saudi-pdpl.com

Table of Contents

Article 1

Article 2

Article 3

Article 4

Article 5

Article 6

Article 7

Article 8

Article 9

Article 10

Article 11

Article 12

Article 13

Article 14

Article 15

Article 16

Article 17

Article 18

Article 19

Article 20

Article 21

Article 22

Article 23

Article 24

Article 25

Article 26

Article 27

Article 28

Article 29

Article 30

Article 31

Article 32

Article 33

Article 34

Article 35

Article 36

Article 37

Article 38

Article 39

Article 40

Article 41

Article 42

Article 43

Article 32

Repealed.

FAQs

Lawful data transfers outside Saudi Arabia must use one of these appropriate safeguards: 

  • Adequacy decisions: Transfers to countries or entities recognized by SDAIA as having equivalent data protection. 
  • Standard Contractual Clauses (SCCs): Pre-approved contract templates (like EU SCCs) that bind both data exporter and importer under PDPL standards.  
  • Binding Common Rules (BCRs): Internal rules for a group of related entities, ensuring PDPL-level protections for intra-group transfers.  
  • Certificates of accreditation: Issued by SDAIA-approved bodies, certifying that the destination entity meets PDPL safeguards.

Yes. SDAIA explicitly endorses and governs these safeguards: 

  • It issues adequate decisions for compliant jurisdictions.  
  • On 1 Sept 2024, SDAIA published formal SCC templates and detailed BCR guidelines for personal data transfer. 
  • Certification mechanisms are also approved by SDAIA, though still emerging under regulations.

Yes, but with careful adaptation: 

  • SCCs and BCRs are modeled closely on GDPR versions, though SDAIA’s formulations are not interchangeable with EU versions. Contracts must follow the exact Arabic/English text approved by SDAIA without unauthorized edits.  
  • Fair alignment allowed: Controllers may adopt GDPR-style clauses or codes of conduct, but these must demonstrate equivalent protections and not conflict with PDPL requirements.
Scroll to Top