Saudi Arabia flag

Saudi Arabia

Saudi Arabia Data Transfers and Localization: The PDPL Transfer Process

By Recording Law Editorial Team16 min read
Saudi Arabia Data Transfers and Localization: The PDPL Transfer Process

Frequently Asked Questions

Does Saudi Arabia's PDPL require personal data to be stored inside the Kingdom?

No. This is a commonly repeated but incorrect claim about Gulf privacy laws. A direct search of the PDPL and its Implementing Regulation found no provision requiring personal data to be processed or stored inside Saudi Arabia by default. The Data Transfer Regulation governs the conditions for moving data out of the Kingdom; it does not prohibit outbound transfer or require data to stay in-country.

Can a company transfer personal data from Saudi Arabia to a country on the strength of an adequacy decision?

Not currently. Data Transfer Regulation Articles 3 and 4 create an adequacy-decision process where SDAIA evaluates a destination and recommends a decision to the Prime Minister, but no adequacy decision has been published for any country, sector, or organization as of this research. The route exists in law but has no practical use today.

What is the default transfer mechanism most companies actually use?

Standard Contractual Clauses, following the standard model SDAIA issued in September 2024 under Data Transfer Regulation Article 5. With no adequacy list available, SCCs are the practical default for vendor and service-provider transfers, while Binding Common Rules suit recurring intra-group transfers within a multinational.

When is a documented risk assessment mandatory for a Saudi data transfer?

Under Data Transfer Regulation Article 8, whenever the transfer relies on an appropriate-safeguards mechanism (Article 5), relies on a narrow exception (Article 6), or is a continuous or large-scale transfer of Sensitive Data regardless of mechanism. In practice, most real transfers meet at least one of these triggers.

What does SDAIA's February 2025 Risk Assessment Guideline actually govern?

It provides SDAIA's implementing guidance on how to conduct the risk assessment that Data Transfer Regulation Article 8 already requires. Article 8 is the underlying legal obligation and fixes what must be assessed; the February 2025 Guideline explains SDAIA's expected method for carrying it out.

What happens if a transfer poses a high privacy risk or affects national security?

Data Transfer Regulation Article 7 requires the controller to immediately stop the transfer and reassess before resuming. This kill-switch obligation is a standing duty that applies for as long as the transfer continues, not a one-time check performed only when the transfer program launches.

Does registering with SDAIA's National Register of Controllers depend on doing cross-border transfers?

The National Register exists under PDPL Article 30(4)(C) and Implementing Regulation Article 34, but the Implementing Regulation delegates the specific registration criteria to separate SDAIA rules rather than fixing them in the Law or Regulation text. Registration status should be confirmed against SDAIA's current published rules directly rather than assumed from the transfer mechanism alone.

What are the penalties for a non-compliant cross-border data transfer?

A transfer-related violation not involving intentional sensitive-data misuse falls under the Article 36 administrative track, a fine of up to SAR 5,000,000, doubled to SAR 10,000,000 on repeat violation. If Sensitive Data is disclosed intentionally to harm the data subject or for personal benefit, Article 35's criminal track applies separately, carrying up to two years' imprisonment and/or a fine of up to SAR 3,000,000. Saudi Arabia has no revenue-percentage fine mechanism like GDPR's 4% of global turnover.

Updates

SDAIA held a third public consultation on proposed amendments to the Implementing Regulation. As of the most recent check, these amendments have not been finalized or adopted, and the live regulatory text still reflects the pre-amendment version. Do not treat the consultation draft as current law.

SDAIA issued its Risk Assessment Guideline for Transferring Personal Data Outside the Kingdom, providing implementing detail for the mandatory Article 8 risk assessments.

SDAIA issued its standard-model Standard Contractual Clauses for cross-border transfers under Data Transfer Regulation Article 5, now the primary safeguard mechanism controllers use given the continued absence of any adequacy decision.

Sources and References

  1. Personal Data Protection Law (Royal Decree No. M/19, as amended by Royal Decree No. M/148) — official English translation(sdaia.gov.sa).gov
  2. Implementing Regulation of the Personal Data Protection Law, including the Data Transfer Regulation chapter (Articles 3-8) — official English translation(sdaia.gov.sa).gov
  3. SDAIA — Regulations and Policies index (SCC model, Risk Assessment Guideline, registration rules, live regulatory status)(sdaia.gov.sa).gov
  4. SDAIA — Data Protection research and regulatory overview(sdaia.gov.sa).gov
Share: