Regulation on the transfer of personal data outside the Kingdom

BY Nassr Albarakati · 05 February 2025

Regulation on the transfer of personal data outside the Kingdom

Regulation on the Transfer of Personal Data Outside the Kingdom, Published 28/2/1446H

Introduction

Protecting personal data is one of the most pressing challenges facing countries today. In response, Saudi Arabia recently issued the Regulation on the Transfer of Personal Data Outside the Kingdom, dated 28/2/1446H, corresponding to 1/9/2024, pursuant to Resolution No. 1840 of the President of the Saudi Data and Artificial Intelligence Authority (SDAIA). The Regulation is designed to strengthen the legal protection of personal data and ensure it is handled in a way that safeguards privacy and security whenever it is transferred or disclosed outside the Kingdom, while balancing the free flow of data internationally with the protection of individuals' rights.

First: The Objectives and Importance of the Regulation

The Regulation pursues a number of core objectives, including:

Ensuring the protection of personal data, by guaranteeing a level of protection no lower than the standards applied within the Kingdom.

Regulating cross-border data transfers, to limit the risks associated with transferring personal data to entities outside the Kingdom.

Strengthening digital trust, by assuring individuals and organizations that their data will remain protected even when transferred outside the Kingdom.

Achieving compliance with international standards, in line with global agreements on the protection of personal data.

Second: Key Definitions Under the Regulation

Article One of the Regulation sets out the core terms needed to understand the regulatory framework, the most important of which are as follows.

Appropriate Safeguards refers to the requirements the competent authority imposes on data controllers, obligating them to comply with the provisions of the Personal Data Protection Law (PDPL) and its regulations when transferring or disclosing personal data to entities outside the Kingdom, in cases where an exemption applies from the requirement to maintain an adequate, or minimum, level of protection for personal data, as the case may be.

Standard Contractual Clauses refers to mandatory clauses used when transferring personal data outside the Kingdom, which ensure a level of protection for the data, once transferred, that is no lower than the level of protection established under the Law and its regulations.

Binding Common Rules apply to every controller and processor that is party to a multinational group of entities, and likewise ensure a level of protection for personal data, once transferred outside the Kingdom, that is no lower than the level established under the Law and its regulations.

Third: Scope of Application

1. Legitimate purposes for transferring data

Article Two addresses the cases in which personal data may be transferred outside the Kingdom, including:

Carrying out operational activities necessary to enable the controller to conduct its business.

Providing a service or benefit to the data subject.

Conducting scientific research and studies.

2. Criteria for selecting eligible countries and foreign entities

Under Article Three, data may only be transferred to countries or organizations that guarantee a level of protection equal to, or higher than, the level of protection applied within the Kingdom. The list of eligible countries and organizations is reviewed every four years against specific criteria, including:

The existence of laws that safeguard personal data and the related rights of data subjects.

The existence of supervisory bodies that ensure compliance with those laws.

The extent to which the foreign entity cooperates with the competent authorities in the Kingdom.

The rules governing the onward transfer of data, under Article 5 of the Regulation.

The competent authority may suspend the transfer or disclosure of data to any country or organization on the list, in accordance with the applicable statutory procedures.

Fourth: Exceptions and Conditions for Exemption

Article Four sets out the cases in which entities may be exempted from certain requirements relating to the transfer of personal data, provided the Appropriate Safeguards continue to be observed, including:

Transfers that serve the Kingdom's interests, where the transfer is linked to an international agreement.

Non-recurring transfers, where it is necessary to transfer the data of a limited number of individuals for a short period of time.

Transfers for scientific research purposes, provided the data transferred is kept to the minimum required.

Fifth: Measures to Strengthen Protection

1. Withdrawal of the exemption

Article Six provides that none of the exemptions apply where an entity fails to implement the Appropriate Safeguards, or where those safeguards prove inadequate. Where this occurs, the entity must stop transferring the personal data and notify the parties to which the data was transferred or disclosed.

2. Risk assessment for data transfers

Article Seven requires entities wishing to transfer personal data to conduct a comprehensive risk assessment, as follows.

When an assessment is required: when transferring or disclosing personal data to an entity outside the Kingdom under Article Four of the Regulation, or when transferring or disclosing sensitive data to entities outside the Kingdom on an ongoing or large-scale basis.

What the assessment must cover: the purpose of the data transfer; the nature of the data being transferred and how sensitive it is; the means used to ensure its protection; the material or non-material impact the transfer of personal data may have; and the measures or controls in place to prevent risks to data subjects, or to limit their impact where they occur.

3. Onward transfer of personal data

Article Five explains how the provisions of the Law and its regulations apply to the onward transfer of personal data that has already been transferred or disclosed to an entity outside the Kingdom, and clarifies that this is without prejudice to Articles 8 and 15 of the PDPL and Article 17 of its Executive Regulations.

4. The role of guidance manuals

Article Eight requires the competent authorities to issue detailed manuals and guidance for the entities concerned, to ensure compliance with the Regulation and achieve the protection it is intended to provide.

Sixth: Entry into Force

Article Nine provides that all provisions of the Regulation take effect from the date of its publication in the Official Gazette.

Conclusion

The Regulation on the Transfer of Personal Data Outside the Kingdom marks an important step toward building an integrated digital framework that protects individual privacy and aligns with international best practice and the goals of Vision 2030. Through this Regulation, Saudi Arabia reaffirms its commitment to strengthening digital trust and creating a legal and regulatory environment that protects individual rights and supports innovation.