Skip to content

Cold Email Laws Saudi Arabia: Everyone Cites the Wrong Law

Cold email into Saudi Arabia is not governed mainly by the PDPL. The operative rule is the Communications, Space and Technology Commission's Regulations for Curbing SPAM Messages and Calls, and it starts from the opposite default to Europe or the United States: promotional messages are blocked for every subscriber from the outset, consent buried in a privacy policy or a service contract is expressly disregarded, and the sender carries the burden of proving consent. Short messages and calls arriving from outside the Kingdom must be service or personal only. Email is treated differently, and that difference is the whole article.

Saudi Arabia did not build a do not call list. It built a do call list, and your sender name has to be added to it one subscriber at a time.

The mistake: reading Saudi Arabia as a GDPR country

Ask an AI assistant whether cold email is legal in Saudi Arabia and you will get the Personal Data Protection Law. Reasonable, and the wrong first document. The PDPL does have a direct marketing article: a controller may not use personal means of communication, including post and email, to send advertising material without the prior consent of the targeted recipient and a clear mechanism to stop. That is about as specific as it gets, because the article then hands the detail to regulations.

Meanwhile there is a document that does contain the detail, and almost nobody sending outbound has read it. I went through it in both English and the governing Arabic this week: Regulations for Curbing SPAM Messages and Calls, Version Three, RC01, October 2022, adopted by CST Decision 493/1444 of 17 October 2022 and in force ninety days later. It binds three groups by name: operators, short message service providers, and senders. If you run campaigns, you are the third group.

The reflex

Saudi has a data protection law like everyone else. We take consent in the signup flow, we put an unsubscribe link in the footer, we are fine.

The regulation that governs the message names that exact kind of consent and says it does not count, and it puts the burden of proving consent on you.

The check first

Ask one question about any Saudi contact: can I show the moment this person separately agreed to receive marketing from us

If the answer lives in a privacy policy or a service contract, the regulation has already told you what it thinks of it.

Two other statutes get dragged in and neither carries the weight people give it. The E-Commerce Law is cited for a consent rule it does not contain: its Article 11 is about deceptive claims and trademark misuse. And the Anti-Cyber Crime Law has no spam offence at all. I read all sixteen articles looking for one. It reaches unlawful access and interception, which is a question about how your list was built, not about sending.

Promotional is switched off by default, for everyone

Here is the clause that reorganises the whole problem. Operators must block promotional messages in full from the outset, and then make available to the end user the option to request receiving them, in whole or in part, from specific sender names according to that user's wish.

Read that as an operator of campaigns. In the United States you scrub against a do not call list, and the default is contact until they object. In Saudi Arabia the default is reversed. Every subscriber starts with promotional traffic off, and your named sender has to be individually let through. The compliance question stops being "has this person opted out" and becomes "has this person opted in to us, by name".

01Sender name registered and approved, then suffixed -AD
02Promotional traffic blocked in full, from the outset, for every subscriber
03The subscriber asks to receive that named sender, in whole or in part
04Only now does your message reach a handset

The machinery is built for that default. Sender names are registered and approved through an operator system, promotional ones carry an -AD suffix, and operators must filter out any bulk message whose sender name is not approved. Promotional messages may not go out from a mobile number, nor between 10pm and 9am, nor between 1am and noon in Ramadan. And address harvesting and dictionary attack software are banned twice over: you may not use the software, and you may not use the addresses it produced.

0hrs
To stop sending after someone asks you to stop
SAR 0m
Maximum fine under the Telecoms Law, not the 5m widely quoted
0am
Earliest a promotional message or call may go out, outside Ramadan

This is the sentence I would print out for anyone running outbound into the Kingdom. When a sender wants to send a promotional message, it must give the end user the choice to expressly agree to receive promotional messages or not, and consent contained in privacy policies and service contracts is not relied upon, and the burden of proving consent falls on the sender. The identical wording appears again for promotional calls.

Most consent architectures I audit fail on that sentence alone, usually through a signup form where agreeing to terms is agreeing to everything. Under GDPR you can at least argue about legitimate interests. Here there is no argument to have: the regulation names the two places people hide consent, excludes both, and puts the evidential burden on you rather than on the person complaining.

Where email actually sits: inside the rule, outside the machinery

Now the part I have not seen written anywhere. It comes from which noun each clause uses.

The clause barring offshore promotional traffic says short messages arriving from parties outside the Kingdom must be service or personal only, and its sibling says the same for calls. Both name a channel. Neither names email. But the express consent duty, the 24 hour stop, the night curfew and the harvested address ban are all written against "promotional messages", and the regulation defines a promotional message as an electronic message of a commercial or marketing nature, and defines electronic message to include email alongside SMS, MMS, flash SMS and fax.

