Saudi Arabia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Saudi Arabia — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send data out of Saudi Arabia, but never without paperwork. You need a reason the law allows. You need a written safeguard, such as the government's own standard contract. And you need a written risk assessment that asks whether the transfer could harm the Kingdom itself. Banks need the central bank's written permission before anything goes abroad. The privacy regulator is fully set up, but it publishes no fines.
Data governance in Saudi Arabia
The eight things that decide how you handle data about people in Saudi Arabia. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law reaches a company anywhere in the world, even with no office in Saudi Arabia. It applies as long as you handle data about people living in the Kingdom. There is no size, revenue or staff number below which you are safe. You do not generally have to appoint a local representative. But many organisations must register on the government's data platform, and some must name a data protection officer.
- What you have to do here:
- Register or notify · Appoint a data protection officer
Article 2(1) of the Personal Data Protection Law covers data about people living in the Kingdom. It applies 'by any means from any party outside the Kingdom'. It also covers data about people who have died, where that data could identify them or a family member. Article 33(4) tells the regulator to build tools to monitor companies outside the Kingdom that handle this data. It also tells the regulator to set out how it will enforce the law abroad. We found nothing published that does either. On registration. Under the rules for the national register of companies inside the Kingdom, you must register on the National Data Governance Platform in four cases. If you are a public body. If handling personal data is your main activity. If you handle sensitive data. Or if you are an individual using personal data beyond personal or family life. Those rules cover companies inside the Kingdom only. They say separate registration rules for companies located outside the Kingdom will be issued later. As at 18 August 2026 we could not find them. You need a data protection officer under Article 32 of the Implementing Regulation in three cases. If you are a public body handling data at large scale. If your core activities need regular and systematic monitoring of people. Or if your core activities involve sensitive data. The officer can be an outside contractor and can sit outside the Kingdom.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Protection Law, Article 2 (scope) and Article 33 (monitoring controllers outside the Kingdom)
sdaia.gov.sa
“The Law applies to any Processing of Personal Data related to individuals that takes place in the Kingdom by any means, including the Processing of Personal Data related to individuals residing in the Kingdom by any means from any party outside the Kingdom.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityThe Rules Governing the National Register of Controllers Within the Kingdom, Articles 2 and 10
sdaia.gov.sa
“Separate registration rules for Controllers located outside the Kingdom will be issued by the Competent Authority.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityImplementing Regulation of the Personal Data Protection Law, Article 32 (data protection officer)
sdaia.gov.sa
Link checked 18 August 2026
Where the data is allowed to live
Yes, with real paperwork. First, your reason for sending it must be on the government's short list of allowed purposes. Then you need a safeguard. That means the government's own standard contract, approved group-wide rules, or a certificate from a licensed body. Then you must write a risk assessment. It has to cover whether the transfer could damage the Kingdom's vital interests. Two industries are much harder. Banks and finance companies must get the central bank's written approval before any data goes to an overseas supplier. The central bank's rules also say cloud services should sit inside Saudi Arabia unless it approves otherwise. For government bodies and critical national infrastructure, the rules changed in 2024 and are now unclear.
INDUSTRY BY INDUSTRY, as at 18 August 2026: BANKING AND FINANCE — data can leave only if conditions are met This is the hardest area of all. The Saudi Central Bank's Rules on Outsourcing (circular 41027017, 15 December 2019) require the bank's written no-objection for ANY outsourcing to a service provider located overseas. It makes no difference whether the arrangement is major or minor. You also need a legal opinion and written confirmation of the central bank's right of access. The application must explain 'why it cannot be done within KSA'. Separately, the Saudi Central Bank's cyber security rulebook, control 3.4.3, states that 'in principle only cloud services should be used that are located in Saudi Arabia'. Anything else needs the central bank's explicit approval. Article 30(1) of the Personal Data Protection Law expressly preserves the Saudi Central Bank's powers. So the general privacy law does not soften any of this. GOVERNMENT AND CRITICAL NATIONAL INFRASTRUCTURE — the area most often reported wrongly. Until 2024 the National Cybersecurity Authority's Essential Cybersecurity Controls contained sub-control 4-2-3-3: 'Entity's information hosting and storage must be inside the Kingdom of Saudi Arabia'. The 2024 edition (ECC-2:2024) DELETED that sub-control. The Cloud Cybersecurity Controls (CCC-2:2024) deleted the two matching cloud sub-controls, 2-3-P-1-10 and 2-3-P-1-11. The published reason is that controls on keeping data in the country moved to the National Data Management Office. That office sits inside the Saudi Data and Artificial Intelligence Authority. It adds that entities must ask that office about keeping data in the country before taking any action. We could find no replacement rule published by that office. So government bodies and critical infrastructure now face a decision case by case, not an automatic ban. PAYMENTS, INSURANCE AND SECURITIES — these all sit under the Saudi Central Bank, the Insurance Authority or the Capital Market Authority. We confirmed the central bank rules above, which cover banks and finance companies. We could not verify a separate published rule on where data must sit for insurance or capital market firms, and we do not claim one exists. TELECOMS — the Communications, Space and Technology Commission runs its rules on a separate platform. We could not reach that platform on 18 August 2026. We could not verify a telecom rule on where data must be stored, and we do not claim one exists. HEALTH — the Personal Data Protection Law adds extra controls for health data in Article 23, but says nothing about where it must be stored. We could not verify a separate health storage rule. MAPPING AND GEOSPATIAL — we could not reach the survey and geospatial authority's website. Nothing verified, nothing claimed.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Protection Law, Article 29 (transfer outside the Kingdom) and Article 30(1) (Saudi Central Bank powers preserved)
sdaia.gov.sa
“The Transfer or Disclosure shall not cause any prejudice to national security or the vital interests of the Kingdom.”
