Skip to article
Compliance

Data residency in Saudi Arabia: what the PDPL asks when your cloud and AI tools run abroad

The PDPL lets personal data leave Saudi Arabia for listed purposes, with only the data needed and an adequate destination or an SDAIA safeguard. A practical guide to data residency in Saudi Arabia for Saudi and foreign companies whose cloud and AI tools handle Saudi residents' data.

Long data centre aisle between dark server racks with green and blue status lights; a technician checks cables far down it.
Illustration: the servers behind your cloud and AI tools may sit abroad, and the PDPL sets conditions for that.

Key takeaways

  • The PDPL sets conditions for sending personal data abroad rather than banning it, and the 2023 amendment removed the old requirement for SDAIA's approval.
  • Access counts: a team abroad that can open data stored in the Kingdom is a transfer under SDAIA's contract templates and risk guideline.
  • SDAIA had published no adequacy list on 29 September 2026, so a transfer needs an Article 4 exemption case, a safeguard (SCCs, binding common rules or a certificate) and a risk assessment.
  • Pick SDAIA's contract template by role; its text cannot be changed, and it is governed by Saudi law and courts, including for foreign importers.
  • Keep one inventory entry per tool: data, countries, purpose, route, safeguard, risk assessment and review date.
On this page
  1. Data residency in Saudi Arabia: the short answer
    1. Data localization in Saudi Arabia: where the rules come from
  2. Saudi company or foreign company: who these rules reach
  3. PDPL data transfer: a decision path in six questions
  4. SDAIA standard contractual clauses, binding common rules or a certificate: which safeguard to use
  5. The transfer risk assessment, as a worksheet
  6. Cloud and AI tools: ten questions for each provider
  7. A one-page inventory: tool, data, country, safeguard
  8. What to do in the next two weeks

Data residency in Saudi Arabia is conditional for most private companies. The Personal Data Protection Law (PDPL) lets a company send personal data abroad, or let someone abroad access it, for a purpose the law lists, without harm to national security and with only the data needed. The destination must also be assessed as adequate by the regulator, the Saudi Data & AI Authority (SDAIA); if not, the transfer must fit one of five exemption cases, each with a safeguard. Stricter hosting rules come from government and sector requirements.

This guide is for Saudi companies whose cloud and AI tools run abroad, and for companies in the Gulf and beyond that process data of people in the Kingdom.

This article is general information, not legal advice. Check your obligations against the current law and its regulations.

Data residency in Saudi Arabia: the short answer

What the law says. PDPL Article 29, as amended in 2023 by Royal Decree M/148, lets a controller (the party deciding why and how personal data is processed) transfer or disclose it abroad for listed purposes, on three conditions [1, Arts. 1(18), 29]:

  • no prejudice to national security or the Kingdom's vital interests;
  • adequate protection abroad, "according to the results of an assessment conducted by the Competent Authority";
  • no more than "the minimum amount of Personal Data needed".

Extreme necessity to protect a person's life or vital interests, or to prevent, examine or treat disease, is exempt [1, Art. 29(3)]. The amendment also dropped the original text's requirement for SDAIA's approval [2].

Data localization in Saudi Arabia: where the rules come from

No single Saudi data residency law covers private companies generally. The National Cybersecurity Authority's Cloud Cybersecurity Controls (CCC-2:2024) cover government bodies, private owners, operators and hosts of critical national infrastructure, and their cloud providers [3]. The 2024 version deleted the two subcontrols requiring cloud services, including storage, processing, disaster recovery, monitoring and support, to be provided from within the Kingdom, and refers entities to SDAIA's National Data Management Office on localisation [3, Annex D]. Some sectors add approvals, such as the Saudi Central Bank's in banking [4].

Saudi company or foreign company: who these rules reach

In the Kingdom, a foreign cloud, SaaS or AI tool holding customer or staff data means a transfer. You are usually the controller and the provider your processor [1, Art. 1(19)]; if it also uses your data for its own purposes, such as model training, it is a controller for that use. Choose processors "providing the necessary guarantees" and monitor them [1, Art. 8].

