Saudi Arabia's regulatory environment for payment collection and billing has changed substantially in the past three years. The ZATCA Fatoora e-invoicing mandate, the PDPL data protection framework that came into effect in 2023, and SAMA's evolving payment system regulations collectively create a compliance surface that small and mid-size businesses cannot safely ignore. Getting these wrong is not just a regulatory exposure. It creates operational and legal risk that compounds as your client base grows.
What follows is a practical overview of the three compliance areas that matter most for a Saudi business running a billing and collections operation, with specific attention to what each requirement actually means for day-to-day practice.
ZATCA E-Invoicing: The Fatoora Requirements
ZATCA's Fatoora e-invoicing programme rolled out in two phases. Phase 1, which took effect in December 2021, required all VAT-registered businesses to generate electronic invoices rather than paper or Word/PDF invoices. Phase 2, beginning in January 2023 for the first wave of large taxpayers and continuing in waves through 2024 and beyond, requires integration with ZATCA's portal for invoice reporting.
For a small or mid-size business, the immediately relevant question is which phase applies to you and what it requires. Phase 1 compliance means generating invoices in a format that meets ZATCA's technical specifications: each invoice must include a UUID (a unique identifier generated at invoice creation), a QR code containing specified metadata, a digital hash for integrity verification, and the issuer's VAT registration number. The invoice must also carry the required fields: buyer and seller details, item descriptions, taxable amounts, VAT rate, and VAT amount calculated correctly.
A common misconception is that issuing a PDF invoice sent by email satisfies Phase 1. It does not, unless that PDF was generated by a system that assigns a UUID, produces the QR code, and retains the required XML representation. A PDF exported from a word processor does not meet the standard regardless of how it is formatted or delivered.
Phase 2 introduces the CSID (Cryptographic Stamp Identifier) mechanism and requires integration with ZATCA's portal. For Phase 2 taxpayers, invoices are submitted to ZATCA in near real-time, cleared, and stamped before delivery to the buyer. The threshold for Phase 2 has been progressively lower with each wave. Businesses should verify their current status with a ZATCA-registered solution provider rather than assuming their size places them outside Phase 2 scope.
VAT Invoice Requirements for Common Billing Scenarios
Saudi VAT at the standard rate of 15 percent applies to most taxable supplies. For a billing and collections operation, the invoicing requirement depends on the nature of the supply and whether the buyer is a VAT-registered business or a non-registered consumer.
For B2B supplies where the buyer is VAT-registered, you issue a full tax invoice. For B2C supplies or supplies below the simplified invoice threshold, a simplified invoice may be used. Schools issuing tuition invoices face a specific question: educational services have had VAT treatment changes over time, and the current position should be verified with a licensed tax adviser rather than assumed from earlier guidance.
For subscriptions and recurring services, each invoice in the series must independently meet the full tax invoice requirements. A subscription covering a 12-month term does not allow one compliant invoice to cover the year. Each monthly or quarterly invoice must be individually compliant, with its own UUID and QR code.
Credit notes, which are issued when an invoice amount needs to be adjusted downward after issuance, have their own requirements under ZATCA. A credit note must reference the original invoice number, include the original UUID, and meet the same technical standards as the original invoice. Teams that issue credit notes through a word processor and send them by email are not issuing compliant credit notes.
PDPL Data Handling Requirements
The Saudi Personal Data Protection Law (PDPL), enforced by the Saudi Data and Artificial Intelligence Authority (SDAIA), applies to any processing of personal data about Saudi residents or data processed within the Kingdom. For a billing and collections operation, the personal data you collect and process includes payment information, contact details, and financial account information that constitutes sensitive personal data under the PDPL definition.
The PDPL's core obligations for a billing system operator include: collecting personal data only for specified, explicit purposes; retaining data for no longer than necessary to fulfil those purposes; implementing appropriate technical and organisational security measures; and obtaining explicit consent where the processing cannot be based on a legitimate contractual or legal basis.
For most B2B billing relationships, the processing of client payment data is justified by the contract between the parties. You need the client's IBAN to issue a payment instruction. You need their contact details to deliver invoices. These are contract-performance purposes, not consent-dependent purposes. However, if you use billing contact details for marketing, that processing may require separate consent.
Data retention is the most commonly overlooked PDPL obligation in billing contexts. Saudi accounting regulations require retention of financial records for specific periods, which creates a legitimate basis for retaining invoice data. But payment contact details for a former client, stored for marketing or re-engagement purposes without a legal basis, do not benefit from the accounting retention period. Billing systems should have documented data retention policies that distinguish between the financial record (retained for compliance purposes) and the operational contact data (retained only as long as the client relationship is active).
SAMA Regulations and Payment System Compliance
The Saudi Arabian Monetary Authority (SAMA) regulates payment services and payment processing in the Kingdom. For businesses that collect payments through licensed payment service providers, SAMA's regulatory requirements are largely discharged by the PSP's own licensing and compliance obligations. However, businesses that build direct integrations to payment rails, or that store or transmit payment card or bank account data, have their own compliance obligations.
For a billing operation using IBAN bank transfer as the primary collection channel, the primary SAMA-adjacent compliance consideration is the security and handling of banking credentials. Storing client IBAN details in an unencrypted spreadsheet or in an email inbox is a data security exposure that is inconsistent with the PDPL's security requirements and with the general principles SAMA expects of entities processing financial data.
For businesses that want to accept Mada card payments or enable SADAD payment links, integration must go through a SAMA-licensed payment aggregator or PSP. The licensing chain matters: a business that receives Mada payment instructions and passes them to an unlicensed intermediary is not compliant regardless of the intermediary's informal arrangements. Verifying that your payment processing chain runs through licensed entities is a table-stakes compliance check for any Saudi fintech-adjacent billing operation.
What "Compliant Collection Practices" Means in Practice
Beyond the formal regulatory frameworks, compliant payment collection in Saudi Arabia involves practical considerations around the dunning and escalation process. There is no Saudi equivalent of the US FDCPA (Fair Debt Collection Practices Act) for B2B collections, but the general principles of contractual obligation and good faith apply. Collection notices that make false or misleading statements about the consequences of non-payment, or that harass rather than inform, create legal exposure under Saudi contract law and, in some cases, under communications regulations.
A practical compliance standard for reminder sequences is straightforward: state amounts accurately, reference the correct invoice, accurately describe any contractual late fee provisions before applying them, and do not imply legal action you are not prepared to take. Compliance in this area is largely about accuracy and good faith rather than adherence to a specific regulatory checklist.
We want to be clear that this article is a practical orientation, not legal advice. For businesses with significant receivables volumes, specific industry VAT questions, or PDPL obligations that extend into sensitive data categories, the right approach is a consultation with a licensed tax adviser and a legal practitioner with experience in Saudi data protection law. The compliance landscape has moved quickly in the past three years, and the cost of getting it wrong has risen with it.