An Overview of Regulation on Personal Data Transfer Outside the Kingdom

Contributors

Anas Baig

Product Marketing Manager at Securiti

Asaad Ahmad Qureshy

Associate Data Privacy Analyst at Securiti

Salma Khan

Data Privacy Analyst at Securiti

CIPP/Asia

Published October 8, 2024 / Updated September 30, 2026

Listen to the content

I. Introduction

Stringent rules govern the transfer of personal data outside the Kingdom of Saudi Arabia to protect individual privacy and maintain data security. With the progression of digital globalization, organizations operating in Saudi Arabia routinely engage in cross-border data transfers, necessitating compliance with evolving data protection regulations.

Saudi Arabia's Personal Data Protection Law (PDPL) governs cross-border data transfers. The law has been fully enforceable since 14 September 2024, and it permits a transfer outside the Kingdom only for a permitted purpose, to a destination that provides an adequate level of protection or under appropriate safeguards, limited to the minimum personal data necessary and, where required, after a documented risk assessment. The Saudi Data and Artificial Intelligence Authority (SDAIA) is the Kingdom's regulatory authority overseeing cross-border data transfer under PDPL, and its violation-review committees issued 48 penalty decisions in 2025, including for disclosing personal data without legal justification.

On September 1, 2024, the SDAIA released an updated version of the Regulation on Personal Data Transfer Outside the Kingdom, providing further details on Article 29 of the Saudi Personal Data Protection Law. It replaced the Transfer Regulation first published on 7 September 2023 and was issued together with SDAIA's Standard Contractual Clauses and Guidelines for Binding Common Rules. This update offers a comprehensive overview of the requirements for cross-border personal data transfers, intending to strengthen the legal framework regulating data privacy and security for transfers outside the Kingdom.

Since then, SDAIA has completed the transfer framework in three steps. The Minimum Personal Data Determination Guideline (in force 30 August 2024) explains how controllers satisfy the data-minimization condition. The Risk Assessment Guideline for Transferring Personal Data Outside the Kingdom (February 2025) sets out a four-phase method for the transfer risk assessment described in section VI. And on 17 February 2026, SDAIA issued the Rules Governing the Issuance of Accreditation Certificates to Controllers and Processors, together with the Rules Governing the Licensing of Activities for Issuing Accreditation Certificates and for Auditing and Inspection of Personal Data Processing Activities, which turn the certificate of accreditation, the third appropriate safeguard, into an operational option. SDAIA has not yet published its list of adequate countries, so in practice every transfer outside the Kingdom currently rests on one of the appropriate safeguards.

II. Key Definitions

a. Appropriate Safeguards

Requirements that SDAIA imposes on controllers so that personal data transferred or disclosed to entities outside the Kingdom receives protection at least equal to that prescribed by the PDPL and its regulations, in the cases where the controller is exempted from the adequacy condition. The Regulation recognizes three appropriate safeguards: Standard Contractual Clauses, Binding Common Rules and a Certificate of Accreditation.

b. Standard Contractual Clauses (SCCs)

Mandatory provisions governing the transfer of personal data outside the Kingdom that ensure an appropriate level of protection for such data. These provisions are in accordance with a standard form issued by SDAIA. SDAIA published its SCCs on 1 September 2024 in four versions: controller-to-controller, controller-to-processor, processor-to-controller and processor-to-processor. They may not be modified, may bind more than two parties, and require the data importer to comply with binding decisions issued under Saudi law; they cannot be relied on where the laws of the recipient country prevent the importer from complying with them.

c. Binding Common Rules (BCRs)

Rules established by the controller, binding on each controller and processing entity within a multinational group, that ensure adequate protection of personal data transferred outside the Kingdom, maintaining a standard no less than that mandated by the Law and Regulations. SDAIA's Guidelines for Binding Common Rules (1 September 2024) set out their minimum content, including data subject rights, cooperation with SDAIA, internal approval, binding effect on every member of the group and breach-notification procedures. See our overview of the BCR Guidelines.

d. Certificate of Accreditation

A certificate issued by an entity licensed by SDAIA confirming that a controller's or processor's processing practices comply with the PDPL, its Implementing Regulations and the Transfer Regulation. Under the rules issued on 17 February 2026, applicants must already be registered on the National Register of Controllers and are assessed by the licensee within 90 business days; the certificate is valid for two years and is revoked if the holder ceases to comply. SDAIA will publish the list of certified entities on its website.

e. Operational Processes

An assortment of procedures relevant to the operational processes essential for the controller's activities, including human resources operations, billing, accounting, and further workflow-related procedures.

III. Purposes for Transferring or Disclosing Personal Data to Entities Outside the Kingdom

Article 29 of the PDPL outlines acceptable purposes for transferring or disclosing personal data to entities outside Saudi Arabia. These include:

  • Performing an obligation under an agreement to which the Kingdom is a party
  • Serving the Kingdom's interests
  • Performing an obligation to which the data subject is a party
  • Any other purposes set out in the Transfer Regulation

Article 2 of the Regulation sets out three additional purposes for transfers outside the Kingdom:

  • Central Processing Operations: Transfers necessary for central data processing to allow the data controller to conduct its activities.
  • Providing Services or Benefits: Transfers that provide a service or benefit to the data subject.
  • Scientific Research and Studies: Transfers made for conducting scientific research or studies.

