A recap of the Pyxos masterclass with Muneeb Imran.
Not every arrangement with a foreign vendor is a cross-border transfer, and assuming otherwise is one of the more common and costly errors in this area. That was one of the clarifying points Muneeb Imran, Data Protection Officer at the Saudi Credit Bureau, made in this masterclass on cross-border personal data transfers, a topic he described as one of the most legally complex and operationally sensitive in PDPL practice.
The starting move is to establish whether a transfer is actually taking place. Where personal data stays hosted and sandboxed inside the Kingdom and a foreign team only accesses it under local controls, the analysis can differ from a true transfer, and some licence or hardware providers may not be processing personal data at all. Accurate data-flow mapping, knowing where data originates, where it travels, and where it ultimately rests, is what makes that determination defensible rather than assumed. The controller and processor roles matter here too, and Imran cautioned that they are often misunderstood in transfer scenarios where several parties touch the data.
Imran organized the compliance work as a structured roadmap rather than a single approval: map and classify the data, determine the lawful basis, identify the transfer purpose, assess adequacy or exceptions, apply safeguards, and run a transfer risk assessment. A distinction he drew carefully is that a transfer needs a lawful basis both for processing the data and for disclosing it outside the Kingdom, and those two bases are not always the same one. Data minimization applies throughout: a transfer should move only the personal data the defined purpose actually requires, not a convenient superset.
Where no adequacy decision covers the destination, the session addressed the safeguards available and the documentation a controller should keep to evidence the decision. The specific mechanisms and when each applies are best taken from the recording and the takeaways.
Two operational overlays deserved the attention they got. The privacy notice has to disclose that personal data may move outside the Kingdom and explain why, in terms specific enough that a person understands what is shared and with whom; a vague reference to global processing does not meet the transparency obligation. And sector rules can sit above the baseline: financial services, healthcare, telecoms, government, and critical infrastructure may require additional controls or even regulator approvals and no-objection letters before offshore storage or critical-system outsourcing can proceed. The baseline framework is a floor, not a ceiling.
The most reassuring note came at the end. Imran's read is that the PDPL was built in the same spirit as GDPR and the wave of laws that followed it across Australia, South Korea, India, and the UAE, with regulators on both sides positioned to recognize one another's frameworks over time. The rules are demanding, but they are demanding in a familiar, internationally legible way, which makes a disciplined transfer program portable rather than a one-off burden.
The closing caution stands on its own: cross-border compliance is not a one-time exercise. As laws, political conditions, and destination-country risks shift, transfer arrangements have to be revisited, because trust, once a person believes their data has moved somewhere unprotected, is among the hardest things to win back.
π₯
About the presenter

Muneeb Imran
Muneeb Imran is a Data Privacy and AI Governance expert and co-author of Data Privacy: A Practical Handbook for Governance and Operations.
