Client alertPrivacy & Data Protection

Does the Saudi PDPL apply to a foreign company outside Saudi Arabia?

A primary-source client alert on when Saudi PDPL applies to an overseas company processing personal data relating to individuals residing in Saudi Arabia.

Published
Reviewed

A company does not need to be incorporated in Saudi Arabia for the Saudi Personal Data Protection Law to matter.

Article 2 of the PDPL extends to processing carried out by an entity outside the Kingdom where the personal data relate to individuals residing in the Kingdom. SDAIA’s own knowledge centre answers the question directly: the PDPL applies to such overseas processing.

That does not mean that every foreign website or every record concerning a Saudi citizen anywhere in the world is automatically within scope. The statutory language requires an analysis of the individual, the data and the processing activity.

This client alert reflects official Saudi materials checked on 23 August 2026. The registration section was updated on 12 September 2026 using SDAIA’s official external-entity service; this does not represent a complete legal re-review of the other topics.

The direct answer

An overseas company should treat the Saudi PDPL as potentially applicable where all of the following are present:

  1. it performs an operation that constitutes processing;
  2. the information is personal data under the PDPL;
  3. the personal data relate to an individual residing in Saudi Arabia; and
  4. no relevant statutory exclusion removes the activity from scope.

The company may be a controller for one activity and a processor for another. A group label such as “foreign parent”, “regional platform” or “global support team” does not decide the legal role.

1. Start with Article 2, not the location of the server

The PDPL applies to processing of personal data in the Kingdom. It also expressly includes processing, by an entity outside the Kingdom, of personal data related to individuals residing in the Kingdom.

The second limb prevents the territorial location of the company, personnel, cloud region or database from becoming the only scope test.

Ask:

  • Whose personal data are processed?
  • Does the individual reside in Saudi Arabia?
  • Which foreign entity determines the purpose and material manner?
  • Which entity processes only on documented instructions?
  • Where do collection, access, analysis, disclosure, storage and deletion occur?

The answer should be recorded for each activity, not once for the whole corporate group.

2. Residence is not the same as nationality

Article 2 uses residence for the overseas-processing limb. SDAIA’s current controller-and-processor guidance explains that residing in the Kingdom is not limited by citizenship and includes temporary and permanent workers.

This distinction produces two cautions:

  • Do not exclude a non-Saudi employee, customer or user who resides in the Kingdom merely because of nationality.
  • Do not assume that every Saudi citizen living abroad satisfies the residence limb without examining the facts and any other basis on which the processing may fall within the PDPL.

The scope register should therefore record residence based on the actual service or employment context, rather than recording nationality alone.

3. Identify the processing, not merely the market

The PDPL defines processing broadly. Collection, recording, preservation, indexing, arrangement, formatting, storage, modification, updating, consolidation, retrieval, use, disclosure, transmission, publication, sharing, linking, blocking, erasure and destruction can each be processing operations.

A foreign company should test concrete activities such as:

  • opening accounts for Saudi-resident users;
  • operating a mobile application used by residents;
  • providing remote customer support;
  • screening or analysing Saudi job applicants;
  • receiving employee data from a Saudi subsidiary;
  • monitoring devices or users located in Saudi Arabia;
  • hosting or administering a Saudi customer’s environment;
  • using resident data to train or evaluate an AI system; and
  • conducting group security, fraud, finance or HR operations.

Mere visibility of a public webpage in Saudi Arabia does not describe these facts. The question is whether the foreign company actually processes relevant personal data.

4. Classify the foreign company for each activity

Under the PDPL, the controller determines the purpose and manner of processing. A processor processes personal data for the controller and on its behalf.

Consider a foreign technology provider serving a Saudi company:

  • If it hosts customer data only on documented instructions, it may act as processor for that activity.
  • If it uses the data for its own product analytics, advertising, fraud model or service development, that separate use requires its own role analysis.
  • If the Saudi and foreign entities jointly determine material elements of the processing, a generic processor clause may not reflect reality.

Likewise, a foreign parent is not automatically a processor merely because a Saudi subsidiary collected the data. Central HR, security or finance activity may involve separate purposes determined by the parent.

The contract follows the classification; it does not create it.

5. Translate scope into the substantive PDPL controls

Once an overseas activity falls within scope, the company should not stop at a territorial memo. It should map the applicable obligations, including:

  • purpose and legal basis;
  • data minimisation and accuracy;
  • privacy notice and collection disclosures;
  • data-subject rights and identity verification;
  • retention, destruction and legal holds;
  • processor selection and written instructions;
  • security and breach assessment;
  • processing-activity records;
  • impact assessment where required;
  • data-protection officer analysis; and
  • transfers and disclosures outside the Kingdom.

The Implementing Regulation adds operational detail, including processor-contract requirements, DPO conditions and the prescribed content of processing records.

For each control, identify who is responsible for implementation and what evidence demonstrates it. A global privacy policy that mentions Saudi Arabia without changing systems, contracts or response procedures is not an operating model.

