Saudi PDPL × AI: How to Run AI on Company Data Without Breaking the Kingdom’s Data Law
Published: 27 July 2026 · Updated: 27 July 2026
Two things about Saudi Arabia’s Personal Data Protection Law are simultaneously true: it is now genuinely enforced, and much of the guidance written about it is out of date — especially on cross-border transfers. This guide is for CTOs and compliance leads who want to run AI on company data in the Kingdom. It covers what the law actually says, where the real exposure sits, and the architecture pattern that keeps AI workloads on the right side of it. It is information, not legal advice.
The enforcement reality: this is no longer theoretical
The PDPL — issued by Royal Decree M/19 in 2021 and amended by Royal Decree M/148 in 2023 — became fully enforceable on 14 September 2024. Any reading of the law as a paper obligation ended that day.
The regulator, SDAIA, has made the point with numbers: it issued 48 violation decisions in 2025 alone. The penalty schedule has teeth — fines reach SAR 5 million per violation and can be doubled for repeat offences. The wrongful disclosure of sensitive personal data is treated more harshly still: up to SAR 3 million and/or two years’ imprisonment.
For a compliance lead, what matters is not the number alone but the posture it reveals: a regulator issuing violation decisions is a regulator examining organisations against the law’s requirements and putting its conclusions in writing. The working assumption for any company processing personal data in the Kingdom is that its compliance will be tested against the text of the law — not against what a conference slide once said the text would be.
And “sensitive” is not an abstract category. Health data is sensitive personal data under the law, which puts hospitals, clinics, insurers and health-tech platforms one misplaced export away from the criminal tier of the penalty schedule.
What the law actually says about cross-border transfers
Here is the claim this page exists to correct, because most of the content ranking today repeats it: “transferring personal data outside Saudi Arabia requires SDAIA approval.” That rule is outdated. Under the amended PDPL and its Transfer Regulations, cross-border transfers are permitted on three grounds: adequacy — the destination provides an adequate level of protection; appropriate safeguards, such as standard contractual clauses or binding corporate rules-style instruments; or specific exemptions. There is no blanket approval requirement.
The distinction is practical, not pedantic. An approval-based rule makes every transfer a discretionary queue; the actual framework makes every transfer a documented decision you are accountable for. You still need to know where the data goes and on which ground each flow stands — but the gatekeeper model is gone.
Each ground carries a different operational cost. Adequacy is the lightest where it applies, because the destination’s own level of protection does the work. Appropriate safeguards are the general-purpose tool: contractual instruments — standard contractual clauses, or binding corporate rules-style commitments inside a group — that bind the recipient to protect the data it receives. Exemptions are the narrow door, reserved for specific situations. Most companies running routine software or AI workloads will live in the middle category, which means the safeguard document is not an appendix to the transfer — it is what makes the transfer lawful.
One caveat survives the correction: sectoral rules still apply on top of the PDPL. SAMA’s requirements for the banking sector are the standard example. The PDPL sets the floor, not the ceiling.
Why “just send it to an LLM API” is a PDPL problem
The default pattern for adding AI to a company — piping database contents into a foreign model API — manufactures two compliance events at once. It is a transfer of personal data outside the Kingdom, which must stand on adequacy, appropriate safeguards or an exemption. And it is processing by a third party whose handling of that data you must be able to account for. Every prompt that carries a customer row is both.
If any of those rows are sensitive — and in healthcare they are by definition — the exposure escalates from administrative fines to the disclosure offence that carries up to SAR 3 million and imprisonment. “We only sent a few fields” is not a defence when those fields are diagnoses.
None of this forbids AI. It forbids unconsidered architecture. The question the PDPL asks of your AI stack is the same one it asks of every other system: where does the data go, on what legal ground, and can you prove it?
The compliant architecture pattern
The simplest way to answer “where does the data go” is to make the answer “nowhere”. That is the pattern DEBO is built on: DEBO deploys inside your environment in the Kingdom, so personal data is processed where it already lawfully sits — there is no cross-border transfer to justify for the AI layer, because there is no transfer. Access is permissioned by role, so each person can only interrogate the data their job entitles them to see, and every question and answer is written to an audit trail — the proof, if SDAIA ever asks, of exactly how personal data was processed.
In-Kingdom processing, permissioned access, and an audit trail are not exotic requirements; they are the architecture the law has been describing all along. Whether you build it or buy it, that is the shape a PDPL-compliant AI deployment takes.
Frequently asked questions
Is the Saudi PDPL actually enforced?
Yes. It has been fully enforceable since 14 September 2024, and SDAIA issued 48 violation decisions in 2025 alone.
Do cross-border transfers need SDAIA approval?
No — that is the outdated rule. Under the amended PDPL and the Transfer Regulations, transfers are permitted on the basis of adequacy, appropriate safeguards (such as standard contractual clauses or binding corporate rules-style instruments), or specific exemptions.
How did the transfer rules change?
The PDPL was issued by Royal Decree M/19 in 2021 and amended by Royal Decree M/148 in 2023. Under the amended framework and its Transfer Regulations, transfers abroad rest on adequacy, appropriate safeguards or exemptions — the older approval-based reading no longer applies.
What are the penalties for violating the PDPL?
Fines of up to SAR 5 million per violation, which can be doubled for repeat offences. Wrongful disclosure of sensitive personal data carries up to SAR 3 million and/or two years’ imprisonment.
Is health data treated differently?
Yes. Health data is sensitive personal data under the PDPL, so its wrongful disclosure falls into the penalty tier that includes imprisonment — not just administrative fines.
Can we use a foreign LLM API on Saudi customer data?
Only if the transfer stands on adequacy, appropriate safeguards or an exemption, and you can account for the third party’s processing — and sectoral rules such as SAMA’s may add further requirements. Processing the data inside the Kingdom avoids the transfer question entirely.
Do sectoral regulators still matter?
Yes. The PDPL sets the floor. Sectoral regulators — SAMA for banking is the standard example — can and do impose additional requirements on top of it.
See in-Kingdom AI on your own data
A 30-minute demo on your own use case: watch DEBO answer questions straight from your database, inside your environment in the Kingdom, with the audit trail to prove where the data stayed.
Book a demo