Saudi Arabia Outbound Calling Compliance: CST (2026)
Saudi outbound calling rules in 2026: CST duties, PDPL opt-in consent, caller identification, recording limits and the fines.
Quick answer
Outbound calling into Saudi Arabia is regulated by the Communications, Space & Technology Commission (CST), formerly CITC, with personal data supervised separately by SDAIA under the Personal Data Protection Law. The consent model is prior opt-in and that consent must be documented so it can be verified later; the opt-out runs at the sender rather than through a national register, because no national Do Not Call list appears in the published Saudi instruments. There is no published permitted-hours rule for outbound voice calls: the 22:00 to 07:00 prohibition usually quoted sits in the anti-spam regulation, whose definition of an electronic message expressly excludes voice calls.
Saudi Arabia is the Gulf market whose outbound rules are most often misquoted. This guide states only what the Act, its regulations and the PDPL actually say, and marks the gaps as gaps.
Saudi outbound compliance at a glance
| Item | Position |
|---|---|
| Regulator | Communications, Space & Technology Commission, CST (هيئة الاتصالات والفضاء والتقنية), renamed from CITC on 10 November 2022. Data protection sits with SDAIA |
| Law and date | Telecommunications and IT Act, Royal Decree M/106 of 02/11/1443H, with Implementing Regulations of November 2022; Bylaws Article 55.9; Regulation for Reduction of SPAM |
| Licence needed | Not published. CST's register shows no telemarketing-specific licence; confirm with CST before launch. Practising a licensable activity without one breaches Act Article Twenty-Six(2), and call-centre services are a regulated CST category (RS14) |
| Calling hours | Not published for voice. The 22:00 to 07:00 rule covers electronic messages, whose definition excludes voice calls. Saudi Arabia runs one zone at UTC+03:00, no daylight saving (secondary source for the offset) |
| Consent model | Prior opt-in, PDPL Articles 25 and 26. Implementing Regulation Article 11 requires documented, purpose-separated consent |
| Do Not Call list | Not published. No national register found; the duty is a free, easy stop mechanism at the sender, plus an operator block for messages |
| Caller ID rule | Bylaws Article 55.9(a): disclose at the start of the call the provider the call is made for, and its purpose. Implementing Regulation Articles 28 and 29: do not hide the sender's identity |
| Recording rule | Act Article Thirty-Two: calls over public networks are confidential and may not be recorded except in cases set out in the regulations. No mandatory recording or retention period published |
| Data protection law | Personal Data Protection Law, Royal Decree M/19 as amended by M/148. In force 14 September 2023, compliance deadline 14 September 2024 (secondary source for the Gregorian dates) |
| Penalties | Act Article Twenty-Seven: up to SAR 25 million, service cessation, a licensing bar or platform blocking. PDPL Article 36: up to SAR 5 million, doubled on repetition; Article 35: up to SAR 3 million and two years for sensitive-data offences |
Who regulates outbound calling in Saudi Arabia
CST regulates the telecommunications and IT sector. It was renamed from the Communications and Information Technology Commission on 10 November 2022 by Cabinet decree No. 235. Many operators still say CITC; the current name is CST.
Article 79(1)(f) of the Implementing Regulations empowers CST to issue user-rights protection rules that include telecommunications marketing controls. Those were issued as document RC05, decision 552/1445 of 08-02-2024, whose text could not be retrieved at the time of writing. RC05 is the most likely home for any Saudi calling-hours rule, do-not-call duty or marketing number rule, so request it from CST and do not assume its contents. SDAIA is the data protection regulator, and PDPL Article 42 has its regulations issued after coordination with CST.
Consent and opt-out
PDPL Article 25 is the operative rule: a controller may not use a data subject's personal means of communication to send advertising or awareness-raising material without prior consent and a clear mechanism letting the recipient stop receiving it. Article 26 adds that personal data may be processed for marketing only if collected directly from the data subject with consent. Sensitive data may never be processed for marketing.
The Implementing Regulation says how consent must look. Article 11: consent may be written, verbal or electronic, must be freely given and purpose-specific, and must be documented so it can be verified later, with a separate consent per purpose. Article 28 requires consent where there was no prior interaction, and material evidence of it. Article 29 requires a stop mechanism as simple as the process used to obtain the consent, and Article 12 makes withdrawal available at any time.
No maximum validity or expiry period for marketing consent exists in Saudi law. The PDPL, its Implementing Regulation, the Transfer Regulation, the anti-spam regulation and the Act were all read, and none sets a term.
Do Not Call
No national Do Not Call register appears in the published Saudi instruments. That is an absence of evidence rather than proof of absence: RC05, the one instrument empowered to carry marketing controls, could not be read.
What is established is an opt-out at the sender. PDPL Article 25(2) and Implementing Regulation Articles 28 and 29 require each sender to run a free, easy stop mechanism and to halt sending immediately on request. Operators must separately offer a free network-level block for messages, and a recipient may complain to the regulator within thirty days of receiving spam.
Calling hours and days
There is no published permitted-hours rule for outbound voice telemarketing. The Act, both generations of its implementing regulations, the anti-spam regulation and the CST regulations register were all searched.
