I. Introduction
Stringent rules govern the transfer of personal data outside the Kingdom of Saudi Arabia to protect individual privacy and maintain data security. With the progression of digital globalization, organizations operating in Saudi Arabia routinely engage in cross-border data transfers, necessitating compliance with evolving data protection regulations.
Saudi Arabia's Personal Data Protection Law (PDPL) governs cross-border data transfers. The law has been fully enforceable since 14 September 2024, and it permits a transfer outside the Kingdom only for a permitted purpose, to a destination that provides an adequate level of protection or under appropriate safeguards, limited to the minimum personal data necessary and, where required, after a documented risk assessment. The Saudi Data and Artificial Intelligence Authority (SDAIA) is the Kingdom's regulatory authority overseeing cross-border data transfer under PDPL, and its violation-review committees issued 48 penalty decisions in 2025, including for disclosing personal data without legal justification.
On September 1, 2024, the SDAIA released an updated version of the Regulation on Personal Data Transfer Outside the Kingdom, providing further details on Article 29 of the Saudi Personal Data Protection Law. It replaced the Transfer Regulation first published on 7 September 2023 and was issued together with SDAIA's Standard Contractual Clauses and Guidelines for Binding Common Rules. This update offers a comprehensive overview of the requirements for cross-border personal data transfers, intending to strengthen the legal framework regulating data privacy and security for transfers outside the Kingdom.
Since then, SDAIA has completed the transfer framework in three steps. The Minimum Personal Data Determination Guideline (in force 30 August 2024) explains how controllers satisfy the data-minimization condition. The Risk Assessment Guideline for Transferring Personal Data Outside the Kingdom (February 2025) sets out a four-phase method for the transfer risk assessment described in section VI. And on 17 February 2026, SDAIA issued the Rules Governing the Issuance of Accreditation Certificates to Controllers and Processors, together with the Rules Governing the Licensing of Activities for Issuing Accreditation Certificates and for Auditing and Inspection of Personal Data Processing Activities, which turn the certificate of accreditation, the third appropriate safeguard, into an operational option. SDAIA has not yet published its list of adequate countries, so in practice every transfer outside the Kingdom currently rests on one of the appropriate safeguards.
II. Key Definitions
a. Appropriate Safeguards
Requirements that SDAIA imposes on controllers so that personal data transferred or disclosed to entities outside the Kingdom receives protection at least equal to that prescribed by the PDPL and its regulations, in the cases where the controller is exempted from the adequacy condition. The Regulation recognizes three appropriate safeguards: Standard Contractual Clauses, Binding Common Rules and a Certificate of Accreditation.
b. Standard Contractual Clauses (SCCs)
Mandatory provisions governing the transfer of personal data outside the Kingdom that ensure an appropriate level of protection for such data. These provisions are in accordance with a standard form issued by SDAIA. SDAIA published its SCCs on 1 September 2024 in four versions: controller-to-controller, controller-to-processor, processor-to-controller and processor-to-processor. They may not be modified, may bind more than two parties, and require the data importer to comply with binding decisions issued under Saudi law; they cannot be relied on where the laws of the recipient country prevent the importer from complying with them.
c. Binding Common Rules (BCRs)
Rules established by the controller, binding on each controller and processing entity within a multinational group, that ensure adequate protection of personal data transferred outside the Kingdom, maintaining a standard no less than that mandated by the Law and Regulations. SDAIA's Guidelines for Binding Common Rules (1 September 2024) set out their minimum content, including data subject rights, cooperation with SDAIA, internal approval, binding effect on every member of the group and breach-notification procedures. See our overview of the BCR Guidelines.
d. Certificate of Accreditation
A certificate issued by an entity licensed by SDAIA confirming that a controller's or processor's processing practices comply with the PDPL, its Implementing Regulations and the Transfer Regulation. Under the rules issued on 17 February 2026, applicants must already be registered on the National Register of Controllers and are assessed by the licensee within 90 business days; the certificate is valid for two years and is revoked if the holder ceases to comply. SDAIA will publish the list of certified entities on its website.
e. Operational Processes
An assortment of procedures relevant to the operational processes essential for the controller's activities, including human resources operations, billing, accounting, and further workflow-related procedures.
