Skip to the content
Global Data RulesData governance rules, country by country

Saudi Arabia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Data can leave Saudi Arabia, but never for free. You need a purpose the law allows, a written safeguard such as the government's own standard contract, and a written risk assessment that asks whether the transfer could harm the Kingdom itself. Banks need the central bank's written permission before anything goes abroad. The privacy regulator is fully set up but publishes no fines.

Eight questions about Saudi Arabia

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Saudi Arabia's rules apply to my company?

Yes. The law reaches a company anywhere in the world with no office in Saudi Arabia, as long as it handles the data of people living in the Kingdom. There is no size, revenue or headcount threshold to fall below. There is no general duty to appoint a local representative, but many organisations must register on the government's data platform and some must name a data protection officer.

High confidenceNational rulesRegister or notifyAppoint a data protection officer

Can I store my users' data outside Saudi Arabia?

Yes, with real paperwork. First the reason for sending it has to be on the government's short list of allowed purposes. Then you need a safeguard: the government's own standard contract, approved group-wide rules, or a certificate from a licensed body. Then you must write a risk assessment that includes whether the transfer could damage the Kingdom's vital interests. Two industries are much harder. Banks and finance companies must get the central bank's written no-objection before any data goes to an overseas supplier, and the central bank's rules say cloud services should sit inside Saudi Arabia unless it approves otherwise. For government bodies and critical national infrastructure the picture changed in 2024 and is now genuinely unclear.

High confidenceYes, with paperworkAllowlistIndustry rules

What do I need in place before data leaves Saudi Arabia?

The model is an approved-destination list, and the list is empty. The law says data may go to a country the regulator has judged good enough, but no such list has been published, so in practice nobody uses that route. Instead almost everyone relies on the escape hatches: sign the government's word-for-word standard contract, or get approved group-wide rules for a multinational, or send to a body holding a certificate from a licensed Saudi accreditation body. On top of that you must run a written risk assessment before the data moves.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesCertification schemePut a transfer safeguard in placeAssess high-risk projects

Who enforces the rules in Saudi Arabia, and what can they do?

The Saudi Data and Artificial Intelligence Authority is the privacy regulator, and it is genuinely up and running. Its National Data Governance Platform is live and takes registrations, self-assessments, breach reports and complaints, and it has published the rulebook for the panels that hear violations and issue fines. What we could not find is a single published fine or named decision, so how hard it bites is still unknown. The financial regulator and the cybersecurity authority, by contrast, have supervised their sectors for years.

Medium confidenceWaking upFixed maximum fineCriminal liability

How long do I have to keep the data?

Both directions apply, and the floor wins when they clash. The ceiling: you must destroy personal data without undue delay once the reason you collected it has gone, and also when someone asks, when they withdraw the only consent you relied on, or when you learn you processed it unlawfully. Destruction must reach backups too. The floor: your written record of processing activities must be kept for five years after the activity ends. If another law sets a keeping period, the law says keep the data until whichever is longer.

High confidenceKeep data for a minimum periodDelete data after a periodKeep records of processing

What happens if there is a breach?

The main clock is 72 hours. If personal data is breached, lost or accessed unlawfully and that could harm the people involved, you must tell the privacy regulator within 72 hours of finding out, through the government's data platform — and you have to be registered on that platform before you can use the service. You must also tell the affected people without undue delay, in plain language. A second, separate clock runs for government bodies and critical national infrastructure, which owe cyber incident reports to the national cybersecurity authority under its own rules. Suppliers owe you notice without undue delay so you can meet your own deadline.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidentsRegister or notify

What trips people up in Saudi Arabia?

Five things that are not in the summary. One: sending data abroad is not only about protecting the individual — you must also assess whether the transfer could harm the Kingdom's own vital interests, and there is a government guide telling you how. Two: the standard contract must be copied word for word, and changing it is itself a breach of the law, while the overseas recipient has to accept Saudi courts. Three: leaking or publishing sensitive data to hurt someone or to profit can put a person in prison for up to two years — this is a criminal charge, not a fine. Four: your supplier contract must go beyond a normal data processing agreement and say whether the supplier is subject to foreign laws and how that affects its compliance. Five: the widely quoted rule that all government and critical infrastructure data must be hosted inside Saudi Arabia was deleted in 2024, and quoting it today is wrong.

