WaqiSecWaqiSec

PDPL Cross-Border Data Transfers: How to Move Personal Data Outside Saudi Arabia Lawfully

WaqiSec Compliance Team · Last reviewed:

SHORT ANSWER

The Saudi PDPL allows personal data to leave the Kingdom when the conditions in Article 29 and SDAIA's Regulation on Personal Data Transfer outside the Kingdom are met. Either the destination has an adequate level of protection, or the controller uses one of three appropriate safeguards: SDAIA's standard contractual clauses, binding common rules, or a certificate of accreditation. A short list of exempt cases relaxes the adequacy and minimum-data conditions, but still requires a safeguard. Transfers made under these safeguards, and continuous or large-scale transfers of sensitive data, need a documented transfer risk assessment.

Legal basisPDPL Article 29; Regulation on Personal Data Transfer outside the Kingdom (amended 2024)
RegulatorSaudi Data & AI Authority (SDAIA)
Route 1Adequate level of protection in the destination (SDAIA assessment)
Route 2Appropriate safeguards: SCCs, binding common rules, certificate of accreditation
Exempt casesRelax the adequacy and minimum-data conditions; a safeguard is still required
SCCs4 SDAIA modules; text cannot be changed except to fill in blanks
Risk assessmentFor transfers under the safeguards (including exempt cases) and continuous or large-scale sensitive data transfers
GuidanceSDAIA transfer risk assessment guideline (2025, non-binding); BCR preparation guideline

What counts as a personal data transfer outside Saudi Arabia?

A transfer happens whenever personal data about individuals in the Kingdom is sent to, stored in or made available to a recipient outside it. Most companies transfer data daily without labeling it that way:

Your records of processing activities should already list each of these with the destination and the mechanism relied on. If they don't, start there.

What does PDPL Article 29 require?

Article 29 permits transfers for defined purposes: performing an obligation under an agreement to which the Kingdom is a party, serving the Kingdom's interests, performing an obligation to which the data subject is a party, or other purposes set by the Regulations. Every transfer must also meet three conditions:

  1. it must not prejudice national security or the vital interests of the Kingdom;
  2. the data must receive an appropriate level of protection, not lower than the PDPL's, which the Transfer Regulation achieves through adequacy or appropriate safeguards; and
  3. only the minimum personal data needed should be transferred.

The 2023 amendments to the PDPL removed the earlier requirement for SDAIA approval of transfers, so there is no permit to apply for. The burden is on the controller to show the transfer is lawful.

The two routes, and the exempt cases

RouteWhen you can use itWhat you need
1. AdequacyThe destination country or organization has been assessed by SDAIA as offering adequate protectionConfirm the destination is covered. As of this guide's review date we are not aware of a published SDAIA adequacy list, so most companies cannot rely on this route yet
2. Appropriate safeguardsNo adequacy decisionSDAIA SCCs, binding common rules, or a certificate of accreditation, plus a transfer risk assessment
Exempt casesThe transfer fits one of the cases listed in the Transfer RegulationThe adequacy and minimum-data conditions are relaxed, but you still need an appropriate safeguard and a risk assessment

In practice, almost every company without an adequacy decision ends up on route 2. Keep sending only the data the recipient needs: Article 29 requires it, and the risk assessment asks how you meet it.

How do SDAIA's standard contractual clauses work?

SDAIA published its own standard contractual clauses (البنود التعاقدية القياسية) in 2024. They come in four modules:

Three rules catch companies out. First, the text cannot be modified apart from completing the blank fields; SDAIA treats other changes as a violation. Second, EU SCCs are a different instrument and do not substitute for SDAIA's clauses. Third, the clauses carry live obligations, including security measures, short breach-notice deadlines between the parties so the controller can meet SDAIA's 72-hour window, and cooperation with SDAIA. See our 72-hour breach notification guide.

Binding common rules and certificates of accreditation

Binding common rules (القواعد المشتركة الملزمة) are SDAIA's equivalent of binding corporate rules. They suit multinational groups that move data between group entities on a regular basis. SDAIA has published a guideline on what they must contain, covering controller obligations, data subject rights, breach handling and records. Confirm with SDAIA how it reviews them before relying on them.

A certificate of accreditation is the third safeguard, issued by an assessment body approved for this purpose. Check with SDAIA which bodies are available before planning around it.

What are the exempt cases?

