Enterprise + Sovereign AI

What should Saudi and GCC buyers ask about PDPL and AI?

Saudi and GCC buyers should ask six PDPL questions of any AI vendor: what personal data enters the system, which lawful basis applies, where processing and transfers occur, whether data is used for training, how long each store retains data, and how data subject rights are supported. Ask for architecture evidence — region maps, configuration exports, subprocessor locations — and map sector rules such as SAMA guidance separately.

Key facts

Regimes in scopeSaudi PDPL plus UAE PDPL, DIFC DPL and free-zone rules; sector rules such as SAMA apply
Saudi regionsa-central-1 (Riyadh) available on Enterprise; GCC default is me-central-1 (UAE)
Residency controlsRegion pinning per workspace, plus VPC, on-prem and air-gapped tiers
Rights supportDocumented assistance with access, deletion and portability requests
Training useContractual limits on using customer data for training; confirm current wording
AuditPer-request logs and key/admin audit events, exportable to SIEM
Contractual frameTerms at /legal/terms and service commitments at /legal/sla
Compliance postureSOC 2 Type II and ISO 27001 readiness in progress (not yet certified)

TL;DR

  • Start with a data map; PDPL answers depend on what enters the system.
  • Ask for residency evidence, not residency promises.
  • Treat sector rules — SAMA, health, government — as separate reviews.
  • Confirm the training-use clause and how it is enforced.
  • Rehearse a rights request and a deletion before go-live.

How it works, step by step

  1. Map personal data flows into prompts, files, embeddings, logs and backups.
  2. Confirm the lawful basis and any sensitive-data restrictions per use case.
  3. Decide the residency requirement and verify the configured region with an export.
  4. Review subprocessors and where each one processes data.
  5. Check the training-use clause and its technical enforcement.
  6. Define retention and deletion for every store, including vectors and backups.
  7. Test a data subject request and document the escalation path.
1Map personal dataflows into prompts,files, embeddings,2Confirm the lawfulbasis and anysensitive-data3Decide theresidencyrequirement and4Reviewsubprocessors andwhere each one5Check thetraining-use clauseand its technical6Define retentionand deletion forevery store,

Try it yourself

Open the AI data residency checklist →

The questions that matter most

  • Scope: which personal data classes enter prompts, files and retrieval indexes — and which must not.
  • Basis and sensitivity: what lawful basis covers each purpose, and does any sensitive-data restriction apply?
  • Transfers: where is data processed, stored, logged and supported from, and what legitimises each cross-border flow?
  • Residency: can processing be pinned to the Kingdom or the UAE, and what is the failover behaviour?
  • Training: is customer data used to improve models, and what enforces the answer?
  • Lifecycle and rights: retention per store, deletion of derived data, and how access and erasure requests are handled.

Sector expectations add to PDPL

Horizontal data protection law is only the floor. Financial institutions add SAMA cyber and outsourcing expectations; government and healthcare add their own controls around classification, local hosting and personnel. The practical move is to run one review per sector commitment, then satisfy the strictest applicable requirement in the architecture rather than averaging across them. Document which rule drove each design decision so an auditor can trace it back.

Turning residency into evidence

A claim of in-Kingdom processing should be provable in five artefacts: a workspace configuration export showing the pinned region; a store-by-store map covering inference, logs, embeddings and backups; a subprocessor list with locations; sample audit events with actor and timestamp; and a retention and deletion schedule. Plugsky offers a Riyadh region on Enterprise, with the UAE as the GCC default, and supports VPC, on-prem and air-gapped tiers when the boundary must be physical. Verify the setting in your own workspace instead of relying on a default.

Contracting and the honest gaps

Anchor contractual positions to the documents you actually sign — /legal/terms for terms and /legal/sla for service commitments — and attach the DPA and subprocessor list to the diligence file. Record that Plugsky's SOC 2 Type II and ISO 27001 status is readiness in progress rather than completed certification, and that specialist endpoints such as audio, images and fine-tuning are coming soon. Neither point disqualifies a vendor, but both belong in the risk register with milestones and compensating controls rather than left implied.

Honest comparison

PDPL considerationPlugskyGlobal API providerSelf-hosted in-Kingdom
Saudi regionRiyadh on Enterprise; UAE default for GCCOften nearest foreign regionYour own facility
Residency evidenceConfig exports, logs, subprocessor listVariesYour own tooling
Failover controlExplicit pinned behaviourProvider routing decidesYou design it
Key custodyBYOK or HSM, customer revocationUsually provider-managedYou operate the HSM
Sector mappingControls available, mapping is your reviewVariesYour responsibility
Ops burdenManagedManagedHigh

Frequently asked questions

Does Plugsky have a Saudi region?

Yes. sa-central-1 (Riyadh) is available on Enterprise, while me-central-1 (UAE) is the default GCC region. Verify the selected region in your workspace and export the configuration for your file.

Is PDPL compliance achieved by choosing a region?

No. Region pinning is one control. You also need lawful basis, transfer analysis, retention and deletion, rights handling, subprocessor review and audit evidence. PDPL compliance is an operating posture, not a setting.

How do we prove data is not used for training?

Ask for the training-use clause and the mechanism that enforces it, then document both in diligence. Confirm the restriction flows down to subprocessors and upstream model providers.

Are derived embeddings covered by PDPL?

Yes. Vectors derived from personal data remain personal data and must be included in residency, retention and deletion scope. Test deletion across the vector store and its backups.

What about SAMA and other sector rules?

Sector frameworks add requirements beyond PDPL. Map them separately, satisfy the strictest applicable one, and keep the evidence trail for each so auditors can trace the design rationale.

Can government workloads be fully offline?

Yes. On-prem and air-gapped deployments are available for environments that forbid external network paths, with physical-media updates and offline key custody.

What rights support should we require?

A documented path for access, correction, deletion and portability requests, with defined timeframes and clear customer-versus-provider responsibilities. Rehearse one request during the pilot.

What is Plugsky's certification status?

SOC 2 Type II and ISO 27001 are documented as readiness in progress rather than completed certification, and the platform documents UAE PDPL and DIFC DPL alignment. Verify current evidence during diligence and track milestones contractually.