HomeArrow IconVirtual data rooms: Set-up, features & FAQsArrow IconVirtual Data Rooms in Saudi Arabia: PDPL, NCA Cloud Controls and In-Kingdom Hosting

Running a deal in Saudi Arabia: what the data room has to do

The Kingdom is now one of the most active transaction markets in the world. It is also one of the most demanding on where information sits.

Most virtual data room conversations in Saudi Arabia end at the same question. Can this room stay inside the Kingdom. This page answers that question and the seven that follow it.

Image

Can you run a Saudi deal in an offshore data room?

Sometimes, but it costs you time and it narrows your options. The Personal Data Protection Law permits transfers outside the Kingdom under specific conditions and safeguards, which means a documented risk assessment and an approved transfer mechanism. That is weeks of legal work on a timetable that rarely has weeks spare. In-Kingdom storage removes the question entirely.

For government entities and for organisations touching critical national infrastructure, the answer is usually firmer. In-Kingdom is the expectation.

Image

Does a due diligence data room actually contain personal data?

Yes, and this is the point most deal teams miss.

A transaction data room is thought of as commercial. Contracts, financials, licences, asset registers. But open any real room and you will find employment agreements, payroll data, management CVs, shareholder registers, customer lists, medical and insurance records, and board minutes naming individuals.

All of that is personal data. The PDPL applies to it. The room is in scope from the first upload.

Image

What is the PDPL and does it apply to my transaction?

The Personal Data Protection Law was issued under Royal Decree M/19 in September 2021 and amended by Royal Decree M/148 in March 2023. It entered force on 14 September 2023. The one year grace period expired on 14 September 2024. It has been in full enforcement since.

It applies to any organisation processing the personal data of individuals located in Saudi Arabia, wherever that organisation sits. A London bank running a Riyadh sale process is in scope. So is a Sydney adviser.

The regulator is the Saudi Data and AI Authority. SDAIA is not passive. It reported 48 enforcement decisions in the period disclosed in early 2026, covering processing without a lawful basis, unauthorised disclosure, and failure to implement technical safeguards.

Ansarada has a local team based in Riyadh, Saudi Arabia.

What happens if data leaves the Kingdom?

Transfers are conditional, not prohibited.

SDAIA issued the Regulation on Personal Data Transfer Outside the Kingdom in August 2024, a Risk Assessment Guideline in February 2025, and a set of approved standard contractual clauses.

In practice you need a lawful basis, a documented risk assessment, an approved safeguard, data minimisation, and no prejudice to national security or the vital interests of the Kingdom.

Penalties reach SAR 5 million per breach, roughly USD 1.3 million, and can double for repeat violations. Intentional or repeated violations involving sensitive personal data can carry criminal exposure. SDAIA can also suspend processing. On a live transaction, that means the room stops.

What are the NCA Cloud Cybersecurity Controls?

A separate regime, from a separate regulator, catching a different set of parties.

The National Cybersecurity Authority issues the Essential Cybersecurity Controls. The Cloud Cybersecurity Controls extend them to cloud services. The current version is CCC-2:2024. It replaced CCC-1:2020 and updated data localisation requirements, transferring localisation authority to the National Data Management Office at SDAIA.

The controls run in two tracks. One for the cloud service provider. One for the cloud service tenant, which is you.

They apply mandatorily to government organisations in the Kingdom and their subsidiaries, inside or outside the country, and to private sector organisations that own, operate or host critical national infrastructure. The NCA encourages every other organisation to adopt them, and large Saudi enterprises increasingly require them of suppliers. The mandatory scope understates the real scope.

If your counterparty is a ministry, a PIF portfolio company, a utility, a port, an airport or a grid operator, assume CCC applies.

Image

Does a software provider need its own data centre in the Kingdom?

No. This is the most commonly misunderstood point in Saudi cloud procurement.

A software provider can meet in-Kingdom hosting requirements by running on infrastructure operated by a registered cloud provider with a Saudi region. The customer contracts with the software provider. The software provider contracts with the infrastructure provider. Data stays in the Kingdom throughout.

That is how every major SaaS platform serving Saudi customers does it. Requiring each software vendor to build its own Riyadh data centre would leave the market with almost no software.

Image

Where does Ansarada store Saudi deal data?

In Jeddah, on Oracle Cloud Infrastructure is the in-Kingdom storage location.

The storage location is selected before the room is created. It is fixed at creation and cannot be changed afterwards, so the jurisdiction cannot be moved once diligence is underway.

The reserve copy of every room is held in the same region as the primary, distributed across multiple data centres and availability domains inside the Kingdom. Backups do not leave Saudi Arabia. Ask any other provider that question. Most replicate backups across regions and most buyers never think to ask.

Documents are encrypted at rest with AES-256 and in transit with TLS 1.2 and above. The storage platform is designed for 99.9 percent availability and eleven nines of annual durability, with each object stored redundantly across three domains, and corrupt data detected and repaired automatically.

What does a Saudi sponsor or government tender actually ask for?

Ten questions: (That Ansarada can answer)

1. Where are documents stored at rest, by city.

2. Where does the backup or reserve copy sit, and does it leave the country.

3. Can the storage location be changed after the room opens, and by whom.

4. Which entity contracts with us, and where is it registered.

5. Where are your support staff located, and what can they access.

6. Are you aligned to NCA Cloud Cybersecurity Controls, and at which level.

7. Which certifications do you hold, with audit dates.

8. Do you use our documents to train AI models.

9. Can you produce a complete, export ready audit trail.

10. What happens to the data after close.

Compare virtual data rooms for Saudi Arabian transactions

Saudi data residencyJeddah hostingMultiple global hosting regionsPurpose-built M&A VDREnterprise security
Ansarada✅ Yes✅ Yes — Jeddah✅ Yes✅ Yes✅ Yes
DiliTrust✅ YesSaudi Arabia – location not publicly specifiedverify--
DatasiteNo public Saudi hosting identified-YesYesYes
IntralinksNo public Saudi hosting identified-YesYesYes
IdealsNo public Saudi hosting identified-YesYesYes

Frequently Asked Questions

Before you open a room in the Kingdom

Confirm the storage region. Confirm where the backup sits. Confirm whether the location can be changed. Confirm what your provider's staff can reach and from where. Get all of it in writing.

Then confirm your own position with Saudi counsel. The obligations sit on you as controller, not only on the platform.

Ansarada has a local team based in Riyadh, Saudi Arabia.