Outside the Kingdom, the law covers "the Processing of Personal Data related to individuals residing in the Kingdom by any means from any party outside the Kingdom" [1, Art. 2]. No Saudi office is needed.

If you are…Saudi law treats you as…Expect…
A foreign shop, app, recruiter or travel service collecting data from people in the KingdomA controllerController duties, including telling people at collection whether their data will be processed outside the Kingdom [1, Art. 13] and, per SDAIA's privacy-policy guideline, where it is stored [5]
A foreign SaaS, cloud or AI provider serving Saudi companiesA processor, and the "data importer" in SDAIA's clausesSDAIA's Template 2 and the processor terms below
A foreign company that uses a Saudi provider to process its dataThe controllerTemplate 4 (processor to controller) when data flows back to you

Registration. SDAIA's data governance platform has a route for entities outside the Kingdom (an active commercial registration and a representative authorised through the Ministry of Foreign Affairs) [6]. Registration rules for controllers outside the Kingdom "will be issued" [7]; we found none on 29 September 2026 [8].

Gulf readers: SDAIA's Regulation on Personal Data Transfer Outside the Kingdom (the Transfer Regulation) applies its country standards to "cities, special economic zones, and global trade centers" too, so a zone can be assessed apart from its country [9, Art. 3(4)].

PDPL data transfer: a decision path in six questions

Transfer includes access: SDAIA's templates cover "granting of access" [10] and its risk guideline "remote access" [11], so a Riyadh database that a support team abroad can open is in scope.

  1. Is personal data of people in the Kingdom stored, processed or viewed abroad? If not, the transfer rules don't apply to this flow; the rest of the PDPL still does.
  2. Are you a government body, a critical-infrastructure operator, or in a sector with its own data rules (such as banking)? Check those rules first; the questions below still apply.
  3. What is the purpose? Article 29 lists the Kingdom's agreements and interests, "an obligation to which the Data Subject is a party", and purposes set by the regulations [1]. The Transfer Regulation adds "central processing" operations, "a service or benefit" to the person, and scientific research [9, Art. 2]. If none fits, don't transfer.
  4. Can you send less? Minimum data is a condition [1, Art. 29(2)(c)]. Remove names and ID numbers where the purpose allows; SDAIA's clauses point to "encryption or de-identification" [10, Clause 11].
  5. Is the destination on SDAIA's adequacy list? SDAIA must publish one, reviewed "every four years, or as necessary" [9, Art. 3]; adequacy is its assessment, not yours [1, Art. 29(2)(b)]. On 29 September 2026 its regulations pages showed none [8]. If listed, send the minimum and record it; if not, go on.
  6. Which exemption case fits? Article 4 lifts the adequacy or minimum-data condition, or both, in five cases, each with a safeguard; the national-security condition stays [9, Art. 4(2)].
CaseIn plain wordsSafeguardSensitive data
APublic bodies: an agreement or the Kingdom's interestsData-protection terms in the agreementPublic bodies only; outside this guide
BOne-off or limited-period, about a limited number of peopleSDAIA's standard contractual clauses or a certified recipientExcluded (see note)
CCentral operations in a multinational groupBinding common rules, standard clauses or a certified recipientAllowed; risk assessment if continuous or large-scale (Art. 7)
DA service or benefit provided directly to the person, within their expectationsA certified recipientExcluded
EScientific research, minimum data onlyStandard clauses or a certified recipientExcluded (see note)

Note on cases B and E: the official Arabic text excludes sensitive data from the whole of both cases [12]; in case B, the English translation ties the exclusion to the certificate option only [9]. Rely on the Arabic. Sensitive data includes health, genetic and identifying biometric data, ethnic origin, religious and political belief, and security and criminal data [1, Art. 1(11)].

Where does an ordinary subscription fit? No case is written for a company subscribing to a foreign cloud or AI service: C needs a multinational group, D a certified recipient, B a limited transfer. Choosing a case is a legal judgement: note which one you rely on and why, have a lawyer check it, and file the note with your risk assessment. Meanwhile, narrow the question:

  • Ask whether the provider can store and process your data in the Kingdom; support access from abroad is still a transfer, but a narrower one, easier to limit and record [10; 11].
  • Prefer a recipient with an SDAIA accreditation certificate once certified entities are listed; it is an accepted safeguard in cases B to E [9, Art. 4(2)].

