Skip to the content
Global Data RulesData governance rules, country by country

Saudi Arabia

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Saudi Arabia — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

You can send data out of Saudi Arabia, but never without paperwork. You need a reason the law allows. You need a written safeguard, such as the government's own standard contract. And you need a written risk assessment that asks whether the transfer could harm the Kingdom itself. Banks need the central bank's written permission before anything goes abroad. The privacy regulator is fully set up, but it publishes no fines.

Data governance in Saudi Arabia

The eight things that decide how you handle data about people in Saudi Arabia. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law reaches a company anywhere in the world, even with no office in Saudi Arabia. It applies as long as you handle data about people living in the Kingdom. There is no size, revenue or staff number below which you are safe. You do not generally have to appoint a local representative. But many organisations must register on the government's data platform, and some must name a data protection officer.

What you have to do here:
Register or notify · Appoint a data protection officer

Where the data is allowed to live

Yes, with real paperwork. First, your reason for sending it must be on the government's short list of allowed purposes. Then you need a safeguard. That means the government's own standard contract, approved group-wide rules, or a certificate from a licensed body. Then you must write a risk assessment. It has to cover whether the transfer could damage the Kingdom's vital interests. Two industries are much harder. Banks and finance companies must get the central bank's written approval before any data goes to an overseas supplier. The central bank's rules also say cloud services should sit inside Saudi Arabia unless it approves otherwise. For government bodies and critical national infrastructure, the rules changed in 2024 and are now unclear.

What to do: Get the paperwork for one of the routes below signed before any data leaves Saudi Arabia.

Sending data out of the country

Saudi Arabia plans to publish a list of approved destination countries. That list is empty. The law says data may go to a country the regulator has judged good enough. No such list has been published, so nobody uses that route. Almost everyone uses the alternatives instead. You sign the government's standard contract word for word. Or you get approved group-wide rules, if you are a multinational. Or you send data to a body holding a certificate from a licensed Saudi accreditation body. On top of that, you must write a risk assessment before the data moves.

What you have to do here:
Put a transfer safeguard in place · Assess high-risk projects
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Saudi Data and Artificial Intelligence Authority is the privacy regulator, and it is up and running. Its National Data Governance Platform is live. It takes registrations, self-assessments, breach reports and complaints. The authority has published the rulebook for the panels that hear violations and issue fines. We could not find a single published fine or named decision. So how hard it punishes people is still unknown. The financial regulator and the cybersecurity authority, by contrast, have supervised their industries for years.

What it costs if you get it wrong:
Fixed maximum fine · Criminal liability
Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There is a maximum and a minimum, and the minimum wins when they clash. The maximum: you must destroy personal data without undue delay once the reason you collected it has gone. You must also destroy it when someone asks, when they withdraw the only consent you relied on, or when you learn you handled it unlawfully. Destruction must reach your backups too. The minimum: your written record of data activities must be kept for five years after the activity ends. If another law sets a keeping period, keep the data for whichever period is longer.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

The main deadline is 72 hours. You must tell the privacy regulator within 72 hours of finding out about a breach. This applies where personal data is breached, lost or accessed unlawfully in a way that could harm the people involved. You report through the government's data platform. You must already be registered on that platform before you can use the service. You must also tell the affected people without undue delay, in plain language. A second, separate deadline runs for government bodies and critical national infrastructure. They owe cyber incident reports to the national cybersecurity authority under its own rules. Suppliers owe you notice without undue delay, so you can meet your own deadline.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents · Register or notify

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things the summary does not tell you. One. Sending data abroad is not only about protecting the individual. You must also assess whether the transfer could harm the Kingdom's own vital interests. There is a government guide telling you how. Two. The standard contract must be copied word for word. Changing it is itself a breach of the law. The overseas recipient also has to accept Saudi courts. Three. Leaking or publishing sensitive data to hurt someone or to make money can put a person in prison for up to two years. That is a criminal charge, not a fine. Four. Your supplier contract must go beyond a normal data protection agreement. It must say whether the supplier is subject to foreign laws, and how that affects its compliance. Five. The widely quoted rule that all government and critical infrastructure data must be hosted inside Saudi Arabia was deleted in 2024. Quoting it today is wrong.