Link checked 18 August 2026
- Official sourceSaudi Central BankSAMA Rules on Outsourcing, section V — outsourcing to third-party service providers located overseas
rulebook.sama.gov.sa
“For any proposed outsourcing arrangements to a third-party service provider located overseas, banks are required to seek a written SAMA no objection”
Link checked 18 August 2026
- Official sourceSaudi Central BankSAMA Cyber Security Framework, control 3.4.3 Cloud Computing — data location
rulebook.sama.gov.sa
“in principle only cloud services should be used that are located in Saudi Arabia, or when cloud services are to be used outside Saudi Arabia that the Member Organization should obtain explicit approval from SAMA”
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityEssential Cybersecurity Controls (ECC-2:2024), Annex — list of updates, deletion of sub-control 4-2-3-3
cdn.nca.gov.sa
“Deletion / Sub-control 4-2-3-3 / Entity's information hosting and storage must be inside the Kingdom of Saudi Arabia / Controls related to data localization have been transferred from the document to the National Data Management Office (NDMO) at the Saudi Data and Artificial Intelligence Authority”
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityCloud Cybersecurity Controls (CCC-2:2024), Annex D — deletion of sub-controls 2-3-P-1-10 and 2-3-P-1-11
cdn.nca.gov.sa
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Saudi Arabia.
Sending data out of the country
Saudi Arabia plans to publish a list of approved destination countries. That list is empty. The law says data may go to a country the regulator has judged good enough. No such list has been published, so nobody uses that route. Almost everyone uses the alternatives instead. You sign the government's standard contract word for word. Or you get approved group-wide rules, if you are a multinational. Or you send data to a body holding a certificate from a licensed Saudi accreditation body. On top of that, you must write a risk assessment before the data moves.
- What you have to do here:
- Put a transfer safeguard in place · Assess high-risk projects
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme
Article 29(1) of the Law allows a transfer for four reasons only. To carry out a duty under an agreement the Kingdom is party to. To serve the interests of the Kingdom. To carry out a duty under an agreement the person themselves is party to. And for other reasons set out in the Regulations. Article 2 of the Regulation on Personal Data Transfer Outside the Kingdom adds three more. Handling data centrally where that is needed to run your business. Providing a service or benefit to the person the data is about. And scientific research. Article 29(2) then adds three conditions, and you must meet all of them. The transfer must not harm national security or the Kingdom's vital interests. The destination must give a good enough level of protection. And you must send the smallest amount of data that will do the job. Article 3 of the Transfer Regulation requires the regulator to publish a list of approved countries and international organisations. The list goes on its official website and must be reviewed every four years. We could not find any published list as at 18 August 2026. The same Article lets the regulator suspend transfers to a listed country at any time. Article 4 lets you skip the approved-destination test and the smallest-amount test in five defined cases. To do that you must use the standard contractual clauses, binding common rules, or an accreditation certificate. Both the Standard Contractual Clauses and the Binding Common Rules guidelines are version 1.0, dated September 2024. Two sharp edges sit in the clauses. Rule 5 says any change to the approved wording 'shall not be recognized by the Competent Authority and shall be deemed a violation'. Rule 8 requires the overseas recipient to accept the Kingdom's courts. Article 7 requires a written risk assessment before a transfer that relies on an exemption. It also requires one before any continuous or large-scale export of sensitive data. Article 5 applies the Law to any onward transfer the overseas recipient makes.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityRegulation on Personal Data Transfer Outside the Kingdom, version 2.0, August 2024 — Articles 2 to 7
sdaia.gov.sa
“The competent authority shall publish on its official website a list of countries or international organizations that provide an appropriate level of protection for personal data not less than that prescribed by the Law and Regulations.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityStandard Contractual Clauses For Personal Data Transfer, version 1.0, September 2024 — rules 5 and 8
sdaia.gov.sa
“If any party modifies the approved text ... such modifications shall not be recognized by the Competent Authority and shall be deemed a violation of the provisions of the Law and Regulations.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityGuidelines for Binding Common Rules (BCR) For Personal Data Transfer, version 1.0, September 2024
sdaia.gov.sa
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityRisk Assessment Guideline for Transferring Personal Data Outside the Kingdom, February 2025
sdaia.gov.sa
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Saudi Data and Artificial Intelligence Authority is the privacy regulator, and it is up and running. Its National Data Governance Platform is live. It takes registrations, self-assessments, breach reports and complaints. The authority has published the rulebook for the panels that hear violations and issue fines. We could not find a single published fine or named decision. So how hard it punishes people is still unknown. The financial regulator and the cybersecurity authority, by contrast, have supervised their industries for years.
