Enterprise + Sovereign AI

What should enterprise teams ask about AI data residency in Saudi Arabia?

Saudi enterprise teams should ask four direct questions: where does each data store physically reside, which subprocessors and model upstreams can see the data, how does failover preserve jurisdiction, and what deletion evidence will you provide at exit? The Personal Data Protection Law issued by royal decree, with SDAIA as regulator, plus NCA cybersecurity controls shape the compliance expectations for regulated buyers.

Key facts

Saudi contextPDPL issued by royal decree; SDAIA is the data and AI regulator
Data planeGCC region-locked plane (me-central-1, UAE); EU, APAC, US planes available
Deployment modelsIn-region cloud, private endpoint in your VPC, on-prem, air-gapped
Identity and accessSAML 2.0 / OIDC SSO, SCIM, workspace/role/resource RBAC on Enterprise
Key custodyBYOK via AWS KMS, Azure Key Vault, HashiCorp Vault or on-prem HSM
AuditAudit log export to SIEM; region-locked log storage
Compliance postureSOC 2 Type II and ISO 27001 readiness in progress (not yet certified); GDPR and PDPL alignment
SLA99.9% uptime on paid plans; Enterprise 4-hour support SLA — see /legal/sla

TL;DR

  • Ask for a store-by-store residency map, not a single region name.
  • Map subprocessors and upstream model providers against Saudi residency expectations.
  • Confirm NCA control alignment for regulated workloads and document gaps.
  • Require failover designs that do not silently move data across borders.
  • Get deletion, export and audit evidence commitments into the contract and DPA.

How it works, step by step

  1. Classify workloads against PDPL and any sector regulator (for example SAMA, CMA or health authorities).
  2. Ask the vendor for the residency map covering inference, embeddings, logs and backups.
  3. Request the subprocessor list with locations and change-notification terms.
  4. Review identity, encryption and audit controls; validate BYOK if key custody is in scope.
  5. Confirm failover and disaster-recovery behavior respects the selected region.
  6. Pilot with test data and verify configuration exports, audit events and deletion.
  7. Escalate unresolved gaps through procurement with compensating controls or a different tier.
1Classify workloadsagainst PDPL andany sector2Ask the vendor forthe residency mapcovering inference,3Request thesubprocessor listwith locations and4Review identity,encryption andaudit controls;5Confirm failoveranddisaster-recovery6Pilot with testdata and verifyconfiguration

Original data

GCC region-locData planeSAML 2.0 / OIDIdentity and accesSOC 2 Type II Compliance posture99.9% uptime oSLASource: Plugsky facts table · updated 2026-09-25

Try it yourself

Open the AI data residency checklist →

The questions that matter

  • Which region terminates inference, and can you export the configuration proving it?
  • Where are embeddings, logs and backups stored, and are they encrypted with your keys?
  • Which subprocessors and model upstreams process the data, and in which countries?
  • What happens during failover — does residency survive an incident?
  • How is data returned and deleted at termination, and what evidence do we receive?
  • How do these answers change for on-prem or air-gapped tiers?

Regulatory backdrop in plain terms

The Saudi PDPL establishes personal data processing obligations including lawful basis, rights support, security and transfer conditions, supervised by SDAIA. Regulated sectors add their own expectations, and the NCA's cybersecurity controls are commonly referenced in procurement. The practical consequence for AI: residency claims must be evidenced, and cross-border processing needs a documented basis. Plugsky documents PDPL alignment, offers a GCC data plane and publishes a DPA; confirm your specific obligations with Saudi counsel.

How to evaluate the answers

Score each response on evidence quality. "We are compliant" is weak; a store map, configuration export, subprocessor list and sample audit event are strong. Where certifications are still in progress — as with Plugsky's SOC 2 and ISO 27001 readiness — ask for the control description and compensating evidence your auditors will accept, and record the remediation timeline.

Common pitfalls

Buyers often accept a regional endpoint as proof of full residency while logs replicate globally, or miss that an upstream model provider is a separate subprocessor. Another recurring issue is treating a completed pilot as evidence of production deletion. Insist on a deletion drill before go-live, and keep the evidence with the contract.

Honest comparison

CapabilityPlugskyHyperscaler AI platformBuilding in-house
Regional capacityGCC region-locked planeIn-country regions for many servicesYour facilities
Deployment rangeCloud, VPC, on-prem, air-gappedShared cloud with dedicated optionsYou own the stack
Arabic capabilityArabic-first with multilingual embeddingsVaries by modelModel-dependent
Identity controlsSSO/SCIM and RBAC on EnterpriseMature IAM integrationYou build it
Audit evidenceSIEM export and region-locked logsNative cloud auditCustom pipelines
CertificationsSOC 2 / ISO 27001 readiness in progressCompleted audits in many regionsYour own programme

Frequently asked questions

Who regulates data protection in Saudi Arabia?

SDAIA oversees the Personal Data Protection Law. Sector regulators add requirements for banking, finance, health and government. Confirm the applicable mix with Saudi counsel.

Does Plugsky process data inside Saudi Arabia?

Plugsky provides a GCC region-locked plane. Ask the enterprise team to confirm current facility mapping and whether it satisfies your regulator for the specific workload.

Do we need NCA controls alignment?

Many regulated procurement processes reference NCA cybersecurity controls. Ask vendors for control mapping documents and be explicit about gaps that require compensating measures.

Can models and data stay fully on-prem?

Yes — on-prem and air-gapped tiers run open-weight models inside your perimeter with the same OpenAI-compatible API used in the cloud tiers.

How do we handle cross-border model calls?

Identify every upstream provider, document the transfer basis, and prefer routing that stays in-region. Residency requirements should be encoded in configuration, not convention.

What contractual documents should we request?

The DPA with subprocessors and breach terms, the SLA, and the security control description. Plugsky publishes a standard DPA and the SLA is available at /legal/sla.

How do we prove deletion later?

Ask for the deletion runbook now and a sample completion certificate. Then run the drill in your own pilot workspace before production data is involved.