Resources

There Is Still No Adequacy List: What That Means for Every Transfer Out of the Kingdom

Resources

There Is Still No Adequacy List: What That Means for Every Transfer Out of the Kingdom

Resources

There Is Still No Adequacy List: What That Means for Every Transfer Out of the Kingdom

The Personal Data Protection Law lets a controller send personal data to a jurisdiction that offers an adequate level of protection. The problem is simple and it has not gone away: SDAIA has not published which jurisdictions those are.

The route that does not exist yet

On paper PDPL has an adequacy route, the same shape as the one European teams know from GDPR. In practice there is no list to rely on. Until SDAIA publishes one, no transfer out of the Kingdom can lean on adequacy alone.

That leaves three working mechanisms, set out in SDAIA's transfer guideline of February 2025:

  • Saudi standard contractual clauses for transfers to a third party abroad

  • Binding common rules for transfers inside a corporate group

  • A certificate of accreditation held by the receiving party

Each one carries the same condition. Before the data moves, you need a documented transfer risk assessment, and that assessment has to be reviewed at least every two years.

Most unpapered transfers sit in infrastructure nobody thinks of as a transfer: a cloud region, a shared service centre, a support tool.

Most unpapered transfers sit in infrastructure nobody thinks of as a transfer: a cloud region, a shared service centre, a support tool.

Where the unpapered transfers hide

When we map data flows for organisations in the Kingdom, the transfers that cause trouble are rarely the obvious ones. They are the ones nobody thought of as a transfer at all.

Flow

Why it is a transfer

What is usually missing

Cloud workloads in a region outside the Kingdom

Personal data is stored or processed abroad

SCCs with the provider and a risk assessment on file

Group shared service centre in another country

HR, finance or customer data is handled offshore

Binding common rules, or SCCs per entity

Offshore support or BPO vendor

Agents view customer records from outside KSA

SCCs, access logging and an assessment

SaaS tools with foreign hosting

CRM, ticketing or analytics data leaves the Kingdom

An inventory entry at all

In plain language

If personal data about people in the Kingdom is read, stored or processed by a system or person outside it, that is a transfer. It needs a contract, a risk assessment and a review date. "We use a global cloud provider" is not a transfer basis.

Why this matters now

The enforcement record already exists. SDAIA's violation committees issued 48 decisions in the year to 16 January 2026, and one of the four behaviours penalised was disclosure of personal data without justification. An undocumented transfer is very close to that description.

Penalties under PDPL reach up to SAR 5 million per violation, and can be doubled for a repeat. The exposure is not theoretical, and it does not need a breach to trigger.

What to do this quarter

  • Build the transfer register. Every system, vendor and group entity that touches Saudi personal data from outside the Kingdom.

  • Pick the mechanism per flow. SCCs for third parties, binding common rules for the group, certificates where a vendor holds one.

  • Write the risk assessments. One per flow or per category, dated, with a review date no more than two years out.

  • Price what is left. Once the gaps are visible, put a dollar figure on them so the board can decide what to fix first.

Next step. The full position, including registration, transfers, the 72-hour breach clock and what SDAIA's committees actually penalised, is in our PDPL briefing pack. Download the briefing pack →

For any comments or information please reach out to info@astragar.com

Get Started Now

Know the Real Cyber Risk Behind the Data

Get Started Now

Know the Real Cyber Risk Behind the Data

Get Started Now

Know the Real Cyber Risk Behind the Data

©Astragar All rights reserved.