6. Separate extraterritorial scope from a transfer outside Saudi Arabia

These issues often arise together but are not identical.

Example A — Saudi controller sends data to a foreign vendor. The Saudi controller must analyse the overseas transfer or disclosure under Article 29 and the Transfer Regulation. The foreign vendor’s own processing may also fall within Article 2.

Example B — foreign company collects data directly from a Saudi-resident customer. Article 2 may apply to the foreign company’s processing. Whether a separate transfer has occurred, and which controller carries the transfer obligation, depends on the actual data route and roles; it should not be assumed from the foreign location alone.

Example C — foreign parent remotely accesses a Saudi subsidiary’s HR system. The Saudi entity should analyse the disclosure or transfer, while the foreign parent’s group use requires a separate purpose, role and scope analysis.

For every route, record the exporter, importer, controller, processor, destination, purpose, legal basis, safeguard, risk assessment and technical access controls.

7. Do not import a representative requirement from another regime

The Rules Governing the National Register of Controllers Within the Kingdom are expressly directed to controllers within Saudi Arabia. Their introduction provided for separate registration rules for controllers outside the Kingdom. That statement alone does not describe the administrative route now available.

Those internal rules define a “representative” as the natural person designated by a controller for platform registration. That definition should not be converted, by analogy, into an automatic conclusion that every overseas controller must appoint a local representative on the same terms.

SDAIA now provides a Registration of External Entities service. It requires a valid commercial registration and representative authorisation through the Ministry of Foreign Affairs service for verifying non-Saudi companies and issuing a digital identity to their representative.

The published steps include:

  1. completing MOFA verification and documentation and obtaining approval;
  2. selecting the external-entity service on the National Data Governance Platform;
  3. creating the representative’s account and completing entity and representative details using the MOFA application data;
  4. assessing whether a data protection officer must be appointed under the applicable conditions; and
  5. completing the application, review and approval before the National Personal Data Protection Register Certificate is issued.

Check registration applicability and current service requirements for the entity at implementation. The service’s availability does not establish a duty for every overseas entity or a local-representative requirement equivalent to one under a foreign regime. Retain the requirements and verification date, assign responsibility for follow-up and reassess when processing or official rules change.

8. Build a scope decision record that can survive a product change

For each overseas processing activity, record:

Field Decision
Product or business process What the foreign company actually does
Individuals Saudi residence and relevant categories
Data Personal and sensitive-data categories
Foreign entity Legal name, country and group role
Role Controller, processor or activity-specific combination
Purpose and legal basis Saudi analysis and evidence
Collection and access Systems, teams and locations
Transfer route Exporter, importer and safeguard if applicable
Saudi controls Notice, rights, retention, security, records and incidents
Registration / contact Current SDAIA rule, route and responsible person
Change triggers New purpose, country, entity, vendor, data or AI use

The record should reopen automatically when a company launches in Saudi Arabia, onboards a Saudi customer, hires a resident employee, enables overseas support, changes cloud architecture or begins a new analytics or AI use.

The management conclusion

Do not ask only whether the foreign company has a Saudi subsidiary. Ask:

Does this foreign entity process personal data relating to individuals residing in Saudi Arabia, for which purpose and role, through which systems and locations, and which Saudi PDPL controls follow?

If the answer cannot be produced activity by activity, the company has not completed its Saudi scope analysis.

Temairik Law assists international businesses with Saudi data-protection scope and compliance, AI governance, cloud arrangements, cybersecurity and market entry. This client alert provides general information and does not constitute legal advice.

Questions foreign companies ask about Saudi PDPL scope

Can Saudi PDPL apply to a company with no Saudi entity?

Yes. Article 2 applies to processing by an entity outside the Kingdom where the personal data relate to individuals residing in the Kingdom. The absence of a Saudi subsidiary does not by itself remove the processing from scope.

Does Saudi nationality decide whether an individual is protected?

Not for the overseas-processing limb of Article 2. The statutory test refers to individuals residing in the Kingdom, and SDAIA guidance explains that residence is not limited by citizenship and includes temporary and permanent workers.

Is making a website available in Saudi Arabia enough by itself?

The legal test is processing personal data relating to individuals residing in the Kingdom, not merely whether a webpage can be viewed there. The company should test the actual accounts, customers, employees, users, devices and processing operations.

Must an overseas controller register in the Saudi National Register?

SDAIA provides an external-entity registration service with verification, authorisation and registration requirements. Check whether registration applies and which current service requirements the entity must meet. The service’s availability alone does not establish a duty for every overseas entity or justify applying the within-Kingdom rules by analogy.

Is access by the foreign parent always only a data-transfer issue?

No. The Saudi entity may have a transfer obligation when it sends or exposes data abroad, while the foreign parent may separately fall within Article 2 because of its own processing of personal data relating to Saudi residents. The roles and each processing activity must be analysed separately.

Consultation

Tell us about your matter.

A few sentences are enough. We aim to respond within one business day. Please leave out confidential details at this stage.