when the purpose ends, answer rights requests within 30 days, report qualifying breaches to SDAIA within 72 hours, and sign compliant contracts with every vendor that touches recordings.

When the PDPL applies to call recordings

SDAIA's National Data Governance Platform dates the PDPL's issuance to 16 September 2021. After 2023 amendments, the law and its Implementing Regulations took effect on 14 September 2023, with a one-year grace period that ended on 14 September 2024, after which SDAIA (the Saudi Data and Artificial Intelligence Authority) can enforce it.

For a contact center, all of the following are personal data when they relate to an identifiable caller:

  • The audio recording, inbound or outbound.
  • Transcripts, whether produced by people or speech recognition.
  • Summaries, intent labels, sentiment scores and QA notes.
  • Metadata such as caller number, time, duration and queue.

Voiceprints used to verify a caller deserve extra care. DLA Piper lists biometric data among the law's sensitive categories, so assess voice biometrics as sensitive data before deployment.

Legal basis and notice at the start of the call

Choosing a legal basis

Consent remains the primary basis, but the 2023 amendments added the controller's legitimate interests, provided the data subject's rights are not prejudiced. Clyde & Co notes this requires a documented balancing assessment, and Addleshaw Goddard notes it cannot be used for sensitive data. Consent must be freely given, specific to each purpose, and explicit for sensitive data, credit data and automated decision-making.

Many contact centers record for quality, disputes and fraud prevention under legitimate interests and seek separate consent for anything beyond that. Counsel should confirm the basis for each purpose.

What the opening notice should cover

Data subjects have the right to be informed of the processing and its legal basis. A short opening message, backed by a full privacy policy online, typically states that the call is recorded and may be transcribed, the purposes, whether an AI agent is handling the call, and how to exercise rights.

Some sectors are explicit. SAMA's debt collection rules require that a retail consumer be notified at the beginning of the call that it is recorded.

Purpose limitation, minimization and retention

Personal data may be processed only for the purposes for which it was collected, and collection must be limited to what is strictly necessary. Decide in advance what each recording is for and who may listen to it. A recording made for disputes should not become a training set for a new product without a fresh assessment.

The law requires destruction once the purpose has been achieved, with exceptions such as anonymization or a legal duty to retain. Clyde & Co notes that destruction must reach all copies, including backups. Sector rules can set minimums: SAMA requires collection calls with retail consumers to be documented and kept for no less than ten years from the date of the call.

Data itemTypical purposeRetention question to answer
Audio recordingQuality, disputes, evidenceIs there a sector minimum? How long are disputes raised?
TranscriptSearch, QA, analyticsMust it outlive the audio? Can it be anonymized?
Summary and intentHandover, CRM historyDoes the customer record have its own rule?
Card and ID numbersVerification onlyCan they be masked and never stored in clear?

Data subject rights and sensitive data

Rights requests about recordings

Callers can access, correct and request destruction of their data. Controllers must respond within 30 days, extendable by 30 days for unusually complex requests. IAPP reports that verbal requests are permitted subject to authentication, so a caller can ask for their recordings on the phone. Agents, human or AI, should recognize such requests, verify identity and log them into a tracked workflow.

Sensitive data on the line

Callers volunteer sensitive data constantly, such as a health condition when rescheduling an appointment. Health data remains sensitive under the amended law. Clyde & Co lists sensitive data processing and new technologies among the cases that require a data protection impact assessment (DPIA), so a voice AI deployment in a clinic or bank is a strong candidate for one. See our guides on medical appointment booking by voice AI and voice AI for banks in Saudi Arabia for sector detail.

Transfers, processors, security and breaches

Cross-border transfer

Transfers outside the Kingdom need a lawful route: an SDAIA adequacy determination, appropriate safeguards such as standard contractual clauses or binding corporate rules, certificates of accreditation, or limited derogations. Clyde & Co notes that SDAIA's standard clauses are invalid if amended beyond their blank fields. DLA Piper adds that some sectors, banking among them, need their own approvals. Hosting recordings inside Saudi Arabia removes most of this analysis, but check where vendors process data for support or model inference.