Article 29 also attaches three conditions to every transfer or disclosure: it must not compromise national security or the Kingdom's vital interests; an adequate level of protection, at least equal to the PDPL's, must exist outside the Kingdom as determined by SDAIA's assessment (or the controller must rely on an appropriate safeguard where the Regulation permits); and the transfer must be limited to the minimum personal data necessary. These conditions do not apply in cases of extreme necessity to protect the life or vital interests of the data subject or to prevent, diagnose, or treat disease.

IV. Guidelines for Assessing Personal Data Protection Levels Outside the Kingdom

On its official website, the SDAIA is to publish the list of countries or international organizations that provide an adequate level of personal data protection on par with the requirements outlined in the PDPL and Implementing Regulations. As of September 2026, no list has been published; until it is, controllers must rely on the appropriate safeguards described in section V for every transfer outside the Kingdom.

This list will be reviewed every four years or more often as required per specific standards to ensure ongoing compliance and appropriateness.

a. Regulatory Requirements for Data Protection and Subject Rights

Countries or organizations must have regulations that protect personal data and honor data subjects' rights, including the ability to seek compensation for damages resulting from violations. The level of protection these regulations provide must, at the bare minimum, meet the standards set by Saudi PDPL and its Implementing Regulations.

b. Supervisory Authority with Cooperative Framework for Data Protection

The foreign country or organization must have a supervisory authority responsible for implementing data privacy legislation. Additionally, to ensure cooperative enforcement and cross-border compliance, this authority must be able and willing to cooperate with SDAIA on personal data protection issues.

c. Alignment of Foreign Regulatory Requirements with Saudi Data Disclosure Laws

The disclosure provisions specified in Saudi PDPL and its Implementing Regulations must not conflict with the regulatory requirements for disclosing personal data in a foreign country or international organization or with any other laws currently in effect in Saudi Arabia.

d. Obligations from International Treaties and Agreements on Data Transfers

Treaty or agreement-bound states and international organizations, as well as those participating in regional or multilateral organizations, have duties that may necessitate the transmission of personal data. When transferring data across borders, these responsibilities must be considered and in line with Saudi data protection legislation.

SDAIA may, following the prescribed legal procedures, amend the list of countries or international organizations that provide an adequate level of personal data protection.

If a review indicates that a country or organization no longer meets the necessary protection requirements, the SDAIA may collaborate with relevant parties to address the concerns. Moreover, it may suspend disclosing or transferring data to certain organizations. Additionally, cities, global trade centers, and special economic zones are all subject to the same evaluation criteria for personal data protection as nations and international organizations.

V. When Controllers May Rely on Appropriate Safeguards Instead of an Adequacy Finding

Article 4 of the Regulation exempts controllers from the adequacy condition in Article 29 where they implement one of the following appropriate safeguards, each of which must guarantee protection at least equal to the PDPL and its Implementing Regulations:

  1. Standard Contractual Clauses: Legal agreements that ensure data protection during transfers, using SDAIA's four standard forms without modification.
  2. Binding Common Rules: Internal policies that apply across a multinational group to safeguard data, prepared in line with SDAIA's BCR Guidelines.
  3. Certificate of Accreditation: Certification that verifies compliance with data protection standards, issued by a body licensed by SDAIA under the rules of 17 February 2026.

When relying on appropriate safeguards, controllers are exempt from ensuring that an adequate level of personal data protection exists outside the Kingdom, which must be at least equal to the protection guaranteed by the PDPL and Implementing Regulations. The 2024 Regulation also relieves controllers relying on an appropriate safeguard of the separate requirement to limit the transfer to the minimum personal data necessary, although the PDPL's general minimization principle continues to apply to the processing itself.

The Regulation then specifies the cases in which a transfer may proceed under appropriate safeguards without an adequacy finding:

a. Standard Provisions for Protecting Personal Data

Data controllers must implement standard provisions for protecting personal data in any relevant agreements or memoranda of understanding where personal data is transferred or disclosed between public entities. This ensures that personal data is protected in compliance with appropriate legal requirements throughout such exchanges.

b. Non-Recurring or Limited Data Transfers

One-time or non-recurring transfers involving a limited number of data subjects may proceed where the controller uses SDAIA's SCCs or transfers the data to an entity holding a certificate of accreditation issued by a body licensed by SDAIA, and the data is not sensitive.

c. Data Transfers for Multinational Entities

A data controller and its affiliates must comply with BCR or SCC provisions that meet legal and regulatory requirements when the controller, as part of a multinational group, transfers or discloses personal data for central operations. Alternatively, the recipient entity must hold a certificate of accreditation from a body licensed by SDAIA.

d. Conditions for Data Transfer or Disclosure when Providing a Service or Benefit

The transfer or disclosure of data is permissible if it:

  1. Provides a service or benefit directly to the data subject.
  2. Does not violate the data subject's expectations or conflict with their interests.
  3. Is made to a party holding a certificate of accreditation issued by a body licensed by SDAIA.
  4. Does not involve sensitive data.

e. Conditions for Data Transfer or Disclosure when Needed for Scientific Research

Personal data may be transferred or disclosed to the extent required for scientific research or studies and must be limited to the minimum necessary. The controller must either use SDAIA's SCCs or transfer the data to an entity holding a certificate of accreditation, and no sensitive data may be involved.

