Saudi Arabia
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Data can leave Saudi Arabia, but never for free. You need a purpose the law allows, a written safeguard such as the government's own standard contract, and a written risk assessment that asks whether the transfer could harm the Kingdom itself. Banks need the central bank's written permission before anything goes abroad. The privacy regulator is fully set up but publishes no fines.
Eight questions about Saudi Arabia
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Saudi Arabia's rules apply to my company?
Yes. The law reaches a company anywhere in the world with no office in Saudi Arabia, as long as it handles the data of people living in the Kingdom. There is no size, revenue or headcount threshold to fall below. There is no general duty to appoint a local representative, but many organisations must register on the government's data platform and some must name a data protection officer.
Article 2(1) of the Personal Data Protection Law applies it to processing 'related to individuals residing in the Kingdom by any means from any party outside the Kingdom', and expressly covers data about deceased people where it could identify them or a family member. Article 33(4) tells the regulator to build tools to monitor controllers and processors located outside the Kingdom and to set procedures for enforcing the law abroad; we found no published instrument doing so. Registration duty: under the Rules Governing the National Register of Controllers Within the Kingdom, a controller must register on the National Data Governance Platform if it is a public body, if its main activity is personal data processing, if it processes sensitive data, or if it is an individual processing beyond personal or family use. Those Rules cover controllers WITHIN the Kingdom only and state that 'Separate registration rules for Controllers located outside the Kingdom will be issued by the Competent Authority' — as at 18 August 2026 we could not locate them. A data protection officer is required under Article 32 of the Implementing Regulation where the controller is a public body processing at large scale, where core activities require regular and systematic monitoring, or where core activities involve sensitive data; the officer may be an external contractor and may sit outside the Kingdom.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Protection Law, Article 2 (scope) and Article 33 (monitoring controllers outside the Kingdom)
sdaia.gov.sa
“The Law applies to any Processing of Personal Data related to individuals that takes place in the Kingdom by any means, including the Processing of Personal Data related to individuals residing in the Kingdom by any means from any party outside the Kingdom.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityThe Rules Governing the National Register of Controllers Within the Kingdom, Articles 2 and 10
sdaia.gov.sa
“Separate registration rules for Controllers located outside the Kingdom will be issued by the Competent Authority.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityImplementing Regulation of the Personal Data Protection Law, Article 32 (data protection officer)
sdaia.gov.sa
Link checked 18 August 2026
Can I store my users' data outside Saudi Arabia?
Yes, with real paperwork. First the reason for sending it has to be on the government's short list of allowed purposes. Then you need a safeguard: the government's own standard contract, approved group-wide rules, or a certificate from a licensed body. Then you must write a risk assessment that includes whether the transfer could damage the Kingdom's vital interests. Two industries are much harder. Banks and finance companies must get the central bank's written no-objection before any data goes to an overseas supplier, and the central bank's rules say cloud services should sit inside Saudi Arabia unless it approves otherwise. For government bodies and critical national infrastructure the picture changed in 2024 and is now genuinely unclear.
SECTOR BY SECTOR, as at 18 August 2026: BANKING AND FINANCE — data can leave with the right paperwork, in practice the hardest wall. The Saudi Central Bank's Rules on Outsourcing (circular 41027017, 15 December 2019) require a written SAMA no-objection for ANY outsourcing arrangement with a service provider located overseas, material or not, plus a legal opinion and a written confirmation of SAMA's right of access. The application must explain 'why it cannot be done within KSA'. Separately the SAMA Cyber Security Framework, control 3.4.3, states that 'in principle only cloud services should be used that are located in Saudi Arabia', with explicit SAMA approval needed otherwise. Article 30(1) of the Personal Data Protection Law expressly preserves the Saudi Central Bank's powers, so the general privacy law does not soften any of this. GOVERNMENT AND CRITICAL NATIONAL INFRASTRUCTURE — the most commonly mis-reported area. Until 2024 the National Cybersecurity Authority's Essential Cybersecurity Controls contained sub-control 4-2-3-3: 'Entity's information hosting and storage must be inside the Kingdom of Saudi Arabia'. The 2024 edition (ECC-2:2024) DELETED that sub-control, and the Cloud Cybersecurity Controls (CCC-2:2024) deleted the two matching cloud sub-controls 2-3-P-1-10 and 2-3-P-1-11. The published reason is that 'Controls related to data localization have been transferred from the document to the National Data Management Office (NDMO) at the Saudi Data and Artificial Intelligence Authority ... and entities must refer to the National Data Management Office regarding data localization before taking any action in this regard.' We could find no replacement localisation rule published by that office. So the position for government bodies and critical infrastructure is now case-by-case referral, not an automatic ban. PAYMENTS, INSURANCE, SECURITIES — all sit under the Saudi Central Bank, the Insurance Authority or the Capital Market Authority. We confirmed the central bank rules above, which cover banks and finance companies. We could not verify a separate published localisation rule for insurance or for capital market institutions and we do not assert one. TELECOMS — the Communications, Space and Technology Commission runs its regulations on a separate platform that was unreachable from our network on 18 August 2026. We could not verify a telecom-specific storage rule and do not assert one. HEALTH — the Personal Data Protection Law adds extra controls for health data (Article 23) but no localisation. We could not verify a separate health storage rule. MAPPING AND GEOSPATIAL — the survey and geospatial authority's website was blocked from our network. Not verified, not asserted.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Protection Law, Article 29 (transfer outside the Kingdom) and Article 30(1) (Saudi Central Bank powers preserved)
sdaia.gov.sa
“The Transfer or Disclosure shall not cause any prejudice to national security or the vital interests of the Kingdom.”