- What it costs if you get it wrong:
- Fixed maximum fine · Criminal liability
The Saudi Data and Artificial Intelligence Authority was named the competent authority for the Law. Its legislative arm is the National Data Management Office. Here is the evidence that it is working, all checked on 18 August 2026. The National Data Governance Platform at dgp.sdaia.gov.sa is live. It offers registration for public and private bodies, a breach notification service, a compliance self-assessment and a public search of the national register. The authority has published Rules of Procedure on Committees for Reviewing Violations. These set out a full decision process. A complaint is registered within 10 days. Charges are filed within 60 days. The respondent replies within 5 days. The panel decides within 30 days. Notification follows within 15 days. An appeal to the competent court can be filed within 60 days. The panels can impose a warning or a fine. Article 36(2) of the Law requires each panel to have at least three members, including a technical specialist and a legal adviser. The authority's president must approve the panel's decisions. Criminal cases under Article 35 go to the Public Prosecution and the courts, not to the authority. We found no register of published enforcement decisions, so we rate enforcement as waking rather than active. Other regulators are clearly working. The Saudi Central Bank publishes a live consolidated rulebook. The National Cybersecurity Authority actively revises its binding controls, and both the essential and cloud control sets were reissued in 2024 and republished in July 2025.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityNational Data Governance Platform — live registration, complaint, breach notification and national register search services
dgp.sdaia.gov.sa
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityRules of Procedure on Committees for Reviewing Violations of the Provisions of the Personal Data Protection Law and its Implementing Regulations
sdaia.gov.sa
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Protection Law, Articles 30 and 34 to 38 — supervision, complaints, penalties and inspection powers
sdaia.gov.sa
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityNational Cybersecurity Authority — Cloud Cybersecurity Controls page, noting the 2024 update on data localisation, published 31 July 2025
nca.gov.sa
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a maximum and a minimum, and the minimum wins when they clash. The maximum: you must destroy personal data without undue delay once the reason you collected it has gone. You must also destroy it when someone asks, when they withdraw the only consent you relied on, or when you learn you handled it unlawfully. Destruction must reach your backups too. The minimum: your written record of data activities must be kept for five years after the activity ends. If another law sets a keeping period, keep the data for whichever period is longer.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep records of how you use data
The maximum. Article 18(1) of the Law requires destruction without undue delay when you no longer need the data. You can instead keep a version with everything that could identify the person stripped out. Article 8 of the Implementing Regulation adds the four triggers for destruction. It requires you to destroy all copies, including backups. You must also tell anyone you gave the data to and ask them to destroy it as well. The minimum. Article 33(1) of the Implementing Regulation requires you to keep your record of data activities while the activity runs. You must also keep it for five years after the activity ends. The clash rule. Article 18(2)(a) covers the case where a legal basis requires you to keep data for a set period. You destroy it at the end of that period, or when the purpose is met, whichever is longer. So a legal minimum always beats the privacy duty to delete. Article 18(2)(b) adds a litigation hold. Data tied to a case before a judicial authority is kept until the case ends. Tax and accounting minimums sit outside the privacy law. Electronic invoices are covered by the E-Invoicing Regulation, which pulls in the record-keeping rules of the value added tax rules. Article 41 of the Law adds a lifelong duty of confidentiality that survives the end of employment or a contract. We could not open the value added tax implementing regulation on the tax authority's site. So we do not state the exact number of years for tax records here.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Protection Law, Article 18 (destruction and retention) and Article 41 (lasting confidentiality)
sdaia.gov.sa
“If there is a legal basis for retaining the Personal Data for a specific period, in which case the Personal Data shall be destroyed upon the lapse of that period or when the purpose of the Collection is satisfied, whichever longer.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityImplementing Regulation, Article 8 (destruction, including backups) and Article 33 (records kept five years after the activity ends)
sdaia.gov.sa
“The Controller shall keep a record of Personal Data Processing activities during all the period Personal Data is being processed, and till to five years after the date of end of any Personal Data Processing activity.”