The rule usually quoted as a Saudi calling window belongs to a different channel. The anti-spam regulation prohibits sending electronic messages from 22:00 to 07:00 without the recipient's consent to receive them then, and the same instrument defines an electronic message so as to exclude voice calls. The curfew binds messaging, not calls. It states clock times without naming a time zone; Saudi Arabia runs a single zone at UTC+03:00 with no daylight saving, a general fact rather than a quotation. No weekend or holiday rule was found.
Caller ID and number presentation
Telecom Act Bylaws Article 55.9 is the closest thing Saudi Arabia has to a telemarketing script rule. The service provider must disclose at the beginning of the call the identity of the provider it is made for and the purpose of the call, and during the call the full price of any product or service discussed and the contacted person's absolute right to cancel a purchase or lease within 72 hours, by calling a specific number given during the call. Article 55.10 lets CST prohibit or regulate outright the use of a network for telemarketing.
Implementing Regulation Article 28(3)(a) requires the sender's name to be mentioned clearly without hiding its identity, and Article 29(2) requires the same for direct marketing material. Anti-spoofing duties sit on operators rather than marketers. Not published: any requirement that marketing calls come from a dedicated or registered number range, any rule on withheld or anonymous CLI, and any registered sender-ID regime for marketing SMS.
Call recording and notices
Saudi Arabia starts from a prohibition, not a permission. Act Article Thirty-Two: calls and information sent over public telecommunications networks are confidential and may not be reviewed, listened to or recorded except in the cases set out in the regulations. Implementing Regulations Article 58(3) adds that providers may not collect, process or disclose a user's communications without consent, except as the laws permit.
A recording is also personal data, since the PDPL's definition of publishing expressly covers audio. Not published: any mandatory recording duty, minimum retention period, or prescribed recording notice script.
Messaging rules for SMS and WhatsApp
Messaging carries the tighter published rules. The anti-spam regulation permits sending after prior consent, or where a prior relationship exists such as a purchase from the sender. Each message must carry the sender's electronic address, name and subject so the recipient can unsubscribe free and easily, and that contact information must stay usable for at least thirty days. Sending must stop within 48 hours of an unsubscribe request, a confirmation must follow, and records are kept six months after it. The 22:00 to 07:00 prohibition applies here.
Data protection and retention
The PDPL was issued by Royal Decree M/19 and amended by M/148. Article 43 brings it into force 720 days after publication in the Official Gazette. Per DLA Piper, that maps to entry into force on 14 September 2023 with a compliance deadline of 14 September 2024 for most entities.
Cross-border transfer runs under the Regulation on Personal Data Transfer Outside the Kingdom, Version 2.0 of August 2024. It permits appropriate safeguards, standard contractual clauses issued in a standard form by the competent authority, and binding common rules for groups. If your dialler, recordings or CRM sit outside the Kingdom, that is the instrument to paper against.
The PDPL sets no fixed retention period for marketing data; the constraints are purpose limitation and the destruction right. Two hard numbers sit nearby: anti-spam records kept six months after an unsubscribe request, and Bylaws Article 55.4 requiring user invoices kept six months from issuance.
Penalties and enforcement
Two separate tracks, and they should not be mixed. Under the Telecommunications and IT Act, Article Twenty-Seven(1) allows one or more of a fine not exceeding SAR 25 million, ceasing the service in full or in part, barring the offender from obtaining or renewing a licence, and blocking a digital content platform. Penalties must be proportionate and the offender must hand over the proceeds. Anti-spam breaches route into this regime rather than carrying their own tariff.
Under the PDPL, Article 36 sets a warning or a fine not exceeding SAR 5 million, doubled on repetition up to twice that limit. Article 35 sets up to two years' imprisonment or a fine not exceeding SAR 3 million, or both, for intentionally disclosing or publishing sensitive data to harm the data subject or gain a benefit. Both statutes are per violation with a repeat-offence multiplier, neither carries per-day accrual, and no published fine tariff by violation type was found.
What changed in 2025 and 2026
The instruments that moved are dated 2024 and remain current at the latest capture from February 2026: CST decisions 515/1445 on SMS and 552/1445 on user rights protection, both 08-02-2024, and SDAIA's Transfer Regulation Version 2.0 of August 2024. Per DLA Piper, as of February 2026 the PDPL is being actively enforced by SDAIA. No 2025 or 2026 CST rule or consultation specifically on promotional calls, marketing number prefixes or a do-not-call register was found.
How DialerBee supports each rule
DialerBee ships a KSA CITC jurisdiction pack, so the rules configured for the Kingdom apply to every call placed under it. Compliance Autopilot checks each attempt against the DNC list, the calling-hours window for its jurisdiction, the consent record, the caller ID's ownership, the frequency limit and the phone format before the call is placed. Because Saudi Arabia publishes no voice calling window, the window you set is your own policy, and enforcing it in the platform makes it the same window on every campaign, with a record of what was in force.