So the two halves land in different places. Cold email from abroad is not caught by the offshore bar that stops offshore SMS and cold calling. It is caught by the consent rule, in full. And the enforcement apparatus, which is sender name registration, operator filtering, default blocking and the 330330 reporting channel, is built entirely for SMS and voice. Email sits inside the obligation and outside the machinery.

That is not a loophole and I would not sell it as one. It means the thing that stops your SMS at the network is absent for email, so the only thing standing between your campaign and a complaint is whether you can produce the consent. Which takes us back to the burden of proof.

Four moves before you send into Saudi Arabia

01

Read the regulation, not a summary of it

Ask for Regulations for Curbing SPAM Messages and Calls, Version Three, RC01, October 2022, adopted by CST Decision 493/1444, and read the Arabic if you can. Second-hand summaries drift: the penalty figure most often quoted online is not the one in the telecoms law that is in force, and the sending hours get restated wrongly too.

02

Separate your Saudi consent record from your privacy policy

The rule is explicit that consent contained in privacy policies and service contracts is not relied on, and that the sender bears the burden of proof. That is a data model question before it is a legal one: you need a timestamped, per-channel, per-recipient record you can produce. If your cold email infrastructure cannot show you when a specific Saudi contact opted in, you do not have consent you can defend.

03

Split SMS and calling away from email in your Saudi playbook

Offshore promotional SMS and offshore promotional calling are barred by a clause that names them. Email is not named in that clause. If you want SMS or voice in the Kingdom you need a licensed local route and a registered sender name, and the person who registers and approves that name has to be a Saudi national. That is a partner decision, not a settings change.

04

Treat a stop request as a 24 hour clock across every channel

The regulation gives you 24 hours from receiving a stop request, and it says stop sending any other messages, not just the campaign that triggered it. It also requires you to send a confirmation that sending has been stopped. Most outbound stacks I audit can suppress a list. Far fewer can prove they did it inside a day and told the person so.

The bottom line

Saudi Arabia is not a harder version of GDPR. It is a different shape. Europe regulates the lawful basis and lets the message through; Saudi Arabia regulates the message and the network it crosses, and starts with the tap closed. The GCC is not one market on this: the rules here are not the rules in the UAE, which I say as someone running a cold email agency out of Dubai.

If you are selling into the Kingdom, the honest sequence is: get email consent you can evidence per recipient, keep SMS and voice on a licensed local route with a registered sender name, and stop treating a privacy policy as a consent record. That is a cold email programme question and an infrastructure question before it is a legal one, which most teams get to last.

Frequently Asked Questions

It is not banned outright, but it is opt-in. The Communications, Space and Technology Commission's Regulations for Curbing SPAM Messages and Calls require a sender to give the recipient an express choice to receive promotional messages, and the regulation defines a promotional message as an electronic message of a commercial or marketing nature, with electronic message defined to include email. So a cold email to a Saudi recipient without prior express consent sits outside what the regulation permits. The PDPL points the same way through its direct marketing article, which requires prior consent and a clear mechanism to stop.
Both can, and they are enforced by different bodies. The PDPL is administered by SDAIA and reaches processing of personal data relating to individuals in the Kingdom even when the processing happens abroad. The CST regulation sits under the Telecommunications and Information Technology Law and binds operators, SMS providers and senders. In practice the CST regulation is the one that describes what your campaign may and may not do, message by message, which is why it is the more useful document to read first.
On the face of the regulation, no. It states that short messages arriving from parties outside the Kingdom must be service or personal messages only, and says the same for calls arriving from outside the Kingdom. Promotional is not on either list. That clause names short messages and calls. It does not name email, which is the asymmetry this article is about.
The regulation itself sets no fine. It says CST will follow up on compliance and act against violators under its own rules, and the penalties come from the Telecommunications and Information Technology Law, Royal Decree M/106. Article 26 treats misuse of telecommunications services as a violation, and Article 27 allows a fine of up to 25 million riyals, suspension of the service, or publication of a summary of the decision at the violator's expense. A figure of 5 million riyals circulates widely online. It is not the figure in the law that is in force.

Sending into Saudi Arabia without a consent record

I have built cold email infrastructure for 200+ businesses, and the Saudi consent record is the piece that is almost never there. Send me your sequence and your list source, and I will tell you which of your Gulf contacts you can actually evidence consent for, and what to change before the next send.

Book a 30-Minute Call

Or email [email protected].