PDPL Cross-Border Data Transfers: How to Move Personal Data Outside Saudi Arabia Lawfully
The Saudi PDPL allows personal data to leave the Kingdom when the conditions in Article 29 and SDAIA's Regulation on Personal Data Transfer outside the Kingdom are met. Either the destination has an adequate level of protection, or the controller uses one of three appropriate safeguards: SDAIA's standard contractual clauses, binding common rules, or a certificate of accreditation. A short list of exempt cases relaxes the adequacy and minimum-data conditions, but still requires a safeguard. Transfers made under these safeguards, and continuous or large-scale transfers of sensitive data, need a documented transfer risk assessment.
| Legal basis | PDPL Article 29; Regulation on Personal Data Transfer outside the Kingdom (amended 2024) |
|---|---|
| Regulator | Saudi Data & AI Authority (SDAIA) |
| Route 1 | Adequate level of protection in the destination (SDAIA assessment) |
| Route 2 | Appropriate safeguards: SCCs, binding common rules, certificate of accreditation |
| Exempt cases | Relax the adequacy and minimum-data conditions; a safeguard is still required |
| SCCs | 4 SDAIA modules; text cannot be changed except to fill in blanks |
| Risk assessment | For transfers under the safeguards (including exempt cases) and continuous or large-scale sensitive data transfers |
| Guidance | SDAIA transfer risk assessment guideline (2025, non-binding); BCR preparation guideline |
What counts as a personal data transfer outside Saudi Arabia?
A transfer happens whenever personal data about individuals in the Kingdom is sent to, stored in or made available to a recipient outside it. Most companies transfer data daily without labeling it that way:
- SaaS tools hosted abroad: CRM, email, HR, payroll, ticketing, analytics
- a group head office in Dubai, London or the US that receives customer or staff data
- offshore support or development teams who can access production data
- backups replicated to a region outside the Kingdom
Your records of processing activities should already list each of these with the destination and the mechanism relied on. If they don't, start there.
What does PDPL Article 29 require?
Article 29 permits transfers for defined purposes: performing an obligation under an agreement to which the Kingdom is a party, serving the Kingdom's interests, performing an obligation to which the data subject is a party, or other purposes set by the Regulations. Every transfer must also meet three conditions:
- it must not prejudice national security or the vital interests of the Kingdom;
- the data must receive an appropriate level of protection, not lower than the PDPL's, which the Transfer Regulation achieves through adequacy or appropriate safeguards; and
- only the minimum personal data needed should be transferred.
The 2023 amendments to the PDPL removed the earlier requirement for SDAIA approval of transfers, so there is no permit to apply for. The burden is on the controller to show the transfer is lawful.
The two routes, and the exempt cases
| Route | When you can use it | What you need |
|---|---|---|
| 1. Adequacy | The destination country or organization has been assessed by SDAIA as offering adequate protection | Confirm the destination is covered. As of this guide's review date we are not aware of a published SDAIA adequacy list, so most companies cannot rely on this route yet |
| 2. Appropriate safeguards | No adequacy decision | SDAIA SCCs, binding common rules, or a certificate of accreditation, plus a transfer risk assessment |
| Exempt cases | The transfer fits one of the cases listed in the Transfer Regulation | The adequacy and minimum-data conditions are relaxed, but you still need an appropriate safeguard and a risk assessment |
In practice, almost every company without an adequacy decision ends up on route 2. Keep sending only the data the recipient needs: Article 29 requires it, and the risk assessment asks how you meet it.
How do SDAIA's standard contractual clauses work?
SDAIA published its own standard contractual clauses (البنود التعاقدية القياسية) in 2024. They come in four modules:
- controller to controller
- controller to processor
- processor to controller
- processor to processor (sub-processor)
Three rules catch companies out. First, the text cannot be modified apart from completing the blank fields; SDAIA treats other changes as a violation. Second, EU SCCs are a different instrument and do not substitute for SDAIA's clauses. Third, the clauses carry live obligations, including security measures, short breach-notice deadlines between the parties so the controller can meet SDAIA's 72-hour window, and cooperation with SDAIA. See our 72-hour breach notification guide.
Binding common rules and certificates of accreditation
Binding common rules (القواعد المشتركة الملزمة) are SDAIA's equivalent of binding corporate rules. They suit multinational groups that move data between group entities on a regular basis. SDAIA has published a guideline on what they must contain, covering controller obligations, data subject rights, breach handling and records. Confirm with SDAIA how it reviews them before relying on them.
A certificate of accreditation is the third safeguard, issued by an assessment body approved for this purpose. Check with SDAIA which bodies are available before planning around it.
What are the exempt cases?
Article 4 of the Transfer Regulation lists cases that are exempted from two Article 29 conditions: the adequate level of protection and the minimum-data limit. According to SDAIA's published text they include transfers between government bodies to implement international agreements, non-repetitive and limited transfers, operational needs within a multinational group, transfers that provide a service or benefit directly to the data subject, and scientific research. Some cases exclude sensitive data, and each has its own conditions. They are not a way around safeguards: a safeguard is still required, and law-firm commentary (Hourani Partners) reads every exempt case the same way.
