{"id":146584,"date":"2026-08-11T09:53:12","date_gmt":"2026-08-11T09:53:12","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=146584"},"modified":"2026-08-11T09:53:12","modified_gmt":"2026-08-11T09:53:12","slug":"saudi-arabia-tmt","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/saudi-arabia-tmt\/","title":{"rendered":"Saudi Arabia: TMT"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-146584","comparative_guide","type-comparative_guide","status-publish","hentry","guides-tmt","jurisdictions-saudi-arabia"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Gowling WLG<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2026\/08\/Ghazzawi-Gowling-WLG-Positive-RGB-Logo_-PNG8820014.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Gowling WLG<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2026\/08\/Ghazzawi-Gowling-WLG-Positive-RGB-Logo_-PNG8820014.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of TMT laws and regulations applicable in Saudi Arabia<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 How are proprietary rights in software and associated materials protected?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>In Saudi Arabia (\u2018KSA\u2019), proprietary rights in software are protected primarily under the Copyright (Royal Decree No. M\/169 of 14\/08\/1447H) (&#8216;Copyright Law&#8217;) , published on 13 February 2026, replaces the 2003 law issued under Royal Decree No M\/41, and enters into force 180 days after publication. This is supplemented by the Anti-Cyber Crime Law (Royal Decree No. M\/17 of 1428H (2007)) (&#8216;ACCL) , which criminalises unauthorised access to, and unlawful use of, computer systems and data and by the Personal Data Protection Law (Royal Decree No M\/19 of 1443H, as amended by Royal Decree No M\/148 of 1444H) (&#8216;PDPL&#8217;), which governs personal data processed through software .<\/p>\n<p>Article 3 of the Copyright Law protects works whatever their type, method of expression, or purpose, listing thirteen non-exhaustive categories of works, with computer programs and their applications appearing at Article 3(11) practitioners should verify against the published text given its recent issuance).<\/p>\n<p>Protection arises automatically on creation, although Article 42 allows registration with the Saudi Authority for Intellectual Property (&#8216;SAIP&#8217;) as a rebuttable presumption of ownership. SAIP and the Communications, Space and Technology Commission (&#8216;CST&#8217;) have published a Software Copyright Protection Guide (29 May 2024) .<\/p>\n<p>Associated materials may attract further protection under the law governing trade secrets, patents (where software produces a technical effect) and trademarks.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Naturally, absent a contrary agreement, economic rights in commissioned software stay with the creator, not the commissioning party.<\/p>\n<p>Article 18 of the Copyright Law draws a clear distinction. Where an employee creates a work in the course of employment and relates to the employer&#8217;s activities, the economic rights vest automatically in the employer, subject to any contrary agreement. Where software is instead created by an independent developer or consultant &#8216;for the account of&#8217; another person \u2014 the typical commissioned development scenario \u2014 Article 18(2) provides that the financial (economic) rights remain with the author unless the parties agree otherwise. A customer that engages a third-party developer or consultancy without a written IP assignment or licence clause will therefore not automatically acquire ownership of the resulting software, even though it commissioned and paid for the work.<\/p>\n<p>The author also retains perpetual, non-transferable and non-waivable moral rights (attribution and objection to prejudicial distortion), which cannot be assigned and must be managed by consent rather than waiver. Best practice is therefore to include: (i) an express written assignment of all economic rights; (ii) a moral rights consent tailored to the anticipated scope of modification, adaptation and rebranding; (iii) clear identification of deliverables, separating newly created code from pre-existing or background IP (with a licence for the latter); and (iv) warranties of originality and non-infringement.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 Are there any specific laws that govern the harm \/ liability caused by Software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>KSA does not have a standalone software liability statute. Harm caused by software or computer systems is addressed through the general civil law of tortious liability under the Civil Transactions Law (Royal Decree No M\/191 of 1444H (2023)) (CTL) , which requires the claimant to prove fault, damage and causation \u2014 there is no strict liability for software defects.<\/p>\n<p>Sector-specific overlays include:<\/p>\n<p>a) the Anti-Cyber Crime Law (ACCL, with civil and criminal liability being independent under Article 119 of the CTL<\/p>\n<p>b) (; the E-Commerce Law (Royal Decree No M\/126, in force October 2019) and its Implementing Regulations , which impose obligations on online service providers relating to disclosure, data privacy and platform conduct; and<\/p>\n<p>c) the PDPL, where a data breach caused by defective or insecure software may expose the responsible party to regulatory sanctions alongside civil liability.