Compliance July 31, 2026 12 min read

Saudi Arabia Outbound Calling Compliance: CITC Rules (2026)

A 2026 guide to outbound calling compliance in Saudi Arabia: CITC rules, consent, calling hours, caller ID, recording, Arabic disclosures, and PDPL data protection.

D
DialerBee Team
July 31, 2026

Quick answer

Outbound calling in Saudi Arabia is governed by the telecom regulator CITC (now often styled CST) plus the Personal Data Protection Law (PDPL) overseen by SDAIA. In practice this means obtaining consent for marketing calls, respecting calling-hour and do-not-disturb norms, presenting truthful caller ID, avoiding commercial concealment, disclosing recording, communicating in Arabic, and protecting personal data.

Saudi Arabia has become one of the most attractive — and most closely regulated — markets for outbound contact centers in the Middle East. Rapid digital adoption, a large mobile-first population, and Vision 2030 investment have created strong demand for outbound calling across banking, telecom, collections, government services, and business process outsourcing (BPO). At the same time, Saudi authorities have steadily tightened the rules around unsolicited marketing calls, caller identification, data protection, and consumer nuisance. For any operator running outbound campaigns into the Kingdom, understanding this framework is now a prerequisite, not an optional extra.

This guide walks through the main compliance categories that outbound teams need to think about when calling Saudi consumers and businesses in 2026: who regulates the space, how consent works for marketing calls, calling-hour and do-not-disturb expectations, anti-spam and anti-commercial-concealment considerations, caller-ID requirements, call recording, Arabic-language disclosures, and data protection under the PDPL. It closes with how a compliance-supporting multilingual dialer helps operators keep campaigns clean. If you also serve neighboring markets, pair this with our broader MENA compliance guide and our Saudi Arabia region page.

Who Regulates Outbound Calling in Saudi Arabia?

Two bodies matter most for outbound operations.

CITC / CST — the telecom and ICT regulator. The Communications, Space & Technology Commission (CST) — formerly the Communications and Information Technology Commission (CITC) — is the primary regulator of telecommunications and information technology services in Saudi Arabia. It oversees telecom licensing, consumer protection in communications services, numbering, and rules addressing unsolicited and nuisance calls. Many operators and search users still refer to it as "CITC," which remains the commonly recognized term, but you will increasingly see "CST" in official materials. CITC has been active in curbing spam calls and messages and in requiring accurate identification of the party behind marketing communications.

SDAIA — the data protection authority. Saudi Arabia's Personal Data Protection Law (PDPL) is administered by the Saudi Data & AI Authority (SDAIA). The PDPL sets out how organizations may collect, process, store, and transfer personal data — including phone numbers and call records — and it applies squarely to outbound calling operations that handle contact lists and recordings.

Beyond these two, sector regulators can layer on additional expectations. For example, financial institutions, debt-collection activities, and licensed telecom resellers may face supervisory rules from their own regulators on top of the CITC and PDPL baseline. Always confirm which sector rules apply to your specific use case.

Consent and Opt-In for Marketing Calls

The clearest theme in Saudi outbound regulation is consent. Marketing and promotional calls are generally expected to rest on the recipient's prior consent, and that consent should be informed, specific, and capable of being withdrawn. In practice this means an outbound team should be able to show where a contact's permission came from — a signed form, an app opt-in, a checkout consent, or a documented business relationship — rather than dialing a purchased or scraped list.

Several principles follow from this:

  • Consent should be documented. Keep a record of the source, timestamp, and scope of each contact's permission so it can be produced if challenged.
  • Opt-out must be honored. When a person asks not to be called again, that request should propagate to your suppression lists quickly and reliably.
  • Purpose limitation matters. Consent given for one purpose (say, service notifications) does not automatically cover unrelated marketing.
  • Existing-relationship exceptions are narrow. Even where an ongoing business relationship exists, do not assume it authorizes unlimited promotional outreach.

Because the precise boundaries of what counts as valid consent — and any exemptions — can change, treat the above as categories to build into your process and confirm the current definitions with CITC/SDAIA and local counsel before launching a campaign.