Link checked 18 August 2026
- Official sourceZakat, Tax and Customs AuthorityE-Invoicing Regulation, 4 December 2020, Article 4(A)(5) — record keeping follows the value added tax rules
zatca.gov.sa
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
The main deadline is 72 hours. You must tell the privacy regulator within 72 hours of finding out about a breach. This applies where personal data is breached, lost or accessed unlawfully in a way that could harm the people involved. You report through the government's data platform. You must already be registered on that platform before you can use the service. You must also tell the affected people without undue delay, in plain language. A second, separate deadline runs for government bodies and critical national infrastructure. They owe cyber incident reports to the national cybersecurity authority under its own rules. Suppliers owe you notice without undue delay, so you can meet your own deadline.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents · Register or notify
Article 20 of the Law creates the duty. Article 24 of the Implementing Regulation sets the 72 hours and the content. You must say what happened and when. You must say when you became aware. You must give the categories and numbers of people affected, the risks, what you have done, and whether you have told the people. If you cannot supply everything inside 72 hours, you may complete the notification later. You must keep records of the breach and the supporting documents. The Saudi Data and Artificial Intelligence Authority's Personal Data Breach Incidents Procedural Guide confirms that you notify through the National Data Governance Platform. It also confirms that you must already be registered on the platform. That is the operational trap. A company that has never registered cannot file on the day it needs to. The same Guide opens by saying it does not displace any breach report required by the National Cybersecurity Authority. That is an open acknowledgement of a second, overlapping set of rules. You must tell the people affected whenever the breach may damage their data or harm their rights or interests. Your message must describe the breach, the risks and the steps you have taken. Under Article 17 of the Implementing Regulation, a supplier who handles data for you must tell you without undue delay.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityImplementing Regulation, Article 24 — notification of personal data breach within 72 hours
sdaia.gov.sa
“The Controller shall notify the Competent Authority within a delay not exceeding (72) hours of becoming aware of the incident, if such incident potentially causes harm to”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Breach Incidents Procedural Guide — Stage One, SDAIA notice
sdaia.gov.sa
“Without prejudice to submitting any report or notice of personal data breach pursuant to Regulations issued by the National Cybersecurity Authority (NCA) and any applicable regulations and rules in the Kingdom of Saudi Arabia, the Controller shall notify SDAIA within a period not exceeding (72) hours”
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityEssential Cybersecurity Controls (ECC-2:2024) — binding on government agencies and critical national infrastructure
cdn.nca.gov.sa
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things the summary does not tell you. One. Sending data abroad is not only about protecting the individual. You must also assess whether the transfer could harm the Kingdom's own vital interests. There is a government guide telling you how. Two. The standard contract must be copied word for word. Changing it is itself a breach of the law. The overseas recipient also has to accept Saudi courts. Three. Leaking or publishing sensitive data to hurt someone or to make money can put a person in prison for up to two years. That is a criminal charge, not a fine. Four. Your supplier contract must go beyond a normal data protection agreement. It must say whether the supplier is subject to foreign laws, and how that affects its compliance. Five. The widely quoted rule that all government and critical infrastructure data must be hosted inside Saudi Arabia was deleted in 2024. Quoting it today is wrong.
- What you have to do here:
- Written vendor contract · Extra vendor secrecy terms · Assess high-risk projects
- What it costs if you get it wrong:
- Criminal liability
1. National interest screening. Article 29(2)(a) of the Law forbids a transfer that would harm national security or the vital interests of the Kingdom. The Saudi Data and Artificial Intelligence Authority's Risk Assessment Guideline of February 2025 gives a whole phase to working this out. It asks for the exact country of storage. It asks whether the cloud is public or private. It asks whether the impact reaches beyond the individual to their family or to society. And it asks whether the recipient's own laws would stop them complying. This is a national sovereignty test bolted onto a privacy test. It has no direct equivalent in European rules. 2. Word-perfect standard clauses, and Saudi courts. Rule 5 of the Standard Contractual Clauses treats any edit to the approved text as a violation. Rule 7 blocks the route entirely where the recipient's local law prevents compliance. Rule 8 requires the recipient to accept the Kingdom's courts and to enforce binding Saudi decisions. Rule 9 requires the recipient to answer the regulator's requests and cooperate with audits. 3. Individuals can go to prison. Article 35 of the Law punishes disclosing or publishing sensitive data with intent to harm or to gain. The penalty is up to two years in prison, a fine of up to 3 million Saudi riyals (about 800,000 US dollars), or both. The fine may be doubled for a repeat offence. Sensitive data in Saudi Arabia includes religious, intellectual or political belief. It also includes data showing that one or both of a person's parents are unknown. Those categories are not on the usual global list. 4. Supplier contracts must go further than usual. Article 17 of the Implementing Regulation requires the contract to state whether your supplier is subject to another country's rules, and the effect on its compliance. It also requires you to drop any need for the person's consent before a disclosure that Saudi law makes compulsory. The supplier must tell you about it. Sub-suppliers need your prior acceptance. A supplier that ignores your instructions is treated as the company that decides how the data is used, and becomes directly liable. 5. The deleted rule about keeping data in the country. Sub-control 4-2-3-3 of the Essential Cybersecurity Controls was removed in the 2024 edition. So were sub-controls 2-3-P-1-10 and 2-3-P-1-11 of the Cloud Cybersecurity Controls. The mandate moved to the National Data Management Office. Anyone still citing 'ECC 4-2-3-3' as a live requirement to host inside the Kingdom is citing a deleted control. What replaced it is a duty to ask that office before acting. 6. One more. You cannot file a breach report if you have not already registered on the National Data Governance Platform.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Protection Law, Article 1(11) (sensitive data), Article 29(2)(a) and Article 35 (imprisonment up to two years)
