Transfers contrary to the PDPL are in principle subject to a fine of up to 5 million riyals; imprisonment of up to two years and a fine of up to 3 million target another offense—the unlawful disclosure or publication of sensitive data when intended to harm the person concerned or to obtain personal advantage. This punitive regime coexists with a stated ambition: to make the country a regional technology hub and attract cloud giants. NEOM is currently presented around twelve sectors on its official website, but this data does not constitute a national digitization objective of sixteen sectors by 2030. These two objectives can create regulatory trade-offs, and the Middle East is not alone in experiencing this tension.
The Essential Points
- Article 29 governs international transfers; sanctions are provided mainly in Articles 35 and 36, which establish penalties, but no primary source consulted demonstrates that they lead many foreign companies to refuse to operate in the country.
- The regional data center market is expected to experience significant growth by 2029, according to sector estimates, but the regime imposes requirements for data transfer and personal data protection without primary demonstration of infrastructure cost increases.
- Riyadh wants to diversify its economy away from oil through Vision 2030, but the model of digital sovereignty chosen may complicate access to technological investments it seeks to capture.
- The dilemma is not unique to Saudi Arabia: Gulf governments, Europe, and India face the same equation between data control and access to global AI and cloud capacities.
- Solutions exist—regulated transfer agreements, sovereign cloud in partnership—but they assume that sovereignty is conceived as an instrument, not an end.
Localization as Wager, Not Certainty
Data localization rests on a simple intuition: if data remains on national territory, it is under national control. The intuition is not wrong. But it assumes that the benefits of control outweigh its costs, and this assumption merits examination.
In Saudi Arabia, the legal framework has hardened rapidly. The Personal Data Protection Law of 2021, amended in 2023, subjects data transfers outside the kingdom to conditions of national security, adequate level of protection, or appropriate guarantees according to SDAIA regulations. Article 29 governs transfers; ordinary violations can be sanctioned with a fine of up to 5 million riyals according to Article 36. Criminal prosecution is expressly provided for intentional disclosure of sensitive data addressed in Article 35. According to the Middle East Institute, overly restrictive digital sovereignty rules can harm regional technological ambitions.
The Saudi framework imposes conditions on international transfers of personal data. It imposes compliance obligations and can result in fines, while the criminal penalty in Article 35 requires intentional disclosure of sensitive data with a specific intent. For a foreign SME or technology start-up, this calculation can make entry into the Saudi market more difficult.
9.6 Billion Dollars of Ambition, Rules That Reduce Its Access
The data center market in the Middle East is presented by sector analysts as one of the most dynamic of the decade, driven by growing demand for computing capacity for AI, cloud, and digital public services. Saudi Arabia intends to capture a share of this growth.
Investment signals are real. In 2024, AWS announced plans to invest more than 5.3 billion dollars in Saudi Arabia. Microsoft and Google also followed with comparable commitments in the cloud. Google, Amazon Web Services, and Oracle followed with comparable commitments. These announcements are notable.
They merit careful reading, however.
Global hyperscalers have the means to build localized infrastructure. For them, localization is a cost of entry into a strategic market, absorbable in balance sheets of hundreds of billions. For mid-sized players, compliance obligations can create barriers to entry. The regime provides clear flexibility mechanisms for certain transfers, so the assumption of their absence is false. The technological ecosystem that Vision 2030 seeks to develop locally must be able to rely on partners that are agile and adapted to its specific needs.
The concentration drift generated by regulatory barriers in digital markets is not unique to the Gulf. It is observed whenever the rules of the game favor actors capable of absorbing high compliance costs.
Compliance Costs Accumulate Quickly
To understand why localization rules weigh so heavily, one must descend to the operational level.
A software publisher serving customers in twenty countries typically administers its data from two or three global data centers, with replication pipelines, geographically distributed backup systems, and APIs that cross borders permanently. Asking it to localize Saudi data requires modifying its architecture, duplicating its security systems, recruiting or training local teams for compliance, and engaging a Saudi legal advisor to navigate a regulatory framework still partially interpreted by courts.
Compliance obligations for transfers can generate costs, but the assertion of general localization requirements is inaccurate. This figure varies by sector, but it is sufficient to deter a number of potential actors.
Legal uncertainty amplifies the problem. When a natural person, including an executive if they personally commit the act, risks up to two years imprisonment for unlawful disclosure or publication of sensitive data when intended to harm the person concerned or to obtain personal advantage, the risk-benefit calculation changes in nature. A general counsel of a European technology company will hesitate to expose its managers to penal risk in a jurisdiction where available administrative and judicial remedies include complaints, compensation, and appeals of certain sanctions, even if the actual probability of prosecution is low. The existence of the sanction can alter the risk-benefit calculation.
Saudi Data Remains Confined from Riyadh
Localization creates another problem, more discreet but structurally important: it governs transfers of personal data, but does not prohibit them and does not demonstrate a severance of global training or inference capacities.