<\/p>\n<p>Software risk allocation is therefore largely contractual \u2014 through warranties, limitations and indemnities \u2014 subject to public-policy limits on excluding or capping liability.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software \u2013 To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software \/ computer systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Beyond tortious liability, use and misuse of software is primarily regulated through the ACCL, alongside sector-specific frameworks from the National Cybersecurity Authority (NCA) and CST, and the PDPL where personal data is involved.<\/p>\n<p>The ACCL aims to enhance information security, protect legitimate computer and network use, safeguard public interest and morals, and protect the national economy. It creates tiered offences: interception, unauthorised access, invasion of privacy and defamation (Article 3 \u2014 up to 1 year and\/or SAR 500,000 (approximately USD 133,595)); fraud, impersonation and unauthorised access to bank\/credit data (Article 4 \u2014 up to 3 years and\/or SAR 2 million (approximately USD 534,383)); interference with or damage to systems\/networks (Article 5 \u2014 up to 4 years and\/or SAR 3 million (approximately USD 801,575)); fraud, forgery, identity theft, or distributing material affecting public order\/privacy (Article 6 \u2014 up to 5 years and\/or SAR 3 million (approximately USD 801,575)); and offences against critical infrastructure or involving terrorism (Article 7 \u2014 up to 10 years and\/or SAR 5 million (approximately USD 1,335,959)).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (Licence and SaaS) \u2013 Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No single statute governs software licensing or SaaS in KSA: these arrangements sit under general contract law in the CTL, alongside the copyright licensing rules noted above. Two frameworks are directly relevant:<\/p>\n<p>\u2022 Telecommunications and Information Technology Act (Royal Decree No M\/106 of 1443H (2022)) (&#8216;Telecoms Act&#8217;), which defines &#8216;Information Technology&#8217; to include software programs and systems and requires overseas providers of IT services accessible to users in KSA, including digital content platforms, to obtain authorisation from the CST before providing such services.<\/p>\n<p>\u2022 CST Regulations for the Provision of Cloud Computing Services (CCS) . &#8216;Cloud service&#8217; is defined to include SaaS, IaaS and PaaS, so a foreign SaaS vendor is capable of falling within scope even without a KSA establishment. The CCS requires all cloud service providers (&#8216;CSPs&#8217;) offering services within or into KSA to register with the CST, and classifies customer data into four sensitivity levels &#8211; from Level 1 (public \/ non-sensitive) through to Level 4 (most sensitive, requiring hosting exclusively within KSA) &#8211; each carrying progressively stricter obligations on data residency, encryption, access controls and incident management, with the Level 4 residency threshold carrying significant implications for market entry by foreign providers.<\/p>\n<p>Sector-specific overlays include the Saudi Central Bank (&#8216;SAMA&#8217;) cloud and outsourcing requirements for financial institutions, and the NCA&#8217;s Cloud Cybersecurity Controls (&#8216;CCC&#8217;), which impose additional cybersecurity baseline requirements on CSPs and their customers in regulated sectors.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If \u2018yes\u2019, what would be considered a market standard level of cap?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes, the market standard is a cap set by reference to fees paid or payable in the 12 months preceding the date of the claim (\u20191x annual fees\u2019), although higher multiples (2x or 3x) are sometimes agreed for critical high value engagements.<\/p>\n<p>Caps are typically subject to carve-outs for confidentiality, data protection and IP infringement (excluded, subject to a higher cap, or left uncapped), and may operate per-claim, in aggregate, or both.<\/p>\n<p>The level agreed reflects contract value, system criticality, data sensitivity, insurance, sector (regulated sectors demand higher caps). There is no statutory minimum or maximum cap in KSA, and courts will enforce freely negotiated limitations, subject to public-policy restrictions on excluding liability for gross negligence, wilful misconduct, fraud, or death or personal injury.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor\u2019s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Certain liability categories are commonly carved out from the general liability cap discussed above, either as unlimited liability or subject to a \u2018super cap\u2019 (typically 2x to 5x the general cap).<\/p>\n<p>Those most frequently carved out include: (i) confidentiality breaches, (ii) data protection breaches and data security breaches (including loss of data), particularly given PDPL penalty exposure, (iii) IPR infringement claims (typically addressed through a full indemnity), (iv)breaches of applicable law (best negotiated narrowly, e.g. limited to specified laws or subject to a materiality threshold) given how broad an unqualified carve-out of this kind can be and (v) wilful or deliberate breaches.