The Personal Data Protection Law lets a controller send personal data to a jurisdiction that offers an adequate level of protection. The problem is simple and it has not gone away: SDAIA has not published which jurisdictions those are.
The route that does not exist yet
On paper PDPL has an adequacy route, the same shape as the one European teams know from GDPR. In practice there is no list to rely on. Until SDAIA publishes one, no transfer out of the Kingdom can lean on adequacy alone.
That leaves three working mechanisms, set out in SDAIA's transfer guideline of February 2025:
Saudi standard contractual clauses for transfers to a third party abroad
Binding common rules for transfers inside a corporate group
A certificate of accreditation held by the receiving party
Each one carries the same condition. Before the data moves, you need a documented transfer risk assessment, and that assessment has to be reviewed at least every two years.

Most unpapered transfers sit in infrastructure nobody thinks of as a transfer: a cloud region, a shared service centre, a support tool.
Where the unpapered transfers hide
When we map data flows for organisations in the Kingdom, the transfers that cause trouble are rarely the obvious ones. They are the ones nobody thought of as a transfer at all.
Flow | Why it is a transfer | What is usually missing |
|---|---|---|
Cloud workloads in a region outside the Kingdom | Personal data is stored or processed abroad | SCCs with the provider and a risk assessment on file |
Group shared service centre in another country | HR, finance or customer data is handled offshore | Binding common rules, or SCCs per entity |
Offshore support or BPO vendor | Agents view customer records from outside KSA | SCCs, access logging and an assessment |
SaaS tools with foreign hosting | CRM, ticketing or analytics data leaves the Kingdom | An inventory entry at all |
In plain language
If personal data about people in the Kingdom is read, stored or processed by a system or person outside it, that is a transfer. It needs a contract, a risk assessment and a review date. "We use a global cloud provider" is not a transfer basis.
Why this matters now
The enforcement record already exists. SDAIA's violation committees issued 48 decisions in the year to 16 January 2026, and one of the four behaviours penalised was disclosure of personal data without justification. An undocumented transfer is very close to that description.
Penalties under PDPL reach up to SAR 5 million per violation, and can be doubled for a repeat. The exposure is not theoretical, and it does not need a breach to trigger.
What to do this quarter
Build the transfer register. Every system, vendor and group entity that touches Saudi personal data from outside the Kingdom.
Pick the mechanism per flow. SCCs for third parties, binding common rules for the group, certificates where a vendor holds one.
Write the risk assessments. One per flow or per category, dated, with a review date no more than two years out.
Price what is left. Once the gaps are visible, put a dollar figure on them so the board can decide what to fix first.
Next step. The full position, including registration, transfers, the 72-hour breach clock and what SDAIA's committees actually penalised, is in our PDPL briefing pack. Download the briefing pack →
For any comments or information please reach out to info@astragar.com







