Your Saudi buyer's DPO asks a one-line question — "who is the controller here?" — and the deal pauses until someone answers it properly. The Personal Data Protection Law (PDPL) has been fully enforceable since 14 September 2024, and for a vendor hosting a workload in the Kingdom it asks three things: get the roles explicit, get a lawful basis for any transfer out, and expect the buyer to check both. Facts checked 30 Aug 2026.
The roles: controller, processor, sub-processor
PDPL, like GDPR, allocates responsibility by role. The party that decides the purposes and means of processing is the controller; parties processing on its instructions are processors and sub-processors. In a typical hosted-software chain:
- Your customer is usually the controller of its end users' and citizens' data.
- You — the vendor operating the application — typically process on the customer's instructions.
- The cloud provider underneath you processes on yours, as a sub-processor.
The allocation is contractual, and Saudi buyers increasingly expect it stated explicitly in the paper, alongside Arabic or bilingual drafting and SAR-denominated commitments (Morgan Lewis on Saudi cloud contracting expectations). Deferring the data-processing agreement is a common way for deals to stall in legal review.
The transfer rule
The Regulation on Personal Data Transfer Outside the Kingdom (in force 1 September 2024) governs any flow of personal data out of Saudi Arabia — including the unglamorous ones: support access from your engineering team abroad, offshore backups, monitoring pipelines.
A transfer needs a lawful basis plus safeguards: standard contractual clauses (SCCs), binding common rules, or accreditation. As at the date checked, no adequacy list had been published — so do not architect on the assumption that your home jurisdiction will be waved through. (Mayer Brown's analysis of the SCCs and guidelines, IAPP's first-anniversary review)
The practical audit for a vendor is short: list every path by which personal data in the Saudi workload could leave the Kingdom — support tooling, logs and telemetry, backup targets, sub-processor locations — and put a basis and safeguard against each.
What the buyer will check
Expect the buyer's DPO and security team to ask, in roughly this order:
- Where does the data sit? In-Kingdom hosting with a CST-registered provider answers the residency half; see the Saudi cloud map for what is actually live.
- Who holds which role? Controller, processor, sub-processor — named, in the contract chain.
- What leaves the Kingdom, and under what safeguard? Your transfer inventory, with SCCs or an alternative safeguard attached.
- What happens on an incident or a data-subject request? The operational commitments that make the roles real.
The honest boundary
None of the above is legal advice, and a serious buyer will expect your answers to be confirmed by Saudi-qualified counsel — the definitive reading of PDPL and its regulations belongs to SDAIA and to your advisers. What a vendor controls is arriving with the structure already framed: roles proposed, transfer inventory drafted, residency answered.
That framing is what the Path Check starts and what a Path Note delivers — the provisional route, sourced, in writing, before the DPO's one-line question arrives.