<\/p>\n<p>Regulatory fines are increasingly carved-out separately, typically limited to fines arising from the vendor&#8217;s own regulatory non-compliance, AI-related liability is an emerging carve-out category, with parties beginning to negotiate specific AI liability caps, although market practice in this area remains unsettled in KSA.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Software Transactions (License and SaaS) \u2013 Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Source-code escrow exists but is not yet standard market practice in KSA, though its profile is rising following the CST&#8217;s publication of a Software Escrow Guideline (November 2025) which establishes a framework for escrow agreements, defines the roles of escrow agents, developers and beneficiaries, and emphasises verification and testing of deposited materials, aligning with broader NCA and SAMA mandates for operational resilience and particularly relevant for organisations operating or supporting critical national infrastructure. Where escrow is required, parties commonly use established international escrow agents with KSA presence (such as Escode (NCC Group), which offers in-country escrow storage in KSA, or The Escrow Company, which offers GCC-jurisdiction agreements); there is no dominant domestic software escrow provider. Release of the source code is triggered by specified events including vendor insolvency, cessation of business, or material breach of the vendor&#8217;s support obligations, and well-drafted escrow agreements will also address verification of deposited materials, deposit-update frequency, and allocation of the agent&#8217;s fees. For cloud\/SaaS, traditional escrow is largely irrelevant since the customer does not run the software independently; equivalent protection instead comes through service continuity and exit provisions \u2014 business continuity\/disaster recovery obligations, data-export and portability rights in usable formats, transition assistance (typically 6\u201312 months post-termination), and continued access during wind-down \u2014 and customers should also confirm that any third-party or open-source components needed to operate the software are separately identified and made available.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no single statute dedicated to IT outsourcing. Transactions are governed by a combination of the CST and NCA rules, the PDPL where personal data is processed, and sector-specific requirements.<\/p>\n<p>In financial services sector, SAMA Rules on Outsourcing requires regulated institutions to: (i) conduct due diligence(ii) obtain prior notification or approval for material outsourcing (iii) include contractual provisions addressing SAMA\u2019s audit rights, business continuity, data security and exit planning and (iv) ensure that outsourced personal data remains appropriately protected.<\/p>\n<p>Separately, the NCA requires contractual flow-down of the Essential Cybersecurity Controls (ECC) to service providers, risk in outsourcing arrangements is therefore primarily allocated through the contract itself, by way of well-drafted data protection, cybersecurity, business continuity and audit provisions, together with any sector-specific regulatory approval requirements that apply.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">IT Outsourcing \u2013 Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no automatic transfer of employees on outsourcing equivalent to the European TUPE regime, and no specific law that governs IT outsourcing in KSA.<\/p>\n<p>Staff do not transfer by operation of law, Article 18 of the Labour Law (Royal Decree M\/51) preserves continuity of service and accrued rights only on a change of ownership or legal form of the employer entity \u2014 not on a pure services outsourcing. The most relevant recent development is the 2024\/2025 amendment to Article 30, which brings subcontracting within scope and requires the provider to be the Ministry of Human Resources and Social Development (MHRSD-) licensed . Any movement of personnel requires either termination and fresh engagement (with consent) or a tripartite transfer agreement and accrued end-of-service gratuity must be respected. Contracts of indefinite duration require 60 days&#8217; written notice from the employer (30 days from the employee, following the February 2025 amendments).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and\/or services, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal law is the Telecoms Act and its Implementing Regulations regulating telecommunications and IT networks and services. The telecom sector is regulated by the CST. The legislation promotes competition, protects users, manages spectrum and numbering, and supports digital transformation under Vision 2030. The CST&#8217;s powers include licensing, spectrum management, penalties, binding regulations, dispute resolution and handling consumer complaints. Calls and information transmitted over public networks are confidential and may only be intercepted in cases specified by law, and service providers must also comply with the PDPL and the NCA framework, alongside the CST&#8217;s own Cybersecurity Regulatory Framework .