Cross-Border Data Transfer Under PDPL — When Your POS Sends Data Abroad
Most POS systems route Saudi transaction data to servers outside the Kingdom. Under PDPL Article 29, this is a cross-border transfer that requires an adequacy assessment or explicit consent — or it's a violation. Here's what that means for your business.
Most POS systems in Saudi Arabia are built on international cloud infrastructure. The software runs on servers in Ireland, the United States, Singapore, or another jurisdiction entirely. When a customer pays at the counter and hands over their phone number for a loyalty point — that data often leaves the Kingdom before the receipt prints.
Under PDPL, that is not just an architectural fact. It is a compliance event.
What PDPL Article 29 Actually Requires
PDPL Article 29 governs personal data transfers outside Saudi Arabia. The rule is not that cross-border transfers are prohibited. The rule is that they require justification — and the bar for that justification is high.
Three bases can legitimize a cross-border transfer:
**Adequate destination.** The receiving country or organization must provide a level of data protection that SDAIA considers adequate — comparable to Saudi standards. Most international cloud hosting jurisdictions have not been formally assessed by SDAIA. If your POS vendor's data center is in a country with no adequacy determination from SDAIA, this basis is unavailable to you.
**Explicit consent.** The data subject must have been informed that their data is being transferred outside the Kingdom, to which country, and for what purpose — and must have consented specifically to that transfer. A generic loyalty enrollment form does not satisfy this requirement. The consent must be specific, informed, and documented.
**Contractual necessity or public interest.** The transfer is strictly necessary to perform a contract with the data subject, or required for a public interest purpose recognized under Saudi law. Customer retail data routed to an international data center for processing does not typically meet this standard.
If none of these bases applies, the transfer is a violation.
What This Looks Like in Saudi Retail
Many merchants are unaware their POS data is leaving the Kingdom at all. The software is hosted internationally, the transaction is processed internationally, and the receipt data — including the customer's name, phone number, and purchase history — is stored internationally.
Common patterns that create cross-border transfer exposure:
- **International cloud POS platforms** with data centers outside Saudi Arabia routing all transaction data to their primary hosting region by default
- **Global payment processors** that store transaction records on international infrastructure before settlement
- **CRM and loyalty platforms** that sync Saudi customer data to EU or US-hosted databases for analytics and campaign management
- **Backup and DR configurations** that replicate Saudi transaction data to international disaster recovery sites without a separate legal basis
Each of these is a cross-border transfer requiring an adequate legal basis under PDPL. If the basis has not been established — no adequacy determination, no documented explicit consent, no qualifying contractual necessity — the transfer is non-compliant.
The Penalty Framework
PDPL enforcement is active. SDAIA has issued 48 formal enforcement decisions since the grace period ended in September 2024. The penalty framework for cross-border transfer violations:
- Administrative fines of up to **SAR 5 million** for a first violation
- **SAR 10 million** for repeat offenders
- **72-hour notification** requirement if a cross-border transfer is involved in a data breach
SDAIA is now licensing accredited PDPL auditors. The next wave of enforcement is structured audits — not just reactive complaint handling.
How Wateer Eliminates the Surface Area
Wateer's architecture was built to keep Saudi customer data inside the Kingdom.
Every receipt issued through Wateer is stored and processed on Saudi-based infrastructure. No transaction data routes to servers outside Saudi Arabia. Merchants who issue receipts through Wateer inherit a zero cross-border transfer posture — the architectural decision that would otherwise require an adequacy assessment, documented consent framework, or vendor renegotiation is simply not necessary.
For retailers currently running international cloud POS systems: PDPL cross-border compliance is solvable, but it requires either renegotiating your vendor's data residency terms (often not available on standard contracts), building an explicit consent mechanism that meets PDPL's specificity requirements (complex and ongoing), or switching to infrastructure that keeps data in the Kingdom by default.
The receipt layer is often the simplest point to fix first. That is where Wateer starts.
---
#
Related reading
Want to see Wateer on your stack?
Talk to Sales