Does the Saudi PDPL apply to a foreign company outside Saudi Arabia?
A primary-source client alert on when Saudi PDPL applies to an overseas company processing personal data relating to individuals residing in Saudi Arabia.
- Published
- Reviewed
A company does not need to be incorporated in Saudi Arabia for the Saudi Personal Data Protection Law to matter.
Article 2 of the PDPL extends to processing carried out by an entity outside the Kingdom where the personal data relate to individuals residing in the Kingdom. SDAIA’s own knowledge centre answers the question directly: the PDPL applies to such overseas processing.
That does not mean that every foreign website or every record concerning a Saudi citizen anywhere in the world is automatically within scope. The statutory language requires an analysis of the individual, the data and the processing activity.
This client alert reflects official Saudi materials checked on 23 August 2026. The registration section was updated on 12 September 2026 using SDAIA’s official external-entity service; this does not represent a complete legal re-review of the other topics.
The direct answer
An overseas company should treat the Saudi PDPL as potentially applicable where all of the following are present:
- it performs an operation that constitutes processing;
- the information is personal data under the PDPL;
- the personal data relate to an individual residing in Saudi Arabia; and
- no relevant statutory exclusion removes the activity from scope.
The company may be a controller for one activity and a processor for another. A group label such as “foreign parent”, “regional platform” or “global support team” does not decide the legal role.
1. Start with Article 2, not the location of the server
The PDPL applies to processing of personal data in the Kingdom. It also expressly includes processing, by an entity outside the Kingdom, of personal data related to individuals residing in the Kingdom.
The second limb prevents the territorial location of the company, personnel, cloud region or database from becoming the only scope test.
Ask:
- Whose personal data are processed?
- Does the individual reside in Saudi Arabia?
- Which foreign entity determines the purpose and material manner?
- Which entity processes only on documented instructions?
- Where do collection, access, analysis, disclosure, storage and deletion occur?
The answer should be recorded for each activity, not once for the whole corporate group.
2. Residence is not the same as nationality
Article 2 uses residence for the overseas-processing limb. SDAIA’s current controller-and-processor guidance explains that residing in the Kingdom is not limited by citizenship and includes temporary and permanent workers.
This distinction produces two cautions:
- Do not exclude a non-Saudi employee, customer or user who resides in the Kingdom merely because of nationality.
- Do not assume that every Saudi citizen living abroad satisfies the residence limb without examining the facts and any other basis on which the processing may fall within the PDPL.
The scope register should therefore record residence based on the actual service or employment context, rather than recording nationality alone.
3. Identify the processing, not merely the market
The PDPL defines processing broadly. Collection, recording, preservation, indexing, arrangement, formatting, storage, modification, updating, consolidation, retrieval, use, disclosure, transmission, publication, sharing, linking, blocking, erasure and destruction can each be processing operations.
A foreign company should test concrete activities such as:
- opening accounts for Saudi-resident users;
- operating a mobile application used by residents;
- providing remote customer support;
- screening or analysing Saudi job applicants;
- receiving employee data from a Saudi subsidiary;
- monitoring devices or users located in Saudi Arabia;
- hosting or administering a Saudi customer’s environment;
- using resident data to train or evaluate an AI system; and
- conducting group security, fraud, finance or HR operations.
Mere visibility of a public webpage in Saudi Arabia does not describe these facts. The question is whether the foreign company actually processes relevant personal data.
4. Classify the foreign company for each activity
Under the PDPL, the controller determines the purpose and manner of processing. A processor processes personal data for the controller and on its behalf.
Consider a foreign technology provider serving a Saudi company:
- If it hosts customer data only on documented instructions, it may act as processor for that activity.
- If it uses the data for its own product analytics, advertising, fraud model or service development, that separate use requires its own role analysis.
- If the Saudi and foreign entities jointly determine material elements of the processing, a generic processor clause may not reflect reality.
Likewise, a foreign parent is not automatically a processor merely because a Saudi subsidiary collected the data. Central HR, security or finance activity may involve separate purposes determined by the parent.
The contract follows the classification; it does not create it.
5. Translate scope into the substantive PDPL controls
Once an overseas activity falls within scope, the company should not stop at a territorial memo. It should map the applicable obligations, including:
- purpose and legal basis;
- data minimisation and accuracy;
- privacy notice and collection disclosures;
- data-subject rights and identity verification;
- retention, destruction and legal holds;
- processor selection and written instructions;
- security and breach assessment;
- processing-activity records;
- impact assessment where required;
- data-protection officer analysis; and
- transfers and disclosures outside the Kingdom.
The Implementing Regulation adds operational detail, including processor-contract requirements, DPO conditions and the prescribed content of processing records.
For each control, identify who is responsible for implementation and what evidence demonstrates it. A global privacy policy that mentions Saudi Arabia without changing systems, contracts or response procedures is not an operating model.
6. Separate extraterritorial scope from a transfer outside Saudi Arabia
These issues often arise together but are not identical.
Example A — Saudi controller sends data to a foreign vendor. The Saudi controller must analyse the overseas transfer or disclosure under Article 29 and the Transfer Regulation. The foreign vendor’s own processing may also fall within Article 2.