Link checked 18 August 2026
- Official sourceSaudi Central BankSAMA Rules on Outsourcing, section V — outsourcing to third-party service providers located overseas
rulebook.sama.gov.sa
“For any proposed outsourcing arrangements to a third-party service provider located overseas, banks are required to seek a written SAMA no objection”
Link checked 18 August 2026
- Official sourceSaudi Central BankSAMA Cyber Security Framework, control 3.4.3 Cloud Computing — data location
rulebook.sama.gov.sa
“in principle only cloud services should be used that are located in Saudi Arabia, or when cloud services are to be used outside Saudi Arabia that the Member Organization should obtain explicit approval from SAMA”
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityEssential Cybersecurity Controls (ECC-2:2024), Annex — list of updates, deletion of sub-control 4-2-3-3
cdn.nca.gov.sa
“Deletion / Sub-control 4-2-3-3 / Entity's information hosting and storage must be inside the Kingdom of Saudi Arabia / Controls related to data localization have been transferred from the document to the National Data Management Office (NDMO) at the Saudi Data and Artificial Intelligence Authority”
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityCloud Cybersecurity Controls (CCC-2:2024), Annex D — deletion of sub-controls 2-3-P-1-10 and 2-3-P-1-11
cdn.nca.gov.sa
Link checked 18 August 2026
What do I need in place before data leaves Saudi Arabia?
The model is an approved-destination list, and the list is empty. The law says data may go to a country the regulator has judged good enough, but no such list has been published, so in practice nobody uses that route. Instead almost everyone relies on the escape hatches: sign the government's word-for-word standard contract, or get approved group-wide rules for a multinational, or send to a body holding a certificate from a licensed Saudi accreditation body. On top of that you must run a written risk assessment before the data moves.
Article 29(1) of the Law limits transfer to four purposes: performing an obligation under an agreement to which the Kingdom is a party; serving the interests of the Kingdom; performing an obligation to which the data subject is a party; and other purposes set out in the Regulations. Article 2 of the Regulation on Personal Data Transfer Outside the Kingdom adds three: central processing needed to run the controller's activities, providing a service or benefit to the data subject, and scientific research. Article 29(2) then imposes three cumulative conditions: no prejudice to national security or the Kingdom's vital interests; an adequate level of protection in the destination; and minimisation to the least data needed. Article 3 of the Transfer Regulation obliges the regulator to publish a list of adequate countries and organisations on its official website and to review it every four years; we could not find any published list as at 18 August 2026, and the same Article lets the regulator suspend transfers to a listed country at any time. Article 4 lets a controller escape the adequacy and minimisation conditions in five defined cases provided it applies standard contractual clauses, binding common rules, or an accreditation certificate. Both the Standard Contractual Clauses and the Binding Common Rules guidelines are version 1.0, September 2024. Two sharp edges in the clauses: rule 5 says any change to the approved wording 'shall not be recognized by the Competent Authority and shall be deemed a violation', and rule 8 requires the overseas data importer to submit to the jurisdiction of the Kingdom. Article 7 requires a documented risk assessment before transfer in the exemption cases and before any continuous or large-scale export of sensitive data. Article 5 applies the Law to onward transfers made by the overseas recipient.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityRegulation on Personal Data Transfer Outside the Kingdom, version 2.0, August 2024 — Articles 2 to 7
sdaia.gov.sa
“The competent authority shall publish on its official website a list of countries or international organizations that provide an appropriate level of protection for personal data not less than that prescribed by the Law and Regulations.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityStandard Contractual Clauses For Personal Data Transfer, version 1.0, September 2024 — rules 5 and 8
sdaia.gov.sa
“If any party modifies the approved text ... such modifications shall not be recognized by the Competent Authority and shall be deemed a violation of the provisions of the Law and Regulations.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityGuidelines for Binding Common Rules (BCR) For Personal Data Transfer, version 1.0, September 2024
sdaia.gov.sa
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityRisk Assessment Guideline for Transferring Personal Data Outside the Kingdom, February 2025
sdaia.gov.sa
Link checked 18 August 2026
Who enforces the rules in Saudi Arabia, and what can they do?
The Saudi Data and Artificial Intelligence Authority is the privacy regulator, and it is genuinely up and running. Its National Data Governance Platform is live and takes registrations, self-assessments, breach reports and complaints, and it has published the rulebook for the panels that hear violations and issue fines. What we could not find is a single published fine or named decision, so how hard it bites is still unknown. The financial regulator and the cybersecurity authority, by contrast, have supervised their sectors for years.