What you have to do here:
Written vendor contract · Extra vendor secrecy terms · Assess high-risk projects
What it costs if you get it wrong:
Criminal liability

What's changing next

Nothing is due to start on a fixed date in the next twelve months. The law and all its main regulations are already fully in force. The risk is the other kind. The government already holds several powers it can use with no consultation. The biggest is the list of approved countries. The regulator is legally required to publish it and has not. The day it appears, every transfer plan in the country needs rechecking. The second biggest is the missing rule on keeping government and critical infrastructure data inside the country. One office was handed that job in 2024 and has not yet written it.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Banking rules

Official name: Rules on Outsourcing · SAMA circular No. 41027017 dated 18/4/1441 AH (15 December 2019); supersedes circular 34720/B.C.S of 20 July 2008 · Regulator directive

In forceYes, with paperwork

A Saudi bank cannot put customer or financial data with an overseas supplier without the central bank's written no-objection first. The application must say why the work cannot be done inside the Kingdom. It must include a legal opinion. It must also confirm that the central bank can inspect the overseas provider. The general privacy law does not override this, because it expressly preserves the central bank's powers.

In force since 15 December 2019

Enforced by Saudi Central Bank

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Finance

Cyber security rules

Official name: SAMA Cyber Security Framework, control 3.4.3 Cloud Computing · Saudi Arabian Monetary Authority Cyber Security Framework, version 1.0, May 2017 · Regulator guideline

In forceYes, with paperwork

For banks, finance companies and other firms supervised by the Saudi Central Bank, public or hybrid cloud must sit inside Saudi Arabia by default. Going outside needs the central bank's explicit approval. The cloud contract must give the firm audit rights. It must keep the firm's data logically separated. It must ban the provider from any secondary use. And it must require irreversible deletion when the contract ends.

In force since 24 May 2017

Enforced by Saudi Central Bank

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Government

Cyber security rules (Government)

Official name: Essential Cybersecurity Controls, sub-control 4-2-3-3 (in-Kingdom hosting and storage) · ECC-1:2018 sub-control 4-2-3-3, deleted by ECC-2:2024 (Annex, List of Updates); issued under Article 10(3) of the NCA Statute and High Order No. 57231 dated 10/11/1439 AH · Government rules

RepealedYes, with paperwork

This is the rule most trackers still get wrong. Until 2024, Saudi government bodies and critical national infrastructure had to host and store their information inside the Kingdom under a cybersecurity control. That control was deleted in the 2024 edition. The requirement was not simply abolished. It was handed to a data office at the national data authority, which has not published a replacement. Entities must now ask that office before making any decision about where data sits.

In force since 1 January 2018

Enforced by National Cybersecurity Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: نظام حماية البيانات الشخصية (Personal Data Protection Law) · Royal Decree No. M/19 dated 9/2/1443 AH, amended by Royal Decree No. M/148 dated 5/9/1444 AH; Implementing Regulation issued 2023 · Act of parliament

In forceYes, with paperwork

Saudi Arabia's general privacy law. It reaches foreign companies serving people in the Kingdom. It runs on consent by default. It requires most serious data handling to be registered on a national platform. It gives you 72 hours to report a breach. Data may leave the country, but only for listed purposes, with a safeguard in place and a written risk assessment first. Penalties include prison for misusing sensitive data.

In force since 14 September 2023Enforced from 14 September 2024

Enforced by Saudi Data and Artificial Intelligence Authority

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, To save someone’s life

Government data rules

Official name: Regulation on Personal Data Transfer Outside the Kingdom, version 2.0 · Issued under Article 29(4) of the Personal Data Protection Law; version 2.0 dated August 2024 · Directly binding regulation

In forceYes, with paperwork

The rules for sending personal data abroad. The intended route is a published list of approved destinations. That list does not exist yet. So organisations use the government's standard contract, approved group-wide rules or an accreditation certificate instead. Every one of those routes also needs a written risk assessment that considers harm to the Kingdom. The law follows the data onward to any further recipient.

In force since 6 September 2024

Enforced by Saudi Data and Artificial Intelligence Authority

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme

Who you would hear from

  • الهيئة السعودية للبيانات والذكاء الاصطناعي

    Competent authority for the Personal Data Protection Law: registration, complaints, breach notification, violation panels, licensing of accreditation and audit bodies

    Fully set up and running. The National Data Governance Platform is live, with registration, self-assessment, breach reporting, complaints and a public register search. The rules of procedure for the violation panels are published. They include a 30-day window for a decision and a 60-day appeal to the courts. We found no published register of fines or named decisions. So its visible enforcement record is still thin.