Example B — foreign company collects data directly from a Saudi-resident customer. Article 2 may apply to the foreign company’s processing. Whether a separate transfer has occurred, and which controller carries the transfer obligation, depends on the actual data route and roles; it should not be assumed from the foreign location alone.
Example C — foreign parent remotely accesses a Saudi subsidiary’s HR system. The Saudi entity should analyse the disclosure or transfer, while the foreign parent’s group use requires a separate purpose, role and scope analysis.
For every route, record the exporter, importer, controller, processor, destination, purpose, legal basis, safeguard, risk assessment and technical access controls.
7. Do not import a representative requirement from another regime
The Rules Governing the National Register of Controllers Within the Kingdom are expressly directed to controllers within Saudi Arabia. Their introduction provided for separate registration rules for controllers outside the Kingdom. That statement alone does not describe the administrative route now available.
Those internal rules define a “representative” as the natural person designated by a controller for platform registration. That definition should not be converted, by analogy, into an automatic conclusion that every overseas controller must appoint a local representative on the same terms.
SDAIA now provides a Registration of External Entities service. It requires a valid commercial registration and representative authorisation through the Ministry of Foreign Affairs service for verifying non-Saudi companies and issuing a digital identity to their representative.
The published steps include:
- completing MOFA verification and documentation and obtaining approval;
- selecting the external-entity service on the National Data Governance Platform;
- creating the representative’s account and completing entity and representative details using the MOFA application data;
- assessing whether a data protection officer must be appointed under the applicable conditions; and
- completing the application, review and approval before the National Personal Data Protection Register Certificate is issued.
Check registration applicability and current service requirements for the entity at implementation. The service’s availability does not establish a duty for every overseas entity or a local-representative requirement equivalent to one under a foreign regime. Retain the requirements and verification date, assign responsibility for follow-up and reassess when processing or official rules change.
8. Build a scope decision record that can survive a product change
For each overseas processing activity, record:
| Field | Decision |
|---|---|
| Product or business process | What the foreign company actually does |
| Individuals | Saudi residence and relevant categories |
| Data | Personal and sensitive-data categories |
| Foreign entity | Legal name, country and group role |
| Role | Controller, processor or activity-specific combination |
| Purpose and legal basis | Saudi analysis and evidence |
| Collection and access | Systems, teams and locations |
| Transfer route | Exporter, importer and safeguard if applicable |
| Saudi controls | Notice, rights, retention, security, records and incidents |
| Registration / contact | Current SDAIA rule, route and responsible person |
| Change triggers | New purpose, country, entity, vendor, data or AI use |
The record should reopen automatically when a company launches in Saudi Arabia, onboards a Saudi customer, hires a resident employee, enables overseas support, changes cloud architecture or begins a new analytics or AI use.
The management conclusion
Do not ask only whether the foreign company has a Saudi subsidiary. Ask:
Does this foreign entity process personal data relating to individuals residing in Saudi Arabia, for which purpose and role, through which systems and locations, and which Saudi PDPL controls follow?
If the answer cannot be produced activity by activity, the company has not completed its Saudi scope analysis.
Temairik Law assists international businesses with Saudi data-protection scope and compliance, AI governance, cloud arrangements, cybersecurity and market entry. This client alert provides general information and does not constitute legal advice.
Official sources
- Personal Data Protection Law — Saudi Data and Artificial Intelligence Authority
- Implementing Regulation of the Personal Data Protection Law — Saudi Data and Artificial Intelligence Authority
- PDPL Knowledge Center: scope questions — Saudi Data and Artificial Intelligence Authority
- Guide to the Saudi Personal Data Protection Law for Controllers and Processors — Saudi Data and Artificial Intelligence Authority
- Rules Governing the National Register of Controllers Within the Kingdom — Saudi Data and Artificial Intelligence Authority
- Regulation on Personal Data Transfer outside the Kingdom — Saudi Data and Artificial Intelligence Authority
- Registration of External Entities — Saudi Data and Artificial Intelligence Authority
Questions foreign companies ask about Saudi PDPL scope
Can Saudi PDPL apply to a company with no Saudi entity?
Yes. Article 2 applies to processing by an entity outside the Kingdom where the personal data relate to individuals residing in the Kingdom. The absence of a Saudi subsidiary does not by itself remove the processing from scope.
Does Saudi nationality decide whether an individual is protected?
Not for the overseas-processing limb of Article 2. The statutory test refers to individuals residing in the Kingdom, and SDAIA guidance explains that residence is not limited by citizenship and includes temporary and permanent workers.
Is making a website available in Saudi Arabia enough by itself?
The legal test is processing personal data relating to individuals residing in the Kingdom, not merely whether a webpage can be viewed there. The company should test the actual accounts, customers, employees, users, devices and processing operations.
Must an overseas controller register in the Saudi National Register?
SDAIA provides an external-entity registration service with verification, authorisation and registration requirements. Check whether registration applies and which current service requirements the entity must meet. The service’s availability alone does not establish a duty for every overseas entity or justify applying the within-Kingdom rules by analogy.
Is access by the foreign parent always only a data-transfer issue?
No. The Saudi entity may have a transfer obligation when it sends or exposes data abroad, while the foreign parent may separately fall within Article 2 because of its own processing of personal data relating to Saudi residents. The roles and each processing activity must be analysed separately.