The Saudi Data and Artificial Intelligence Authority (SDAIA) was named the competent authority for the Law. Its legislative arm is the National Data Management Office. Evidence it is operational, all checked on 18 August 2026: the National Data Governance Platform at dgp.sdaia.gov.sa is live and offers registration for public and private entities, a breach notification service, a compliance self-assessment and a public search of the national register; SDAIA has published Rules of Procedure on Committees for Reviewing Violations, which set out a full adjudication process — complaints registered within 10 days, charges filed within 60 days, the respondent replies within 5 days, the panel decides within 30 days, notification within 15 days, appeal to the competent court within 60 days — and confirm the panels may impose a warning or a fine. Article 36(2) of the Law requires each panel to have at least three members including a technical specialist and a legal adviser, and its decisions must be approved by SDAIA's president. Criminal cases under Article 35 go to the Public Prosecution and the courts, not to SDAIA. We found no register of published enforcement decisions, so we rate enforcement as waking rather than active. Sector regulators are separately and clearly operational: the Saudi Central Bank publishes a live consolidated rulebook, and the National Cybersecurity Authority actively revises its binding controls (both the essential and cloud control sets were reissued in 2024 and republished in July 2025).
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityNational Data Governance Platform — live registration, complaint, breach notification and national register search services
dgp.sdaia.gov.sa
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityRules of Procedure on Committees for Reviewing Violations of the Provisions of the Personal Data Protection Law and its Implementing Regulations
sdaia.gov.sa
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Protection Law, Articles 30 and 34 to 38 — supervision, complaints, penalties and inspection powers
sdaia.gov.sa
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityNational Cybersecurity Authority — Cloud Cybersecurity Controls page, noting the 2024 update on data localisation, published 31 July 2025
nca.gov.sa
Link checked 18 August 2026
How long do I have to keep the data?
Both directions apply, and the floor wins when they clash. The ceiling: you must destroy personal data without undue delay once the reason you collected it has gone, and also when someone asks, when they withdraw the only consent you relied on, or when you learn you processed it unlawfully. Destruction must reach backups too. The floor: your written record of processing activities must be kept for five years after the activity ends. If another law sets a keeping period, the law says keep the data until whichever is longer.
Ceiling: Article 18(1) of the Law requires destruction without undue delay when the data is no longer needed, with the option to keep a version stripped of anything that could identify the person. Article 8 of the Implementing Regulation adds the four destruction triggers and requires destruction of all copies including backups, plus telling anyone the data was disclosed to and asking them to destroy it as well. Floor: Article 33(1) of the Implementing Regulation requires the record of processing activities to be kept throughout processing 'and till to five years after the date of end of any Personal Data Processing activity'. Conflict rule: Article 18(2)(a) says where a legal basis requires retention for a set period, destroy at the end of that period or when the purpose is met, 'whichever longer' — so a statutory minimum always beats the privacy duty to delete. Article 18(2)(b) adds a litigation hold: data tied to a case before a judicial authority is kept until proceedings end. Tax and accounting floors sit outside the privacy law: electronic invoices are governed by the E-Invoicing Regulation, which folds in the record-keeping rules of the value added tax rules, and Article 41 of the Law imposes a lifelong confidentiality duty that survives the end of employment or a contract. We could not open the value added tax implementing regulation text on the tax authority's site, so we do not state the exact number of years for tax records here.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Protection Law, Article 18 (destruction and retention) and Article 41 (lasting confidentiality)
sdaia.gov.sa
“If there is a legal basis for retaining the Personal Data for a specific period, in which case the Personal Data shall be destroyed upon the lapse of that period or when the purpose of the Collection is satisfied, whichever longer.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityImplementing Regulation, Article 8 (destruction, including backups) and Article 33 (records kept five years after the activity ends)
sdaia.gov.sa
“The Controller shall keep a record of Personal Data Processing activities during all the period Personal Data is being processed, and till to five years after the date of end of any Personal Data Processing activity.”
Link checked 18 August 2026
- Official sourceZakat, Tax and Customs AuthorityE-Invoicing Regulation, 4 December 2020, Article 4(A)(5) — record keeping follows the value added tax rules
zatca.gov.sa
Link checked 18 August 2026
What happens if there is a breach?
The main clock is 72 hours. If personal data is breached, lost or accessed unlawfully and that could harm the people involved, you must tell the privacy regulator within 72 hours of finding out, through the government's data platform — and you have to be registered on that platform before you can use the service. You must also tell the affected people without undue delay, in plain language. A second, separate clock runs for government bodies and critical national infrastructure, which owe cyber incident reports to the national cybersecurity authority under its own rules. Suppliers owe you notice without undue delay so you can meet your own deadline.
