Picture a Riyadh marketing team preparing a campaign. One list comes from the online store, one from an exhibition scanner, one from old sales enquiries and another from WhatsApp conversations. The CRM marks most records “contactable,” so the campaign appears ready. Then somebody asks a basic question: what exactly did each person agree to receive? Saudi PDPL direct marketing turns that question into an operating requirement, not a wording exercise for the privacy page.
A single opt-in field is too weak. It does not show the purpose explained, the source of the data, the channel covered, the time and method of agreement, or whether the person later withdrew. It also rarely reaches every campaign tool, agency file and sales phone before the next send.
The practical answer is a consent ledger: one reviewable record that connects permission to purpose and makes withdrawal executable everywhere. This is not legal advice, and sector-specific requirements may add constraints. It is the operating shape executives should demand from marketing, technology, privacy and their processors.
Saudi PDPL direct marketing starts with provable purpose
The official Personal Data Protection Law says personal data may be processed for marketing, except sensitive data, when it was collected directly from the person and they agreed in accordance with the law. The Implementing Regulation makes the operating detail clearer. Consent should be freely given, tied to clear and specific purposes, separately obtained for each purpose and documented so it can be verified later.
That means “customer,” “lead” and “contactable” are not permission states. They are CRM labels. A person who requested a delivery update has not automatically agreed to a promotional sequence. A badge scan proves attendance, not the purpose described at the scanner. A historic purchase proves a transaction. The marketing team still needs to establish the applicable permission and other requirements before using the record for a new purpose.
1. Separate identity from permission
Start with the person or contact point, but do not attach one permanent marketing truth to it. The same phone number may have several relationships: customer, business buyer, event attendee and service contact. Permission can differ by brand, purpose and channel.
SDAIA's guide for controllers and processors uses a retail phone number as a direct example of personal data even when the store does not hold the person's name. The operational lesson is blunt: a list does not become anonymous because the campaign platform shows only numbers.
2. Give every consent record five fields
A usable ledger does not need to be elaborate. It needs to answer five questions without reconstructing a campaign from screenshots:
- Subject: which person or contact point does this state apply to?
- Source: where and when was the data collected?
- Purpose: what specific marketing use was explained?
- Proof: what wording, action, time, language and channel show the agreement?
- State: is permission active, withdrawn, disputed, expired by policy or unavailable?
Store the notice or form version, not only a boolean. If wording changes, the business can see which records were collected under which promise. Keep the original source even after systems merge records. Otherwise a clean customer profile can hide a dirty permission history.
This extends the argument in the field note on first-party data strategy: permission is part of the asset. More identifiers without a traceable job create exposure, not understanding.
3. Make withdrawal a system event
The Saudi regulation requires a way to stop marketing that is as easy as the way consent was obtained, clear sender identity, and a stop without undue delay after withdrawal. The difficult part is not putting an unsubscribe link in an email. It is making one decision propagate across email, SMS, WhatsApp, call lists, ad audiences, CRM tasks and files already sent to processors.
Create one suppression event with a timestamp, source and scope. Apply it before campaign selection, not after message generation. Confirm downstream tools have accepted it. If a processor or agency receives audiences in batches, define how removals reach old files and how completion is evidenced. The Controller still needs visibility; outsourcing delivery does not make the customer's choice somebody else's operating problem.
The Communications, Space and Technology Commission's anti-spam regulations are a useful reminder that telecom requirements sit beside data protection. A PDPL workflow should route channel and sector questions to the right legal owner instead of assuming one consent design answers every rule.
4. Keep service messages out of the marketing shortcut
Order updates, security alerts, requested quotes and promotions have different purposes. Teams create risk when they hide an offer inside a service notification because the service channel has higher reach. Classify templates before activation. State the purpose, required data, lawful basis or consent evidence, channel, owner and suppression behaviour.
The existing note on CRM and WhatsApp integration explains why conversation context must reach the customer record. Add permission context to that handoff. A salesperson should not have to remember that a customer opted out in another platform, and a bot should not infer marketing permission from a friendly reply.
Run the proof before the campaign
Take one planned Saudi campaign and sample records from every source. For each record, ask:
- Can we show the collection source and the exact purpose presented?
- Can we verify the consent action, time, method and notice version?
- Does the selected channel fit that recorded state?
- Would a withdrawal now stop every downstream send?
- Can the sender and responsible business be identified clearly?
Do not repair missing evidence by labelling the whole database opted in. Move uncertain records into a review or re-permission path designed with legal counsel. Delete or restrict data when required by the applicable policy and law. The objective is not the largest send. It is a list the business can explain.
Good marketing automation connects a customer signal to an owned action and returns the outcome. For Saudi PDPL direct marketing, consent and withdrawal are signals with veto power. They must travel faster than the campaign.
The decisive test is simple. If a customer says stop in one channel today, can the business prevent tomorrow's message from every other channel and show why? If not, the organisation does not have consent management. It has scattered checkboxes and hope.