III. Purposes for Transferring or Disclosing Personal Data to Entities Outside the Kingdom
Article 29 of the PDPL outlines acceptable purposes for transferring or disclosing personal data to entities outside Saudi Arabia. These include:
- Performing an obligation under an agreement to which the Kingdom is a party
- Serving the Kingdom's interests
- Performing an obligation to which the data subject is a party
- Any other purposes set out in the Transfer Regulation
Article 2 of the Regulation sets out three additional purposes for transfers outside the Kingdom:
- Central Processing Operations: Transfers necessary for central data processing to allow the data controller to conduct its activities.
- Providing Services or Benefits: Transfers that provide a service or benefit to the data subject.
- Scientific Research and Studies: Transfers made for conducting scientific research or studies.
Article 29 also attaches three conditions to every transfer or disclosure: it must not compromise national security or the Kingdom's vital interests; an adequate level of protection, at least equal to the PDPL's, must exist outside the Kingdom as determined by SDAIA's assessment (or the controller must rely on an appropriate safeguard where the Regulation permits); and the transfer must be limited to the minimum personal data necessary. These conditions do not apply in cases of extreme necessity to protect the life or vital interests of the data subject or to prevent, diagnose, or treat disease.
IV. Guidelines for Assessing Personal Data Protection Levels Outside the Kingdom
On its official website, the SDAIA is to publish the list of countries or international organizations that provide an adequate level of personal data protection on par with the requirements outlined in the PDPL and Implementing Regulations. As of September 2026, no list has been published; until it is, controllers must rely on the appropriate safeguards described in section V for every transfer outside the Kingdom.
This list will be reviewed every four years or more often as required per specific standards to ensure ongoing compliance and appropriateness.
a. Regulatory Requirements for Data Protection and Subject Rights
Countries or organizations must have regulations that protect personal data and honor data subjects' rights, including the ability to seek compensation for damages resulting from violations. The level of protection these regulations provide must, at the bare minimum, meet the standards set by Saudi PDPL and its Implementing Regulations.
b. Supervisory Authority with Cooperative Framework for Data Protection
The foreign country or organization must have a supervisory authority responsible for implementing data privacy legislation. Additionally, to ensure cooperative enforcement and cross-border compliance, this authority must be able and willing to cooperate with SDAIA on personal data protection issues.
c. Alignment of Foreign Regulatory Requirements with Saudi Data Disclosure Laws
The disclosure provisions specified in Saudi PDPL and its Implementing Regulations must not conflict with the regulatory requirements for disclosing personal data in a foreign country or international organization or with any other laws currently in effect in Saudi Arabia.
d. Obligations from International Treaties and Agreements on Data Transfers
Treaty or agreement-bound states and international organizations, as well as those participating in regional or multilateral organizations, have duties that may necessitate the transmission of personal data. When transferring data across borders, these responsibilities must be considered and in line with Saudi data protection legislation.
SDAIA may, following the prescribed legal procedures, amend the list of countries or international organizations that provide an adequate level of personal data protection.
If a review indicates that a country or organization no longer meets the necessary protection requirements, the SDAIA may collaborate with relevant parties to address the concerns. Moreover, it may suspend disclosing or transferring data to certain organizations. Additionally, cities, global trade centers, and special economic zones are all subject to the same evaluation criteria for personal data protection as nations and international organizations.
V. When Controllers May Rely on Appropriate Safeguards Instead of an Adequacy Finding
Article 4 of the Regulation exempts controllers from the adequacy condition in Article 29 where they implement one of the following appropriate safeguards, each of which must guarantee protection at least equal to the PDPL and its Implementing Regulations:
- Standard Contractual Clauses: Legal agreements that ensure data protection during transfers, using SDAIA's four standard forms without modification.
- Binding Common Rules: Internal policies that apply across a multinational group to safeguard data, prepared in line with SDAIA's BCR Guidelines.
- Certificate of Accreditation: Certification that verifies compliance with data protection standards, issued by a body licensed by SDAIA under the rules of 17 February 2026.
When relying on appropriate safeguards, controllers are exempt from ensuring that an adequate level of personal data protection exists outside the Kingdom, which must be at least equal to the protection guaranteed by the PDPL and Implementing Regulations. The 2024 Regulation also relieves controllers relying on an appropriate safeguard of the separate requirement to limit the transfer to the minimum personal data necessary, although the PDPL's general minimization principle continues to apply to the processing itself.