Record every transfer, "including the legal basis for the Transfer and recipient parties", in your record of processing activities [13, Art. 33(5)(g)]. If you fail to apply the safeguards, or SDAIA finds them inadequate, the exemption lapses: halt the transfer and notify the recipients [9, Art. 6].

Card: before data goes abroad: purpose, national security, minimum data, SDAIA's list, Art. 4 case, risk assessment, record.
Summary: key checks from the six-question decision path, ending with a record of each transfer's basis and recipients.

SDAIA standard contractual clauses, binding common rules or a certificate: which safeguard to use

SDAIA's standard contractual clauses (SCCs) are fixed contract terms that the exporter in the Kingdom and the importer abroad sign as a transfer safeguard [9, Arts. 1(4), 4(1)]. Version 1.0 (September 2024) has four templates; the parties keep the one that fits their roles and "delete those that do not apply" [10].

Personal data flows from……toTemplate
Your company in the KingdomA foreign cloud, SaaS or AI provider acting on your instructions2: Controller to Processor
Your company in the KingdomA foreign company using the data for its own purposes1: Controller to Controller
A Saudi processorIts sub-processor abroad3: Processor to Processor
A Saudi processorIts client abroad (the controller)4: Processor to Controller

What the importer signs up to [10]:

  • Fixed text. Only the blanks may be filled in; other changes "shall not be recognized by the Competent Authority", and extra terms must not contradict or weaken the clauses (Rules 4, 5).
  • Saudi law and courts. The importer submits to Saudi law and jurisdiction and cooperates with SDAIA's requests and audits (Rules 8 and 9; Clause 8).
  • Home-country law. No transfer if the importer's local laws block compliance (Rule 7).
  • Deadlines. The importer warns the exporter within 24 hours if it can't comply; transfers then stop, and it has 30 days, extendable by 30, to show compliance, or the parties agree to end the contract (Clause 12). Template 2 adds 24 hours for breach reports and 48 for relaying data subjects' requests (sections 6(D), 10(A)).
  • Onward transfers abroad go only to parties that have acceded to the clauses (Template 2, section 8).
  • At the end, data is destroyed or returned, and destruction documented (Template 2, section 5; Clause 12).
City towers with warm-lit windows under a deep blue dusk sky, above light trails, date palms and low sand-coloured houses.
Illustration: an importer abroad signing SDAIA's clauses submits to Saudi law and courts and cooperates with SDAIA's audits.

Binding common rules suit groups. They "must be approved internally by the authorized person within the Group of Entities", bind every member, and fall under Saudi law and courts [14]. The guideline describes no SDAIA pre-approval step.

An accreditation certificate is issued by an SDAIA-licensed body to a controller or processor "operating either within or outside the Kingdom" [15, Art. 1(3)]. Applicants must be in the National Register of Controllers; the licensee's evaluation takes up to 90 business days; certificates last two years; and holders abroad must report conflicting changes in their home rules or practices [15, Arts. 3, 6, 8, 9]. A certificate is an option in cases B to E and the only safeguard in D. SDAIA is to publish licensees and certified entities [15, Arts. 5, 13]; on 29 September 2026 we found neither list on its regulations pages or its data governance platform's public pages [8].

The transfer risk assessment, as a worksheet

A risk assessment is required before any Article 4 transfer and before sending sensitive data abroad "on a continuous or widespread basis", covering six elements [9, Art. 7]. SDAIA's February 2025 guideline, "not legally binding", explains the steps and offers a supporting tool [11].