<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country. Please include a brief overview of the relevant licensing or authorisation regime in your response.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The provision of telecommunications services generally requires a licence, registration or authorisation from the CST. The regime distinguishes between individual licences for operators deploying their own network infrastructure, service-based licences for providers using existing infrastructure and class authorisations for lower-risk services through simplified registration. Applicants for individual licences must meet eligibility, technical and financial criteria, and the CST may impose conditions including quality-of-service standards, coverage and roll-out obligations and Saudi employment targets. Telecommunications equipment must obtain CST type approval before commercial deployment, and any change of control of a licensee requires prior CST approval. Non-compliance may result in financial penalties, licence suspension or revocation.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Access to communications data is grounded in the Telecom Act (Article 32 of which makes calls and information over public networks confidential save in cases specified by law) and its Implementing Regulations, the ACCL \u2014 under which the CST provides technical assistance to security agencies during investigation and trial.<\/p>\n<p>Data that may be requested includes subscriber information, traffic data (metadata), location data and, in appropriate cases, communications content. Providers must retain such data and disclose it to authorised bodies on lawful request, typically on a confidential basis and without notifying the data subject. Metadata requests carry no general requirement for prior judicial authorisation, though content interception requires higher-level authority. Safeguards include statutory scope limitations and PDPL data-protection duties, but the ability to challenge requests is limited, particularly in national security contexts.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Telecommunications \u2013 Please summarise the principal laws (present or impending) that impose cyber security and\/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and\/or provision of telecommunications services.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Cybersecurity and operational resilience obligations flow from Telecom Act and its Implementing Regulations together with the CST&#8217;s Cybersecurity Regulatory Framework for licensed ICT, telecom and postal providers, and the NCA controls (the ECC; the Critical Systems Cybersecurity Controls (&#8216;CSCC&#8217;) for critical national infrastructure; and the CCC for cloud services). Operators must conduct risk assessments, implement technical and governance controls, maintain 24\/7 incident response, and notify data breaches to the CST and affected users.<\/p>\n<p>The NCA, whose competencies are preserved under the Telecoms Act, audits compliance and can impose penalties particularly for critical national infrastructure. The PDPL and the ACCL apply in parallel.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>KSA does not maintain a domestic SSO specific to mobile communications; technical standards are set by international bodies \u2014 principally 3GPP for mobile telecommunications (4G LTE and 5G NR), the ITU for spectrum allocation, IEEE for wireless networking and IoT protocols, and ETSI \u2014 which interact with domestic implementation through two key bodies:<\/p>\n<p>a) the CST, which manages spectrum, type-approval and licensing (requiring all telecommunications and connected devices, including IoT, connected and autonomous vehicles, and digital health technologies, to demonstrate conformity before commercial deployment), regulates IoT connectivity through M2M\/eSIM requirements and V2X standards, and applies its Cybersecurity Regulatory Framework to licensed ICT providers; and<\/p>\n<p>b) the Saudi Standards, Metrology and Quality Organization (SASO), the national standards body responsible for adopting technical regulations aligned with international standards, including the Technical Regulation for Communications and IT Devices (published August 2024, with conformity assessment conducted through the SABER platform), SASO IEC 62443-4-2:2026 mandating Arabic user interfaces and local PKI for IoT gateways (effective April 2026), and a joint SASO\/CST Technical Regulation for Autonomous Vehicles (effective April 2025, mandating Saudi-specific safety standard SHC 801).