Call recording laws in Saudi Arabia: what call centres must do under the PDPL

By Adnan Bassem — Founder, InfoDriven (Dubai). Building Arabic-first speech recognition for GCC call centers.Published June 10, 2026

ComplianceLast updated: June 10, 2026

Is it legal to record customer calls in Saudi Arabia?

Yes — call recording is a routine, regulator-expected practice in Saudi contact centres, and the Communications, Space and Technology Commission (CST, the renamed CITC) actually requires recording on key transactional and complaint interactions handled by licensed telecom services. The legal question is not whether you may record but under what conditions: the customer must be notified at the start of the call, the recording must have a lawful basis under the Personal Data Protection Law, and retention and access must be controlled.

The standard operational pattern is an automated notice before the agent connects — "هذه المكالمة مسجلة لغرض الجودة" (this call is recorded for quality purposes) — followed by the customer continuing the call, which in practice evidences awareness. Saudi practice is notification-driven rather than US-style one-party / all-party consent: every participant on the call should hear the disclosure. Where recording serves purposes beyond quality and dispute resolution (for example training AI models or marketing analysis), the safer posture is to name those purposes in the notice and the privacy policy, and to take specific legal advice before relying on a broad-purpose disclosure.

Does the Saudi PDPL apply to call recordings?

Yes, squarely. The Saudi Personal Data Protection Law was issued under Royal Decree M/19 of 1443H (2021) and amended by Royal Decree M/148 of 1444H (2023). It applies to any processing of personal data of individuals residing in the Kingdom, regardless of where the controller is located. Voice recordings are personal data whenever they identify or can identify a natural person — and a customer-service call almost always does, through the caller's voice, name, phone number, and account references spoken aloud.

That scope pulls the whole call-recording pipeline into PDPL territory: the recording platform, the storage layer, any transcription or analytics processor, and any vendor with access. Controllers must establish a lawful basis for processing (consent is the default; legitimate interest and contractual necessity are recognised but narrowly), maintain records of processing activity, and run data-protection impact assessments for high-risk processing — large-scale call recording qualifies. A transcription vendor like CallScribe sits in this chain as a processor, which means the controller needs a Data Processing Addendum covering security, sub-processors, breach notification, and deletion on termination.

What changed when SDAIA enforcement began in September 2024?

Full enforcement by the Saudi Data and Artificial Intelligence Authority (SDAIA) began on 14 September 2024, after a one-year compliance grace period that followed the 2023 amendment (Royal Decree M/148) and the implementing regulations issued the same year. Before that date, the PDPL was law on paper with a forgiving runway; since that date, controllers are expected to be operating compliantly — registered where mandated, with lawful bases documented, DPIAs completed for high-risk processing, and processor contracts in place.

For call-centre operators the practical effect has been procurement-level: Saudi enterprises now routinely ask transcription and analytics vendors for their PDPL posture in writing before onboarding — where audio is processed, which sub-processors touch it, what the retention and deletion mechanics are, and whether in-Kingdom processing is available for sensitive workloads. If your recording or transcription stack cannot answer those questions, that is the gap to close first.

Can Saudi call recordings be stored outside the Kingdom?

Often yes, with conditions. The 2023 amendment relaxed the original cross-border-transfer regime: transfers to jurisdictions with adequate protection are permitted; transfers elsewhere require either explicit consent, contractual safeguards approved by SDAIA, or specific exemptions. EU processing has been treated as adequate under the implementing regulations for most use cases, which is why an EU-hosted transcription posture (CallScribe's default is Hetzner infrastructure in Helsinki and Falkenstein, with no audio or transcripts sent to US-based third-party APIs during transcription) is a known and workable arrangement for many Saudi controllers.

The exceptions matter. For in-scope sensitive workloads — financial services under SAMA, health data, government and NCA-classified deployments — in-Kingdom processing is frequently mandated or strongly expected, and the answer is an enterprise deployment via NCA-approved cloud providers or GCC-resident worker nodes rather than the default EU posture. Map your call categories before choosing an architecture: general retail support traffic and SAMA-regulated KYC calls do not necessarily have the same residency answer.

What extra rules apply to banks and financial firms? The SAMA overlay

The Saudi Central Bank (SAMA) imposes a financial-services layer on top of the PDPL and CST rules. SAMA's Banking Consumer Protection Principles and the Insurance Authority's conduct-of-business rules add longer retention requirements for KYC verbal-verification calls, sales calls for investment products, and dispute calls — typically five to ten years — together with stricter access controls and prompt retrievability for regulator inquiry.