sdaia.gov.sa
“any individual discloses or publishes Sensitive Data, in violation of the provisions of the Law, with the intention of harming the Data Subject or achieving a personal benefit shall be punished with imprisonment for a period not exceeding (two years), or a fine not exceeding (three million) Riyals, or both.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityImplementing Regulation, Article 17 — processor selection and mandatory contract terms
sdaia.gov.sa
“Clarification of whether the Processor is subject to Regulations in other countries and the impact on their compliance with the Law and its Regulations.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityRisk Assessment Guideline for Transferring Personal Data Outside the Kingdom, February 2025 — vital interests of the Kingdom
sdaia.gov.sa
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityEssential Cybersecurity Controls (ECC-2:2024) — deletion of the in-Kingdom hosting sub-control
cdn.nca.gov.sa
Link checked 18 August 2026
What's changing next
Nothing is due to start on a fixed date in the next twelve months. The law and all its main regulations are already fully in force. The risk is the other kind. The government already holds several powers it can use with no consultation. The biggest is the list of approved countries. The regulator is legally required to publish it and has not. The day it appears, every transfer plan in the country needs rechecking. The second biggest is the missing rule on keeping government and critical infrastructure data inside the country. One office was handed that job in 2024 and has not yet written it.
POWERS THE GOVERNMENT ALREADY HOLDS, all traceable to text already in force: 1. The approved-country list. Article 3 of the Transfer Regulation requires the Saudi Data and Artificial Intelligence Authority to publish a list. The list names countries and international organisations that protect data well enough. It must review the list every four years, or sooner if needed. We found no list as at 18 August 2026. Publishing one would immediately change which transfers need standard contractual clauses. Article 3(4) says the same tests apply to cities, special economic zones and global trade centres. So a country could be listed or excluded in part. 2. Suspending transfers. Article 3(3) lets the authority suspend transfer or disclosure to any listed country or organisation. There is no public procedure and no notice period. 3. Withdrawing an exemption. Article 6 of the Transfer Regulation lets the authority decide that your safeguards are not good enough in a specific case. You must then stop the transfer and tell every recipient. That power can shut down one company on its own. 4. The transferred mandate on keeping data in the country. The National Cybersecurity Authority moved this question for government bodies and critical national infrastructure to the National Data Management Office in the 2024 control sets. That office has not published a replacement control. It could publish a binding rule requiring hosting inside the Kingdom at any time. 5. Registration rules for companies based outside the Kingdom. The current register rules cover companies inside the Kingdom. They say separate rules for those outside will be issued. When they arrive, foreign companies serving Saudi residents will pick up a registration duty they do not have today. 6. Rewriting the standard contract. Rule 11 of the Standard Contractual Clauses lets the authority change the clauses when it chooses, with transitional rules to follow. Article 4(4) of the Transfer Regulation lets it review whether safeguards are good enough every two years, or sooner if needed. The first review window has already opened.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityRegulation on Personal Data Transfer Outside the Kingdom — Article 3 (list and suspension), Article 4(4) (two-yearly review), Article 6 (revocation of exemption)
sdaia.gov.sa
“The competent authority may suspend the transfer or disclosure of personal data to any of the countries or organizations listed in paragraph (1) of this Article, in accordance with the statutory procedures.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityThe Rules Governing the National Register of Controllers Within the Kingdom — separate rules promised for controllers outside the Kingdom
sdaia.gov.sa
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityCloud Cybersecurity Controls (CCC-2:2024) — localisation mandate transferred to the National Data Management Office
cdn.nca.gov.sa
“entities must refer to the National Data Management Office regarding data localization before taking any action in this regard.”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Banking rules
Official name: Rules on Outsourcing · SAMA circular No. 41027017 dated 18/4/1441 AH (15 December 2019); supersedes circular 34720/B.C.S of 20 July 2008 · Regulator directive
A Saudi bank cannot put customer or financial data with an overseas supplier without the central bank's written no-objection first. The application must say why the work cannot be done inside the Kingdom. It must include a legal opinion. It must also confirm that the central bank can inspect the overseas provider. The general privacy law does not override this, because it expressly preserves the central bank's powers.
Enforced by Saudi Central Bank
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Put a transfer safeguard in placeYou need the Saudi Central Bank's written no-objection for every overseas outsourcing arrangement, large or small.
