00 · The short version
Start with the data you process, whether you provide or consume cloud services, and the regulators that cover your organization. PDPL, NDMO, NCA and CST have different scopes. This guide, reviewed on 14 September 2026, helps you check hosting location, provider registration and transfer requirements before choosing an architecture.
regulatory frameworks to check: SDAIA · NDMO · NCA · CST
from awareness to notify SDAIA when the breach meets Article 24 criteria
maximum general administrative fine; repeat violations may increase it
The transition period ended on 14 September 2024. Hosting decisions need to account for the current law and its implementing rules.[S1]
What the current rules require
These are scoped duties, not automatic penalties for every incident. Use the current amended law rather than penalty summaries based on the original 2021 text.[S2]
Saudi hosting can simplify a residency requirement, but the main database is only one part of the flow. Check backups, logs, AI calls and overseas support access. For a transfer, document the applicable legal route and any required risk assessment.[S3]
Selected published rules, guidance and provider announcements. An announcement or a review date is not an effective date.
The me-central2 region is available; verify the services and sovereignty controls required by your workload.
Personal-data processing and transfer requirements are already applicable.
Annex D removes two provider subcontrols and refers localization to NDMO. It does not grant blanket offshore-hosting permission.
Scope includes notified non-CNI private SMEs and large entities. Check the category and timetable in the NCA notice.
GCCC-CSP-2:2026, linked by NCA, helps providers implement controls and prepare evidence. It is guidance supporting CCC-2:2024.
AWS lists Saudi Arabia among planned regions. The earlier January launch and unconfirmed region code have been removed from this guide.
Microsoft says local cloud workloads will be available from Q4 2026. This remains a future date at review; verify availability before committing.
01 · The reality nobody states plainly
A PDPL sensitive-data label is not itself a government security classification or a universal Class C hosting requirement. Check data-governance scope, the applicable NCA controls, CST provider registration and any sector-specific restrictions separately. CCC-2:2024 removed two provider localization subcontrols and directs entities to NDMO; that change does not authorize every offshore workload.
Document which rule requires a location or approval for this workload. A cloud-region name is not evidence of compliance.
02 · The four regulators at a glance
Map your obligations to the right authority before you architect anything.
| Regulator | Governs | Key instrument | What it wants from you |
|---|---|---|---|
| SDAIA (PDPL) | Personal-data processing within statutory scope | PDPL + Implementing Regulation + Transfer Regulation | Lawful basis, privacy notice, records, processor controls, DPO where required, conditional breach notification and lawful transfers |
| NDMO | National data governance and classification within policy scope | Data Governance Policies + Classification Policy | Check whether the policy covers your organization or data; classify and apply the relevant handling rules |
| NCA | Cybersecurity for entities within each control set’s scope | ECC-2:2024 · NCNICC-1:2025 · CCC · DCC · NCS · CSCC | Determine your baseline and any NCA notification; cloud use alone does not make every control set mandatory |
| CST | Cloud service provisioning and provider registration | Cloud Computing Services Provisioning Regulations | Providers check registration requirements; customers verify the exact provider, registration category and service scope |
03 · Step one: classify
Where NDMO policy applies, classify data under its four levels. Separately identify personal and sensitive data under PDPL; the two systems are not interchangeable.
Gravest impact to national interest if exposed. Strictest handling and residency.
Serious impact. Apply the competent authority’s handling and hosting requirements.
Limited/internal impact. Controlled access and logging.
No harm on disclosure. Residency flexible.
PDPL "sensitive data"
04 · Step two: where can it live
Use this as a planning checklist. A PDPL label alone does not determine a CST registration category or authorize a transfer.
| Data | Hosting decision | Provider check | Cross-border |
|---|---|---|---|
| Public / non-personal | Check contracts and any sector rules | Verify registration and service scope | PDPL transfer rules apply only if personal data is involved |
| Personal (non-sensitive) | Local or overseas subject to applicable rules | Check provider obligations independently | Document the lawful route and any required assessment |
| Sensitive personal (health, biometric...) | Check sector rules; sensitivity alone is not a blanket local-hosting rule | No universal Class C rule based only on the PDPL label | Heightened safeguards; Article 7 assessment where triggered |
| Government-classified data | Apply the competent authority’s classification and location requirements | Confirm the approved provider category and workload | Do not transfer without confirming the applicable authority requirements |
Check each service’s availability, backups and support access as well as its region. An announced region cannot be treated as a live hosting option. Provider statements below are not a certification of your workload.
Saudi cloud regions: available and announced
| Provider | Status | Region | Verified |
|---|---|---|---|
| AWS Middle East (Saudi Arabia) | Announced; AWS does not list it as launched | Saudi Arabia; region code not confirmed | 2026-09-14 |
| Google Cloud Dammam | Available · Class C; Saudi billing through CNTXT | me-central2 · Dammam | 2026-09-14 |
| Microsoft Azure Saudi Arabia East | Availability announced from Q4 2026; still a future date | Eastern Province | 2026-09-14 |
Provider statements checked 14 September 2026. Verify service availability and CST registration before contracting.
05 · If any data leaves the Kingdom
Do not assume that a destination is approved: this review did not locate a published SDAIA adequacy list. Check the current position for the intended destination.
PDPL Article 29 and the Transfer Regulation govern the purpose, minimum data needed and protection for a transfer. The Regulation provides adequacy and specified safeguard routes, with conditions and limited exceptions. Saudi SCCs, binding common rules and accreditation are not interchangeable permissions for every transfer; identify the provision that fits your case.
Transfer Risk Assessment (TRA)
Current transfer rules: SDAIA source. The August 2024 version remains the published text located in this review. Consultation proposals are not proof that a replacement rule has taken effect.
