The Regulation on Personal Data Transfer Outside the Kingdom operationalises PDPL Article 29. First issued in September 2023, it was reissued as version 2.0 in September 2024, and SDAIA published Standard Contractual Clauses and a transfer risk-assessment guideline to support it.
How transfers work. A transfer or disclosure outside the Kingdom needs a permitted purpose — the Law's purposes (a Kingdom treaty obligation, the Kingdom's interests, an obligation the data subject is party to) extended by Article 2 to central processing operations, providing a service or benefit to the data subject, and scientific research. SDAIA is to publish and review — every four years or as needed — a list of countries and organisations providing an adequate level of protection (Art. 3); pending that list, transfers rely in practice on Article 4's exemptions, which require appropriate safeguards: SDAIA's Standard Contractual Clauses, Binding Common Rules for corporate groups, or an accreditation certificate. The Law and Regulation continue to apply to any onward transfer (Art. 5), exemptions lapse if safeguards fail (Art. 6), and a documented risk assessment is required before transfers under the exemptions and for continuous or large-scale transfers of sensitive data (Art. 7).
Frequently asked questions
Do we need SDAIA's approval for each transfer?
No. There is no per-transfer approval requirement. The controller must have a permitted purpose (PDPL Art. 29; Transfer Regulation Art. 2), meet the conditions or fall within an Article 4 exemption backed by appropriate safeguards, and document a risk assessment where Article 7 requires one.
Is there a Saudi adequacy list?
Article 3 directs the competent authority to publish a list of countries and international organisations with an adequate level of protection, reviewed every four years or as necessary. As of mid-2026 no list had been published, so transfers in practice proceed under the Article 4 exemptions with appropriate safeguards.
Which safeguards are recognised?
Article 4 recognises three: Standard Contractual Clauses issued by SDAIA (published September 2024), Binding Common Rules for transfers within a corporate group, and accreditation certificates issued by licensed bodies. EU-style SCCs are not a recognised Saudi safeguard.
When is a transfer risk assessment mandatory?
Article 7 requires one before transferring or disclosing personal data under the Article 4 exemptions, and whenever sensitive data is transferred on a continuous or wide-scale basis. The assessment covers the purpose and legal basis, the nature and scope of the transfer, the safeguards applied, data minimisation, the potential effects and their likelihood, and mitigation measures.
Key provisions
Art. 1 — Definitions. Adopts the definitions of Article 1 of the Personal Data Protection Law and defines terms specific to this Regulation, including Appropriate Safeguards, Operational Processes, Standard Contractual Clauses, and Binding Common Rules applicable to transfers of personal data outside the Kingdom.
Art. 2 — Other Purposes for Transfer. Specifies additional purposes for transferring or disclosing personal data to a party outside the Kingdom under Article 29 of the Law, including performing central processing operations necessary for the controller's activities, providing a service or benefit to the data subject, and conducting scientific research and studies.
Art. 3 — Adequacy Assessment. Requires the competent authority to publish, and review every four years or as necessary, a list of countries and international organisations providing an adequate level of personal data protection, based on criteria including legislation, supervisory bodies, and cooperation. The authority may amend the list or suspend transfers; the standards also apply to cities, special economic zones, and global trade centres.
Art. 4 — Exemptions and Appropriate Safeguards. Exempts controllers, in defined cases, from the adequacy and data-minimisation conditions of Article 29 of the Law, provided appropriate safeguards apply: standard contractual clauses, binding common rules, or accreditation certificates. Cases cover public-body agreements, limited transfers, multinational central operations, services to data subjects, and scientific research; the competent authority may review the safeguards every two years or as necessary.
Art. 5 — Subsequent Transfers of Personal Data. Provides that the Law and its Regulations continue to apply to any subsequent transfer of personal data that has already been transferred or disclosed to a party outside the Kingdom, without prejudice to Articles 8 and 15 of the Law and Article 17 of the Implementing Regulation.
Art. 6 — Revocation of Exemption. Terminates exemptions granted under Article 4 of the Regulation where the controller fails to implement the appropriate safeguards or the competent authority finds those safeguards inadequate in a specific case. The controller must then halt the transfer or disclosure and notify the entities that received the personal data.
Art. 7 — Risk Assessment for Transfers. Requires the controller to conduct a risk assessment before transferring or disclosing personal data outside the Kingdom under Article 4 exemptions, or when transferring sensitive data continuously or widely. The assessment covers purpose, legal basis, nature and scope, safeguards, data minimisation, potential effects and their likelihood, and mitigation measures.
Art. 8 — Guides and Guidelines. Directs the competent authority to issue guides and guidelines related to the provisions of this Regulation on the transfer of personal data outside the Kingdom.
Art. 9 — Entry into Force. The Regulation enters into force on the date of its publication in the Official Gazette.
2025-02-25 — Guideline on cross-border transfer risk assessment: SDAIA published a non-binding, four-phase methodology for assessing the risks of transferring personal data outside the Kingdom, with a companion risk-assessment tool on the National Data Governance Platform.