High confidenceCriminal liabilityWritten vendor contractExtra vendor secrecy termsAssess high-risk projectsRepealed

What is changing soon in Saudi Arabia?

Nothing is scheduled to commence on a fixed date in the next twelve months — the law and all its main regulations are already fully in force. The risk is the opposite kind: several switches the government already holds and can flip with no consultation. The biggest is the approved-country list, which the regulator is legally required to publish and has not; the day it appears, every transfer plan in the country needs rechecking. The second biggest is the missing localisation rule for government and critical infrastructure, which one office was handed in 2024 and has not yet written.

Medium confidenceIn forceAllowlist

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    2 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    5 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules2 rules

نظام حماية البيانات الشخصية (Personal Data Protection Law)

Act of parliament · Royal Decree No. M/19 dated 9/2/1443 AH, amended by Royal Decree No. M/148 dated 5/9/1444 AH; Implementing Regulation issued 2023

In forceYes, with paperwork

Saudi Arabia's general privacy law. It reaches foreign companies serving people in the Kingdom, runs on consent by default, requires registration on a national platform for most serious processing, and gives 72 hours to report a breach. Data may leave, but only for listed purposes, with a safeguard in place and a written risk assessment first. Penalties include prison for misusing sensitive data.

In force since 14 September 2023But only enforceable from 14 September 2024

Enforced by Saudi Data and Artificial Intelligence Authority

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Someone's life is at risk

High confidence

Regulation on Personal Data Transfer Outside the Kingdom, version 2.0

Directly binding regulation · Issued under Article 29(4) of the Personal Data Protection Law; version 2.0 dated August 2024

In forceYes, with paperwork

The rules for sending personal data abroad. The intended route is a published list of approved destinations, which does not exist yet, so in practice organisations use the government's standard contract, approved group-wide rules or an accreditation certificate. Every one of those routes also requires a written risk assessment that considers harm to the Kingdom, and the law follows the data onward to any further recipient.

In force since 6 September 2024

Enforced by Saudi Data and Artificial Intelligence Authority

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme

High confidence

Industry rules5 rules

Rules on Outsourcing

Regulator directive · SAMA circular No. 41027017 dated 18/4/1441 AH (15 December 2019); supersedes circular 34720/B.C.S of 20 July 2008 · Banking

In forceYes, with paperwork

A Saudi bank cannot put customer or financial data with an overseas supplier without the central bank's written no-objection first. The application must say why the work cannot be done inside the Kingdom, include a legal opinion, and confirm the central bank can inspect the overseas provider. The general privacy law does not override this, because it expressly preserves the central bank's powers.

In force since 15 December 2019

Enforced by Saudi Central Bank

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

SAMA Cyber Security Framework, control 3.4.3 Cloud Computing

Regulator guideline · Saudi Arabian Monetary Authority Cyber Security Framework, version 1.0, May 2017 · Finance

In forceYes, with paperwork

For banks, finance companies and other firms supervised by the Saudi Central Bank, the starting answer on public or hybrid cloud is that it must sit inside Saudi Arabia. Going outside needs the central bank's explicit approval, and the cloud contract must give the firm audit rights, keep its data logically separated, ban the provider from any secondary use, and require irreversible deletion when the contract ends.

In force since 24 May 2017

Enforced by Saudi Central Bank

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Essential Cybersecurity Controls, sub-control 4-2-3-3 (in-Kingdom hosting and storage)

Government rules · ECC-1:2018 sub-control 4-2-3-3, deleted by ECC-2:2024 (Annex, List of Updates); issued under Article 10(3) of the NCA Statute and High Order No. 57231 dated 10/11/1439 AH · Government

RepealedYes, with paperwork

This is the rule most trackers still get wrong. Until 2024 Saudi government bodies and critical national infrastructure had to host and store their information inside the Kingdom under a cybersecurity control. That control was deleted in the 2024 edition. The requirement was not simply abolished — it was handed to a data office at the national data authority, which has not published a replacement, and entities must now ask that office before making any localisation decision.

In force since 1 January 2018

Enforced by National Cybersecurity Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Who you would hear from

  • الهيئة السعودية للبيانات والذكاء الاصطناعي

    Competent authority for the Personal Data Protection Law: registration, complaints, breach notification, violation panels, licensing of accreditation and audit bodies

    Fully constituted and running. The National Data Governance Platform is live with registration, self-assessment, breach reporting, complaints and public register search. Rules of procedure for the violation panels are published, including a 30-day decision window and a 60-day appeal to the courts. We found no published register of fines or named decisions, so the visible enforcement record is still thin.

