In this articleSections · 4
Executive summary
SDAIA's draft amendments to the PDPL Implementing Regulation are open for public comment on Istitlaa until 5 November 2026. The draft adds Article 23(2): the controller shall store personal data within the Kingdom, with transfers still allowed under the law. It also drops the harm condition from 72-hour breach notification and requires registration for controllers that transfer personal data abroad. None of this is in force yet. Map your offshore data flows now and comment before the window closes.
SDAIA has put a second round of amendments to the PDPL Implementing Regulation out for public comment. The window on Istitlaa runs from 6 October to 5 November 2026.
One line in it changes how Saudi founders should think about hosting:
The Controller shall store Personal Data within the Kingdom.
That is the proposed new Article 23(2). It is a draft, not law. But if it survives, local storage stops being something only certain sectors and government work require and becomes the starting point for everyone who processes personal data in Saudi Arabia.
Checked against the Istitlaa project page on 10 October 2026. Not legal advice; the binding text is the Arabic one.
What the draft actually says
The full proposed Article 23(2) has two sentences:
The Controller shall store Personal Data within the Kingdom. Personal Data may be transferred or disclosed outside the Kingdom in accordance with the provisions of the Law and its Implementing Regulations.
So this is not a ban on offshore hosting. Transfers stay possible through the routes the law already recognises under Article 29 and the transfer regulation. What changes is the default. Today, a startup on a Frankfurt or Virginia region asks "is this transfer allowed?". Under the draft, the first question becomes "why is this data not stored in the Kingdom?", and the transfer route has to answer it.
How SDAIA will read the two sentences together in practice is not settled yet. Treat the safe reading as: keep the primary copy local where you can, and document a lawful route for every flow that leaves.
The other changes worth knowing
Breach notification gets wider. The current Article 24 requires notifying SDAIA within 72 hours when a breach may cause harm to personal data or data subjects. The proposed text keeps the 72 hours and drops the harm condition. A breach, damage or unauthorised access would be notifiable on its own.
More companies would register. The proposed Article 34 requires registration in the National Register of Controllers through SDAIA's platform if any of these apply:
- You are a public entity.
- Processing personal data is your core activity.
- You process sensitive data, or data about people lacking full legal capacity.
- You transfer or disclose personal data outside the Kingdom.
The last trigger matters most for startups. If your stack sends personal data to an offshore cloud region, an AI API or a support tool, you would be registering.
SDAIA gets a response deadline. A new Article 36 (Repeated) gives entities 20 business days to answer SDAIA's requests about how they apply the law.
Data subjects get a direct complaint path. A new Article 3(4) lets a data subject complain to SDAIA if the controller does not handle their request within the set period.
What is not changing yet
Nothing in this draft binds anyone today. The current Implementing Regulation still applies, including the harm-conditioned breach rule. The draft says the amended regulation would enter into force 60 days after publication in the Official Gazette, and the text can still change after the consultation.
This is also not the 2025 draft. SDAIA ran a first round from 27 April to 27 May 2025; that listing is closed. The current one is a separate project with new provisions, including the storage paragraph.
What I would do this month
- Map every flow that leaves the Kingdom. Not just the main database: backups, logs, analytics, email, AI model calls, embeddings and support tools. My founder guide to Saudi hosting lists where data usually hides.
- Write down the legal route for each one now. Under current law you need it anyway. Under the draft, it is what justifies not storing locally.
- Check your registration exposure. If any of the four Article 34 triggers fit, assume you would register and find out what the platform asks for.
- Rehearse a 72-hour breach report without the harm filter. Who decides, who writes, who sends.
- Comment before 5 November. If the storage default would hurt your product, Istitlaa is where that argument counts. Specific, practical comments (what it would cost, what a workable exception looks like) are more useful than general objections.
If you sell into SAMA-regulated firms, CMA entities or government, the direction is familiar: those buyers already ask for Saudi hosting or a documented approval. The draft would bring the rest of the market closer to that expectation.
The Saudi hosting and compliance guide tracks this draft on its timeline and will be updated when the consultation closes.
Common questions
Does the new PDPL draft ban hosting personal data outside Saudi Arabia?
No. The proposed Article 23(2) says the controller shall store personal data within the Kingdom, and in the same paragraph says personal data may be transferred or disclosed outside the Kingdom under the law and its regulations. Read together, local storage becomes the default and offshore transfer stays possible through the existing legal routes. The draft is not in force.
When would the PDPL Implementing Regulation amendments take effect?
Not yet. Public comments on Istitlaa run from 6 October to 5 November 2026. The draft says the amended regulation enters into force 60 days after it is published in the Official Gazette. Until then, the current Implementing Regulation applies.
What changes for breach notification under the draft?
The current text requires notifying SDAIA within 72 hours when a breach may cause harm to personal data or data subjects. The proposed Article 24 keeps the 72 hours but drops that harm condition, so notification would apply to personal data breaches, damage or unauthorised access generally.
Would my company need to register with SDAIA under the draft?
Under the proposed Article 34, registration in the National Register of Controllers is required if you are a public entity, if processing personal data is your core activity, if you process sensitive data or data about people lacking legal capacity, or if you transfer personal data outside the Kingdom. Many SaaS and AI products would meet at least one of these.
