Law / Saudi Arabia

Personal Data Protection Law, cross-border transfer

Royal Decree No. M/19, Art. 29; Regulation on Personal Data Transfer Outside the Kingdom

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 14 September 2023.

A cross border transfer rule binding public and private bodies.

As of 29 August 2026.

What it requires

  • An app transferring the personal data of an individual in Saudi Arabia to a recipient outside the Kingdom must confirm the transfer does not prejudice national security or Kingdom interests, that the destination affords a level of protection at least equivalent to the Law, and that the transfer is limited to the minimum data needed, following the Transfer Regulation's Appropriate Safeguards or Operational Processes conditions where an adequacy finding is not in place.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Law Art. 29 permits a Controller to transfer personal data outside the Kingdom only for one of four enumerated purposes (international-agreement obligation, Kingdom interests, a Data Subject's own contractual obligation, or a Regulations-specified purpose), and only where the transfer does not prejudice national security or Kingdom vital interests, an adequate level of protection at least equivalent to the Law's own applies per a Competent Authority assessment, and the transfer is limited to the minimum data needed.

The standalone Regulation on Personal Data Transfer Outside the Kingdom operationalizes this with defined "Appropriate Safeguards" the competent authority may impose where an exemption from the adequacy requirement is granted, and an "Operational Processes" basis for data tied to a controller's own internal operations.

No provision compelling in-Kingdom data storage as a default rule was found; this is a multi-factor national-security-and-adequacy gate rather than either a blanket ban or an open transfer policy, more restrictive in structure than the UAE's or Jordan's equivalent provisions in this batch.

The original sdaia.gov.sa path for the Regulation 404s; it is now served from SDAIA's Digital Government Platform, and the "Appropriate Safeguards" and "Operational Processes" quotations above are confirmed against that working URL.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

Read the law

official statute and Transfer Regulation text, SDAIA document library

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app