All Masterclasses
    Past Masterclass March 16, 2026

    Cross-Border Personal Data Transfers under Saudi PDPL

    Cross-border data transfers are one of the most legally complex areas of Saudi PDPL compliance, arising through SaaS platforms, cloud migrations, offshore support, and intra-group operations. The transfer rules exist to ensure personal data remains adequately protected once it leaves the Kingdom. This masterclass examines how to determine when a transfer is actually taking place, identify the lawful basis for both processing and disclosure, and apply the safeguards available under Article 29 of the PDPL and SDAIA's transfer regulations where no adequacy decision exists. It addresses the common error of assuming any foreign-vendor relationship is a transfer, and why sector-specific rules often go further than the baseline.

    Presenters

    Muneeb Imran
    Muneeb Imran
    Data Privacy & AI Governance Expert, DPO, and Co-Author 'Data Privacy: Practical Handbook for Governance & Operations'

    Recording

    We'll email you the link and passcode.Read the Blog Post

    Key takeaways

    • Cross-border transfers are not prohibited under the Saudi Personal Data Protection Law (PDPL), but they are subject to strict procedural and legal requirements whose purpose is to ensure personal data stays adequately protected once it leaves the Kingdom.
    • Article 29 of the PDPL governs cross-border transfers and must be read together with the Saudi Data and AI Authority (SDAIA) transfer regulations rather than in isolation, and transfers must not harm national security or the Kingdom's vital interests.
    • Transfers arise through a range of common triggers, including SaaS deployments, cloud migrations, offshore support, mergers, shared services, and intra-group processing.
    • The Data Protection Officer (DPO) must identify a lawful basis both for processing the personal data and for disclosing or transferring it outside Saudi Arabia. These two bases may coincide but do not always.
    • Data minimization applies to transfers: move only the personal data the defined purpose requires.
    • Transfer compliance follows a structured sequence from data mapping and lawful-basis determination through adequacy assessment, safeguards, and a transfer risk assessment, rather than a single approval step.
    • The Record of Processing Activities (RoPA) is a core transfer control and should capture data categories, destination jurisdictions, and the lawful basis for both processing and disclosure.
    • Where no SDAIA adequacy decision or whitelist covers the destination, organizations may rely on prescribed safeguards.
    • Transfer Risk Assessments or Transfer Impact Assessments are key accountability tools, especially where adequacy is unavailable or sensitive data is involved.
    • Privacy notices must disclose that personal data may be transferred outside Saudi Arabia and explain the purpose, specifically enough that data subjects understand what is shared, with whom, and why.
    • Sector-specific rules can exceed the baseline framework. Financial, health, telecom, government, and critical-infrastructure sectors may require additional controls, and in some cases regulator approvals or no-objection letters before offshore storage or critical-system outsourcing proceeds.
    • Not every foreign-vendor relationship is a cross-border transfer. Assuming a non-KSA vendor automatically means data is transferred abroad is a common error.
    • Where data remains hosted and sandboxed within Saudi Arabia and a foreign support team accesses it only under local controls, the analysis may differ from a true transfer, and some license or hardware providers may not process personal data at all.
    • Controller and processor roles remain decisive in transfer scenarios and are often misunderstood, so accurate data-flow mapping, knowing where data originates, travels, and resides, is essential.
    • Transfer compliance is not a one-time exercise. Arrangements should be reassessed as laws, political conditions, and destination-country risks evolve, since trust is among the hardest risks to recover once data is believed to have moved to an inadequately protected jurisdiction.

    Frequently Asked Questions