Data controllers must ensure that data subjects' rights are protected, compliance with PDPL and its Implementing Regulations is maintained, and data subjects can conveniently submit complaints and seek damages for violations. Moreover, the SDAIA may review the adequacy of the appropriate safeguards listed for each exemption instance every two years or as often as needed.

VI. Risk Assessment for Cross-Border Data Transfers

Under the Regulation, a risk assessment is required in two situations: before transferring or disclosing personal data under one of the appropriate safeguards described above, and whenever sensitive data is transferred or disclosed outside the Kingdom on a continuous or large-scale basis. This is narrower than the 2023 Regulation, which required an assessment before every transfer.

When transferring or disclosing personal data to a party outside the Kingdom, a risk assessment should address several key elements. Among them are:

  • the purpose and legal basis for the transfer;
  • a description of the nature of the transfer, including the data processing activities and geographical scope;
  • the safeguards in place to ensure adequate data protection in line with legal requirements;
  • measures ensuring only the minimum necessary data is transferred;
  • the potential material or moral effects of the transfer and their likelihood; and
  • controls to prevent or mitigate risks to data subjects.

SDAIA's Risk Assessment Guideline for Transferring Personal Data Outside the Kingdom (February 2025) turns these elements into a four-phase method: preparation (deciding whether an assessment is required, and defining the purpose, legal basis, nature and geographic scope of the transfer); assessing negative impacts and potential risks to data subjects; assessing transfer-specific risks, including the recipient jurisdiction's legal framework and the receiving entity's security measures; and assessing implications for the Kingdom's vital interests. The assessment should be documented before the transfer and repeated when its volume, sensitivity or destination changes.

VII. How Securiti Can Help

Securiti helps organizations operationalize the Transfer Regulation. Its platform discovers and classifies personal and sensitive data across on-premises, cloud and SaaS systems, maps every flow that leaves the Kingdom to its purpose, recipient and safeguard, and records transfers in the record of processing activities. Assessment automation runs transfer risk assessments and vendor assessments from templates aligned to SDAIA's guideline, tracks SCCs, Binding Common Rules and accreditation certificates against each vendor, and flags transfers for reassessment when their volume or sensitivity changes, so the evidence is ready when SDAIA asks.

Securiti is the pioneer of the DataAI Command Platform, a centralized platform that enables the safe use of data and GenAI. Securiti provides unified data intelligence, controls, and orchestration across hybrid multi-cloud environments. Large global enterprises rely on Securiti's DataAI Command Platform for data security, privacy, governance, and compliance.

Request a demo to learn more. See also our Saudi Arabia PDPL solution, the PDPL overview and the BCR Guidelines overview.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 59:11
Data Controls for AI: Findings from the 2026 GigaOm DSPM Research
Watch Now View
Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight
Choosing the Right DSPM: An Industry Analyst’s Perspective
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Latest
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach View More
Australia’s Office of AI: Why Annual Audits Miss What Your AI Can Reach
Picture this: a fictional but entirely plausible scenario. An Australian financial institution's AI systems spend six months accessing a customer data repository nobody has...
View More
A Complete DSPM Needs Classification and Context
Classification is one of the core functions a DSPM program handles, and it usually runs in tandem with discovery, since together they form the...
View More
DSPM for AI: Extending Data Posture to Prompts, Pipelines & Agents
Learn how DSPM for AI helps enterprises discover sensitive data, assess exposure, govern access, reduce risk, and secure data before AI systems and agents...
DSPM vs DLP: Key Data Security Differences Explained View More
DSPM vs DLP: Key Data Security Differences Explained
Compare DSPM vs DLP to understand how they differ in data discovery, classification, monitoring, prevention, risk reduction, and protecting sensitive enterprise data.
The Context Layer for Data+AI Security View More
The Context Layer for Data+AI Security
Discover how Securiti’s DataAI Command Graph connects data, identity, cloud, and AI findings to uncover contextual risk and toxic combinations.
View More
Privacy RFP Buyer’s Guide: 120+ Questions to Evaluate Privacy Automation Platforms
Download the Privacy RFP Buyer’s Guide with 120+ practical questions to evaluate privacy automation platforms across compliance, security, integrations, governance, and scalability.
The Toxic Combination Problem in DataAI Risks View More
The Toxic Combination Problem in DataAI Risks
Discover how siloed security alerts create hidden toxic risk combinations and how correlated context helps reduce alert fatigue and uncover compound risks faster.
The Cloud Storage Bill Nobody Reads View More
The Cloud Storage Bill Nobody Reads
Hidden cloud storage costs add up fast. Learn how redundant, obsolete, and trivial data drives unnecessary spend, expands risk, and why automated data minimization...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New