When is a transfer risk assessment required?
Article 7 of the amended Transfer Regulation requires a documented risk assessment in two situations:
- transfers made under Article 4, that is, relying on an appropriate safeguard, including the exempt cases; and
- continuous or large-scale transfers of sensitive data, even to an adequate destination.
SDAIA published a guideline on carrying out the assessment in early 2025. Clyde & Co notes it is non-binding guidance. The Global Privacy Blog summarizes it in four parts:
| Part | Questions it answers |
|---|---|
| Preparation | Purpose and legal basis, data flow, whether a DPIA is also needed |
| Processing risks | What could go wrong with the data itself |
| Transfer risks | Type of data, the recipient's compliance and security, the destination's legal environment |
| National security and vital interests | Whether the transfer could affect the Kingdom's security or vital interests |
Where high, irreversible risk remains after mitigation, the guideline points to alternatives or stopping the transfer. Under Article 6 of the Transfer Regulation, controllers must also stop a transfer and notify the recipients if the safeguard is breached or no longer offers adequate protection.
Step-by-step plan for PDPL transfers
- Inventory transfers from your RoPA, SaaS invoices and IT architecture.
- Classify the data in each flow, flagging sensitive data.
- Pick the route: adequacy (not yet available in practice) or a safeguard, and note if an exempt case applies.
- Sign the right SCC module with each vendor or group entity, without editing the text.
- Run and file the risk assessment for each transfer or group of similar transfers.
- Minimize: send only the fields the recipient needs.
- Update your privacy notice to say that data goes abroad.
- Review yearly and when SDAIA publishes adequacy decisions or new guidance.
Sector rules can add hosting requirements on top of the PDPL, for example NCA controls for government entities and critical infrastructure operators, and SAMA rules for regulated financial institutions. Check them separately.
Common cross-border transfer mistakes
- Assuming GDPR transfer paperwork covers Saudi data
- Editing SDAIA's SCCs to match a vendor's template
- Forgetting remote access by offshore teams
- No risk assessment on file for transfers that rely on safeguards
- Treating an exempt case as a reason to skip the safeguard
- Privacy notice that does not mention transfers abroad
PDPL transfer checklist
- List of every transfer: destination, recipient, data, purpose
- Route chosen and documented for each transfer
- Correct SDAIA SCC module signed, unmodified
- Transfer risk assessment filed where required
- Sensitive data transfers reviewed separately
- Data minimized for each recipient
- Privacy notice and RoPA updated
- Annual review date set
For the wider picture, see the Saudi PDPL compliance guide.
Frequently Asked Questions
Can personal data be transferred outside Saudi Arabia?
Yes. The PDPL allows transfers when Article 29 and SDAIA's Transfer Regulation are met: an adequate destination or an appropriate safeguard such as SDAIA's standard contractual clauses, only the minimum necessary data unless an exempt case applies, and no harm to national security or the Kingdom's vital interests.
Do I need SDAIA approval to transfer data abroad?
No. The 2023 amendments removed the approval requirement. The controller must instead ensure and document that each transfer meets the legal conditions.
Can I use the EU standard contractual clauses for Saudi transfers?
No. SDAIA has issued its own standard contractual clauses in four modules, and their text cannot be modified except to fill in the blank fields.
Has SDAIA published a list of adequate countries?
As of this guide's review date we are not aware of a published SDAIA adequacy list, so most companies rely on appropriate safeguards such as SDAIA's standard contractual clauses.
When is a transfer risk assessment required under the PDPL?
Under Article 7 of the Transfer Regulation, for transfers relying on an appropriate safeguard (including the exempt cases) and for continuous or large-scale transfers of sensitive data. SDAIA published non-binding guidance on how to carry it out in 2025.
Does using a cloud service hosted outside Saudi Arabia count as a transfer?
Yes. Storing or making personal data available outside the Kingdom, including in SaaS and cloud services, is a transfer and needs a lawful route under the PDPL.
Related guides
Sources
- SDAIA — Regulation on Personal Data Transfer outside the Kingdom
- SDAIA — Standard Contractual Clauses
- SDAIA — Guidelines for Binding Common Rules
- SDAIA National Data Governance Platform — Personal Data Protection Law (Art. 29)
- Mayer Brown — Updates to Saudi PDPL regulations, SCCs and guidelines (2024)
- Clyde & Co — Saudi transfer risk assessment guidelines (2025)
- Global Privacy Blog — Saudi data transfer risk assessment guidelines (2025)
- Hourani Partners — SDAIA's updated cross-border transfer rules
- Clyde & Co — Saudi Arabia issues Implementing Regulations
This guide is general information, not legal advice. Always check the official text from the relevant authority before making decisions.