Demystifying Cross-Border Data Transfers in Saudi Arabia
A practical briefing for Mohammed AlDhabaan & Partners Eversheds Sutherland
July 03, 2025
Demystifying Cross-Border Data Transfers in Saudi ArabiaA practical briefing for Mohammed AlDhabaan & Partners Eversheds SutherlandJuly 03, 2025 1. Why this matters Saudi organizations increasingly rely on regional or global cloud, HR/payroll, CRM and analytics platforms. Article 29 of the Personal Data Protection Law (PDPL) and the SDAIA Regulation on Personal Data Transfer outside the Kingdom (Transfer Regulation) indeed restrict how personal data may leave KSA - but they do not impose a blanket ban. For most day-to-day business scenarios transfers remain perfectly lawful once the steps below are followed.
2. Sector-specific checkpoints - check before proceed PDPL and the SDAIA Transfer Regulation are your starting point, but some industries carry extra rules that must be complied with. For example, organizations in Saudi Arabia's financial sector, such as banks, insurance companies, and fintech firms, may need to first obtain a "no-objection" letter from the Saudi Central Bank before transferring or storing personal data outside the Kingdom. Also, the data of Saudi governmental agencies, as a general rule, must not be transferred to cloud-storage systems located outside the Kingdom. Therefore, before proceeding with the transfers, always check your sector-specific rules – whether they add any additional restrictions to the requirements of the six-step compliance roadmap.
3. The six-step compliance roadmap Follow the below key six steps to legally transfer personal data outside Saudi Arabia.
4. Key documents you must keep - Records of Processing Activities (RoPA) - must list every cross-border processing, its lawful basis and security controls. - Transfer Risk Assessment files – prepare the assessment report, based on the published SDAIA guidance. - Executed SCCs / approved BCR policy / certificates – formalize these documents that are the required safeguards for transfer of personal data outside Saudi Arabia. Check article 4 on which document is required for your transfer.
5. How we can help you Eversheds and Konexo supports Saudi and international companies in managing cross-border data transfers with clarity and confidence. Here is how we can help: - Fast-track transfer assessments and implementation – We run tailored PDPL transfer reviews and prepare regulator-ready documentation, including TRA reports and other necessary documents. - Sector rule overlays – We identify any SAMA, NCA or other sector-specific requirements that may apply to your project. - Training and readiness – We equip your legal, compliance and IT teams with the practical knowledge they need to handle cross-border data transfers. Each solution is hands-on, fast to deploy, and tailored to the Saudi regulatory landscape. Latest Insights
Latest News
Latest Events
client news June 03, 2026 A blueprint for growth: Eversheds Sutherland supports Leonard Design Group ... client news June 02, 2026 Next stop, public ownership: Eversheds Sutherland advises DfT on GTR transi... firm news June 01, 2026 Eversheds Sutherland strengthens restructuring offering with senior partner... firm news June 01, 2026 Eversheds Sutherland strengthens Commercial Advisory practice with technolo... virtual UK employment law training June 09, 2026 1pm - 4pm (BST) Virtual virtual Nordic (Denmark, Finland, Norway and Sweden) employment law training June 16, 2026 12.45pm - 4pm (BST) Virtual virtual Introduction to Swiss employment law June 23, 2026 2pm - 5pm (GMT) Virtual virtual UAE - Employment law in the Dubai International Financial Centre September 10, 2026 9.30am - 1.30pm (GMT) Virtual |