Saudi standard contractual clauses are the instrument most transfers of personal data out of the Kingdom now rest on, and the reason is a gap rather than a preference. The Personal Data Protection Law permits transfer or disclosure outside the Kingdom only where the destination offers an adequate level of protection, as assessed by the Saudi Data and AI Authority. The Transfer Regulation requires SDAIA to publish a list of adequate countries and review it every four years.
At the time of writing, no list has been published. Every transfer therefore has to fit one of the Regulation’s exemption cases, each tied to a safeguard, and for a controller outside a multinational group the safeguard is SDAIA’s Standard Contractual Clauses, issued in September 2024 in four templates. This guide explains the framework, the four templates, the three appendices, the rules that make an edited clause a violation, and the risk assessment that must come first.
What this guide covers
- Why Saudi standard contractual clauses carry the load
- The eleven rules of the Saudi standard contractual clauses
- The four templates of the Saudi standard contractual clauses
- The three appendices
- Before signing the Saudi standard contractual clauses: the risk assessment
- Binding common rules and certificates
- Onward transfers and losing the exemption
- What a transfer programme built on Saudi standard contractual clauses needs
- Frequently asked questions about Saudi standard contractual clauses

Why Saudi standard contractual clauses carry the load
Article 29 of the law sets three conditions for any transfer or disclosure outside the Kingdom: no prejudice to national security or the Kingdom’s vital interests; an adequate level of protection at least equivalent to the law’s, according to SDAIA’s assessment; and the minimum data. Article 3 of the Transfer Regulation creates the adequacy list and its criteria. Article 4 then provides that, in five cases, a controller is exempt from the adequacy and minimum-data conditions provided it applies appropriate safeguards, which it names: standard contractual clauses, binding common rules, and accreditation certificates from bodies SDAIA has licensed.
With no list, the adequacy route is closed, and every transfer goes through Article 4. Our guide to the Saudi PDPL sets the transfer rules in the context of the whole law.
| Exemption case (TR Art 4(2)) | Safeguard required |
|---|---|
| (a) Transfer between public bodies to implement an agreement to which the Kingdom is party, or to serve its interests | Standard protection provisions in the agreement or memorandum |
| (b) Non-recurring, or for a limited period, involving a limited number of data subjects | The standard contractual clauses; or an accreditation certificate held by the recipient, if the data is not sensitive |
| (c) Central operations within a group of multinational entities | Binding common rules or the standard contractual clauses; or the recipient’s accreditation certificate |
| (d) A service or benefit provided directly to the data subject, within their expectations | The recipient’s accreditation certificate, and the data is not sensitive |
| (e) Scientific research, limited to the minimum data | The standard contractual clauses; or the recipient’s certificate, if the data is not sensitive |
The eleven rules of the Saudi standard contractual clauses
SDAIA’s document, published on its laws and regulations page, opens with rules that govern how the clauses may be used. The ones that decide outcomes:
- The clauses are included in the main contract or placed in a separate agreement; nothing in the main contract may conflict with them or limit their protection. Additional conditions are allowed only if consistent.
- Any modification of the approved text, other than completing the blank fields, is not recognised by SDAIA and is a violation of the law and the Regulations. This is the rule that distinguishes the Saudi clauses from contract templates a lawyer might improve.
- More than two parties may join, as exporters or importers, over the life of the contract.
- The clauses cannot be used where the laws of the recipient country prevent the importer from complying with them.
- The importer submits to the jurisdiction of the Kingdom and undertakes to comply with binding decisions under its laws.
- The importer must respond to SDAIA’s requests, cooperate with its audits and corrective measures, and confirm actions in writing.
- If the exporter concludes that the importer cannot fulfil the clauses, or the importer says so, the exporter must suspend transfers unless alternative measures meeting the law are adopted.
- SDAIA may change the clauses and will issue transitional rules when it does.
The four templates of the Saudi standard contractual clauses
The Saudi standard contractual clauses come in four templates, and the parties must select the one that matches their roles and delete the others.
| Template | Exporter in the Kingdom | Importer outside | Typical use |
|---|---|---|---|
| First | Controller | Controller | Sharing customer data with a foreign partner or group company that decides its own purposes |
| Second | Controller | Processor | Cloud hosting, SaaS, outsourced support outside the Kingdom |
| Third | Processor | Sub-processor | A Saudi processor engaging a foreign sub-processor |
| Fourth | Processor | Controller | A Saudi processor returning or reporting data to a foreign controller |
The clauses themselves run to twelve: purpose and scope; modification and impact; rights of data subjects, who may notify SDAIA of any violation; interpretation; details of transfers; addition of new parties; compliance with SDAIA’s requests; compensation; personal data security; duration and termination; and the role-specific obligations of the template chosen.
