SAUDI ARABIA
Since September 2021, last amended in September 2023
Since September 2023, last amended in September 2024
Since September 2023, last amended in September 2024
Pillar Cross-border data policies |
Indicator Conditional flow regime
Personal Data Protection Law, implemented by Royal Decree M/19
مرسوم ملكي رقم (م/19) وتاريخ 1443/2/9هـ نظام حماية البيانات الشخصية
Regulation on Personal Data Transfer Outside the Kingdom
لائحة نقل البيانات الشخصية إلى خارج المملكة
مرسوم ملكي رقم (م/19) وتاريخ 1443/2/9هـ نظام حماية البيانات الشخصية
Regulation on Personal Data Transfer Outside the Kingdom
لائحة نقل البيانات الشخصية إلى خارج المملكة
Art. 29.1 of Saudi Arabia’s Personal Data Protection Law (PDPL) and Art. 2 of the Regulation on Personal Data Transfer Outside the Kingdom permit controllers to transfer or disclose personal data abroad where a legitimate purpose exists, such as fulfilling obligations under agreements to which the Kingdom is a party, serving national interests, performing contractual obligations involving the data subject, enabling centralised processing for operational purposes, providing a service or benefit to the data subject, or conducting scientific research and studies. In addition to fulfilling these purposes, Art. 29.2 of the PDPL requires that transfers neither compromise national security nor vital interests, occur only to jurisdictions offering protection equivalent to Saudi standards as assessed by the Saudi Data and Artificial Intelligence Authority (SDAIA), and involve only the minimum necessary data. These conditions do not apply in cases of extreme necessity, such as safeguarding life or preventing or treating infectious diseases (Art. 29.3). Where no adequacy decision or international agreement exists, Art. 4 of the Regulations mandates appropriate safeguards, including SDAIA-issued Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs) for multinational groups, or certification by an SDAIA-licensed entity. Exemptions from adequacy and data minimisation requirements may apply in specific cases, such as transfers between public bodies under agreements serving national interests, occasional or time-limited transfers involving few data subjects, intra-group transfers for central operations, transfers to provide a direct benefit to the data subject without violating expectations, and transfers for scientific research, provided that safeguards such as SCCs, BCRs, or certification are implemented and sensitive data is excluded where required.
Coverage Horizontal
Sources
- https://web.archive.org/web/20230628152743/https://sdaia.gov.sa/en/SDAIA/about/Documents/Personal%20Data%20English%20V2-23April2023-%20Reviewed-.pdf
- https://web.archive.org/web/20250904142821/https://dgp.sdaia.gov.sa/wps/wcm/connect/e5bbede0-1119-4f70-b4ef-f043ce58d780/Regulation+on+Personal+Data+Transfer+Outside+the+Kingdom..pdf?MOD=AJPERES&CONVE...
- https://www.dataguidance.com/notes/saudi-arabia-data-protection-overview
- Show more...
SAUDI ARABIA
Since January 2018, as amended in October 2023
Pillar Cross-border data policies |
Indicator Conditional flow regime
Cloud Computing Services Provisioning Regulations
Section 3-3-8 of the Cloud Computing Services Provisioning Regulations stipulates that cloud service providers must notify their subscribers and obtain their consent if their content is transferred outside Saudi Arabia. This iteration represents the fourth version of the legislation. The previous three versions were referred to as the Cloud Computing Regulatory Framework. Since its inception, the legislation has included similar requirements. Section 3.3.11 of both the first and second versions mandated that cloud service providers inform their customers in advance if their content would be transferred, stored, or processed outside the Kingdom, whether permanently or temporarily. In the third version, Section 3-3-10 required that cloud service providers clearly inform both the Commission and the subscriber in advance and obtain their approval if the subscriber's content would be transferred abroad.