Article 20 of the Law creates the duty; Article 24 of the Implementing Regulation sets the 72 hours and the required content: what happened and when, when you became aware, the categories and numbers of people affected, the risks, what you have done, and whether you have told the people. If you cannot supply everything inside 72 hours you may complete the notification later, and you must keep records of the breach and supporting documents. SDAIA's Personal Data Breach Incidents Procedural Guide confirms the notification runs through the National Data Governance Platform and that prior registration on the platform is a precondition — this is the operational trap, because a company that has never registered cannot file on the day it needs to. The same Guide opens with the words 'Without prejudice to submitting any report or notice of personal data breach pursuant to Regulations issued by the National Cybersecurity Authority', which is the express acknowledgement of a second, overlapping regime. Notification to individuals is required whenever the breach may damage their data or prejudice their rights or interests, and must describe the breach, the risks, and the steps taken. Processors must notify the controller without undue delay under Article 17 of the Implementing Regulation.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityImplementing Regulation, Article 24 — notification of personal data breach within 72 hours
sdaia.gov.sa
“The Controller shall notify the Competent Authority within a delay not exceeding (72) hours of becoming aware of the incident, if such incident potentially causes harm to”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Breach Incidents Procedural Guide — Stage One, SDAIA notice
sdaia.gov.sa
“Without prejudice to submitting any report or notice of personal data breach pursuant to Regulations issued by the National Cybersecurity Authority (NCA) and any applicable regulations and rules in the Kingdom of Saudi Arabia, the Controller shall notify SDAIA within a period not exceeding (72) hours”
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityEssential Cybersecurity Controls (ECC-2:2024) — binding on government agencies and critical national infrastructure
cdn.nca.gov.sa
Link checked 18 August 2026
What trips people up in Saudi Arabia?
Five things that are not in the summary. One: sending data abroad is not only about protecting the individual — you must also assess whether the transfer could harm the Kingdom's own vital interests, and there is a government guide telling you how. Two: the standard contract must be copied word for word, and changing it is itself a breach of the law, while the overseas recipient has to accept Saudi courts. Three: leaking or publishing sensitive data to hurt someone or to profit can put a person in prison for up to two years — this is a criminal charge, not a fine. Four: your supplier contract must go beyond a normal data processing agreement and say whether the supplier is subject to foreign laws and how that affects its compliance. Five: the widely quoted rule that all government and critical infrastructure data must be hosted inside Saudi Arabia was deleted in 2024, and quoting it today is wrong.
1. National-interest screening. Article 29(2)(a) of the Law forbids a transfer that would prejudice national security or the vital interests of the Kingdom, and SDAIA's Risk Assessment Guideline of February 2025 devotes a whole phase to identifying factors for that analysis. It asks for the exact country of storage, whether it is public or private cloud, whether the impact reaches beyond the individual to their family or to society, and whether the recipient's own laws obstruct compliance. This is a sovereignty test bolted onto a privacy test, and it has no direct equivalent in European practice. 2. Word-perfect standard clauses and submission to Saudi jurisdiction. Rule 5 of the Standard Contractual Clauses treats any edit to the approved text as a violation; rule 7 blocks the route entirely where the recipient's local law prevents compliance; rule 8 requires the importer to submit to the Kingdom's jurisdiction and to enforce binding Saudi decisions; rule 9 requires the importer to answer the regulator's requests and cooperate with audits. 3. Criminal liability for individuals. Article 35 of the Law punishes disclosing or publishing sensitive data with intent to harm or to gain, with up to two years in prison or a fine up to 3 million Saudi riyals (about US$800,000), or both, and the fine may be doubled for a repeat offence. Sensitive data in Saudi Arabia expressly includes religious, intellectual or political belief, and data showing that one or both of a person's parents are unknown — categories that are not on the usual global list. 4. Supplier contracts must go further than a normal processing agreement. Article 17 of the Implementing Regulation requires the contract to state whether the processor is subject to another country's regulations and the effect on its compliance, and to remove any requirement for the individual's consent before a disclosure that Saudi law makes mandatory, provided the processor tells the controller. Sub-processors need the controller's prior acceptance, and a processor that ignores instructions is treated as a controller and is directly liable. 5. The deleted localisation rule. Sub-control 4-2-3-3 of the Essential Cybersecurity Controls and sub-controls 2-3-P-1-10 and 2-3-P-1-11 of the Cloud Cybersecurity Controls were removed in the 2024 editions and the mandate moved to the National Data Management Office. Anyone still citing 'ECC 4-2-3-3' as a live in-Kingdom hosting mandate is citing a deleted control. The duty that replaced it is a duty to ask that office before acting. 6. Bonus: you cannot file a breach report if you have not already registered on the National Data Governance Platform.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Protection Law, Article 1(11) (sensitive data), Article 29(2)(a) and Article 35 (imprisonment up to two years)
sdaia.gov.sa
“any individual discloses or publishes Sensitive Data, in violation of the provisions of the Law, with the intention of harming the Data Subject or achieving a personal benefit shall be punished with imprisonment for a period not exceeding (two years), or a fine not exceeding (three million) Riyals, or both.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityImplementing Regulation, Article 17 — processor selection and mandatory contract terms
sdaia.gov.sa
“Clarification of whether the Processor is subject to Regulations in other countries and the impact on their compliance with the Law and its Regulations.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityRisk Assessment Guideline for Transferring Personal Data Outside the Kingdom, February 2025 — vital interests of the Kingdom
sdaia.gov.sa
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityEssential Cybersecurity Controls (ECC-2:2024) — deletion of the in-Kingdom hosting sub-control
cdn.nca.gov.sa
Link checked 18 August 2026
What is changing soon in Saudi Arabia?
