Wadira — Find your way through Saudi data & privacy law.

HomeFrameworksPersonal Data Protection (PDPL) › Regulation on Personal Data Transfer Outside KSA

Regulation on Personal Data Transfer Outside KSA

TypeImplementing Regulation
Issuing authoritySaudi Data & AI Authority / National Data Management Office (SDAIA / NDMO)
FrameworkPersonal Data Protection (PDPL)
TierImplementing & executive regulation
Legal statusBinding
DatesUpdated 2024

The Regulation on Personal Data Transfer Outside the Kingdom operationalises PDPL Article 29. First issued in September 2023, it was reissued as version 2.0 in September 2024, and SDAIA published Standard Contractual Clauses and a transfer risk-assessment guideline to support it.

How transfers work. A transfer or disclosure outside the Kingdom needs a permitted purpose — the Law's purposes (a Kingdom treaty obligation, the Kingdom's interests, an obligation the data subject is party to) extended by Article 2 to central processing operations, providing a service or benefit to the data subject, and scientific research. SDAIA is to publish and review — every four years or as needed — a list of countries and organisations providing an adequate level of protection (Art. 3); pending that list, transfers rely in practice on Article 4's exemptions, which require appropriate safeguards: SDAIA's Standard Contractual Clauses, Binding Common Rules for corporate groups, or an accreditation certificate. The Law and Regulation continue to apply to any onward transfer (Art. 5), exemptions lapse if safeguards fail (Art. 6), and a documented risk assessment is required before transfers under the exemptions and for continuous or large-scale transfers of sensitive data (Art. 7).

Frequently asked questions

Do we need SDAIA's approval for each transfer?

No. There is no per-transfer approval requirement. The controller must have a permitted purpose (PDPL Art. 29; Transfer Regulation Art. 2), meet the conditions or fall within an Article 4 exemption backed by appropriate safeguards, and document a risk assessment where Article 7 requires one.

Is there a Saudi adequacy list?

Article 3 directs the competent authority to publish a list of countries and international organisations with an adequate level of protection, reviewed every four years or as necessary. As of mid-2026 no list had been published, so transfers in practice proceed under the Article 4 exemptions with appropriate safeguards.

Which safeguards are recognised?

Article 4 recognises three: Standard Contractual Clauses issued by SDAIA (published September 2024), Binding Common Rules for transfers within a corporate group, and accreditation certificates issued by licensed bodies. EU-style SCCs are not a recognised Saudi safeguard.

When is a transfer risk assessment mandatory?

Article 7 requires one before transferring or disclosing personal data under the Article 4 exemptions, and whenever sensitive data is transferred on a continuous or wide-scale basis. The assessment covers the purpose and legal basis, the nature and scope of the transfer, the safeguards applied, data minimisation, the potential effects and their likelihood, and mitigation measures.

Key provisions

Documents

Updates for this instrument

In this framework


Content and register data licensed CC BY 4.0 — cite the live URL. Machine-readable register (JSON) · Markdown register · Content last verified: 2026-07-27