Coverage Cloud-computing sector
Sources
- https://web.archive.org/web/20241122182539/https://www.cst.gov.sa/en/RulesandSystems/RegulatoryDocuments/Documents/CCSPR_EN.pdf
- https://web.archive.org/web/20180219121730/http://www.citc.gov.sa/en/RulesandSystems/RegulatoryDocuments/Documents/CCRF_En.pdf
- https://web.archive.org/web/20190819/http://www.citc.gov.sa/en/RulesandSystems/RegulatoryDocuments/Documents/CCRF_En.pdf
- https://web.archive.org/web/20210725/http://www.citc.gov.sa/en/RulesandSystems/RegulatoryDocuments/Documents/CCRF_En.pdf
- https://web.archive.org/web/20240414021338/https://www.dataguidance.com/notes/saudi-arabia-data-transfers
- Show more...
SAUDI ARABIA
Reported in 2021, last reported in 2024
Pillar Telecom infrastructure & competition |
Indicator Presence of shares owned by the government in telecom companies
Presence of shares owned by the government in the telecom sector
The Saudi telecommunications market is dominated by three operators holding unified licences: Saudi Telecom Company (STC), Etihad Etisalat Company (Mobily) and Mobile Telecommunication Company Saudi Arabia (Zain KSA). It is reported that the State holds 62% of STC’s shares through the Public Investment Fund (PIF), a further 6.9% through the General Organization for Social Insurance (GOSI), and 4.9% of Zain KSA’s shares through GOSI. Although Saudi Arabia has reportedly pursued a limited privatisation programme for state-owned enterprises and assets since 2002, open to both domestic and foreign investors, this has so far resulted only in the partial privatisation of state-owned operators in the telecommunications sector.
Coverage Telecommunications sector
Sources
- https://web.archive.org/web/20250906092213/https://www.stc.com/content/dam/groupsites/en/pdf/stc_Annual-2024-en.pdf
- https://web.archive.org/web/20250805200757/https://mobily.com.sa/web/en/personal/about-mobily/overview
- https://web.archive.org/web/20251222133246/https://www.argaam.com/en/article/articledetail/id/1761464
- https://web.archive.org/web/20230920231731/https://www.state.gov/reports/2022-investment-climate-statements/saudi-arabia/
- https://web.archive.org/web/20240916163124/https://www.mordorintelligence.com/industry-reports/saudi-arabia-telecom-market
- Show more...
SAUDI ARABIA
N/A
Pillar Telecom infrastructure & competition |
Indicator Functional/accounting separation for operators with significant market power
Lack of mandatory functional separation for dominant network operators
According to Saudi Arabia's Accounting Separation Regulatory Framework, accounting separation is applied and required by law for operators with significant market power. However, functional separation for operators with significant market power is not required by law.
Coverage Telecommunications sector
SAUDI ARABIA
Since November 2022
Pillar Telecom infrastructure & competition |
Indicator Licensing restrictions to operate in the telecom market
Implementing Regulations of the Telecommunication Act
According to Art. 6 of the Implementing Regulations of the Telecommunication Act, the Communications, Space and Technology Commission (CST) Board of Directors may decide to cap the number of licences, registrations or permits in a given telecom/ICT market.
Coverage Telecommunications sector
SAUDI ARABIA
Since February 2024
Pillar Telecom infrastructure & competition |
Indicator Licensing restrictions to operate in the telecom market
Regulations of Localization Obligations for telecommunications Service Providers
According to Section 5.1.5 of the Regulations of Localization Obligations for Telecommunications Service Providers, service providers must submit localisation and replacement plans to the CST. These plans must include, at a minimum, a career path detailing the courses and training programmes offered to Saudi personnel, the number of such programmes, the entities providing them, and the names, numbers and targets of employees trained, together with related data. They must also specify the total annual spending on training in SAR and its percentage of total revenues, as well as the percentage of spending on local content relative to the company’s total expenses.
Coverage Telecommunications sector
SAUDI ARABIA
N/A
Pillar Telecom infrastructure & competition |
Indicator Signature of the WTO Telecom Reference Paper
Lack of appendment of WTO Telecom Reference Paper to schedule of commitments
Saudi Arabia has not appended the World Trade Organization (WTO) Telecom Reference Paper to its schedule of commitments.
Coverage Telecommunications sector
SAUDI ARABIA
N/A
Pillar Telecom infrastructure & competition |
Indicator Presence of an independent telecom authority
Presence of independent telecom authority
It is reported that the Communications, Space & Technology Commission (CST), the executive authority for the supervision and administration of services in the telecommunications sector, is independent from the government in the decision-making process.