<\/p>\n<p>The NCA sets additional cybersecurity standards applicable to connected technologies, including the ECC and IoT security standard; the Saudi Food and Drug Authority (SFDA) regulates AI-enabled and connected medical devices; and the General Authority of Civil Aviation (GACA) regulates commercial drones and aerial logistics, requiring a Drone Operator Licence for autonomous aerial operations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Mobile communications and connected technologies \u2013 How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Interoperability standards drive connected technology development in KSA by reducing fragmentation, lowering costs and accelerating deployment at scale, supporting Vision 2030&#8217;s digital transformation objectives. The CST enforces interoperability through spectrum management, IoT regulations and mandatory type-approval aligned with international standards, and SASO reinforces this through its Technical Regulation for Communications and IT Devices (August 2024, with conformity assessment via the SABER platform) and SASO IEC 62443-4-2:2026, imposing uniform cybersecurity, Arabic UI and local PKI requirements on IoT gateways. Practical applications include the CST&#8217;s M2M\/eSIM regulations and IoT-VNO class licensing for smart-city and logistics deployments.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The principal law is the PDPL, in force from 14 September 2023 with grace period for compliance ending on 14 September 2024, supplemented by Implementing Regulations and Regulations on Personal Data Transfer. The regime is overseen by the Saudi Data and Artificial Intelligence Authority (SDAIA). The PDPL has extra-territorial effect and requires personal data to be processed lawfully, fairly and transparently. Data subjects have rights of access, correction, destruction and portability, and cross-border transfers require adequate protection or appropriate safeguards such as binding corporate rules or standard contractual clauses.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Sanctions under the PDPL are both criminal and administrative. Unlawful disclosure or transfer of sensitive personal data with intent to harm or gain personal benefit may attract imprisonment of up to two years and\/or a fine of up to SAR 3 million (approximately USD 801,575). SDAIA may impose warnings and administrative fines of up to SAR 5 million (approximately USD 1,335,959) per violation, doubled to SAR 10 million (approximately USD 2,671,918) for repeat offences, covering breaches such as processing without lawful basis, security failures, missed breach notifications, non-compliance with access requests and unlawful cross-border transfers, and may order corrective measures including cessation of processing and data deletion. Affected individuals also have a private right of compensation, running in parallel to regulatory enforcement.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Data Protection \u2013 What data protection rules are relevant to technology contracts in your country?  Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Technology contracts routinely address PDPL compliance, allocating controller and processor roles through (i) detailed processing agreements covering scope and purposes, (ii) documented instructions (iii) confidentiality (iv) security measures; sub-processor controls with prior written consent (v) breach notification (enabling the controller\u2019s 72-hour notification to SDAIA), (vi) audit rights, (vii) data return and deletion on termination and (viii) cooperation on data-subject requests. Cross-border transfers require processing only in approved jurisdictions, with transfers permitted where adequate protection exists or safeguards such as SDAIA-approved standard contractual clauses are in place. Contracts with international elements sometimes reference the EU GDPR and occasionally the CCPA where a multinational counterparty\u2019s global compliance requires it, but purely domestic contracts reference the PDPL alone.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Cybersecurity is regulated principally by the NCA which has issued several mandatory frameworks: the (ECC), setting baseline requirements for government entities, their subsidiaries, and private-sector entities operating systems on behalf of government, across five domains (governance, defence, resilience, third-party\/cloud, and industrial control systems); the (CCC), for cloud service providers and cloud-using entities; and the (CSCC), for industrial control systems, operational technology and critical national infrastructure. Organisations must conduct self-assessments, document compliance, and report to the NCA. The ACCL provides the criminal dimension by penalising attacks on systems and data.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Sanctions derive principally from the ACCL, with penalties escalating from Article 3 to Article 7 (refer to Q4). Aggravating factors include organised crime, abuse of public position, offences against minors and recidivism, and courts may order confiscation, publication of the judgment and website closure. The NCA and sector regulators (CST, SAMA) may separately impose compliance directives, remediation requirements and administrative penalties under their own frameworks.