Element (Art. 7(2))What to writeEvidence to keep
A. Purpose and legal basisWhy the tool needs the data; the Article 29 purpose; the Article 4 caseContract, privacy notice, lawyer's note
B. Nature and geographic scopeWhat the provider does; exact country and place (public or private cloud, headquarters) of storage, processing, backup and remote access; retention; onward disclosures [11]Provider's written statements
C. Safeguards and their adequacyTemplate, binding common rules or certificate (number, licensee, expiry)Signed clauses, appendices filled in
D. Minimum dataFields sent against fields needed; what is masked (skip if your Article 4 case lifts this condition)Field list
E. Possible material or moral effects, and their likelihoodHarm to the person, their family and friends, or the wider communityRating with reasons
F. Measures to prevent or reduce harmEncryption, access limits, deletion, audit rights, breach-notice timesSecurity appendix, audit clause
ResultGo, go with extra measures, or stopSign-off, date, next review

The guideline's last step: if risk stays high, with effects on people or the community that may not be reversible in the near term, "the controller should explore alternative methods", such as changing or dropping the processing [11].

Cloud and AI tools: ten questions for each provider

Your processor contract must cover the purpose, data categories, duration, breach notice "without undue delay", "whether the Processor is subject to Regulations in other countries", mandatory disclosures under Saudi law, and subcontractors; new sub-processors need your prior acceptance [13, Art. 17(1), (5)].

Send these in writing; questions 7 to 9 are our practical advice, the rest follow from the texts above. Providers abroad: expect these questions from Saudi customers, and keep written answers and Template 2 appendices ready.

  1. Where is our data stored, processed, backed up and accessed from, including by support staff?
  2. Which sub-processors do you use, and where? Will you tell us before adding one, including when a new AI feature sends our data to another provider or region?
  3. Could another country's laws force you to disclose our data?
  4. Will you sign SDAIA's Template 2 unchanged?
  5. Will you report breaches to us within 24 hours?
  6. When the contract ends, will you delete or return our data and confirm it in writing?
  7. AI: are prompts, files and outputs logged or stored? For how long, and where?
  8. AI: are they used to train or improve models, and can the contract exclude that?
  9. AI: can your staff read our content, and from where?
  10. Do you hold an SDAIA accreditation certificate? From which licensee, and until when?

Minimise before you send. Before AI summarises support tickets, remove names, ID and iqama (residence permit) numbers and phone numbers it doesn't need, and keep sensitive data out unless the risk assessment is done. New to AI? Start with one repetitive task. For customer-reply assistants, see our WhatsApp AI guide. Law firms also owe clients confidentiality; see AI for law firms in Saudi Arabia.

Say it plainly to your customers. The law requires you to tell people at collection whether their data will be processed outside the Kingdom [1, Art. 13]. State the main location, then the exceptions. O AI describes its own setup this way: "Core hosting (compute, database and files) is on Saudi-based cloud infrastructure inside the Kingdom. A small number of supporting services, such as AI processing and email delivery, can run outside the Kingdom; the privacy policies describe each flow."

A one-page inventory: tool, data, country, safeguard

One column per tool here; one row per tool in your own sheet, including free tools staff signed up for. The examples are hypothetical.

FieldRiyadh retailerDubai HR software companyAI ticket summariser
Tool and provider's roleCRM hosted in Europe; processorHR platform used by Saudi clients; their processor and data importerAI API summarising tickets in another region; processor
Personal data (sensitive?)Customer names, phones, purchases; noStaff records, iqama numbers; sick-leave notes can be health data (sensitive)Ticket text, pseudonymised; screen for health or ID details
Stored, processed, accessed fromEurope; support access from a third countryIts servers and sub-processorsProcessing and log regions, in writing
PurposeAn obligation the customer is party to (orders, delivery)Clients' HR operationsOperational processes (customer support)
Route and safeguardArticle 4 case, lawyer-checked; Template 2Template 2 with each client; Article 17 terms; consider a certificate; check registrationArticle 4 case, lawyer-checked; Template 2
Risk assessmentDone, datedSupports clients' assessmentsDone, dated
Record, owner, reviewRecord and privacy policy updated; IT lead; yearlySub-processor list shared; compliance lead; on every changeRecord updated; support manager; six-monthly
Cartoon: O-bot holds a checklist beside an open suitcase of glowing cyan cubes, before a lowered barrier at a border line.
Illustration: for each tool, note what data leaves, where it goes and which safeguard lets it cross.