Calling Hours and Do-Not-Disturb Norms

Outbound teams are generally expected to respect reasonable calling windows and to avoid contacting people at times likely to cause nuisance — for example, late at night, very early in the morning, and during recognized rest days and religious observances. Saudi consumers are protected against harassment and excessive repeat calling, so operators should also cap call frequency per contact and avoid aggressive redialing after non-answers.

We deliberately do not publish specific permitted-hour times here, because those norms are set and updated by the regulator and can differ by campaign type. The safe operating posture is to configure conservative calling windows in your dialer, apply local Saudi time zone logic, pause on public holidays and religious dates, and confirm the currently required windows with CITC before scaling.

Anti-Spam and Anti-Commercial-Concealment

CITC has prioritized reducing spam and deceptive commercial communications. Two connected ideas are important for outbound teams:

Anti-spam. Unsolicited bulk marketing calls — particularly high-volume automated dialing without consent — attract regulatory attention and consumer complaints. Volume alone can flag a campaign as abusive even if each individual call seems benign.

Anti-commercial-concealment. This principle targets the practice of hiding or misrepresenting who is actually behind a commercial activity or communication. For outbound, the takeaway is transparency: callers should clearly identify the real organization on whose behalf they are calling and the purpose of the call, rather than masking it behind a generic script or a misleading brand. Concealing the true commercial party — or fronting for an unlicensed entity — is exactly the kind of behavior regulators want to eliminate.

Caller-ID Requirements

Truthful caller identification is central to Saudi consumer protection. The general expectation is that outbound calls present accurate, non-deceptive caller ID so recipients can see who is contacting them. Spoofing, disguising, or falsifying the calling number — and using numbers that impersonate legitimate institutions — is the type of conduct regulators actively pursue.

Practically, operators should use registered, correctly provisioned numbers from their carrier, avoid any form of number manipulation intended to mislead, and ensure that the displayed identity matches the actual calling organization. Where a distinct marketing line or verified business identity is available through your carrier, using it helps both compliance and answer rates.

Call Recording

Call recording is common and often operationally valuable in Saudi contact centers — for quality assurance, dispute resolution, and demonstrating what was said and agreed. However, recording captures personal data and therefore intersects with the PDPL. The prudent approach is to disclose that a call may be recorded, capture the caller's acknowledgment where appropriate, store recordings securely with access controls, retain them only as long as there is a lawful and documented reason, and be able to fulfill data-subject rights over that content.

As with other areas, do not assume a single blanket rule; confirm the current disclosure and retention expectations for your sector.

Arabic-Language Disclosures

Arabic is the official language of Saudi Arabia, and consumer-facing communications are generally expected to be available and intelligible in Arabic. For outbound calling this has real operational weight: consent language, recording disclosures, opt-out instructions, and the core purpose of the call should be communicable in clear Modern Standard Arabic (and ideally in the dialects your audience actually uses). Relying solely on English scripts or machine-translated prompts risks both non-comprehension and a weaker compliance position. Right-to-left (RTL) rendering also matters for any on-screen agent scripts, SMS follow-ups, and written disclosures. Our Arabic and RTL support is built for exactly this.

Data Protection Under the PDPL

The PDPL, administered by SDAIA, is the backbone of data compliance for outbound operations. Contact lists, dialing outcomes, notes, and recordings are all personal data. Core PDPL-aligned practices for an outbound team include:

  • Lawful basis and transparency — process personal data on a valid basis and be clear with individuals about how their data is used.
  • Data-subject rights — be able to respond to access, correction, and deletion requests, including for recordings.
  • Minimization and retention — collect only what you need and keep it only as long as justified.
  • Security — protect data with access controls, encryption where appropriate, and audit trails.
  • Cross-border transfer care — moving Saudi personal data outside the Kingdom, including to cloud infrastructure, is subject to specific safeguards; confirm the current transfer requirements before doing so.