Coverage Telecommunications sector
SAUDI ARABIA
Since 2018 until 2024
Since October 2020
Since May 2019
Since October 2020
Since May 2019
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Essential Cybersecurity Controls
Cloud Cybersecurity Controls (CCC – 1: 2020)
Regulations on the Use of Information and Communication, Technologies in Government Entities
Cloud Cybersecurity Controls (CCC – 1: 2020)
Regulations on the Use of Information and Communication, Technologies in Government Entities
The National Cybersecurity Authority’s (NCA) Essential Cybersecurity Controls establish baseline cybersecurity requirements for governmental and semi-governmental entities in Saudi Arabia, as well as private organisations managing critical national infrastructure. While the previous version mandated domestic hosting and storage of information, the updated framework removes this explicit obligation and delegates data localisation requirements to the National Data Management Office (NDMO). The NDMO stipulates that personal data transfers remain governed by the Personal Data Protection Law and Data Transfer Regulation, whereas government data is subject to localisation under the Regulations on the Use of Information and Communication Technologies in Government Entities, which require hosting on servers within Saudi Arabia (Arts. 2 and 3). Complementing these measures, the NCA’s Cloud Cybersecurity Controls extend protections to the cloud computing environments used in the public sector and in critical infrastructure, obliging cloud service providers, whether operating domestically or internationally, to deliver services, including storage, processing, monitoring, and disaster recovery, from within the Kingdom to safeguard information systems and infrastructures against cyber threats (Arts. 2.3.P.1.10 and 2.3.P.1.11).
Coverage Public sector and critical infrastructure
Sources
- https://web.archive.org/web/20240127163214/https://nca.gov.sa/ecc-en.pdf
- https://web.archive.org/web/20250426070651/https://istitlaa.ncc.gov.sa/en/security/nca/ecc22024/Documents/ECC%202-2024%20EN%2019092024.pdf
- https://web.archive.org/web/20240302101100/https://nca.gov.sa/ccc-en.pdf
- https://web.archive.org/web/20250905013753/https://laws.boe.gov.sa/BoeLaws/Laws/LawDetails/eb1ceceb-d684-404c-afd7-aa6400f17220/1
- https://www.dataguidance.com/notes/saudi-arabia-data-transfers
- Show more...
SAUDI ARABIA
Since January 2018, last amended in October 2023
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Cloud Computing Services Provisioning Regulations
Section 3-3-6 of the Cloud Computing Services Provisioning Regulations, as issued by the Communications, Space & Technology Commission, stipulates that cloud service providers and their subscribers (defined as individuals or entities with whom a cloud service provider agrees to deliver its services under a cloud computing contract or other commercial arrangement) must ensure that data pertaining to Saudi Arabia's public sector is stored within the country's national borders.
The Regulations represent the fourth iteration of this legislation. Since the inception of the first version, the legislation has incorporated certain restrictions. Section 3.3.8 of the initial version, referred to as the Cloud Computing Regulatory Framework, stipulated that no Level 3 data could be transferred outside Saudi Arabia unless explicitly authorised by the government. Level 3 data encompassed, among other categories, sensitive information held by public authorities.
The Regulations represent the fourth iteration of this legislation. Since the inception of the first version, the legislation has incorporated certain restrictions. Section 3.3.8 of the initial version, referred to as the Cloud Computing Regulatory Framework, stipulated that no Level 3 data could be transferred outside Saudi Arabia unless explicitly authorised by the government. Level 3 data encompassed, among other categories, sensitive information held by public authorities.
Coverage Cloud-computing sector
Sources
- https://web.archive.org/web/20241122182539/https://www.cst.gov.sa/en/RulesandSystems/RegulatoryDocuments/Documents/CCSPR_EN.pdf
- https://web.archive.org/web/20180219121730/http://www.citc.gov.sa/en/RulesandSystems/RegulatoryDocuments/Documents/CCRF_En.pdf
- https://web.archive.org/web/20240414021338/https://www.dataguidance.com/notes/saudi-arabia-data-transfers
- https://web.archive.org/web/20240630145833/https://www2.itif.org/2019-worst-mercantilist-policies.pdf
- Show more...
