Table of Contents
Article 1
Article 2
Article 3
Article 4
Article 5
Article 6
Article 7
Article 8
Article 9
Article 10
Article 11
Article 12
Article 13
Article 14
Article 15
Article 16
Article 17
Article 18
Article 19
Article 20
Article 21
Article 22
Article 23
Article 24
Article 25
Article 26
Article 27
Article 28
Article 29
Article 30
Article 31
Article 32
Article 33
Article 34
Article 35
Article 36
Article 37
Article 38
Article 39
Article 40
Article 41
Article 42
Article 43
Article 32
Repealed.
FAQs
Lawful data transfers outside Saudi Arabia must use one of these appropriate safeguards:
- Adequacy decisions: Transfers to countries or entities recognized by SDAIA as having equivalent data protection.
- Standard Contractual Clauses (SCCs): Pre-approved contract templates (like EU SCCs) that bind both data exporter and importer under PDPL standards.
- Binding Common Rules (BCRs): Internal rules for a group of related entities, ensuring PDPL-level protections for intra-group transfers.
- Certificates of accreditation: Issued by SDAIA-approved bodies, certifying that the destination entity meets PDPL safeguards.
Yes. SDAIA explicitly endorses and governs these safeguards:
- It issues adequate decisions for compliant jurisdictions.
- On 1 Sept 2024, SDAIA published formal SCC templates and detailed BCR guidelines for personal data transfer.
- Certification mechanisms are also approved by SDAIA, though still emerging under regulations.
Yes, but with careful adaptation:
- SCCs and BCRs are modeled closely on GDPR versions, though SDAIA’s formulations are not interchangeable with EU versions. Contracts must follow the exact Arabic/English text approved by SDAIA without unauthorized edits.
- Fair alignment allowed: Controllers may adopt GDPR-style clauses or codes of conduct, but these must demonstrate equivalent protections and not conflict with PDPL requirements.