Reference

Who regulates what in Saudi Arabia

Five authorities shape cybersecurity and data protection in the Kingdom. Knowing which one governs which question saves weeks.

The authorities

National Cybersecurity Authority (NCA)

The national cybersecurity regulator. Issues the Essential Cybersecurity Controls and the controls that extend them, and monitors compliance for the entities in their scope.

Applies to: Mandatory for government entities and their affiliated companies, and for private-sector organizations that own, operate or host critical national infrastructure; its extensions reach critical systems, cloud, telework and operational technology.

nca.gov.sa/en (opens in a new tab)

Saudi Data and Artificial Intelligence Authority (SDAIA)

The competent authority for the Personal Data Protection Law. Receives breach notifications, runs the National Register of Controllers and publishes the implementing rules.

Applies to: Every organization that processes personal data in the Kingdom, and parties outside the Kingdom that process personal data of people residing in it.

sdaia.gov.sa/en (opens in a new tab)

Saudi Central Bank (SAMA)

Regulates banks and other financial institutions and mandates the SAMA Cyber Security Framework for them. Its rules do not apply outside the institutions it regulates.

Applies to: Banks and other financial institutions SAMA regulates.

www.sama.gov.sa/en-US (opens in a new tab)

Communications, Space and Technology Commission (CST)

The regulator for communications, space and technology. For cloud, it registers service providers under the Regulations for the Provision of Cloud Computing Services and sets which provider categories may host which classes of government data.

Applies to: Telecom operators and other communications, space and technology providers; in cloud, service providers serving the Kingdom and their subscribers, with added obligations for subscribers holding government data.

www.cst.gov.sa/en (opens in a new tab)

Digital Government Authority (DGA)

Sets digital government platforms and standards for government entities.

Applies to: Government entities.

dga.gov.sa/en (opens in a new tab)

Quick answers

Who do I report a personal data breach to?

SDAIA, within 72 hours, under Article 24 of the Implementing Regulation. Read the breach guide.

Who decides where government data can be hosted in the cloud?

Several authorities share it. CST registers cloud providers by category, and subscribers holding government data must use a CST-registered provider. The classification levels come from the National Data Management Office (NDMO) at SDAIA, or from the sector regulator, and CCC-2:2024 refers data localization to the NDMO. The NCA sets the cloud and critical-systems controls. Read the residency guide.

Does SAMA regulate my fintech?

Only if SAMA licenses or regulates your business. SAMA's framework applies to the institutions it regulates, not to every company in financial services.

Ten minutes to know exactly where you stand

Tell us what you do and who regulates you. We will show you which Saudi rules apply, where the gaps usually are, and the shortest route to ready. No slides, no pitch.