Saudi Outbound Compliance at a Glance

Compliance areaWhat to consider
RegulatorCITC / CST for telecom conduct; SDAIA for PDPL data protection
ConsentDocumented, informed, purpose-limited opt-in for marketing; honor opt-out
Calling hoursConservative local windows; pause on holidays and observances; cap frequency
Anti-spam / concealmentNo abusive bulk dialing; identify the true commercial party and purpose
Caller IDAccurate, registered numbers; no spoofing or impersonation
RecordingDisclose, secure, retain lawfully; treat recordings as personal data
LanguageClear Arabic disclosures and scripts; RTL rendering for text
Data protectionPDPL: lawful basis, minimization, rights, security, transfer safeguards

How DialerBee Supports Compliant Outbound in Saudi Arabia

DialerBee is built with compliance-supporting controls that map to the categories above — not as a guarantee of compliance, which no software can provide, but as tooling that helps operators run cleaner, more defensible campaigns. Configurable calling windows let teams enforce conservative local hours and pause on holidays and observances, while frequency caps limit repeat dialing to a single contact. Consent tracking records the source, scope, and timestamp of each contact's permission, and suppression handling propagates opt-outs across campaigns so do-not-call requests are respected. Truthful caller-ID handling works with your registered carrier numbers rather than encouraging any form of masking.

On language, DialerBee's language-aware AI supports 9 languages including full Arabic and RTL handling, so consent language, recording disclosures, and opt-out instructions can be delivered clearly in Arabic. Call recording is paired with secure storage and access controls, and detailed audit logs give compliance teams the evidence trail they need to respond to regulator or data-subject inquiries. These capabilities align with PDPL-oriented practices around minimization, security, and data-subject rights. In selected pilot conditions, operators using these controls have reported cleaner campaign hygiene and fewer nuisance complaints, though results vary by market and configuration. Explore the full feature set on our compliance features page, and see market-specific detail on the Saudi Arabia region page.

Frequently Asked Questions

Who regulates outbound calling in Saudi Arabia?

The telecom and ICT regulator is CITC — the Communications, Space & Technology Commission, formerly the Communications and Information Technology Commission and now often styled CST. Separately, the Personal Data Protection Law (PDPL), which governs how contact data and recordings are handled, is administered by SDAIA, the Saudi Data & AI Authority. Sector regulators may add further rules for banking, collections, or telecom resellers.

Do I need consent to make marketing calls in Saudi Arabia?

Marketing and promotional calls are generally expected to rest on the recipient's prior, informed consent, and that consent should be specific and withdrawable. You should be able to document where each contact's permission came from and honor opt-out requests promptly. Because definitions and any exemptions can change, confirm the current consent requirements with CITC and SDAIA and with qualified local counsel before launching campaigns.

What are the calling-hour rules in Saudi Arabia?

Outbound teams are generally expected to respect reasonable calling windows, avoid nuisance times such as late night and early morning, and pause during rest days and religious observances. We do not publish specific permitted times because they are set by the regulator and can differ by campaign type. The safe approach is to configure conservative windows using Saudi local time and confirm the current requirements with CITC.

Is call recording allowed in Saudi Arabia?

Call recording is common and operationally useful, but recordings are personal data and fall under the PDPL. The prudent approach is to disclose that calls may be recorded, store recordings securely with access controls, retain them only as long as there is a lawful documented reason, and be able to fulfill data-subject rights over that content. Confirm the current disclosure and retention expectations for your sector.

What is commercial concealment and why does it matter for outbound?

Anti-commercial-concealment principles target hiding or misrepresenting the real party behind a commercial activity or communication. For outbound calling, the takeaway is transparency: callers should clearly identify the true organization they are calling for and the purpose of the call, rather than masking it behind a generic or misleading script. Concealing the commercial party or fronting for an unlicensed entity is the kind of conduct regulators actively pursue.

How does DialerBee help with Saudi Arabia compliance?

DialerBee provides compliance-supporting controls — including configurable calling windows, frequency caps, consent tracking, opt-out suppression, truthful caller-ID handling, secure call recording, and detailed audit logs. Its language-aware AI supports 9 languages with full Arabic and RTL handling for clear disclosures. These features map to CITC and PDPL categories and give compliance teams a defensible evidence trail, but operators remain responsible for confirming current requirements.

This article is for general informational purposes and is not legal advice. Saudi regulations and their enforcement change — confirm current requirements with CITC (CST), SDAIA, and qualified local counsel.

Ready to see DialerBee in action?

15-minute live demo. No slides. No commitment.

Schedule a Demo