SAUDI ARABIA
Since April 2020, last amended in October 2023
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
General Principles for Personal Data Protection in the Telecommunication, IT, and Postal Services
القواعد العامة للمحافظة على خصوصية البيانات الشخصية للمستخدمين في قطاع الاتصالات وتقنية المعلومات
القواعد العامة للمحافظة على خصوصية البيانات الشخصية للمستخدمين في قطاع الاتصالات وتقنية المعلومات
Art. 5.4 of the General Principles for Personal Data Protection in the Telecommunication, IT, and Postal Services requires that service providers of telecommunication, IT and postal services process customers’ personal data within Saudi Arabia and prohibits them from processing customers’ personal data out of Saudi Arabia without the authorisation of Communications, Space and Technology Commission (CST).
Coverage Telecommunication, IT, and postal services
Sources
- https://web.archive.org/web/20250904173012/https://www.cst.gov.sa/en/regulations-and-licenses/regulations/Document-404
- https://web.archive.org/web/20220201095003/https://www.citc.gov.sa/en/RulesandSystems/privacy/Documents/Data_Privacy_Principles_For_ICT_en.pdf
- https://web.archive.org/web/20231113183333/https://cms.law/en/int/expert-guides/cms-expert-guide-to-data-protection-and-cyber-security-laws/saudi-arabia
- Show more...
SAUDI ARABIA
Since May 2017
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Cyber Security Framework of Saudi Arabian Monetary Authority
Art. 3.4.3 of the Cyber Security Framework of the Saudi Arabian Monetary Authority mandates that financial institutions should use cloud services located in Saudi Arabia. If the cloud services are outside Saudi Arabia, financial services should obtain explicit approval from the Saudi Arabian Monetary Authority. These apply to banks, insurance and/or reinsurance companies, financing companies and credit bureaus operating in Saudi Arabia.
Coverage Financial sector
Sources
- https://web.archive.org/web/20220402113924/https://www.sama.gov.sa/en-US/Laws/BankingRules/SAMA%20Cyber%20Security%20Framework.pdf
- https://web.archive.org/web/20210613074800/https://www.lw.com/thoughtLeadership/data-protection-privacy-laws-middle-east-2013
- https://web.archive.org/web/20231113183333/https://cms.law/en/int/expert-guides/cms-expert-guide-to-data-protection-and-cyber-security-laws/saudi-arabia
- Show more...
SAUDI ARABIA
N/A
Pillar Intellectual Property Rights (IPRs) |
Indicator Adoption of the WIPO Copyright Treaty
Lack of signature of the WIPO Copyright Treaty
Saudi Arabia has not signed the World Intellectual Property Organization (WIPO) Copyright Treaty.
Coverage Horizontal
SAUDI ARABIA
Since June 2020
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
National Data Governance Interim Regulations
Saudi Arabia’s National Data Management Office published the National Data Governance Interim Regulations, which requires firms to store and process personal data within Saudi Arabia “in order to ensure the preservation of the digital national sovereignty over such data.” Data Controllers may only process or transfer personal data outside the Kingdom after obtaining written approval from the relevant regulatory authority (Art. 5.4.16).
Coverage Horizontal
Sources
- https://web.archive.org/web/20231112034131/https://sdaia.gov.sa/ndmo/Files/PoliciesEn.pdf
- https://web.archive.org/web/20231028144242/https://itif.org/publications/2021/07/19/how-barriers-cross-border-data-flows-are-spreading-globally-what-they-cost/
- https://web.archive.org/web/20231113183333/https://cms.law/en/int/expert-guides/cms-expert-guide-to-data-protection-and-cyber-security-laws/saudi-arabia
- Show more...
SAUDI ARABIA
N/A
Pillar Intellectual Property Rights (IPRs) |
Indicator Adoption of the WIPO Performances and Phonograms Treaty
Lack of signature of the WIPO Performances and Phonograms Treaty
Saudi Arabia has not signed the World Intellectual Property Organization (WIPO) Performances and Phonograms Treaty.
Coverage Horizontal
