Skip to main content

Data Residency

Data residency is the question of where data physically lives — the country or jurisdiction in which it is stored and processed — and the obligations that attach to that location. Residency is distinct from data sovereignty (whose laws govern the data) and from cross-border transfer rules (what happens when data moves), but in practice the three are assessed together.

In the Saudi context, residency requirements arrive in layers. The PDPL does not impose a blanket localization mandate, but its restrictions on transferring personal data outside the Kingdom mean that keeping data in-Kingdom is often the simplest compliant posture. On top of that, sector regulators impose explicit residency requirements for certain classes of data — particularly in finance and government — and national cloud policy tiers workloads by classification level, with the most sensitive classes restricted to in-Kingdom facilities.

For a Saudi DMO, the operational implication is that hosting location must be first-class metadata. Every dataset in the catalog should carry where it is hosted — an in-Kingdom data center, an in-Kingdom cloud region, or a foreign region — alongside its classification and whether it contains personal data. With that in place, residency assessments for new systems become routine, and lineage can flag flows that quietly replicate restricted data into out-of-Kingdom destinations before they become audit findings.

In the product