Processor contracts

A vendor that stores, transcribes or analyzes recordings is a processor. The regulations require a written agreement that includes breach notice to the controller without undue delay and prior controller approval for sub-processors. The controller remains responsible for verifying compliance.

Security and breach notification

Encrypt recordings in transit and at rest, restrict playback by role, log every access, and mask card and ID numbers. Controllers must notify SDAIA of a breach within 72 hours of becoming aware of it, through the National Data Governance Platform according to DLA Piper, and notify affected individuals without undue delay where harm may result. Penalties include fines of up to SAR 5 million, and up to two years' imprisonment and/or a SAR 3 million fine for unlawful disclosure of sensitive data.

Practical checklist for call recordings

  1. Map where call data lives: telephony, recorder, transcription, CRM, QA tools, backups.
  2. Document the legal basis and purpose for each data item.
  3. Update the opening message and privacy policy; disclose AI handling.
  4. Set retention per data item, including sector minimums, and automate deletion across backups.
  5. Mask card and ID numbers in recordings and transcripts.
  6. Run a DPIA before launching voice AI, speech analytics or voice biometrics.
  7. Restrict access by role and log who listened to or exported what.
  8. Accept rights requests by phone, verify identity and meet the 30-day deadline.
  9. Confirm data location for every vendor and any transfer mechanism.
  10. Sign processor agreements with breach notice and sub-processor approval clauses.
  11. Rehearse a breach runbook that meets the 72-hour SDAIA deadline.
  12. Keep records of processing; Clyde & Co notes a five-year retention after processing ends.

How Ranen handles this

Ranen hosts calls, recordings and transcripts in data centers inside Saudi Arabia, with TLS 1.3 in transit, AES-256 at rest and customer-managed keys for enterprise clients. Card and ID numbers are masked automatically. Every word and action is logged and reviewable, with roles, single sign-on and human approval for sensitive actions. Client data is never used to train models for other customers and is deleted on request. Callers can ask for a person at any time, and the handover to staff carries a summary. You can request a demo on your own call recordings.

Frequently asked questions

Is call recording legal in Saudi Arabia under the PDPL?

The PDPL does not ban call recording. It requires a legal basis, a defined purpose, notice, security, and deletion when the purpose ends. Some sectors, such as banking, add their own rules.

Do I need consent to record customer calls?

Not always. The amended PDPL allows legitimate interests after a balancing assessment, but not for sensitive data. Where consent is used, it must be specific to each purpose.

How long can a contact center keep call recordings?

Only as long as the purpose requires, unless a law or regulator sets a longer period, and deletion must reach backups.

Are AI call transcripts personal data?

Yes. Transcripts, summaries and intent labels linked to an identifiable caller are personal data and need the same controls as the audio.

Sources

  1. SDAIA: National Data Governance Platform, Personal Data Protection
  2. Clyde & Co: Saudi Arabia's Personal Data Protection Law becomes enforceable
  3. Clyde & Co: Saudi Arabia issues Implementing Regulations to the Personal Data Protection Law
  4. Clyde & Co: Countdown to compliance with the Saudi Arabia PDPL
  5. DLA Piper: Data Protection in Saudi Arabia
  6. IAPP: Saudi Arabia publishes final Personal Data Protection Law
  7. Addleshaw Goddard: Saudi Arabia issues amendments to PDPL
  8. Al Tamimi & Company: An overview of Saudi Arabia's new Personal Data Protection Law
  9. SAMA Rulebook: Debt Collection Regulations and Procedures for Individual Customers

Hear Ranen on your own calls

Book a demo and we run Ranen on a sample of your call recordings, then size the plan with you.

Related articles

All articles