The most performant AI models, those that power medical assistants, industrial diagnostic tools, financial recommendation systems, are trained on heterogeneous masses of data, often cross-border. A quality Arabic language processing model needs Saudi, Egyptian, Moroccan, Iraqi, Lebanese data, and the capacity to combine them with multilingual corpora to develop robust representations. Regulation can govern transfers of personal data, but it does not prohibit them and it provides pathways for international transfer.
Saudi Arabia has launched ambitious AI projects in its ministries, but these projects depend precisely on access to global cloud capacities and pre-trained models; localization rules impose conditions on international transfers but provide for authorized transfers, and their concrete effect on this access must be demonstrated separately. The kingdom wants both cutting-edge AI services and control of the data that feeds them. Reconciling these two requirements demands clear articulation of what must be protected and how.
The region is not alone facing this dilemma. India imposed localization rules in finance and health before relaxing them partially after measuring their impact on investment attractiveness. The European Union built with the GDPR a framework that protects the data of citizens without prohibiting its cross-border processing, provided that legal guarantees follow. These experiences offer lessons, provided they are read correctly.
Pathways That Allow Avoiding a Choice Between Control and Capacity
The dilemma between digital sovereignty and access to global capacities is not unsolvable. Mechanisms exist to navigate between the two.
The first is the model of sovereign cloud in partnership. Saudi Arabia has signed agreements with international cloud service providers aimed at deploying localized capacities with data residence commitments and compliance clauses. If these agreements are well-structured and their application effectively monitored, they allow hyperscalers to deploy their capacities locally while responding to sovereignty requirements. It is an imperfect model—data remains in infrastructure operated by American entities—but it offers an operational balance that outright prohibition cannot achieve.
The second mechanism is that of regulated transfer agreements, inspired by the European model of standard contractual clauses or adequacy decisions. The idea: define precisely which categories of data can cross borders, under what contractual conditions and with what security guarantees, rather than prohibiting wholesale. SDAIA has published dedicated regulation on transfers outside the kingdom as well as guidelines on guarantees and binding common rules.
The third lever is local training. If Saudi Arabia wants to reduce its dependence on foreign capacities in the medium term, it must invest massively in engineers, data architects, and locally trained security experts. Vision 2030 includes significant educational components, and programs such as those of King Abdullah University of Science and Technology (KAUST) move in this direction. But building a sovereign technological ecosystem takes a generation, not a political term.
None of these pathways is free, and none allows avoiding trade-offs. Absolute digital sovereignty, in the sense of total control over all data processed on the territory, may be difficult to reconcile with integration into global technological value chains. Saudi decision-makers must define precisely what they seek to protect, and for what reasons, before setting the rules that surround it.
A Full-Scale Test for Global South Data Governance
Saudi Arabia represents a textbook case, but its choices will have effects beyond its borders.
The Gulf as a whole is simultaneously constructing its digital governance frameworks, with approaches that diverge. The United Arab Emirates opted for a more flexible regime, with digital free zones, notably the Dubai International Financial Centre, which allow freer data flows under contractual guarantees. Qatar and Bahrain seek their own balance. This regional divergence itself creates a problem: companies operating in multiple Gulf countries face incompatible regimes, which multiplies compliance costs without producing additional protection.
Broadly speaking, Saudi Arabia and its neighbors are part of a set of Global South countries seeking to articulate strong technological ambitions with requirements for political control over their data. Technological outsourcing dynamics and the dependencies they create are perceived as a real, not imaginary, sovereignty risk. The challenge is finding regulatory instruments that effectively protect without erecting barriers that impoverish the populations they are supposed to defend.
If Saudi Arabia calibrates its framework by making sanctions proportionate, transfer procedures practicable, and cloud partnership agreements controllable, it could offer a useful model to other developing countries seeking to protect their data without cutting themselves off from the global digital economy. The regime includes explicit exemptions and guarantees; its net effect on market attractiveness is not established by the primary sources consulted.
The regional data center market will develop, with or without intelligent localization rules. The question is who will benefit, and under what conditions.
Sources
- Middle East Institute, Middle East Cyber Sovereignty Hampers Economic Diversification: https://www.mei.edu/publications/middle-east-cyber-sovereignty-hampers-economic-diversification
- Saudi Data and Artificial Intelligence Authority (SDAIA), Personal Data Protection Law and Implementing Regulations 2021-2023: https://sdaia.gov.sa
- Microsoft Announcement, 5.3 Billion Dollar Investment in Saudi Arabia (2024): https://news.microsoft.com
- Gartner, Federated Data Governance Frameworks and Digital Sovereignty (no guaranteed URL)
- Institute for National Security Studies (INSS), Research on Digital Sovereignty in the Middle East (no guaranteed URL)