Article 4 of the Transfer Regulation lists cases that are exempted from two Article 29 conditions: the adequate level of protection and the minimum-data limit. According to SDAIA's published text they include transfers between government bodies to implement international agreements, non-repetitive and limited transfers, operational needs within a multinational group, transfers that provide a service or benefit directly to the data subject, and scientific research. Some cases exclude sensitive data, and each has its own conditions. They are not a way around safeguards: a safeguard is still required, and law-firm commentary (Hourani Partners) reads every exempt case the same way.

When is a transfer risk assessment required?

Article 7 of the amended Transfer Regulation requires a documented risk assessment in two situations:

  1. transfers made under Article 4, that is, relying on an appropriate safeguard, including the exempt cases; and
  2. continuous or large-scale transfers of sensitive data, even to an adequate destination.

SDAIA published a guideline on carrying out the assessment in early 2025. Clyde & Co notes it is non-binding guidance. The Global Privacy Blog summarizes it in four parts:

PartQuestions it answers
PreparationPurpose and legal basis, data flow, whether a DPIA is also needed
Processing risksWhat could go wrong with the data itself
Transfer risksType of data, the recipient's compliance and security, the destination's legal environment
National security and vital interestsWhether the transfer could affect the Kingdom's security or vital interests

Where high, irreversible risk remains after mitigation, the guideline points to alternatives or stopping the transfer. Under Article 6 of the Transfer Regulation, controllers must also stop a transfer and notify the recipients if the safeguard is breached or no longer offers adequate protection.

Step-by-step plan for PDPL transfers

  1. Inventory transfers from your RoPA, SaaS invoices and IT architecture.
  2. Classify the data in each flow, flagging sensitive data.
  3. Pick the route: adequacy (not yet available in practice) or a safeguard, and note if an exempt case applies.
  4. Sign the right SCC module with each vendor or group entity, without editing the text.
  5. Run and file the risk assessment for each transfer or group of similar transfers.
  6. Minimize: send only the fields the recipient needs.
  7. Update your privacy notice to say that data goes abroad.
  8. Review yearly and when SDAIA publishes adequacy decisions or new guidance.

Sector rules can add hosting requirements on top of the PDPL, for example NCA controls for government entities and critical infrastructure operators, and SAMA rules for regulated financial institutions. Check them separately.

Common cross-border transfer mistakes

PDPL transfer checklist

For the wider picture, see the Saudi PDPL compliance guide.

Frequently Asked Questions

Can personal data be transferred outside Saudi Arabia?

Yes. The PDPL allows transfers when Article 29 and SDAIA's Transfer Regulation are met: an adequate destination or an appropriate safeguard such as SDAIA's standard contractual clauses, only the minimum necessary data unless an exempt case applies, and no harm to national security or the Kingdom's vital interests.

Do I need SDAIA approval to transfer data abroad?

No. The 2023 amendments removed the approval requirement. The controller must instead ensure and document that each transfer meets the legal conditions.

Can I use the EU standard contractual clauses for Saudi transfers?

No. SDAIA has issued its own standard contractual clauses in four modules, and their text cannot be modified except to fill in the blank fields.

Has SDAIA published a list of adequate countries?

As of this guide's review date we are not aware of a published SDAIA adequacy list, so most companies rely on appropriate safeguards such as SDAIA's standard contractual clauses.

When is a transfer risk assessment required under the PDPL?

Under Article 7 of the Transfer Regulation, for transfers relying on an appropriate safeguard (including the exempt cases) and for continuous or large-scale transfers of sensitive data. SDAIA published non-binding guidance on how to carry it out in 2025.

Does using a cloud service hosted outside Saudi Arabia count as a transfer?

Yes. Storing or making personal data available outside the Kingdom, including in SaaS and cloud services, is a transfer and needs a lawful route under the PDPL.

Related guides

Sources

  1. SDAIA — Regulation on Personal Data Transfer outside the Kingdom
  2. SDAIA — Standard Contractual Clauses
  3. SDAIA — Guidelines for Binding Common Rules
  4. SDAIA National Data Governance Platform — Personal Data Protection Law (Art. 29)
  5. Mayer Brown — Updates to Saudi PDPL regulations, SCCs and guidelines (2024)
  6. Clyde & Co — Saudi transfer risk assessment guidelines (2025)
  7. Global Privacy Blog — Saudi data transfer risk assessment guidelines (2025)
  8. Hourani Partners — SDAIA's updated cross-border transfer rules
  9. Clyde & Co — Saudi Arabia issues Implementing Regulations

This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.

💬