  • مكتب إدارة البيانات الوطنية

    National regulator for data management and governance; since 2024 also holds the keeping data in the country mandate for government bodies and critical national infrastructure

    The legislative arm of the Saudi Data and Artificial Intelligence Authority. It publishes the national data management standards and the data classification policy, and it scores government bodies each year. It has not yet published the control on keeping data in the country that it was handed by the National Cybersecurity Authority in 2024.

  • البنك المركزي السعودي

    Banks, finance companies, payment service providers, money exchange, credit bureaus

    It keeps a live consolidated rulebook at rulebook.sama.gov.sa, with version histories. Article 30(1) of the Personal Data Protection Law expressly preserves its powers. So its data rules sit on top of the privacy law rather than under it.

  • الهيئة الوطنية للأمن السيبراني

    Binding cybersecurity controls for government agencies and private operators of critical national infrastructure, and for cloud providers serving them

    Actively revising its binding controls. The essential controls, cloud controls, data controls and operational technology controls were all reissued in 2024 and republished on the site in July 2025.

  • هيئة الاتصالات والفضاء والتقنية

    Telecoms, information technology, postal and space sectors; supervises the Cloud Computing Special Economic Zone

    Clearly active as an industry regulator. We could not reach its rules platform on 18 August 2026, so we could not verify any telecom rule about where data must be stored.

  • هيئة الزكاة والضريبة والجمارك

    Tax and customs records, electronic invoicing

  • هيئة الحكومة الرقمية

    Digital government platforms and licensing of providers serving government entities

    Article 35 of the Implementing Regulation names it as the body the privacy regulator must work with on licensing companies that serve government bodies. Its own website blocked our requests, so we relied on the Implementing Regulation for its role.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the one-year grace period for compliance ran to 14 September 2024

    We could not confirm the exact last day of the grace period. The version of the law we obtained from the regulator contains Article 43, which brings the law into force 720 days after publication. That gives 14 September 2023. It does not contain the transitional wording added by the 2023 amending Royal Decree. We could not open the official gazette copy, so this date is worked out rather than quoted. Plan to the earlier date.

  • That no list of countries with an adequate level of protection has been published

    We could not confirm whether a list of approved countries exists. Article 3 of the Transfer Regulation requires the regulator to publish one on its official website. We found no list there, and none on the National Data Governance Platform, on 18 August 2026. A list published in Arabic only, or behind the platform's login, would not have been visible to us. Check the platform before you rely on this.

  • That the Saudi privacy regulator has issued no public enforcement decisions

    We found no published register of fines or named decisions. Saudi rules do not require the regulator to publish them. So the absence of published decisions does not prove there are none. Our enforcement rating of 'waking' reflects what we can see, not a claim that nothing is happening.

  • Whether a telecom-specific data storage or localisation rule exists

    We could not confirm whether telecoms have their own rule on where data must be stored. The Communications, Space and Technology Commission runs its rules on a separate platform, mutasilind.cst.gov.sa, which refused all connections from our network on 18 August 2026. The older cloud computing link on the previous regulator domain now redirects to the home page. If you are a telecom operator, ask the commission directly.

  • Whether health, insurance, securities or geospatial rules impose storage inside the Kingdom

    We could not confirm the rules for these four industries. We could not reach the survey and geospatial authority's website. We did reach the capital market and insurance rulebooks, but found no rule there on where data must be stored. Treat these four industries as unchecked rather than clear. Ask your own regulator before you rely on this.

  • Whether the National Data Management Office has issued any replacement keeping data in the country control since the 2024 cybersecurity control deletions

    We could not confirm whether a replacement rule on hosting location exists. We searched the national data management standards and the data classification policy on the regulator's own site and found none. A rule sent to government bodies directly, rather than published, would not be visible to us. This is the biggest open question in this record. If you serve government bodies, ask the National Data Management Office.

  • The exact minimum retention period for tax and value added tax records

    We could not confirm how many years tax records must be kept. Every direct link we tried to the value added tax implementing regulation returned the tax authority's error page. So we note that the E-Invoicing Regulation points to those rules, without giving a number of years. Ask the tax authority for the exact period.

  • The exact date the Regulation on Personal Data Transfer Outside the Kingdom was published in the official gazette

    We could not confirm the exact date this regulation took effect. It is dated August 2024 and says it starts on publication in the official gazette. We could not reach the gazette site. We record 6 September 2024, which matches the September 2024 date on the standard contractual clauses and binding common rules guidelines. That date is worked out, not quoted.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.