Consent is tracked per contact with its source, timestamp and channel, which is what Implementing Regulation Article 11 asks for, and suppression carries across campaigns. Caller-ID pool control governs which number each campaign presents. Recording carries configurable retention per campaign and per tenant plus legal hold, which matters where recording is prohibited unless a basis exists. Scripts run in 11 languages including Arabic, so the identity disclosure and the 72-hour cancellation notice reach the recipient in their own language. These are compliance-supporting controls that help you meet your obligations; they do not replace legal review.
Saudi outbound compliance checklist
- Request CST document RC05 directly and read it before writing internal calling policy.
- Collect marketing consent directly from the data subject, never from a bought list, and log its time and means with a separate consent per purpose.
- Build the withdrawal mechanism before you ask for consent, make stopping as easy as opting in, and halt on request free of charge.
- Open every call by naming the party it is made for and the purpose of the call.
- State the full price during the call, and give the 72-hour cancellation right and the number for it.
- Keep outbound voice inside a conservative daytime window you have confirmed with CST.
- Keep marketing messages outside 22:00 to 07:00 and keep the sender contact live for thirty days.
- Document a lawful basis before recording any call, and paper every transfer abroad against the August 2024 Transfer Regulation.
- Keep anti-spam consent and unsubscribe records for six months after the request.
- Attribute fines to the right statute: SAR 25 million is the Telecom Act, SAR 5 million is the PDPL.
Sources
- Telecommunication and Information Technology Act, Royal Decree M/106 of 02/11/1443H (CST, archived). web.archive.org
- Bylaws of the Telecommunications Act, Decision No. 11 of 17/05/1423H as amended, Article 55.9 (CST, archived). web.archive.org
- Regulation for Reduction of SPAM (CITC, archived). web.archive.org
- CST register entry, RC05 Regulations of User Rights Protection Rules, decision 552/1445, 08-02-2024. web.archive.org
- Personal Data Protection Law, Royal Decree M/19 as amended by M/148 (SDAIA). sdaia.gov.sa
- Implementing Regulation of the PDPL (SDAIA). sdaia.gov.sa
- Regulation on Personal Data Transfer Outside the Kingdom, Version 2.0, August 2024 (SDAIA). sdaia.gov.sa
- DLA Piper, Data Protection Laws of the World, Saudi Arabia, accessed 11 September 2026 (secondary source for the Gregorian dates and enforcement posture). dlapiperdataprotection.com
Frequently asked questions
Who regulates outbound calling in Saudi Arabia?
The Communications, Space & Technology Commission, CST, renamed from CITC on 10 November 2022. Personal data is supervised separately by SDAIA under the Personal Data Protection Law, and the two regimes interlock: the PDPL has its regulations issued after coordination with CST.
What are the permitted calling hours in Saudi Arabia?
No permitted-hours rule for outbound voice calls is published. The 22:00 to 07:00 prohibition usually quoted as a Saudi calling window comes from the anti-spam regulation, which defines an electronic message so as to exclude voice calls. Set a conservative daytime window as policy and confirm it with CST.
Do I need consent to make marketing calls in Saudi Arabia?
Yes. PDPL Article 25 forbids using a person's personal means of communication to send advertising material without prior consent and requires a clear stop mechanism. Article 26 allows processing for marketing only where the data was collected directly from the data subject with consent.
Does Saudi Arabia have a national Do Not Call register?
No national register appears in the published instruments, but that is an absence of evidence rather than proof of absence, because CST document RC05 could not be read. What is established is a sender-side duty: a free, easy stop mechanism, sending halted immediately on request, plus an operator block for messages.
Is call recording allowed in Saudi Arabia?
Recording starts from a prohibition. Act Article Thirty-Two makes calls over public networks confidential and bars recording them except in cases set out in the regulations, and a recording is also personal data under the PDPL. Document a lawful basis before you record; no retention period is published.
What is the 72-hour rule in Saudi telemarketing?
Telecom Act Bylaws Article 55.9(d) requires the caller to disclose during the call the contacted person's absolute right to cancel a purchase or lease of any service within 72 hours, by calling a specific number given during the call. The same article requires the caller to identify the party the call is made for, state its purpose and give the full price.
What fines apply in Saudi Arabia?
They come from two different statutes. The Telecommunications and IT Act allows up to SAR 25 million plus service cessation, a licensing bar or platform blocking. The PDPL allows up to SAR 5 million for general violations, doubled on repetition, and up to SAR 3 million with two years' imprisonment for sensitive-data offences. Do not attribute a Telecom Act figure to the PDPL.
Related reading
- Saudi Arabia outbound dialer overview
- Compliance Autopilot
- Caller-ID pool control
- MENA compliance guide
This article is for general informational purposes and is not legal advice. CST document RC05, the instrument empowered to carry telecommunications marketing controls, could not be retrieved at the time of writing. Confirm current requirements with CST, SDAIA and qualified local counsel.
Related articles
Ready to see DialerBee in action?
Book a 15-minute live demo, or start a free trial and dial today — no slides, no commitment.
14-day free trial · no credit card · 11 languages · BYOC · compliance-supporting controls