Nothing is scheduled to commence on a fixed date in the next twelve months — the law and all its main regulations are already fully in force. The risk is the opposite kind: several switches the government already holds and can flip with no consultation. The biggest is the approved-country list, which the regulator is legally required to publish and has not; the day it appears, every transfer plan in the country needs rechecking. The second biggest is the missing localisation rule for government and critical infrastructure, which one office was handed in 2024 and has not yet written.
DORMANT SWITCHES, all traceable to text already in force: 1. The adequacy list. Article 3 of the Transfer Regulation requires SDAIA to publish a list of countries and international organisations with adequate protection, reviewed every four years or as needed. No list found as at 18 August 2026. Publication would immediately change which transfers need standard contractual clauses. Article 3(4) says the same tests apply to cities, special economic zones and global trade centres, so a jurisdiction could be listed or excluded in part. 2. Suspension of transfers. Article 3(3) lets SDAIA suspend transfer or disclosure to any listed country or organisation. No public procedure or notice period. 3. Withdrawal of an exemption. Article 6 of the Transfer Regulation lets SDAIA decide that a controller's safeguards are inadequate in a specific case, at which point the controller must halt the transfer and tell every recipient. That is a one-organisation kill switch. 4. The transferred localisation mandate. The National Cybersecurity Authority moved data localisation for government bodies and critical national infrastructure to the National Data Management Office in the 2024 control sets. That office has not published a replacement control. It could publish a binding in-Kingdom hosting rule at any time. 5. Registration rules for controllers based outside the Kingdom. The current register rules cover controllers within the Kingdom and state that separate rules for those outside will be issued. When they arrive, foreign companies serving Saudi residents acquire a registration duty they do not have today. 6. Rewriting the standard contract. Rule 11 of the Standard Contractual Clauses lets SDAIA change the clauses at its discretion, with transitional rules to follow. Article 4(4) of the Transfer Regulation lets it review the adequacy of safeguards every two years or as needed — the first such review window has already opened.
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityRegulation on Personal Data Transfer Outside the Kingdom — Article 3 (list and suspension), Article 4(4) (two-yearly review), Article 6 (revocation of exemption)
sdaia.gov.sa
“The competent authority may suspend the transfer or disclosure of personal data to any of the countries or organizations listed in paragraph (1) of this Article, in accordance with the statutory procedures.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityThe Rules Governing the National Register of Controllers Within the Kingdom — separate rules promised for controllers outside the Kingdom
sdaia.gov.sa
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityCloud Cybersecurity Controls (CCC-2:2024) — localisation mandate transferred to the National Data Management Office
cdn.nca.gov.sa
“entities must refer to the National Data Management Office regarding data localization before taking any action in this regard.”
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
2 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
5 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules2 rules
نظام حماية البيانات الشخصية (Personal Data Protection Law)
Act of parliament · Royal Decree No. M/19 dated 9/2/1443 AH, amended by Royal Decree No. M/148 dated 5/9/1444 AH; Implementing Regulation issued 2023
Saudi Arabia's general privacy law. It reaches foreign companies serving people in the Kingdom, runs on consent by default, requires registration on a national platform for most serious processing, and gives 72 hours to report a breach. Data may leave, but only for listed purposes, with a safeguard in place and a written risk assessment first. Penalties include prison for misusing sensitive data.
Enforced by Saudi Data and Artificial Intelligence Authority
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Someone's life is at risk
What it makes you do
- Get consentConsent is the default basis. Legitimate interest is available but never for sensitive data.
- Document a legitimate interestNot usable where sensitive data is processed.
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhereRight to obtain the data in a readable and clear format.
- Secure the data
- Report breaches to the regulator — within 72 hoursFiled through the National Data Governance Platform; prior registration on the platform is a precondition.
- Tell affected peopleWithout undue delay, in simple and clear language, where the breach may damage the person's data or prejudice their rights.
- Keep records of processing — 5 yearsKept throughout processing and for five years after the activity ends.
- Delete data after a periodDestroy without undue delay once the purpose ends, including all backups; a statutory minimum period overrides.
- Assess high-risk projects — applies at: Sensitive data, data linking from multiple sources, large-scale or systematic monitoring, emerging technologies, automated decisions, or any high-risk product or service
- Appoint a data protection officer — applies at: Public bodies processing at large scale; controllers whose core activity requires regular systematic monitoring; controllers whose core activity is sensitive dataMay be an employee or an external contractor, and may be located outside the Kingdom.
- Register or notify — applies at: Public bodies; controllers whose main activity is personal data processing; controllers processing sensitive data; individuals processing beyond personal or family useRegistration on the National Data Governance Platform. Certificate valid up to five years.