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. CST-licensed ICT, telecom and postal providers are subject to the CST&#8217;s Cybersecurity Regulatory Framework, and cloud service providers must register under the CST&#8217;s Cloud Computing Regulatory Framework and comply with the NCA&#8217;s CCC. The NCA also requires government entities, their subsidiaries, entities operating systems on their behalf, and operator with critical national infrastructure (energy, water, telecommunications, transport, healthcare and financial services) to implement the Essential and, where relevant, the CSCC (see Q20 for the full NCA framework structure). Sector regulators such as SAMA impose additional cybersecurity requirements on regulated institutions.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Cybersecurity \u2013 Please summarise the regulatory framework for the reporting of cybersecurity incidents.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Cybersecurity incidents must be reported to the NCA by entities subject to its controls, with initial notification generally required within hours of detection depending on severity, followed by a detailed report covering the nature and classification of the incident, systems and data affected, timeline, scope of impact, containment measures and ongoing risk assessment.<\/p>\n<p>Where personal data is breached, separate notification to SDAIA under the PDPL is required within 72 hours, with notification to affected individuals where there is a risk of harm. Coordination between the NCA, SDAIA, the CST and sector regulators is important \u2014 an incident affecting a financial institution, for example, may trigger parallel reporting to the NCA, SDAIA, CST and SAMA. Entities must maintain documented incident-response and recovery procedures as part of ongoing ECC\/CSCC compliance.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Which body(ies), if any, is\/are responsible for the regulation of artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The lead authority is SDAIA, established in 2019, and reporting directly to the Prime Minister, which sets national data and AI policy through the National Strategy for Data and AI (2020) and the AI Ethics and Generative AI Guidelines, and hosts the National Data and Management Office (NDMO), the National Centre for AI and the Global AI Summit. The CST, the NCA, and sector regulators (SAMA, the Saudi Food and Drug Authority (SFDA)), coordinate on connectivity, cybersecurity and sector-specific applications. . There is no single AI regulator with binding enforcement powers; SDAIA leads through strategy and guidance, with binding obligations supplied through the PDPL and sector-specific rules.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no standalone binding AI statute. SDAIA has issued non-binding AI Ethics Principles (2023), and Generative AI Guidelines, promoting fairness, transparency, accountability, privacy and safety. More recently, In April 2026, e SDAIA published the National Artificial Intelligence Risk Management Framework. This is the first national-level guide that sets out a single approach for finding, assessing, treating and monitoring artificial intelligence (AI) risks. Where AI systems process personal data, the PDPL applies, including requirements for lawful basis, transparency on automated decision-making, and data-subject rights and sector-specific AI applications remain subject to existing sectoral regulation (SAMA for financial services, the SFDA for healthcare).<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and\/or generative AI (including agentic AI)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There are no specific binding provisions for LLMs or generative AI. SDAIA Generative AI Guidelines (public and government versions) cover transparency and disclosure of AI-generated content; accountability and human oversight before acting on AI outputs; bias mitigation and monitoring; sound data governance compliant with the PDPL; and cybersecurity protection against adversarial attacks and data leakage. The guidelines are advisory rather than mandatory, but alignment is strongly recommended. Processing personal data through such systems remains subject to the PDPL. Emerging contractual approaches typically address restrictions on using customer data for model training; confidentiality of prompts and outputs; ownership of AI-generated content; warranties regarding accuracy and non-infringement; indemnities for IP infringement in outputs; and service-level commitments. Provisions addressing agentic AI are not yet established.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no statutory requirement for AI-specific contract provisions, but they are increasingly common and considered best practice. Commonly addressed issues include (i) accuracy and reliability warranties ,(ii) ownership and use of input and training data with restrictions on vendor use of customer data (iii), IP ownership of and indemnities for outputs (iv), PDPL-compliant security (v),transparency, human oversight and monitoring (vi),tailored caps or carve-outs for AI-related claims, and (vii) compliance warranties aligned with SDAIA ethical guidance.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Artificial Intelligence \u2013 Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes. Given legal uncertainty surrounding AI-generated material &#8211; the current Copyright Law requires human authorship, so autonomously generated works do not attract protection, and the questions remain around whether AI outputs can infringe training-data copyright or produce outputs stylistically similar to protected works.