For most of the last decade, a Saudi organisation choosing a cloud platform had to accept that its data would sit somewhere else. That is changing quickly, but not evenly — and the gap between what has launched and what has been announced is where most procurement mistakes are currently made.
This is where things actually stand in 2026, and what it means for a platform decision taken this year.
What Is Live in the Kingdom Today
- Oracle Cloud — Jeddah live since February 2020, Riyadh since July 2024. The longest in-country presence of any hyperscaler, both operating with single availability domains.
- Alibaba Cloud — Riyadh live since June 2022, operated through the SCCC joint venture.
- Huawei Cloud — Riyadh live since September 2023, with three availability zones.
- Google Cloud — Dammam live since November 2023. Access is routed through CNTXT, its joint venture with Aramco, and is restricted to customers based in the Kingdom.
- Tencent Cloud — Saudi region live since February 2025, with two availability zones.
What Is Announced but Not Yet Available
- Microsoft Azure — the Saudi Arabia East region has been confirmed for availability in Q4 2026.
- Amazon Web Services — announced in March 2024 with a $5.3 billion commitment and a target of December 2026. It had not launched as of mid-2026.
The significance is easy to miss. The two platforms with the largest enterprise software ecosystems in the Kingdom — the ones most Saudi organisations are already standardised on for productivity, identity and analytics — are the two whose in-country regions arrive last. Any workload built on Azure or AWS during 2026 is running outside Saudi Arabia unless it was deliberately placed elsewhere.
What the Regulation Actually Requires
A persistent assumption in Kingdom procurement is that personal data may never leave the country. That is not what the Personal Data Protection Law says.
The law came into force on 14 September 2023, with the compliance grace period ending a year later. The Saudi Data and Artificial Intelligence Authority supervises it, and enforcement is no longer theoretical — SDAIA issued 48 violation decisions across 2025 and 2026.
What it requires in practice:
- Cross-border transfers are permitted with safeguards. Because no adequacy country list has been published, transfers currently rely on standard contractual clauses or binding corporate rules acceptable to SDAIA.
- Controllers must register on SDAIA’s National Data Governance Platform.
- A Data Protection Officer is required for public entities, organisations processing sensitive data at scale, and organisations conducting cross-border transfers — which includes most companies running workloads outside the Kingdom.
- Breaches must be notified within 72 hours of the organisation becoming aware of them.
- Data must be classified across four tiers, from public through internal and confidential to restricted or sensitive. Health, biometric and financial data sit in the highest tier and carry explicit consent and enhanced security obligations.
Penalties reach SAR 5 million per breach, roughly USD 1.3 million, doubling for repeat offences, with custodial sentences of up to two years available for egregious violations involving sensitive data.
Where Sector Rules Bite Harder Than PDPL
For regulated industries, the binding constraint is usually not the general data protection law. It is the sector regulator.
Financial institutions answer to the Saudi Central Bank, whose expectations around outsourcing, cloud adoption and cross-border processing are the practical governing requirement for any banking data architecture. Cloud service arrangements may also involve the Communications, Space and Technology Commission. An architecture that satisfies PDPL and fails SAMA expectations has solved the wrong problem.
The pattern we see most often is a team that has done careful PDPL analysis and never involved the compliance function that owns the sector relationship. That conversation is cheaper before the platform is chosen.
How to Make the Decision This Year
- Classify before you choose. Which of your workloads actually touch tier three or tier four data? Usually far fewer than assumed, and the answer narrows the problem considerably.
- Split the estate deliberately. Regulated workloads and general workloads do not have to sit in the same region, or with the same provider. Treating the estate as one decision forces the strictest constraint onto everything.
- Plan for the region you will have, not only the one you have now. If your strategic platform is Azure or AWS, design so that a region migration in 2027 is a configuration change rather than a rebuild.
- Check the access model, not only the map pin. Google’s Dammam region is in-country but reached through CNTXT and limited to Saudi-based customers — a real constraint for organisations with regional operations.
- Get the safeguards documented early. Standard contractual clauses take time to agree. Starting them after the architecture is signed off is how go-live dates slip.
Frequently Asked Questions
Does PDPL force us to keep all data in Saudi Arabia?
No. It permits cross-border transfer with appropriate safeguards. What it does require is that you can demonstrate the safeguard, that the transfer is limited to the minimum data needed, and that it does not compromise national security. Sector regulators may impose stricter rules than PDPL itself.
Should we wait for the Azure or AWS Saudi region before starting?
Rarely. Waiting a year usually costs more than designing for portability now. What matters is that the architecture does not hard-code assumptions that make a later region move expensive.
We are a bank. Does any of this change for us?
The Saudi Central Bank’s expectations, not PDPL, are usually the governing requirement for financial services. Involve your compliance function before shortlisting platforms rather than after.
Do we need a Data Protection Officer?
If you are a public entity, process sensitive data at scale, or transfer personal data outside the Kingdom, yes — and the appointment has to be registered.
What happens if we get it wrong?
Fines reach SAR 5 million per breach and double for repeat violations. SDAIA has issued 48 violation decisions across 2025 and 2026, so the enforcement risk is no longer hypothetical.
Working Through It
We design data platforms for organisations in Saudi Arabia that have to satisfy both a regulator and a delivery deadline. Tell us what workloads you are moving, what data they touch, and which regulator you answer to, and we will map the realistic options rather than the vendor-preferred one.
Talk to us about your platform decision.
Related Reading
- Business intelligence tools in Saudi Arabia: what they really cost
- Self-service BI tools in Saudi Arabia
- Data management consulting in Saudi Arabia
- SAMA regulatory reporting and BI — banking case study
- Data management and engineering services
Not sure which solution fits your needs?
Every engagement is scoped to what you actually need. Tell us a bit about your goals and we will get back to you with the right approach.



Leave A Comment