  • مكتب إدارة البيانات الوطنية

    National regulator for data management and governance; since 2024 also holds the data localisation mandate for government bodies and critical national infrastructure

    The legislative arm of SDAIA. It publishes the national data management standards and the data classification policy and scores government entities yearly. It has not yet published the data localisation control transferred to it from the National Cybersecurity Authority in 2024.

  • البنك المركزي السعودي

    Banks, finance companies, payment service providers, money exchange, credit bureaus

    Maintains a live consolidated rulebook at rulebook.sama.gov.sa with version histories. Its powers are expressly preserved by Article 30(1) of the Personal Data Protection Law, so its data rules sit on top of the privacy regime rather than under it.

  • الهيئة الوطنية للأمن السيبراني

    Binding cybersecurity controls for government agencies and private operators of critical national infrastructure, and for cloud providers serving them

    Actively revising binding controls: the essential controls, cloud controls, data controls and operational technology controls were reissued in 2024 and republished on the site in July 2025.

  • هيئة الاتصالات والفضاء والتقنية

    Telecoms, information technology, postal and space sectors; supervises the Cloud Computing Special Economic Zone

    Clearly active as a sector regulator, but its regulations platform was unreachable from our network on 18 August 2026, so we could not verify any telecom-specific data storage rule.

  • هيئة الزكاة والضريبة والجمارك

    Tax and customs records, electronic invoicing

  • هيئة الحكومة الرقمية

    Digital government platforms and licensing of providers serving government entities

    Named in Article 35 of the Implementing Regulation as the body SDAIA must coordinate with on licensing entities that serve government bodies. Its own website blocked our requests, so we relied on the Implementing Regulation for its role.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the one-year grace period for compliance ran to 14 September 2024

    The consolidated text of the law we obtained from the regulator contains Article 43 (in force 720 days after publication, giving 14 September 2023) but not the transitional provision added by the 2023 amending Royal Decree. We could not open the official gazette copy, so the exact final day of the grace period is inferred rather than quoted. Plan to the earlier date.

  • That no list of countries with an adequate level of protection has been published

    This is a negative. Article 3 of the Transfer Regulation obliges the regulator to publish one on its official website, and we found no such list on that site or on the National Data Governance Platform on 18 August 2026. A list published in Arabic only, or behind the platform's login, would not have been visible to us.

  • That the Saudi privacy regulator has issued no public enforcement decisions

    We found no published register of fines or named decisions. Saudi practice does not require the regulator to publish them, so absence of published decisions is not evidence that none exist. The enforcement rating of 'waking' reflects what is observable, not a claim that nothing is happening.

  • Whether a telecom-specific data storage or localisation rule exists

    The Communications, Space and Technology Commission runs its regulations on a separate platform (mutasilind.cst.gov.sa) which refused all connections from our network on 18 August 2026, and the older cloud computing framework link on the legacy regulator domain now redirects to the home page. We therefore neither assert nor deny a telecom rule.

  • Whether health, insurance, securities or geospatial rules impose storage inside the Kingdom

    We could not verify any. The survey and geospatial authority's domain was blocked by our network's egress policy; the capital market and insurance regulators' rulebooks were reachable but we did not locate a storage-location provision in the time available. Treat these four sectors as unresearched rather than as clear.

  • Whether the National Data Management Office has issued any replacement data localisation control since the 2024 cybersecurity control deletions

    We searched the national data management standards and the data classification policy published on the regulator's own site and found no hosting-location requirement. A rule issued to government entities directly, rather than published, would not be visible to us. This is the single most consequential open question in this record.

  • The exact minimum retention period for tax and value added tax records

    The tax authority's regulation pages load their document lists with scripts and every direct link we tried to the value added tax implementing regulation returned the site's error page. We therefore state the cross-reference from the E-Invoicing Regulation without asserting a number of years.

  • The exact date the Regulation on Personal Data Transfer Outside the Kingdom was published in the official gazette

    The regulation itself is dated August 2024 and says it enters into force on publication in the gazette. We could not reach the gazette site. We record 6 September 2024, which matches the September 2024 dating of the accompanying standard contractual clauses and binding common rules guidelines, but it is inferred.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.