The three appendices
The appendices are where the Saudi standard contractual clauses are completed for a particular transfer.
Appendix 1, the list of parties: each exporter and importer with name, address, contact information, signature, date and role. Appendix 2, the description of the transferred personal data: categories of data subjects; categories of personal data; any sensitive data and the restrictions and safeguards applied to it, such as purpose limitation, access restrictions, access logging, limits on onward transfer or additional measures; the purpose of the transfer; and the retention period or criteria.
Appendix 3, security measures: the organisational, administrative, technical and security measures applied to the transferred data, to meet Article 19 of the law and Article 23 of the Implementing Regulation. SDAIA’s document gives eight example control families (physical access, system access, data access, disclosure control, input control, separation of duties, availability, segregation) and warns that they are examples: the appendix must describe the facts of the transfer, not copy the list.
The appendices are the blank fields the rules allow the parties to complete. Everything else is fixed.
Before signing the Saudi standard contractual clauses: the risk assessment
Article 7 of the Transfer Regulation requires a risk assessment before any transfer under an Article 4 exemption, and before any continuous or widespread transfer of sensitive data. It must cover the purpose and legal basis; the nature and geographical scope of the transfer; the safeguards and their adequacy; the minimisation measures; the potential material or moral effects on data subjects and their likelihood; and the controls that will prevent or mitigate them.
SDAIA’s Risk Assessment Guideline (February 2025) organises the work in four phases: preparation and mapping of the processing lifecycle; assessment of the processing’s own risks; the transfer-specific analysis, including the recipient’s legal regime; and the factors bearing on the Kingdom’s vital interests under Article 29(2)(a). A supporting tool is on the National Data Governance Platform.
Binding common rules and certificates
For a group of multinational entities transferring data for central operations, binding common rules are the alternative to Saudi standard contractual clauses.
SDAIA’s BCR guidelines (September 2024) require the rules to bind every member, its staff and subcontractors; to carry the data subject rights and a complaint and compensation mechanism; to make the Kingdom member liable for violations abroad; to submit claims to the Kingdom’s courts; to be transparent to data subjects; and to be backed by training, complaints handling, audit with results available to SDAIA, and supervision by a DPO or a DPO network. An accreditation certificate from a body SDAIA has licensed is the third safeguard, usable in several cases only where the data is not sensitive.
Onward transfers and losing the exemption
Saudi standard contractual clauses do not end the analysis. The law and the Regulations apply to onward transfers by the recipient, so the clauses and the processor agreement must bind the importer’s own onward recipients. If the controller fails to implement a safeguard, or SDAIA determines that a safeguard is inadequate for a case, the exemption falls away: the controller must halt the transfer and notify the recipients. The rules on the clauses add the importer’s own duty to say when it cannot comply, and the exporter’s duty to suspend.
What a transfer programme built on Saudi standard contractual clauses needs
A transfer register listing every transfer, its purpose, its exemption case, its safeguard and its assessment; a decision record per transfer; a risk assessment template on the four phases; a completion guide for the clauses covering template selection and the three appendices; a BCR guide for groups; a processor agreement with a transfer clause that mirrors the Regulation; and a revocation procedure.
The Saudi PDPL Toolkit ships each of them, written for the position as it stands, with the adequacy list tracked as a pending item in its change register so the procedure can be relaxed when SDAIA publishes. The clauses themselves are SDAIA’s, taken from its site; the pack carries guidance, not copies. For the differences from the EU transfer regime, see Saudi PDPL vs GDPR, and for the EU mechanisms our guide to international data transfers.
Frequently asked questions about Saudi standard contractual clauses
Can we use EU standard contractual clauses instead?
No. The Transfer Regulation names the Saudi standard contractual clauses, binding common rules and accreditation certificates as the safeguards. EU clauses may govern the European side of a flow but are not a Saudi safeguard.
Can our lawyers improve the wording?
No. SDAIA’s rules state that any change to the approved text other than the blank fields is not recognised and is a violation. Additional conditions may be added to the main contract only if they do not conflict.
Which template do we need for cloud hosting abroad?
The second template, controller to processor, if the organisation is the controller. A Saudi processor using a foreign cloud provider uses the third, processor to sub-processor.
Is a risk assessment always required?
Before any transfer under an Article 4 exemption, which today is every transfer, and before continuous or widespread transfers of sensitive data.