<\/p>\n<p>Practical contractual approaches include (i) confirming ownership of inputs, allocating ownership of outputs (commonly to the customer), (ii) reserving vendor licences for model improvement with consent, (iii) prohibiting use of customer data for training without opt-in, (iv) providing non-infringement warranties and indemnities and (v) including disclaimers regarding protectability of AI-generated content.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Blockchain \u2013 What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no comprehensive law governing blockchain or digital assets. A standing government committee (comprising SAMA, CMA and other bodies) declared virtual currencies unlicensed in 2018, and the Ministry of Finance issued a public warning against dealing in virtual currencies in 2019; however, there are no specific criminal penalties for individuals who trade digital assets. SAMA and the CMA are actively exploring institutional use cases \u2014 SAMA through its Digital Riyal wholesale CBDC pilot and fintech sandbox, and the CMA through its own sandbox and recent consultation on asset-backed securities (including tokenised structures, April 2026). Both regulators operate regulatory sandboxes to test distributed-ledger and digital-asset use cases. As of mid-2026, there is no formal VASP licensing framework (unlike the UAE&#8217;s VARA regime or Bahrain&#8217;s CBB crypto-asset module), but the expected trajectory is towards a dedicated regulatory framework addressing licensing, custody, anti-money laundering and consumer protection. The regulatory landscape is expected to develop materially over the next two to three years. In addition to the above, CST has issued Guidelines for Blockchain Adoption . This guidelines document aims to adopt best practices and executive and technical recommendations related to Blockchain technology.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Search Engines and Marketplaces \u2013 Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No bespoke law governs search engines or marketplaces; general frameworks apply. The E-Commerce Law governs online sales, provider disclosure and consumer rights, imposing mandatory disclosure, pricing transparency, contract formation rules, a seven-day cooling-off period (subject to exceptions for perishable, personalised or digital goods), record-keeping, merchant identifiability, complaint mechanisms and a prohibition on misleading advertising, reinforced by the general consumer protection rules. The PDPL governs user data collection, requiring consent or another lawful basis for profiling and targeted advertising.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Social media and online platforms are regulated through overlapping regimes. The Audiovisual Media Law (Royal Decree No. M\/33 of 2017) and its Implementing Regulations provide the foundational framework for all broadcasting and media content activities, mandating licensing through the General Authority for Media Regulation (GAMR) and imposing content standards aligned with KSA&#8217;s values; GAMR&#8217;s mandate was expanded in September 2023 (Cabinet Decision No. 174) to encompass the entire media sector, including oversight of broadcasting content via the internet and social media, and a draft Media Law to replace the existing statute has been consulted upon.<\/p>\n<p>The CST separately regulates digital content platforms, including through its IGNITE programme for the digital-content sector, which encompasses licensing requirements for digital content providers and a framework for content accessed from or directed at KSA. The ACCL addresses unlawful online content including defamation, fraud and content affecting public order, and the PDPL applies to platforms&#8217; handling of user data, including profiling, targeted advertising and analytics. This is in addition to the CST Regulations for Providing Digital Content Platform Services, which establish operational and regulatory obligations for digital platform providers; and the E-Commerce Law, which applies to commercial activities conducted through social media, including online advertising and influencer marketing.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Social Media \u2013 What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Sanctions derive from two principal sources. Under the ACCL, criminal penalties escalate from Article 3 to Article 7 (refer to Q4), with the maximum being imprisonment of up to 10 years and\/or a fine of up to SAR 5 million (approximately USD 1,335,959) for the most serious offences involving critical infrastructure or terrorism. Repeat offences within three years attract enhanced penalties. Courts may order device confiscation, website closure, judgment publication and deportation of non-Saudi nationals.<\/p>\n<p>Separately, under the Visual and Audible Media Law and its Implementing Regulations, GAMR may impose administrative penalties including fines (doubled for repeat or continuing violations), suspension from engaging in the profession for up to six months, and licence revocation. GAMR also has direct authority to impose fines and to discontinue broadcasting or suspend a licence as a precautionary measure. Administrative measures across both regimes include content removal, platform blocking and licence revocation.