06 · Step three: secure it
ECC-2:2024 covers government and critical national infrastructure entities. NCNICC-1:2025 covers non-CNI private SMEs and large entities notified by NCA. Confirm your scope, category and timetable. NCA also publishes the 2026 GCCC-CSP implementation guide for cloud providers; it supports CCC-2:2024 rather than replacing it.
| Control set | Applies when | In one line |
|---|---|---|
| ECC-2:2024 | Government and CNI entities within scope | Essential Cybersecurity Controls; assess the scope before treating it as your baseline |
| NCNICC-1:2025 | Non-CNI private SMEs and large entities notified by NCA | Category A: 65 controls across 3 domains; Category B: 26 controls in 1 domain. Check the NCA notice and official sizing criteria |
| CCC-2:2024 + GCCC-CSP-2:2026 guide | In-scope government/CNI cloud tenants and providers serving them | Separate provider/tenant duties. The 2026 guide supports implementation; localization still needs NDMO, PDPL and sector review |
| DCC-1:2022 | Government and CNI entities within scope | Data protection controls; map the official classification vocabulary to your data policy |
| NCS-1:2020 | Where the applicable controls require cryptography | Check the version served by NCA; a consultation document alone does not establish a replacement standard |
| CSCC-1:2019 | Critical systems within scope | Additional critical-system controls; a government workload is not automatically a critical system |
Not sure NCA applies to you? → Does NCA cybersecurity apply to my company?
07 · If you provide hosting
A cloud customer and a cloud provider have different duties. CST’s class overview lists individuals, nonprofit and private-sector customers under A, B and C; the government-data scope expands by class. Check the provider’s current registration and your workload’s other requirements before contracting.
Government public data, alongside individuals, nonprofit and private-sector customers.
Adds government data labelled Confidential in CST’s English class overview to the Class A scope.
Adds government Secret and Top Secret data to the Class B scope. Registration alone does not approve a particular workload.
Cloud regulations v4 and the provider guide v5 took effect on 10 October 2023. Data-center service operators must also assess CST’s separate Data Center Services Regulations, effective 1 January 2024. A PDPL sensitive-data flag does not automatically select Class C; confirm the relevant classification, registration conditions and sector approvals.
08 · What it costs to get wrong
The current amended PDPL distinguishes administrative violations from the specific sensitive-data offense. The former one-year/SAR 1 million cross-border offense is not in current Article 35 and has been removed from this guide.
Maximum general administrative fine under Article 36; warning also available
Article 35 sensitive-data offense: imprisonment and/or fine, with the required intent
Breach notice from awareness when Article 24 criteria are met
The 72-hour breach clock
Start with the scope of each regulator. PDPL governs covered personal-data processing; sector rules can add requirements. NCNICC covers specified non-CNI private entities notified by NCA.
Regulators
Key obligations
Hosting note
Apply government-data handling and cloud requirements by classification. Class C covers government Secret/Top Secret data; it is not automatically required for all government data.
The gotcha
NDMO 'Restricted' and NCA/CCC 'Confidential' can label the same level; reconcile the terminology before mapping controls.
Regulators
Key obligations
Hosting note
Local hosting can simplify the design. PDPL sensitivity alone does not establish universal residency or Class C; a transfer needs the applicable legal route and sector review.
The gotcha
Consent and transfer safeguards do not override sector restrictions or remove the need to limit health-data access.
Regulators
Key obligations
Hosting note
SAMA’s framework calls for Saudi-located cloud in principle; cloud outside Saudi Arabia needs explicit SAMA approval.
The gotcha
Section 3.4.3 covers public and hybrid cloud for its Member Organizations and excludes internal private cloud. Financial data alone does not establish SAMA scope.
Regulators
Key obligations
Hosting note
PDPL does not impose universal local hosting for customer data. Review transfer conditions and any payment-service or sector requirements separately.
The gotcha
A purchase does not by itself supply consent for unrelated marketing.
Regulators
Key obligations
Hosting note
For student personal data, prefer in-Kingdom or safeguarded transfers; document processors handling minors' data.
The gotcha
Children’s data is not automatically PDPL-sensitive by age alone. Check both the actual data category and legal-capacity requirements.
Regulators
Key obligations
Hosting note
Choose an available service that meets the applicable hosting and transfer conditions. Verify provider registration and region availability; Class C is not a universal SME requirement.
The gotcha
Headcount alone does not establish an NCNICC duty. Check the official scope, Monshaat category and any NCA notice.
09 · The shortcut
Use your answers to identify matters to check: residency, provider registration, NCA scope, DPO triggers and sector requirements. The output is a planning aid; it cannot determine every legal obligation from four answers.
Answers are drawn only from the sourced knowledge base on this page and cite their [S#] source. It tells you when it has no verified source instead of guessing.
Try one:
Not legal advice. Confirm against the primary regulator documents (see Sources) and a Saudi-qualified advisor before go-live.
Answer seven questions to identify the frameworks and follow-up checks relevant to your workload. Each result links to its source.
10 · The 90-day shortcut
The whole thing on one page, phased. This is the shortcut version of everything above.
Days 1–30
Days 31–60
Days 61–90
Not legal advice. Confirm specifics against the primary regulator documents and a Saudi-qualified advisor before go-live.
11 · Show your work
Sources for the regulatory review and provider availability. A newer review date does not imply a new legal rule.
Hosting and privacy review: 14 September 2026. This update corrects earlier summaries and adds the 2026 NCA provider implementation guide; it does not announce a new blanket localization law.
12 · FAQ
Short, sourced answers to the questions teams ask first. Each links its primary source.