- Written vendor contractThe application must include a legal opinion confirming you comply with the Banking Control Law. It must also confirm the Saudi Central Bank's right of access to the overseas provider.
- Independent auditAnnual return on outsourcing services provided and received.
What it costs if you get it wrong
- Loss of your licenceSupervisory action under the Banking Control Law for outsourcing without no-objection
Sources
- Official sourceSaudi Central BankRules on Outsourcing, section V — Outsourcing to Third-Party Service Providers Located Overseas, paragraph 42
rulebook.sama.gov.sa
“For any proposed outsourcing arrangements to a third-party service provider located overseas, banks are required to seek a written SAMA no objection”
Link checked 18 August 2026
- Official sourceSaudi Central BankRules on Outsourcing — circular No. 41027017, status In-Force
rulebook.sama.gov.sa
Link checked 18 August 2026
Cyber security rules
Official name: SAMA Cyber Security Framework, control 3.4.3 Cloud Computing · Saudi Arabian Monetary Authority Cyber Security Framework, version 1.0, May 2017 · Regulator guideline
For banks, finance companies and other firms supervised by the Saudi Central Bank, public or hybrid cloud must sit inside Saudi Arabia by default. Going outside needs the central bank's explicit approval. The cloud contract must give the firm audit rights. It must keep the firm's data logically separated. It must ban the provider from any secondary use. And it must require irreversible deletion when the contract ends.
Enforced by Saudi Central Bank
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryBy default, public and hybrid cloud services must be located in Saudi Arabia. Using cloud outside the Kingdom needs the Saudi Central Bank's explicit approval. This does not apply to private, internal cloud.
- Written vendor contractThe contract must set cyber security requirements before use. It must give you rights to review, audit and examine the provider. It must keep your data separated, ban any secondary use of it, and require irreversible deletion when the contract ends.
- Secure the data
Sources
- Official sourceSaudi Central BankSAMA Cyber Security Framework, control 3.4.3 Cloud Computing — data location and contractual requirements
rulebook.sama.gov.sa
“in principle only cloud services should be used that are located in Saudi Arabia, or when cloud services are to be used outside Saudi Arabia that the Member Organization should obtain explicit approval from SAMA”
Link checked 18 August 2026
Cyber security rules (Government)
Official name: Essential Cybersecurity Controls, sub-control 4-2-3-3 (in-Kingdom hosting and storage) · ECC-1:2018 sub-control 4-2-3-3, deleted by ECC-2:2024 (Annex, List of Updates); issued under Article 10(3) of the NCA Statute and High Order No. 57231 dated 10/11/1439 AH · Government rules
This is the rule most trackers still get wrong. Until 2024, Saudi government bodies and critical national infrastructure had to host and store their information inside the Kingdom under a cybersecurity control. That control was deleted in the 2024 edition. The requirement was not simply abolished. It was handed to a data office at the national data authority, which has not published a replacement. Entities must now ask that office before making any decision about where data sits.
Enforced by National Cybersecurity Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThis is no longer a standing duty. It was replaced by a duty to ask the National Data Management Office at the Saudi Data and Artificial Intelligence Authority before deciding where data sits.
Sources
- Official sourceNational Cybersecurity AuthorityEssential Cybersecurity Controls (ECC-2:2024), Annex — List of Updates
cdn.nca.gov.sa
“Deletion / Sub-control 4-2-3-3 / Entity's information hosting and storage must be inside the Kingdom of Saudi Arabia / Controls related to data localization have been transferred from the document to the National Data Management Office (NDMO) at the Saudi Data and Artificial Intelligence Authority for as per the mandates, and entities must refer to the National Data Management Office regarding data localization before taking any action in this regard.”
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityNational Cybersecurity Authority — Essential Cybersecurity Controls page (ECC-2:2024), published 31 July 2025
nca.gov.sa
Link checked 18 August 2026
Cyber security rules (2024)
Official name: Cloud Cybersecurity Controls (CCC-2:2024) · CCC-2:2024, replacing CCC-1:2020; issued under Article 10(3) of the NCA Statute and Royal Decree No. 57231 · Government rules
Binding cybersecurity rules for any cloud provider serving Saudi government bodies or private operators of critical national infrastructure. They bind those customers too. The 2024 edition removed the two controls that required the service, its storage, disaster recovery, monitoring and support to be delivered from inside the Kingdom. It pointed entities to the national data office instead.
Enforced by National Cybersecurity Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Hold a security certificateBinding on every cloud provider serving a Saudi government body or a private operator of critical national infrastructure, and on those customers themselves. Compliance with the Essential Cybersecurity Controls is required as well.
- Keep the data in the countryThe two in-Kingdom service delivery sub-controls (2-3-P-1-10 and 2-3-P-1-11) were deleted in this edition and moved to the National Data Management Office.