- Written vendor contract
- Extra vendor secrecy termsThe contract must state whether the processor is subject to another country's laws and the effect on compliance; confidentiality survives the end of the relationship.
- Put a transfer safeguard in place
- Get a parent's consent for childrenFramed as consent of the legal guardian where the data subject fully or partly lacks legal capacity; no fixed digital age is stated in the Law.
What it costs if you get it wrong
- Criminal liability: SAR 3,000,000 and/or 2 years imprisonment — about $800 thousandDisclosing or publishing sensitive data with intent to harm the individual or to gain a personal benefit; fine may be doubled for a repeat offence
- Fixed maximum fine: SAR 5,000,000 — about $1 millionAny other violation of the Law or the Regulations; may be doubled for a repeat violation
- Claims by individualsIndividuals may sue for proportionate compensation for material or moral damage
- Order to stopThe regulator may seize the means or tools used in a violation and a court may order confiscation and publication of the decision at the violator's expense
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityPersonal Data Protection Law (consolidated English text)
sdaia.gov.sa
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityImplementing Regulation of the Personal Data Protection Law
sdaia.gov.sa
“This Regulation shall be published in the official gazette and on the official website of the Competent Authority and shall come into force from the date of the Law's enforcement.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthoritySDAIA Laws and Regulations index — the law, the implementing regulation and all subordinate rules
sdaia.gov.sa
Link checked 18 August 2026
Regulation on Personal Data Transfer Outside the Kingdom, version 2.0
Directly binding regulation · Issued under Article 29(4) of the Personal Data Protection Law; version 2.0 dated August 2024
The rules for sending personal data abroad. The intended route is a published list of approved destinations, which does not exist yet, so in practice organisations use the government's standard contract, approved group-wide rules or an accreditation certificate. Every one of those routes also requires a written risk assessment that considers harm to the Kingdom, and the law follows the data onward to any further recipient.
Enforced by Saudi Data and Artificial Intelligence Authority
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme
What it makes you do
- Put a transfer safeguard in placeStandard contractual clauses, binding common rules, or an accreditation certificate from a body licensed by SDAIA. The standard clauses must be reproduced word for word.
- Assess high-risk projectsWritten risk assessment required before any transfer relying on an exemption, and before any continuous or large-scale export of sensitive data. It must cover the effect on the Kingdom's vital interests.
- Keep records of processingThe processing record must describe every transfer outside the Kingdom, its legal basis and its recipients.
What it costs if you get it wrong
- Order to stopIf the regulator finds the safeguards inadequate, the controller must halt the transfer and notify every recipient
Sources
- Official sourceSaudi Data and Artificial Intelligence AuthorityRegulation on Personal Data Transfer Outside the Kingdom, version 2.0, August 2024
sdaia.gov.sa
“The Regulation shall enter into force on the date of its publication in the Official Gazette.”
Link checked 18 August 2026
- Official sourceSaudi Data and Artificial Intelligence AuthorityStandard Contractual Clauses For Personal Data Transfer, version 1.0, September 2024
sdaia.gov.sa
“To ensure effective enforcement of these Clauses, the Personal Data Importer submits to the jurisdiction of the Kingdom”
Link checked 18 August 2026
Industry rules5 rules
Rules on Outsourcing
Regulator directive · SAMA circular No. 41027017 dated 18/4/1441 AH (15 December 2019); supersedes circular 34720/B.C.S of 20 July 2008 · Banking
A Saudi bank cannot put customer or financial data with an overseas supplier without the central bank's written no-objection first. The application must say why the work cannot be done inside the Kingdom, include a legal opinion, and confirm the central bank can inspect the overseas provider. The general privacy law does not override this, because it expressly preserves the central bank's powers.
Enforced by Saudi Central Bank
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Put a transfer safeguard in placeWritten SAMA no-objection required for every overseas outsourcing arrangement, material or not.
- Written vendor contractThe application must include a legal opinion confirming compliance with the Banking Control Law and a written confirmation of SAMA's right of access to the overseas provider.
- Independent auditAnnual return on outsourcing services provided and received.
What it costs if you get it wrong
- Loss of your licenceSupervisory action under the Banking Control Law for outsourcing without no-objection
Sources
- Official sourceSaudi Central BankRules on Outsourcing, section V — Outsourcing to Third-Party Service Providers Located Overseas, paragraph 42
rulebook.sama.gov.sa
“For any proposed outsourcing arrangements to a third-party service provider located overseas, banks are required to seek a written SAMA no objection”
Link checked 18 August 2026
- Official sourceSaudi Central BankRules on Outsourcing — circular No. 41027017, status In-Force
rulebook.sama.gov.sa
Link checked 18 August 2026
SAMA Cyber Security Framework, control 3.4.3 Cloud Computing
Regulator guideline · Saudi Arabian Monetary Authority Cyber Security Framework, version 1.0, May 2017 · Finance
For banks, finance companies and other firms supervised by the Saudi Central Bank, the starting answer on public or hybrid cloud is that it must sit inside Saudi Arabia. Going outside needs the central bank's explicit approval, and the cloud contract must give the firm audit rights, keep its data logically separated, ban the provider from any secondary use, and require irreversible deletion when the contract ends.
