KSAPDPL.COM

Table of Contents

Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – Introduction
Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – Purpose
Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – Definitions
Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – Scope
Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – The Geographical Scope of Binding Common Rules
Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – Requirements for Binding Common Rules
Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – General Guidelines
Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – Details of the Entity Implementing the BCR (First Section)
Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – Description and Details to Be Covered by the BCR (Second Section)
Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – Binding Nature of the BCR
Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – Cooperation with the Competent Authority
Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – Personal Data Protection Measures

Guidelines for Binding Common Rules (BCR) For Personal Data Transfer – Scope

Overview

Guidelines for Binding Common Rules (BCR) for Personal Data Transfer – Scope defines who the BCR framework applies to and in which transfer scenarios it may be used. It clarifies that these guidelines govern the use of Binding Common Rules by Controllers and Processors when transferring personal data outside the Kingdom of Saudi Arabia to jurisdictions that do not provide an appropriate level of personal data protection.

This section establishes the applicability of BCRs without reducing the legal responsibilities of Controllers under the Saudi Personal Data Protection Law (PDPL), its Implementing Regulations, and the oversight of the Competent Authority (SDAIA).

SDAIA's Official Text

The text below reproduces official PDPL law, regulation, or guideline issued by the Saudi Data & AI Authority, verified against the original SDAIA source. No changes or reinterpretation applied.

Scope

This document specifies the requirements and guidelines related to Binding Common Rules. It applies to data controllers or processors based on the instructions of the data controller and on their behalf, without prejudicing the responsibilities of the data controller to the competent authority or the data subject, as applicable, when transferring personal data outside the Kingdom to a country or international organization that does not have an appropriate level of Personal Data protection.

Plain-Language Explanation

The explanation below is provided to help you understand the SDAIA’s legal text and does not replace or override the official PDPL law, regulation, or guideline.

Applicability of the Guidelines

This provision explains that the document applies specifically to the requirements and guidance governing Binding Common Rules. It establishes that the Guidelines are intended to regulate how BCRs are prepared, implemented, and relied upon as an appropriate safeguard for personal data transfers outside the Kingdom.

Controllers and Processors in Scope

The scope includes data controllers and processors acting based on the instructions of the data controller and on its behalf. This confirms that processors within a group structure may fall within the scope of the BCR framework, provided their processing activities are carried out under the authority and instructions of the controller.

Preservation of Controller Responsibilities

This section clarifies that applying Binding Common Rules does not prejudice or limit the responsibilities of the data controller toward the Competent Authority or the data subject.

 

Controllers remain fully accountable for compliance with the Personal Data Protection Law (PDPL) and its Implementing Regulations, regardless of whether personal data is transferred under BCRs.

Transfers to Jurisdictions Without Adequate Protection

The scope is limited to situations where personal data is transferred outside the Kingdom to a country or international organization that does not provide an appropriate level of personal data protection.

 

In these circumstances, Binding Common Rules operate as a safeguard mechanism to ensure that personal data transferred outside the Kingdom continues to receive protection consistent with Saudi legal and regulatory requirements.

Saudi Personal Data Protection Law Compliance Services (KSA PDPL)

KSA PDPL Compliance Implementation

Achieve PDPL Compliance in 4 weeks or less.

Data Protection Officer As A Service (DPOaaS)

Let us handle your daily PDPL Compliance Operations.

KSA PDPL Compliance Audit (External)

Audit your PDPL compliance obligations.

Scroll to Top