- Secure the dataIncludes screening and vetting of provider personnel working inside the Kingdom.
Sources
- Official sourceNational Cybersecurity AuthorityCloud Cybersecurity Controls (CCC-2:2024), scope of work and Annex D (List of Updates)
cdn.nca.gov.sa
“Controls related to data localization have been transferred from the document to the National Data Management Office (NDMO) at the Saudi Data and Artificial Intelligence Authority”
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityNational Cybersecurity Authority — Cloud Cybersecurity Controls page
nca.gov.sa
“The Cloud Cybersecurity Controls (CCC - 2: 2024) have been updated to reflect changes related to data localization requirements.”
Link checked 18 August 2026
State and security data rules
Official name: National Data Management and Personal Data Protection Standards; Data Classification Policy and Regulations · Issued by the National Data Management Office under Cabinet Resolution No. 292 dated 27/4/1441 AH · Government policy document
If you are a supplier holding Saudi government data, these standards bind you as well as the government body. They cover fifteen data management areas. They require every piece of government data to be classified into one of four levels. Compliance is scored each year. This is also where the job of setting rules on keeping government and critical infrastructure data in the country was moved in 2024. No such control has appeared in them yet.
Enforced by National Data Management Office
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep records of how you use dataFifteen data management domains, assessed for compliance yearly.
- Written vendor contractScope extends to business partners handling government data, who must apply the standards to all government data in their control.
- Secure the dataGovernment data must be classified as Top Secret, Secret, Restricted or Public before it is handled.
Sources
- Official sourceNational Data Management Office, Saudi Data and Artificial Intelligence AuthorityNational Data Management and Personal Data Protection Standards, purpose and scope
sdaia.gov.sa
“In addition to Public Entities, the scope of the National Data Management and Personal Data Protection Standards also extends to business partners handling government data.”
Link checked 18 August 2026
- Official sourceNational Data Management Office, Saudi Data and Artificial Intelligence AuthorityData Classification Policy and Regulations — Top Secret, Secret, Restricted, Public
sdaia.gov.sa
Link checked 18 August 2026
Applies to every company2 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: نظام حماية البيانات الشخصية (Personal Data Protection Law) · Royal Decree No. M/19 dated 9/2/1443 AH, amended by Royal Decree No. M/148 dated 5/9/1444 AH; Implementing Regulation issued 2023 · Act of parliament
Saudi Arabia's general privacy law. It reaches foreign companies serving people in the Kingdom. It runs on consent by default. It requires most serious data handling to be registered on a national platform. It gives you 72 hours to report a breach. Data may leave the country, but only for listed purposes, with a safeguard in place and a written risk assessment first. Penalties include prison for misusing sensitive data.
Enforced by Saudi Data and Artificial Intelligence Authority
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, To save someone’s life
What you have to do
- Get consentConsent is the default basis. Legitimate interest is available but never for sensitive data.
- Document a legitimate interestYou cannot use this where sensitive data is involved.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhereRight to obtain the data in a readable and clear format.
- Secure the data
- Report breaches to the regulator — within 72 hoursYou file through the National Data Governance Platform. You must already be registered on it.
- Tell affected peopleWithout undue delay, in simple and clear language. Required where the breach may damage the person's data or harm their rights.
- Keep records of how you use data — 5 yearsKept while the data activity runs, and for five years after it ends.
- Delete data after a periodDestroy without undue delay once the purpose ends, including all backups. A minimum period set by law overrides this.
- Assess high-risk projects — applies at: Sensitive data, data linking from multiple sources, large-scale or systematic monitoring, emerging technologies, automated decisions, or any high-risk product or service
- Appoint a data protection officer — applies at: Public bodies processing at large scale; controllers whose core activity requires regular systematic monitoring; controllers whose core activity is sensitive dataMay be an employee or an external contractor, and may be located outside the Kingdom.
- Register or notify — applies at: Public bodies; controllers whose main activity is personal data processing; controllers processing sensitive data; individuals processing beyond personal or family useRegistration on the National Data Governance Platform. Certificate valid up to five years.
- Written vendor contract
- Extra vendor secrecy termsThe contract must say whether your supplier is subject to another country's laws, and the effect on compliance. The duty of confidentiality survives the end of the relationship.
- Put a transfer safeguard in place
- Get a parent's consent for childrenWritten as consent from the legal guardian where the person fully or partly lacks legal capacity. The Law sets no fixed digital age.
