Past Masterclass March 16, 2026
Cross-Border Personal Data Transfers under Saudi PDPL
Cross-border data transfers are one of the most legally complex areas of Saudi PDPL compliance, arising through SaaS platforms, cloud migrations, offshore support, and intra-group operations. The transfer rules exist to ensure personal data remains adequately protected once it leaves the Kingdom. This masterclass examines how to determine when a transfer is actually taking place, identify the lawful basis for both processing and disclosure, and apply the safeguards available under Article 29 of the PDPL and SDAIA's transfer regulations where no adequacy decision exists. It addresses the common error of assuming any foreign-vendor relationship is a transfer, and why sector-specific rules often go further than the baseline.
Presenters

Muneeb Imran
Data Privacy & AI Governance Expert, DPO, and Co-Author 'Data Privacy: Practical Handbook for Governance & Operations'
Recording
We'll email you the link and passcode.Read the Blog Post
Key takeaways
- Cross-border transfers are not prohibited under the Saudi Personal Data Protection Law (PDPL), but they are subject to strict procedural and legal requirements whose purpose is to ensure personal data stays adequately protected once it leaves the Kingdom.
- Article 29 of the PDPL governs cross-border transfers and must be read together with the Saudi Data and AI Authority (SDAIA) transfer regulations rather than in isolation, and transfers must not harm national security or the Kingdom's vital interests.
- Transfers arise through a range of common triggers, including SaaS deployments, cloud migrations, offshore support, mergers, shared services, and intra-group processing.
- The Data Protection Officer (DPO) must identify a lawful basis both for processing the personal data and for disclosing or transferring it outside Saudi Arabia. These two bases may coincide but do not always.
- Data minimization applies to transfers: move only the personal data the defined purpose requires.
- Transfer compliance follows a structured sequence from data mapping and lawful-basis determination through adequacy assessment, safeguards, and a transfer risk assessment, rather than a single approval step.
- The Record of Processing Activities (RoPA) is a core transfer control and should capture data categories, destination jurisdictions, and the lawful basis for both processing and disclosure.
- Where no SDAIA adequacy decision or whitelist covers the destination, organizations may rely on prescribed safeguards.
- Transfer Risk Assessments or Transfer Impact Assessments are key accountability tools, especially where adequacy is unavailable or sensitive data is involved.
- Privacy notices must disclose that personal data may be transferred outside Saudi Arabia and explain the purpose, specifically enough that data subjects understand what is shared, with whom, and why.
- Sector-specific rules can exceed the baseline framework. Financial, health, telecom, government, and critical-infrastructure sectors may require additional controls, and in some cases regulator approvals or no-objection letters before offshore storage or critical-system outsourcing proceeds.
- Not every foreign-vendor relationship is a cross-border transfer. Assuming a non-KSA vendor automatically means data is transferred abroad is a common error.
- Where data remains hosted and sandboxed within Saudi Arabia and a foreign support team accesses it only under local controls, the analysis may differ from a true transfer, and some license or hardware providers may not process personal data at all.
- Controller and processor roles remain decisive in transfer scenarios and are often misunderstood, so accurate data-flow mapping, knowing where data originates, travels, and resides, is essential.
- Transfer compliance is not a one-time exercise. Arrangements should be reassessed as laws, political conditions, and destination-country risks evolve, since trust is among the hardest risks to recover once data is believed to have moved to an inadequately protected jurisdiction.
Frequently Asked Questions
Yes, subject to strict procedural and legal requirements. Article 29 of the PDPL, read alongside SDAIA's Regulations on Personal Data Transfers outside the Kingdom, permits transfers where adequate protection is maintained, a lawful basis for disclosure exists, the transfer does not harm national security, and appropriate safeguards or exceptions apply.
Article 29 of the PDPL governs cross-border transfers, supplemented by SDAIA's Regulations on Personal Data Transfers outside the Kingdom, updated September 2024. Sector-specific regulators, including SAMA and CST, may impose additional restrictions or approval requirements alongside the baseline framework.
Where no adequacy decision covers the destination, organizations may rely on safeguards including Standard Contractual Clauses (SCCs), Binding Common Rules (BCRs) for intra-group transfers, or certifications of compliance issued by entities licensed by SDAIA. SCCs are generally relevant for external vendor transfers and BCRs for intra-group arrangements, and a Transfer Risk Assessment should accompany them, particularly where sensitive personal data is involved.
No. If personal data remains hosted and sandboxed within Saudi Arabia and the foreign vendor only accesses it under local controls, the analysis may differ from a true transfer. License and hardware suppliers may not process personal data at all. Accurate data-flow mapping is essential to the determination.
Yes. Privacy notices must disclose that personal data may be transferred outside Saudi Arabia and explain the purpose. Disclosure should be specific enough that data subjects understand what is shared, with whom, and why; vague references to "global processing" do not satisfy PDPL transparency requirements.
Yes, in several sectors. Financial services, healthcare, telecoms, government, and critical infrastructure may require additional controls or regulator approvals, including no-objection letters, before offshore storage or critical-system outsourcing can proceed. The baseline PDPL framework is a floor, not a ceiling.
