

Are You Dual-Compliant? Navigating the Dual Data Laws of KSA & Egypt
Episode notes
The era of "one-size-fits-all" data compliance in the Middle East is over. Many organizations operating in key markets like Saudi Arabia (KSA) and Egypt are falling into a critical compliance gap by focusing only on the national data laws (KSA PDPL, Egypt DPL) and ignoring stricter, sector-specific regulations.
In this essential episode, your hosts Annie Garcia and Rob Healey introduce the concept of Dual-Compliance. We break down exactly why financial institutions, healthcare providers, and tech firms must answer to two masters—the national Data Protection Authority and powerful sectoral regulators like SAMA and the CBE. Ignoring these layers can lead to severe penalties and operational disruption.
🔑 Key Discussion Points & Dual-Compliance Checklist
We provide a roadmap for navigating the two major compliance environments:
- 1. Defining Dual-Compliance: Why compliance is a layered issue in the MENA region. The national PDPL/DPL is the baseline, but the sectoral regulator holds the veto power.
- 2. KSA’s Financial Gauntlet (SDAIA vs. SAMA): We detail how the Saudi Central Bank (SAMA) mandates strict Data Residency and rigorous Cloud Outsourcing requirements that go far beyond the general KSA PDPL.
- 3. The Egyptian Exemption (DPL vs. CBE): Learn about the critical carve-out in Egypt's Data Protection Law: entities regulated by the Central Bank of Egypt (CBE) are exempt from the DPL. Instead, they must comply solely with the stricter Banking Law No. 194 of 2020.
- 4. Cross-Border Hurdles: We discuss the complexity of moving data out of both nations, including Egypt's requirement for a mandatory PDPC permit or license for most transfers.
🛠️ Actionable Takeaways
- Identify Your Regulator(s): Immediately determine which sectoral regulator (SAMA, CBE, MoH, etc.) has jurisdiction over your data in KSA and Egypt, in addition to the national DPA.
- Layer Your Audit: Your next compliance audit must compare your practices against both the general data law and the specific sectoral rules.
- Validate Third-Party Contracts: Scrutinize all cloud and outsourcing contracts for KSA/Egypt to ensure they meet the specific data residency and due diligence standards imposed by sectoral bodies like SAMA and the CBE.
🔗 Resources
- Read the Article: Are You Dual-Compliant? Why the PDPL Isn't the Only Data Law You Need to Follow in KSA & Egypt
- Book Your Dual-Compliance Consultation: Connect with Formiti experts who specialize in layered MENA data law. [Insert Link to Formiti Consultation Page]