Enforced by Saudi Central Bank
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryDefault position is that public and hybrid cloud services must be located in Saudi Arabia; using cloud outside the Kingdom requires explicit SAMA approval. Does not apply to private (internal) cloud.
- Written vendor contractContract must include cyber security requirements before use, rights to review, audit and examine the provider, data segregation, no secondary use of the data, and irreversible deletion on termination.
- Secure the data
Sources
- Official sourceSaudi Central BankSAMA Cyber Security Framework, control 3.4.3 Cloud Computing — data location and contractual requirements
rulebook.sama.gov.sa
“in principle only cloud services should be used that are located in Saudi Arabia, or when cloud services are to be used outside Saudi Arabia that the Member Organization should obtain explicit approval from SAMA”
Link checked 18 August 2026
Essential Cybersecurity Controls, sub-control 4-2-3-3 (in-Kingdom hosting and storage)
Government rules · ECC-1:2018 sub-control 4-2-3-3, deleted by ECC-2:2024 (Annex, List of Updates); issued under Article 10(3) of the NCA Statute and High Order No. 57231 dated 10/11/1439 AH · Government
This is the rule most trackers still get wrong. Until 2024 Saudi government bodies and critical national infrastructure had to host and store their information inside the Kingdom under a cybersecurity control. That control was deleted in the 2024 edition. The requirement was not simply abolished — it was handed to a data office at the national data authority, which has not published a replacement, and entities must now ask that office before making any localisation decision.
Enforced by National Cybersecurity Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryNo longer a standing obligation. Replaced by a duty to refer the question to the National Data Management Office at SDAIA before taking any data localisation decision.
Sources
- Official sourceNational Cybersecurity AuthorityEssential Cybersecurity Controls (ECC-2:2024), Annex — List of Updates
cdn.nca.gov.sa
“Deletion / Sub-control 4-2-3-3 / Entity's information hosting and storage must be inside the Kingdom of Saudi Arabia / Controls related to data localization have been transferred from the document to the National Data Management Office (NDMO) at the Saudi Data and Artificial Intelligence Authority for as per the mandates, and entities must refer to the National Data Management Office regarding data localization before taking any action in this regard.”
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityNational Cybersecurity Authority — Essential Cybersecurity Controls page (ECC-2:2024), published 31 July 2025
nca.gov.sa
Link checked 18 August 2026
Cloud Cybersecurity Controls (CCC-2:2024)
Government rules · CCC-2:2024, replacing CCC-1:2020; issued under Article 10(3) of the NCA Statute and Royal Decree No. 57231 · Government
Binding cybersecurity rules for any cloud provider serving Saudi government bodies or private operators of critical national infrastructure, and for those customers. The 2024 edition removed the two controls that required the service, its storage, disaster recovery, monitoring and support to be delivered from inside the Kingdom, and pointed entities to the national data office instead.
Enforced by National Cybersecurity Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Hold a security certificateBinding on every cloud provider serving a Saudi government body or a private operator of critical national infrastructure, and on those customers themselves. Compliance with the Essential Cybersecurity Controls is required as well.
- Keep the data in the countryThe two in-Kingdom service delivery sub-controls (2-3-P-1-10 and 2-3-P-1-11) were deleted in this edition and moved to the National Data Management Office.
- Secure the dataIncludes screening and vetting of provider personnel working inside the Kingdom.
Sources
- Official sourceNational Cybersecurity AuthorityCloud Cybersecurity Controls (CCC-2:2024), scope of work and Annex D (List of Updates)
cdn.nca.gov.sa
“Controls related to data localization have been transferred from the document to the National Data Management Office (NDMO) at the Saudi Data and Artificial Intelligence Authority”
Link checked 18 August 2026
- Official sourceNational Cybersecurity AuthorityNational Cybersecurity Authority — Cloud Cybersecurity Controls page
nca.gov.sa
“The Cloud Cybersecurity Controls (CCC - 2: 2024) have been updated to reflect changes related to data localization requirements.”
Link checked 18 August 2026
National Data Management and Personal Data Protection Standards; Data Classification Policy and Regulations
Government policy document · Issued by the National Data Management Office under Cabinet Resolution No. 292 dated 27/4/1441 AH · Government
If you are a supplier holding Saudi government data, these standards bind you as well as the government body. They cover fifteen data management areas, require every piece of government data to be classified into one of four levels, and are scored for compliance each year. They are also the place where the data localisation mandate for government and critical infrastructure was moved in 2024, but no localisation control has yet appeared in them.
Enforced by National Data Management Office
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep records of processingFifteen data management domains, assessed for compliance yearly.
- Written vendor contractScope extends to business partners handling government data, who must apply the standards to all government data in their control.
- Secure the dataGovernment data must be classified as Top Secret, Secret, Restricted or Public before it is handled.