Review each entry when a provider changes regions or sub-processors, and when SDAIA publishes its list; SDAIA may also revise each case's safeguards "every two years or as necessary" [9, Art. 4(4)]. Keep the record of processing for five years after the processing ends [13, Art. 33(1)].

What to do in the next two weeks

  1. List every tool that touches personal data, including chat, AI and backups.
  2. Fill in an inventory entry for each, and send the ten questions to each provider abroad.
  3. Choose a route and safeguard for each tool, and have a lawyer check the choice.
  4. Run the risk assessment where required, then update your record of processing and privacy policy.

Buying new software? Add questions 1 to 6 to the brief in our build-or-buy guide.

O AI is a Saudi AI and software company in Al Khobar. Not sure which of your tools send personal data abroad? Book a free consultation to talk it through, with no commitment. We reply within one business day.

Frequently asked questions

Are there data residency requirements in Saudi Arabia?

Not as a blanket rule under the PDPL. Article 29 allows transfers abroad for listed purposes, on conditions: no harm to national security, adequate protection or one of SDAIA's safeguards, and only the minimum data needed (PDPL Article 29). NCA's cloud controls cover government bodies, critical-infrastructure operators and their cloud providers, and refer data localisation to SDAIA's National Data Management Office (NCA, CCC-2:2024). Some sectors, such as banking, have their own approvals (DLA Piper).

Can personal data be transferred outside Saudi Arabia without SDAIA's approval or the person's consent?

The amended Article 29 does not list SDAIA's approval as a condition; the original 2021 text did (PDPL Art. 29, as amended by Royal Decree M/148). Nor does Article 29 name the person's consent as a transfer condition. The processing itself still needs a lawful basis, and the transfer must meet Article 29's conditions or fit an exemption case with safeguards. PDPL Article 13 also requires you to tell people, when you collect data from them, whether it will be transferred, disclosed or processed outside the Kingdom; SDAIA's privacy-policy guideline adds where it is stored.

Does the PDPL apply to a company outside Saudi Arabia?

Yes, when it processes personal data of people residing in the Kingdom, "by any means from any party outside the Kingdom" (PDPL Article 2). A foreign provider serving Saudi companies should expect to sign SDAIA's Template 2 clauses, under Saudi law and courts (SDAIA Standard Contractual Clauses). SDAIA's platform has a registration route for entities outside the Kingdom (SDAIA National Data Governance Platform), but we found no published rules on which foreign companies must register, so check rather than assume.

How do Saudi PDPL transfer rules compare with the GDPR?

The tools look alike, but the texts are separate. An EU adequacy decision does not put a country on SDAIA's list (Transfer Regulation Article 3). SDAIA's clauses come as four templates and the EU's as four modules, and neither may be altered beyond its options and blanks (SDAIA Standard Contractual Clauses; European Commission SCC Q&A); but SDAIA's are governed by Saudi law and courts, and the importer answers SDAIA's requests and audits. The EU's transfer impact assessment (Clause 14) has a Saudi counterpart in the transfer risk assessment (Transfer Regulation Article 7).

Has SDAIA published its list of countries with adequate protection?

Not when we checked. The Transfer Regulation requires SDAIA to publish a list of countries and international organisations with an appropriate level of protection and to review it every four years or as necessary (Transfer Regulation Article 3). On 29 September 2026 we found no list on SDAIA's regulations pages (SDAIA, Laws and Regulations). Until one appears, no transfer can rely on adequacy: it needs one of the Article 4 exemption cases, with its safeguard and a risk assessment, and for ordinary cloud or AI subscriptions a lawyer's view on which case fits. Check again before you decide.

Does pasting customer data into an AI tool hosted abroad count as a transfer?

Yes, if the tool processes or stores that personal data outside the Kingdom, or staff abroad can access it. SDAIA's contract templates define a transfer to include "granting of access", and its risk guideline lists remote access as a form of transfer (SDAIA Standard Contractual Clauses; SDAIA Risk Assessment Guideline). Remove what the task doesn't need, use a business plan with a written contract that carries the processor terms the Implementing Regulation requires (Implementing Regulation Article 17), and handle it like any other transfer.