The Regulation then specifies the cases in which a transfer may proceed under appropriate safeguards without an adequacy finding:
a. Standard Provisions for Protecting Personal Data
Data controllers must implement standard provisions for protecting personal data in any relevant agreements or memoranda of understanding where personal data is transferred or disclosed between public entities. This ensures that personal data is protected in compliance with appropriate legal requirements throughout such exchanges.
b. Non-Recurring or Limited Data Transfers
One-time or non-recurring transfers involving a limited number of data subjects may proceed where the controller uses SDAIA's SCCs or transfers the data to an entity holding a certificate of accreditation issued by a body licensed by SDAIA, and the data is not sensitive.
c. Data Transfers for Multinational Entities
A data controller and its affiliates must comply with BCR or SCC provisions that meet legal and regulatory requirements when the controller, as part of a multinational group, transfers or discloses personal data for central operations. Alternatively, the recipient entity must hold a certificate of accreditation from a body licensed by SDAIA.
d. Conditions for Data Transfer or Disclosure when Providing a Service or Benefit
The transfer or disclosure of data is permissible if it:
- Provides a service or benefit directly to the data subject.
- Does not violate the data subject's expectations or conflict with their interests.
- Is made to a party holding a certificate of accreditation issued by a body licensed by SDAIA.
- Does not involve sensitive data.
e. Conditions for Data Transfer or Disclosure when Needed for Scientific Research
Personal data may be transferred or disclosed to the extent required for scientific research or studies and must be limited to the minimum necessary. The controller must either use SDAIA's SCCs or transfer the data to an entity holding a certificate of accreditation, and no sensitive data may be involved.
Data controllers must ensure that data subjects' rights are protected, compliance with PDPL and its Implementing Regulations is maintained, and data subjects can conveniently submit complaints and seek damages for violations. Moreover, the SDAIA may review the adequacy of the appropriate safeguards listed for each exemption instance every two years or as often as needed.
VI. Risk Assessment for Cross-Border Data Transfers
Under the Regulation, a risk assessment is required in two situations: before transferring or disclosing personal data under one of the appropriate safeguards described above, and whenever sensitive data is transferred or disclosed outside the Kingdom on a continuous or large-scale basis. This is narrower than the 2023 Regulation, which required an assessment before every transfer.
When transferring or disclosing personal data to a party outside the Kingdom, a risk assessment should address several key elements. Among them are:
- the purpose and legal basis for the transfer;
- a description of the nature of the transfer, including the data processing activities and geographical scope;
- the safeguards in place to ensure adequate data protection in line with legal requirements;
- measures ensuring only the minimum necessary data is transferred;
- the potential material or moral effects of the transfer and their likelihood; and
- controls to prevent or mitigate risks to data subjects.
SDAIA's Risk Assessment Guideline for Transferring Personal Data Outside the Kingdom (February 2025) turns these elements into a four-phase method: preparation (deciding whether an assessment is required, and defining the purpose, legal basis, nature and geographic scope of the transfer); assessing negative impacts and potential risks to data subjects; assessing transfer-specific risks, including the recipient jurisdiction's legal framework and the receiving entity's security measures; and assessing implications for the Kingdom's vital interests. The assessment should be documented before the transfer and repeated when its volume, sensitivity or destination changes.
VII. How Securiti Can Help
Securiti helps organizations operationalize the Transfer Regulation. Its platform discovers and classifies personal and sensitive data across on-premises, cloud and SaaS systems, maps every flow that leaves the Kingdom to its purpose, recipient and safeguard, and records transfers in the record of processing activities. Assessment automation runs transfer risk assessments and vendor assessments from templates aligned to SDAIA's guideline, tracks SCCs, Binding Common Rules and accreditation certificates against each vendor, and flags transfers for reassessment when their volume or sensitivity changes, so the evidence is ready when SDAIA asks.
Securiti is the pioneer of the DataAI Command Platform, a centralized platform that enables the safe use of data and GenAI. Securiti provides unified data intelligence, controls, and orchestration across hybrid multi-cloud environments. Large global enterprises rely on Securiti's DataAI Command Platform for data security, privacy, governance, and compliance.
Request a demo to learn more. See also our Saudi Arabia PDPL solution, the PDPL overview and the BCR Guidelines overview.