What it costs if you get it wrong
- Criminal liability: SAR 3,000,000 and/or 2 years imprisonment — about $800 thousandDisclosing or publishing sensitive data with intent to harm the individual or to gain a personal benefit; fine may be doubled for a repeat offence
- Fixed maximum fine: SAR 5,000,000 — about $1 millionAny other violation of the Law or the Regulations; may be doubled for a repeat violation
- Claims by individualsIndividuals may sue for proportionate compensation for material or moral damage
- Order to stopThe regulator may seize the means or tools used in a violation and a court may order confiscation and publication of the decision at the violator's expense
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Protection Law (consolidated English text)
sdaia.gov.sa
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityImplementing Regulation of the Personal Data Protection Law
sdaia.gov.sa
“This Regulation shall be published in the official gazette and on the official website of the Competent Authority and shall come into force from the date of the Law's enforcement.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthoritySDAIA Laws and Regulations index — the law, the implementing regulation and all subordinate rules
sdaia.gov.sa
Link checked 18 August 2026
Government data rules
Official name: Regulation on Personal Data Transfer Outside the Kingdom, version 2.0 · Issued under Article 29(4) of the Personal Data Protection Law; version 2.0 dated August 2024 · Directly binding regulation
The rules for sending personal data abroad. The intended route is a published list of approved destinations. That list does not exist yet. So organisations use the government's standard contract, approved group-wide rules or an accreditation certificate instead. Every one of those routes also needs a written risk assessment that considers harm to the Kingdom. The law follows the data onward to any further recipient.
Enforced by Saudi Data and Artificial Intelligence Authority
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme
What you have to do
- Put a transfer safeguard in placeStandard contractual clauses, binding common rules, or an accreditation certificate from a body licensed by the Saudi Data and Artificial Intelligence Authority. The standard clauses must be copied word for word.
- Assess high-risk projectsWritten risk assessment required before any transfer relying on an exemption, and before any continuous or large-scale export of sensitive data. It must cover the effect on the Kingdom's vital interests.
- Keep records of how you use dataYour record of data activities must describe every transfer outside the Kingdom, its legal basis and its recipients.
What it costs if you get it wrong
- Order to stopIf the regulator finds the safeguards inadequate, the controller must halt the transfer and notify every recipient
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityRegulation on Personal Data Transfer Outside the Kingdom, version 2.0, August 2024
sdaia.gov.sa
“The Regulation shall enter into force on the date of its publication in the Official Gazette.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityStandard Contractual Clauses For Personal Data Transfer, version 1.0, September 2024
sdaia.gov.sa
“To ensure effective enforcement of these Clauses, the Personal Data Importer submits to the jurisdiction of the Kingdom”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the one-year grace period for compliance ran to 14 September 2024
We could not confirm the exact last day of the grace period. The version of the law we obtained from the regulator contains Article 43, which brings the law into force 720 days after publication. That gives 14 September 2023. It does not contain the transitional wording added by the 2023 amending Royal Decree. We could not open the official gazette copy, so this date is worked out rather than quoted. Plan to the earlier date.
That no list of countries with an adequate level of protection has been published
We could not confirm whether a list of approved countries exists. Article 3 of the Transfer Regulation requires the regulator to publish one on its official website. We found no list there, and none on the National Data Governance Platform, on 18 August 2026. A list published in Arabic only, or behind the platform's login, would not have been visible to us. Check the platform before you rely on this.
That the Saudi privacy regulator has issued no public enforcement decisions
We found no published register of fines or named decisions. Saudi rules do not require the regulator to publish them. So the absence of published decisions does not prove there are none. Our enforcement rating of 'waking' reflects what we can see, not a claim that nothing is happening.
Whether a telecom-specific data storage or localisation rule exists
We could not confirm whether telecoms have their own rule on where data must be stored. The Communications, Space and Technology Commission runs its rules on a separate platform, mutasilind.cst.gov.sa, which refused all connections from our network on 18 August 2026. The older cloud computing link on the previous regulator domain now redirects to the home page. If you are a telecom operator, ask the commission directly.
Whether health, insurance, securities or geospatial rules impose storage inside the Kingdom
We could not confirm the rules for these four industries. We could not reach the survey and geospatial authority's website. We did reach the capital market and insurance rulebooks, but found no rule there on where data must be stored. Treat these four industries as unchecked rather than clear. Ask your own regulator before you rely on this.
Whether the National Data Management Office has issued any replacement keeping data in the country control since the 2024 cybersecurity control deletions
We could not confirm whether a replacement rule on hosting location exists. We searched the national data management standards and the data classification policy on the regulator's own site and found none. A rule sent to government bodies directly, rather than published, would not be visible to us. This is the biggest open question in this record. If you serve government bodies, ask the National Data Management Office.
The exact minimum retention period for tax and value added tax records
We could not confirm how many years tax records must be kept. Every direct link we tried to the value added tax implementing regulation returned the tax authority's error page. So we note that the E-Invoicing Regulation points to those rules, without giving a number of years. Ask the tax authority for the exact period.
The exact date the Regulation on Personal Data Transfer Outside the Kingdom was published in the official gazette
We could not confirm the exact date this regulation took effect. It is dated August 2024 and says it starts on publication in the official gazette. We could not reach the gazette site. We record 6 September 2024, which matches the September 2024 date on the standard contractual clauses and binding common rules guidelines. That date is worked out, not quoted.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.