Key facts
| Saudi context | PDPL issued by royal decree; SDAIA is the data and AI regulator |
| Data plane | GCC region-locked plane (me-central-1, UAE); EU, APAC, US planes available |
| Deployment models | In-region cloud, private endpoint in your VPC, on-prem, air-gapped |
| Identity and access | SAML 2.0 / OIDC SSO, SCIM, workspace/role/resource RBAC on Enterprise |
| Key custody | BYOK via AWS KMS, Azure Key Vault, HashiCorp Vault or on-prem HSM |
| Audit | Audit log export to SIEM; region-locked log storage |
| Compliance posture | SOC 2 Type II and ISO 27001 readiness in progress (not yet certified); GDPR and PDPL alignment |
| SLA | 99.9% uptime on paid plans; Enterprise 4-hour support SLA — see /legal/sla |
TL;DR
- Ask for a store-by-store residency map, not a single region name.
- Map subprocessors and upstream model providers against Saudi residency expectations.
- Confirm NCA control alignment for regulated workloads and document gaps.
- Require failover designs that do not silently move data across borders.
- Get deletion, export and audit evidence commitments into the contract and DPA.
How it works, step by step
- Classify workloads against PDPL and any sector regulator (for example SAMA, CMA or health authorities).
- Ask the vendor for the residency map covering inference, embeddings, logs and backups.
- Request the subprocessor list with locations and change-notification terms.
- Review identity, encryption and audit controls; validate BYOK if key custody is in scope.
- Confirm failover and disaster-recovery behavior respects the selected region.
- Pilot with test data and verify configuration exports, audit events and deletion.
- Escalate unresolved gaps through procurement with compensating controls or a different tier.
Original data
Try it yourself
Open the AI data residency checklist →
The questions that matter
- Which region terminates inference, and can you export the configuration proving it?
- Where are embeddings, logs and backups stored, and are they encrypted with your keys?
- Which subprocessors and model upstreams process the data, and in which countries?
- What happens during failover — does residency survive an incident?
- How is data returned and deleted at termination, and what evidence do we receive?
- How do these answers change for on-prem or air-gapped tiers?
Regulatory backdrop in plain terms
The Saudi PDPL establishes personal data processing obligations including lawful basis, rights support, security and transfer conditions, supervised by SDAIA. Regulated sectors add their own expectations, and the NCA's cybersecurity controls are commonly referenced in procurement. The practical consequence for AI: residency claims must be evidenced, and cross-border processing needs a documented basis. Plugsky documents PDPL alignment, offers a GCC data plane and publishes a DPA; confirm your specific obligations with Saudi counsel.
How to evaluate the answers
Score each response on evidence quality. "We are compliant" is weak; a store map, configuration export, subprocessor list and sample audit event are strong. Where certifications are still in progress — as with Plugsky's SOC 2 and ISO 27001 readiness — ask for the control description and compensating evidence your auditors will accept, and record the remediation timeline.
Common pitfalls
Buyers often accept a regional endpoint as proof of full residency while logs replicate globally, or miss that an upstream model provider is a separate subprocessor. Another recurring issue is treating a completed pilot as evidence of production deletion. Insist on a deletion drill before go-live, and keep the evidence with the contract.
Honest comparison
| Capability | Plugsky | Hyperscaler AI platform | Building in-house |
|---|---|---|---|
| Regional capacity | GCC region-locked plane | In-country regions for many services | Your facilities |
| Deployment range | Cloud, VPC, on-prem, air-gapped | Shared cloud with dedicated options | You own the stack |
| Arabic capability | Arabic-first with multilingual embeddings | Varies by model | Model-dependent |
| Identity controls | SSO/SCIM and RBAC on Enterprise | Mature IAM integration | You build it |
| Audit evidence | SIEM export and region-locked logs | Native cloud audit | Custom pipelines |
| Certifications | SOC 2 / ISO 27001 readiness in progress | Completed audits in many regions | Your own programme |
Frequently asked questions
Who regulates data protection in Saudi Arabia?
SDAIA oversees the Personal Data Protection Law. Sector regulators add requirements for banking, finance, health and government. Confirm the applicable mix with Saudi counsel.
Does Plugsky process data inside Saudi Arabia?
Plugsky provides a GCC region-locked plane. Ask the enterprise team to confirm current facility mapping and whether it satisfies your regulator for the specific workload.
Do we need NCA controls alignment?
Many regulated procurement processes reference NCA cybersecurity controls. Ask vendors for control mapping documents and be explicit about gaps that require compensating measures.
Can models and data stay fully on-prem?
Yes — on-prem and air-gapped tiers run open-weight models inside your perimeter with the same OpenAI-compatible API used in the cloud tiers.
How do we handle cross-border model calls?
Identify every upstream provider, document the transfer basis, and prefer routing that stays in-region. Residency requirements should be encoded in configuration, not convention.
What contractual documents should we request?
The DPA with subprocessors and breach terms, the SLA, and the security control description. Plugsky publishes a standard DPA and the SLA is available at /legal/sla.
How do we prove deletion later?
Ask for the deletion runbook now and a sample completion certificate. Then run the drill in your own pilot workspace before production data is involved.