Key facts
| Regimes in scope | Saudi PDPL plus UAE PDPL, DIFC DPL and free-zone rules; sector rules such as SAMA apply |
| Saudi region | sa-central-1 (Riyadh) available on Enterprise; GCC default is me-central-1 (UAE) |
| Residency controls | Region pinning per workspace, plus VPC, on-prem and air-gapped tiers |
| Rights support | Documented assistance with access, deletion and portability requests |
| Training use | Contractual limits on using customer data for training; confirm current wording |
| Audit | Per-request logs and key/admin audit events, exportable to SIEM |
| Contractual frame | Terms at /legal/terms and service commitments at /legal/sla |
| Compliance posture | SOC 2 Type II and ISO 27001 readiness in progress (not yet certified) |
TL;DR
- Start with a data map; PDPL answers depend on what enters the system.
- Ask for residency evidence, not residency promises.
- Treat sector rules — SAMA, health, government — as separate reviews.
- Confirm the training-use clause and how it is enforced.
- Rehearse a rights request and a deletion before go-live.
How it works, step by step
- Map personal data flows into prompts, files, embeddings, logs and backups.
- Confirm the lawful basis and any sensitive-data restrictions per use case.
- Decide the residency requirement and verify the configured region with an export.
- Review subprocessors and where each one processes data.
- Check the training-use clause and its technical enforcement.
- Define retention and deletion for every store, including vectors and backups.
- Test a data subject request and document the escalation path.
Try it yourself
Open the AI data residency checklist →
The questions that matter most
- Scope: which personal data classes enter prompts, files and retrieval indexes — and which must not.
- Basis and sensitivity: what lawful basis covers each purpose, and does any sensitive-data restriction apply?
- Transfers: where is data processed, stored, logged and supported from, and what legitimises each cross-border flow?
- Residency: can processing be pinned to the Kingdom or the UAE, and what is the failover behaviour?
- Training: is customer data used to improve models, and what enforces the answer?
- Lifecycle and rights: retention per store, deletion of derived data, and how access and erasure requests are handled.
Sector expectations add to PDPL
Horizontal data protection law is only the floor. Financial institutions add SAMA cyber and outsourcing expectations; government and healthcare add their own controls around classification, local hosting and personnel. The practical move is to run one review per sector commitment, then satisfy the strictest applicable requirement in the architecture rather than averaging across them. Document which rule drove each design decision so an auditor can trace it back.
Turning residency into evidence
A claim of in-Kingdom processing should be provable in five artefacts: a workspace configuration export showing the pinned region; a store-by-store map covering inference, logs, embeddings and backups; a subprocessor list with locations; sample audit events with actor and timestamp; and a retention and deletion schedule. Plugsky offers a Riyadh region on Enterprise, with the UAE as the GCC default, and supports VPC, on-prem and air-gapped tiers when the boundary must be physical. Verify the setting in your own workspace instead of relying on a default.
Contracting and the honest gaps
Anchor contractual positions to the documents you actually sign — /legal/terms for terms and /legal/sla for service commitments — and attach the DPA and subprocessor list to the diligence file. Record that Plugsky's SOC 2 Type II and ISO 27001 status is readiness in progress rather than completed certification, and that specialist endpoints such as audio, images and fine-tuning are coming soon. Neither point disqualifies a vendor, but both belong in the risk register with milestones and compensating controls rather than left implied.
Honest comparison
| PDPL consideration | Plugsky | Global API provider | Self-hosted in-Kingdom |
|---|---|---|---|
| Saudi region | Riyadh on Enterprise; UAE default for GCC | Often nearest foreign region | Your own facility |
| Residency evidence | Config exports, logs, subprocessor list | Varies | Your own tooling |
| Failover control | Explicit pinned behaviour | Provider routing decides | You design it |
| Key custody | BYOK or HSM, customer revocation | Usually provider-managed | You operate the HSM |
| Sector mapping | Controls available, mapping is your review | Varies | Your responsibility |
| Ops burden | Managed | Managed | High |
Frequently asked questions
Does Plugsky have a Saudi region?
Yes. sa-central-1 (Riyadh) is available on Enterprise, while me-central-1 (UAE) is the default GCC region. Verify the selected region in your workspace and export the configuration for your file.
Is PDPL compliance achieved by choosing a region?
No. Region pinning is one control. You also need lawful basis, transfer analysis, retention and deletion, rights handling, subprocessor review and audit evidence. PDPL compliance is an operating posture, not a setting.
How do we prove data is not used for training?
Ask for the training-use clause and the mechanism that enforces it, then document both in diligence. Confirm the restriction flows down to subprocessors and upstream model providers.
Are derived embeddings covered by PDPL?
Yes. Vectors derived from personal data remain personal data and must be included in residency, retention and deletion scope. Test deletion across the vector store and its backups.
What about SAMA and other sector rules?
Sector frameworks add requirements beyond PDPL. Map them separately, satisfy the strictest applicable one, and keep the evidence trail for each so auditors can trace the design rationale.
Can government workloads be fully offline?
Yes. On-prem and air-gapped deployments are available for environments that forbid external network paths, with physical-media updates and offline key custody.
What rights support should we require?
A documented path for access, correction, deletion and portability requests, with defined timeframes and clear customer-versus-provider responsibilities. Rehearse one request during the pilot.
What is Plugsky's certification status?
SOC 2 Type II and ISO 27001 are documented as readiness in progress rather than completed certification, and the platform documents UAE PDPL and DIFC DPL alignment. Verify current evidence during diligence and track milestones contractually.