HomeArrow IconVirtual Data RoomArrow IconVirtual Data Rooms in Saudi Arabia: PDPL, NCA Cloud Controls and In-Kingdom Hosting

Running a deal in Saudi Arabia: what the data room has to do

The Kingdom is now one of the most active transaction markets in the world. It is also one of the most demanding on where information sits.

Most virtual data room conversations in Saudi Arabia end at the same question. Can this room stay inside the Kingdom. This page answers that question and the eight that follow it.

Image

Can you run a Saudi deal in an offshore data room?

Sometimes, but it costs you time and it narrows your options. The Personal Data Protection Law permits transfers outside the Kingdom under specific conditions and safeguards, which means a documented risk assessment and an approved transfer mechanism. That is weeks of legal work on a timetable that rarely has weeks spare. In-Kingdom storage removes the question entirely.

For government entities and for organisations touching critical national infrastructure, the answer is usually firmer. In-Kingdom is the expectation.

Image

Does a due diligence data room actually contain personal data?

Yes, and this is the point most deal teams miss.

A transaction data room is thought of as commercial. Contracts, financials, licences, asset registers. But open any real room and you will find employment agreements, payroll data, management CVs, shareholder registers, customer lists, medical and insurance records, and board minutes naming individuals.

All of that is personal data. The PDPL applies to it. The room is in scope from the first upload.

Image

What is the PDPL and does it apply to my transaction?

The Personal Data Protection Law was issued under Royal Decree M/19 in September 2021 and amended by Royal Decree M/148 in March 2023. It entered force on 14 September 2023. The one year grace period expired on 14 September 2024. It has been in full enforcement since.

It applies to any organisation processing the personal data of individuals located in Saudi Arabia, wherever that organisation sits. A London bank running a Riyadh sale process is in scope. So is a Sydney adviser.

The regulator is the Saudi Data and AI Authority. SDAIA is not passive. It reported 48 enforcement decisions in the period disclosed in early 2026, covering processing without a lawful basis, unauthorised disclosure, and failure to implement technical safeguards.

What happens if data leaves the Kingdom?

Transfers are conditional, not prohibited.

SDAIA issued the Regulation on Personal Data Transfer Outside the Kingdom in August 2024, a Risk Assessment Guideline in February 2025, and a set of approved standard contractual clauses.

In practice you need a lawful basis, a documented risk assessment, an approved safeguard, data minimisation, and no prejudice to national security or the vital interests of the Kingdom.

Penalties reach SAR 5 million per breach, roughly USD 1.3 million, and can double for repeat violations. Intentional or repeated violations involving sensitive personal data can carry criminal exposure. SDAIA can also suspend processing. On a live transaction, that means the room stops.

What are the NCA Cloud Cybersecurity Controls?

A separate regime, from a separate regulator, catching a different set of parties.

The National Cybersecurity Authority issues the Essential Cybersecurity Controls. The Cloud Cybersecurity Controls extend them to cloud services. The current version is CCC-2:2024. It replaced CCC-1:2020 and updated data localisation requirements, transferring localisation authority to the National Data Management Office at SDAIA.

The controls run in two tracks. One for the cloud service provider. One for the cloud service tenant, which is you.

They apply mandatorily to government organisations in the Kingdom and their subsidiaries, inside or outside the country, and to private sector organisations that own, operate or host critical national infrastructure. The NCA encourages every other organisation to adopt them, and large Saudi enterprises increasingly require them of suppliers. The mandatory scope understates the real scope.

If your counterparty is a ministry, a PIF portfolio company, a utility, a port, an airport or a grid operator, assume CCC applies.

Image

Does a software provider need its own data centre in the Kingdom?

No. This is the most commonly misunderstood point in Saudi cloud procurement.

A software provider can meet in-Kingdom hosting requirements by running on infrastructure operated by a registered cloud provider with a Saudi region. The customer contracts with the software provider. The software provider contracts with the infrastructure provider. Data stays in the Kingdom throughout.

That is how every major SaaS platform serving Saudi customers does it. Requiring each software vendor to build its own Riyadh data centre would leave the market with almost no software.

Image

Where does Ansarada store Saudi deal data?

In Jeddah, on Oracle Cloud Infrastructure. Saudi Arabia is the only region Ansarada serves from Oracle, and Jeddah is the only in-Kingdom storage location.

The storage location is selected before the room is created. It is fixed at creation and cannot be changed afterwards, so the jurisdiction cannot be moved once diligence is underway.

The reserve copy of every room is held in the same region as the primary, distributed across multiple data centres and availability domains inside the Kingdom. Backups do not leave Saudi Arabia. Ask any other provider that question. Most replicate backups across regions and most buyers never think to ask.

Documents are encrypted at rest with AES-256 and in transit with TLS 1.2 and above. The storage platform is designed for 99.9 percent availability and eleven nines of annual durability, with each object stored redundantly across three domains, and corrupt data detected and repaired automatically.

What operates from outside the Kingdom?


Two things. Stated plainly, because a serious buyer will ask.

Ansarada's application layer and a small number of production support staff operate from outside the Kingdom under documented controls. Documents rest in Jeddah.

Under the PDPL this is permitted with a lawful basis and an appropriate safeguard, and Ansarada can provide the documentation to support it. Any provider claiming zero offshore touch on a globally operated platform should be asked to put that claim in writing.

Ansarada has a local team based in Riyadh, Saudi Arabia.