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Spatial Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No law specifically governs spatial computing, AR, VR, XR or the metaverse; such activities are subject to generally applicable frameworks. IP law protects software and content, the PDPL governs processing of personal data, including potentially sensitive biometric and behavioural data captured by immersive devices (facial geometry, eye-tracking, hand-tracking, gait patterns), which may constitute sensitive personal data requiring explicit consent and enhanced protections. SASO imposes mandatory technical regulations on spatial computing hardware entering the Saudi market. Consumer protection rules apply to virtual transactions, CST rules apply to underlying connectivity, radio-frequency type-approval and digital content, and GAMR content-licensing requirements may apply where spatial computing platforms deliver audiovisual media content.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Quantum Computing \u2013 Please summarise the principal laws (present or impending), if any, that govern quantum computing and\/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no specific law governing quantum computing or quantum cryptography. The field is addressed through generally applicable frameworks (IP, PDPL and NCA controls). KSA has invested significantly under Vision 2030, through KAUST research programmes, partnerships with international quantum technology companies, and investment through entities such as TAQNIA. Cryptography and quantum-resistant techniques fall within the NCA&#8217;s remit, and NCA guidance on transitioning to quantum-resistant algorithms (aligned with NIST&#8217;s post-quantum cryptography suite) is expected, with the &#8216;harvest now, decrypt later&#8217; risk making early preparation advisable.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Datacentres \u2013 Does your jurisdiction have any specific regulations that apply to data centres?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes, KSA has a dedicated regulatory framework for data centres. The Data Centers Services Regulations (DSCR) , issued by the CST in August 2023 and effective from January 2024, require all wholesale and retail data centre service providers to register with the CST under one of four categories\u2014Qualifying, Limited, Standard, or Advanced\u2014based on their operational stage and tier certification level, with registrations valid for three years at no fee. Registered providers must comply with obligations covering physical security, SLAs, business continuity, disaster recovery, risk management, customer notification, carrier neutrality (for Standard and Advanced tiers), and energy management\/sustainability planning, and they must also navigate overlapping requirements under the CCS (if offering cloud services), the PDPL, NCA mandates, data localization rules for sensitive categories of data, and applicable telecommunications regulations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 What are your top 3 predictions for significant developments in technology law in the next 3 years?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Over the next three years, we expect three major developments to shape technology law in KSA.<\/p>\n<p>\u2022 First, KSA is likely to introduce a more comprehensive, risk-based AI regulatory framework, moving beyond high-level principles to impose governance, transparency, and accountability requirements for AI systems, particularly those deployed in high-risk sectors.<\/p>\n<p>\u2022 Second, the legal focus on data will expand beyond privacy compliance to regulating the data economy, with clearer rules on data sharing, monetisation, licensing, and the use of datasets for AI development.<\/p>\n<p>\u2022 Third, regulation will increasingly concentrate on AI infrastructure and digital sovereignty, introducing enhanced legal requirements for cloud services, data centres, cross-border processing, AI outsourcing, and cybersecurity, reflecting KSA&#8217;s significant investment in sovereign AI capabilities and digital infrastructure.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">General \u2013 Do technology contracts in your country commonly include provisions to address sustainability \/ net-zero obligations or similar environmental commitments?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Sustainability and net-zero provisions are emerging but not yet standard in KSA technology contracts. Driven by the Saudi Green Initiative and Vision 2030, ESG is reaching the tech sector through data centre energy efficiency, carbon measurement and reduction targets, circular-economy principles for hardware, and supply-chain sustainability. Standardisation is expected to grow, propelled by government procurement, international climate commitments and investor expectations.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">6077<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/146584","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=146584"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}