Riyadh | +966‑557400202 | hello@nazztec.com
Cloud & DevOps

Data Residency Requirements for Cloud Adoption in the Kingdom

Residency rarely comes from one law. How PDPL, NCA controls, data classification and sector regulation combine — and a method for deciding where each workload can live.

18 August 20267 min readNAZZTEC Editorial Team
Data Residency Requirements for Cloud Adoption in the Kingdom — cover illustration

Key takeaways

  • Residency obligations come from several sources that must be read together.
  • Data classification is the starting point for every hosting decision.
  • PDPL restricts transfers of personal data outside the Kingdom to defined conditions.
  • Hybrid designs let sensitive data stay local while other workloads use global services.

Why residency is a design input, not an afterthought

Saudi Arabia's digital transformation has accelerated cloud adoption across government and the private sector. At the same time, the Kingdom has built a clear expectation that sensitive data is protected and, in many cases, kept in-country. Organisations that treat residency as a checkbox at the end of a migration often discover they must redesign.

There is rarely a single rule that answers the question “can this data leave the Kingdom?” The answer comes from reading several obligations together.

The main sources of obligation

  • Personal Data Protection Law (PDPL) — restricts transfers of personal data outside the Kingdom to defined conditions, supported by a dedicated transfer regulation.
  • NCA frameworks — the Essential and Cloud Cybersecurity Controls set expectations for hosting and cloud use, particularly for government and critical infrastructure.
  • National data management standards — the National Data Management Office sets data governance and classification standards for public sector data.
  • Sector regulators — SAMA and other regulators set requirements for regulated entities, including for outsourcing and cloud.
  • Cloud regulation — the Communications, Space and Technology Commission regulates cloud service provision in the Kingdom.
  • Contracts — customers, particularly government bodies, frequently impose residency terms of their own.

Start with classification

The national data classification approach groups data by sensitivity — from public through restricted, secret and top secret. Classification determines which hosting options are acceptable. Before any cloud decision:

  • Inventory the data the workload will hold, including logs and backups.
  • Classify it using the scheme that applies to your organisation.
  • Identify any personal data and sensitive personal data under PDPL.
  • Check sector and contractual requirements that apply on top.

A practical decision method

Data profileTypical hosting approach
Highly sensitive government or critical infrastructure dataIn-Kingdom hosting with providers and services that meet the applicable NCA and sector requirements
Personal data of Saudi residentsIn-Kingdom by default; transfers only where a PDPL condition and documented assessment support them
Regulated financial dataPer SAMA outsourcing and cloud requirements, confirmed with the regulator where needed
Public or low-sensitivity dataBroader choice, including global services, subject to contract terms

These are general patterns, not legal advice. Specific decisions should be confirmed against the current text of each obligation.

Hidden data flows to check

  • Backups and disaster recovery copies in another region.
  • Logs and telemetry sent to global security or monitoring services.
  • Support access by provider staff located abroad.
  • AI and analytics services that process data outside the region.
  • SaaS tools adopted by business teams without review.

Designing for residency without losing capability

Residency does not have to mean giving up modern services. Hybrid architectures keep sensitive data and its processing in-Kingdom while using global services for non-sensitive workloads. Tokenisation and pseudonymisation can let analytics run on data that no longer identifies individuals. And because in-country cloud capacity in the Kingdom has expanded quickly, options that were unavailable a few years ago may now exist — always confirm current service availability in each in-country region before finalising a design.

Questions to ask your cloud provider

  • Which of your services are available in your in-Kingdom region, and which are not?
  • Where are backups, replicas, logs and support data stored and processed?
  • Can your staff outside the Kingdom access our data, and under what controls?
  • How do you evidence alignment with the NCA cloud controls and CST requirements?
  • What happens to our data at the end of the contract, and how is deletion confirmed?
  • How will you notify us of incidents, and within what time?

Record the answers in the contract or its annexes. A residency commitment made in a sales meeting is only useful if it is written down.

Keeping residency decisions current

Residency is not a one-off decision. Regulations are updated, providers open new regions and add services, and your own workloads change. Review hosting decisions at least annually and whenever a significant change occurs — a new data type, a new provider service or a regulatory update. A simple register of workloads, their data classification, hosting location and the rationale behind it makes these reviews quick and gives auditors a clear trail.

Frequently asked questions

Can personal data be stored outside Saudi Arabia?
Only where the PDPL and its transfer regulation allow it, which requires meeting defined conditions and, in many cases, a documented assessment. In-Kingdom hosting avoids the question for most workloads.
Do backups count for data residency?
Yes. Backups, replicas and logs are copies of the data and are subject to the same considerations.
Are global SaaS tools prohibited?
Not inherently. They must be assessed against the classification of the data they will hold and the applicable transfer rules.
Keep reading

More insights

NCA Cloud Cybersecurity Controls (CCC) Explained — cover illustration
Cloud & DevOps

NCA Cloud Cybersecurity Controls (CCC) Explained

How the CCC extends the ECC for cloud, what it asks of providers and of tenants, and how to turn shared responsibility into evidence both sides can rely on.

25 August 20267 min read

Talk to the team behind this briefing

Tell us what you are working on. A senior NAZZTEC consultant will come back within one business day with a practical view.

We respond to every enquiry within one business day.