If our provider stores data in Saudi Arabia, is there still a transfer?

There can be, for parts of the service. Storage in the Kingdom removes one flow, but SDAIA's contract templates count "granting of access" as a transfer and its risk guideline counts remote access (SDAIA Standard Contractual Clauses; SDAIA Risk Assessment Guideline). Support staff abroad who can open the data, backups or disaster recovery in another country, and AI features processed in another region are each a flow to record. Ask the provider in writing where data is stored, processed, backed up and accessed from, and give each flow its own inventory entry.

How this article was made: Researched from the PDPL, SDAIA's regulations and guidelines, the official gazette, NCA, the European Commission and DLA Piper; opened 29 Sep 2026. Drafted with AI help, then checked against those sources. Not reviewed by a lawyer. Images are AI-generated.

Sources

  1. Personal Data Protection Law (English translation, as amended by Royal Decree M/148; the Arabic text on laws.boe.gov.sa is the official version) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
  2. Personal Data Protection Law, official Arabic text with the original and amended Article 29 (نظام حماية البيانات الشخصية) (opens in a new tab)Bureau of Experts at the Council of Ministers · laws.boe.gov.sa
  3. Cloud Cybersecurity Controls (CCC – 2: 2024) (opens in a new tab)National Cybersecurity Authority (NCA) · cdn.nca.gov.sa
  4. Data Protection Laws of the World: Saudi Arabia, Transfer (last updated 11 February 2026) (opens in a new tab)DLA Piper · dlapiperdataprotection.com
  5. Elaboration and Developing Privacy Policy Guideline (Version 1.0, August 2024) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
  6. Registration of entities outside the Kingdom (تسجيل الجهات خارج المملكة; page in Arabic) (opens in a new tab)Saudi Data & AI Authority (SDAIA), National Data Governance Platform · dgp.sdaia.gov.sa
  7. The Rules Governing the National Register of Controllers Within the Kingdom (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
  8. Laws and Regulations (index page, checked 29 September 2026) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
  9. Regulation on Personal Data Transfer Outside the Kingdom (Version 2.0, August 2024) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
  10. Standard Contractual Clauses for Personal Data Transfer (Version 1.0, September 2024) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
  11. Risk Assessment Guideline for Transferring Personal Data Outside the Kingdom (February 2025) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
  12. Regulation on Personal Data Transfer Outside the Kingdom, official Arabic text published 1 September 2024 (لائحة نقل البيانات الشخصية إلى خارج المملكة) (opens in a new tab)Umm Al-Qura (official gazette) · uqn.gov.sa
  13. Implementing Regulation of the Personal Data Protection Law (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
  14. Guidelines for Binding Common Rules (BCR) for Personal Data Transfer (Version 1.0, September 2024) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
  15. Rules Governing the Issuance of Accreditation Certificates for Controllers and Processors (Issue 1.0, 2026) (opens in a new tab)Saudi Data & AI Authority (SDAIA) · sdaia.gov.sa
  16. New Standard Contractual Clauses – Questions and Answers overview (opens in a new tab)European Commission · commission.europa.eu

About the author

Abdullah Alshalawiعبدالله الشلوي

Founder & CEO

I'm Abdullah Alshalawi, founder and CEO of O AI (أو إيه آي). I started the company in Al Khobar in March 2026 to help businesses in Saudi Arabia use AI in a practical way: bringing it into the work their teams already do, building custom software around how they work, and automating the repetitive tasks that slow them down.

I also lead Rushd (رُشد), our practice-management platform for law firms, on the web, iPhone and Android. It brings cases, clients, court sessions and billing into one place, with AI-assisted drafting in Arabic and English.

On this blog I write practical guides for business owners and law firms in the Kingdom: where AI helps and where it stops, what drives the cost of custom software, and how to start with one task and measure the result before spending more.

More articles by Abdullah Alshalawi