Sources
- Official sourceNational Data Management Office, Saudi Data and Artificial Intelligence AuthorityNational Data Management and Personal Data Protection Standards, purpose and scope
sdaia.gov.sa
“In addition to Public Entities, the scope of the National Data Management and Personal Data Protection Standards also extends to business partners handling government data.”
Link checked 18 August 2026
- Official sourceNational Data Management Office, Saudi Data and Artificial Intelligence AuthorityData Classification Policy and Regulations — Top Secret, Secret, Restricted, Public
sdaia.gov.sa
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the one-year grace period for compliance ran to 14 September 2024
The consolidated text of the law we obtained from the regulator contains Article 43 (in force 720 days after publication, giving 14 September 2023) but not the transitional provision added by the 2023 amending Royal Decree. We could not open the official gazette copy, so the exact final day of the grace period is inferred rather than quoted. Plan to the earlier date.
That no list of countries with an adequate level of protection has been published
This is a negative. Article 3 of the Transfer Regulation obliges the regulator to publish one on its official website, and we found no such list on that site or on the National Data Governance Platform on 18 August 2026. A list published in Arabic only, or behind the platform's login, would not have been visible to us.
That the Saudi privacy regulator has issued no public enforcement decisions
We found no published register of fines or named decisions. Saudi practice does not require the regulator to publish them, so absence of published decisions is not evidence that none exist. The enforcement rating of 'waking' reflects what is observable, not a claim that nothing is happening.
Whether a telecom-specific data storage or localisation rule exists
The Communications, Space and Technology Commission runs its regulations on a separate platform (mutasilind.cst.gov.sa) which refused all connections from our network on 18 August 2026, and the older cloud computing framework link on the legacy regulator domain now redirects to the home page. We therefore neither assert nor deny a telecom rule.
Whether health, insurance, securities or geospatial rules impose storage inside the Kingdom
We could not verify any. The survey and geospatial authority's domain was blocked by our network's egress policy; the capital market and insurance regulators' rulebooks were reachable but we did not locate a storage-location provision in the time available. Treat these four sectors as unresearched rather than as clear.
Whether the National Data Management Office has issued any replacement data localisation control since the 2024 cybersecurity control deletions
We searched the national data management standards and the data classification policy published on the regulator's own site and found no hosting-location requirement. A rule issued to government entities directly, rather than published, would not be visible to us. This is the single most consequential open question in this record.
The exact minimum retention period for tax and value added tax records
The tax authority's regulation pages load their document lists with scripts and every direct link we tried to the value added tax implementing regulation returned the site's error page. We therefore state the cross-reference from the E-Invoicing Regulation without asserting a number of years.
The exact date the Regulation on Personal Data Transfer Outside the Kingdom was published in the official gazette
The regulation itself is dated August 2024 and says it enters into force on publication in the gazette. We could not reach the gazette site. We record 6 September 2024, which matches the September 2024 dating of the accompanying standard contractual clauses and binding common rules guidelines, but it is inferred.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Saudi Arabia versus Argentina
- Saudi Arabia versus Armenia
- Saudi Arabia versus Australia
- Saudi Arabia versus Austria
- Saudi Arabia versus Azerbaijan
- Saudi Arabia versus Brazil
- Saudi Arabia versus Bulgaria
- Saudi Arabia versus Cambodia
- Saudi Arabia versus Canada
- Saudi Arabia versus China
- Saudi Arabia versus Croatia
- Saudi Arabia versus Cyprus
- Saudi Arabia versus Estonia
- Saudi Arabia versus France
- Saudi Arabia versus Georgia
- Saudi Arabia versus Germany
- Saudi Arabia versus Greece
- Saudi Arabia versus Hong Kong SAR
- Saudi Arabia versus Hungary
- Saudi Arabia versus Iceland
- Saudi Arabia versus India
- Saudi Arabia versus Indonesia
- Saudi Arabia versus Ireland
- Saudi Arabia versus Israel
- Saudi Arabia versus Italy
- Saudi Arabia versus Japan
- Saudi Arabia versus Latvia
- Saudi Arabia versus Lithuania
- Saudi Arabia versus Luxembourg
- Saudi Arabia versus Malta
- Saudi Arabia versus Mexico
- Saudi Arabia versus Mongolia
- Saudi Arabia versus Nepal
- Saudi Arabia versus Netherlands
- Saudi Arabia versus Poland
- Saudi Arabia versus Russia
- Saudi Arabia versus Serbia
- Saudi Arabia versus Singapore
- Saudi Arabia versus Slovakia
- Saudi Arabia versus Slovenia
- Saudi Arabia versus South Korea
- Saudi Arabia versus Spain
- Saudi Arabia versus Sri Lanka
- Saudi Arabia versus Sweden
- Saudi Arabia versus Switzerland
- Saudi Arabia versus Taiwan
- Saudi Arabia versus Thailand
- Saudi Arabia versus Turkey
- Saudi Arabia versus Ukraine
- Saudi Arabia versus United Arab Emirates
- Saudi Arabia versus United Kingdom
- Saudi Arabia versus United States
- Saudi Arabia versus Uzbekistan