Operationally this means per-call-category retention rather than one blanket window: a Saudi bank commonly keeps general support calls for around one year under CST-aligned practice while keeping KYC-verification and dispute calls for five to ten years under SAMA-aligned rules. Your recording and transcription stack needs per-project or per-category retention configuration to do that without manual re-classification, plus append-only audit logs showing who accessed which transcript and when. The exact windows for your licence class should be confirmed with compliance counsel against the current SAMA circulars — they are updated periodically and vary by product line.

Call-recording compliance checklist for Saudi call centres

Use this as a starting inventory for a PDPL-era audit of an existing Saudi call-recording operation. It is a practitioner checklist, not legal advice — run the output past counsel, especially for SAMA-regulated or government traffic.

  • Recording disclosure plays before the agent connects, in Arabic (and English where traffic warrants), naming the purposes of recording
  • Lawful basis per call category documented in the record of processing activities
  • DPIA completed for large-scale call recording and any AI-driven analytics on the audio
  • Cross-border map: where audio, transcripts, and backups physically sit, and the transfer mechanism for each destination
  • Processor DPAs in place with every transcription, analytics, and storage vendor, including sub-processor disclosure
  • Per-category retention windows configured (general support vs KYC vs disputes), with automated deletion at expiry
  • Access to recordings and transcripts logged append-only; privileged access reviewed quarterly
  • PII redaction applied to searchable transcripts (IDs, card numbers, IBANs) while original audio follows the retention rule
  • SAMA / Insurance Authority overlays confirmed with counsel for any regulated financial traffic
  • Data-subject request workflow tested: locate, export, and delete a specific caller's recordings on request

Sources

  1. Saudi Personal Data Protection Law, Royal Decree M/19 of 1443H (2021), as amended by Royal Decree M/148 of 1444H (2023)
  2. SDAIA, Personal Data Protection Law implementing regulations (2023); full enforcement from 14 September 2024
  3. Communications, Space and Technology Commission (CST, formerly CITC) telecom licensing and consumer-protection rules on call recording
  4. SAMA Banking Consumer Protection Principles; Insurance Authority conduct-of-business rules (retention windows for financial-services calls)

Frequently asked questions

Do I need explicit "press 1 to consent" consent to record calls in Saudi Arabia?

Standard Saudi practice is a clear pre-call notification ("هذه المكالمة مسجلة لغرض الجودة") rather than an affirmative keypress. The PDPL requires a lawful basis, and notification-backed continuation of the call is the widely used pattern for quality and dispute purposes. For secondary purposes such as AI training or marketing analytics, name them in the notice and privacy policy and confirm the approach with counsel.

Are call transcripts treated the same as call recordings under the PDPL?

Treat them the same. A transcript of an identifiable caller is personal data just as the audio is, and it inherits the same lawful-basis, retention, transfer, and access-control obligations. In some respects transcripts are higher-risk because they are full-text searchable — which is why PII redaction in the searchable transcript layer is a sensible default.

Can a Saudi bank use a transcription vendor hosted in the EU?

For many workloads yes — EU jurisdictions have been treated as adequate under the PDPL implementing regulations for most use cases, with a DPA in place. But SAMA-regulated sensitive workloads, health data, and government deployments frequently require in-Kingdom processing, in which case the vendor needs an enterprise option via NCA-approved cloud or in-region worker nodes. CallScribe offers both postures and will tell you which your use case needs.

How long must a Saudi call centre keep recordings?

There is no single number. CST-aligned practice for general operator calls is around one year, scaled by interaction type; SAMA-aligned windows for KYC, investment-sales, and dispute calls typically run five to ten years. Configure retention per call category and confirm the exact windows for your licence with compliance counsel.

What happens if a Saudi call centre ignores the PDPL?

Since SDAIA's enforcement began on 14 September 2024, non-compliance carries regulatory exposure including administrative penalties, and — at least as damaging commercially — failure of enterprise procurement reviews, since Saudi buyers now ask vendors and BPOs for documented PDPL posture. Specific penalty exposure depends on the violation and should be assessed with counsel.

Test it on your own Arabic calls

Dialect-aware transcription with diarization and sentiment — built for GCC call centers.

Try CallScribe free →

5 min/mo free · No credit card