Guides
Practical guides for Saudi compliance
Each guide answers one practical question, cites the official text, and ends with the steps to take.
Start with the question you have
Breach notification: the 72-hour rule
What to tell SDAIA, when the clock starts, and how to notify the people affected.
Read the guideData protection officer and registration
The three cases that require a DPO and the four that require registration with SDAIA.
Read the guideCloud and data residency
Government data classification, cloud provider registration, data localization and the rules for critical systems.
Read the guideISO 27001, SOC 2, PCI DSS and GDPR alongside Saudi rules
Which international frameworks appear next to the NCA controls and the PDPL, and how to run one program.
Read the guideTen minutes to know exactly where you stand
Tell us what you do and who regulates you. We will show you which Saudi rules apply, where the gaps usually are, and the shortest route to ready. No slides, no pitch.