iAssets · Data protection
Health data residency in Saudi Arabia: what the law actually requires
A great deal of vendor material states that Saudi law requires health data to be hosted inside the Kingdom. It does not. The Personal Data Protection Law permits transfer outside Saudi Arabia subject to conditions, and the National Cybersecurity Authority removed its hosting mandates in 2024.
That correction matters in both directions. It means a cloud deployment is not automatically unlawful — and it means anyone selling you on-premise by citing a residency law is either mistaken or hoping you will not check. What the law does impose is real, and it is stricter than most buyers expect in the places that actually matter.
Health data is Sensitive Data, and the consequences are criminal
The Personal Data Protection Law classifies Health Data explicitly within its definition of Sensitive Data, and defines Health Data as any personal data related to an individual's health condition or to health services received by that individual. A clinical asset system holds work orders, technician notes and device histories that can touch this category.
The penalties are not administrative. Disclosure or publication of sensitive data in violation of the Law carries imprisonment of up to two years, a fine of up to three million Saudi riyals, or both.
The Law also applies extraterritorially — it reaches the processing of personal data relating to individuals residing in the Kingdom by any party outside it. A vendor hosting abroad is not outside the Law's scope simply by being abroad.
- Health Data is named within Sensitive Data
- Defined as data on an individual's health condition or health services received
- Up to two years imprisonment and/or up to SAR 3 million for unlawful disclosure
- Extraterritorial reach over processing relating to residents of the Kingdom
Cross-border transfer is permitted, subject to three conditions
Rather than prohibiting transfer, the Law sets conditions on it. A controller may transfer personal data outside the Kingdom where the transfer does not prejudice national security or the Kingdom's vital interests, where there is an adequate level of protection for the data that is no less than the Law provides, and where the transfer is limited to the minimum amount of personal data needed.
That is an adequacy-and-minimisation test, not a localisation rule. It is a meaningful obligation — but it is the wrong obligation to describe as "data must stay in Saudi Arabia", and a procurement team that has read the Law will notice.
- No prejudice to national security or the Kingdom's vital interests
- An adequate level of protection, no less than the Law provides
- Limited to the minimum amount of personal data needed
- The National Cybersecurity Authority removed its hosting mandates in 2024
The obligations that do bite for a maintenance system
The Law restricts access to Health Data, including medical files, to the minimum number of employees or workers necessary. For a CMMS this is a design question rather than a policy one: role-based access has to be real, and a technician should see the device and the work, not the patient context around it.
The Implementing Regulation also incorporates by reference the requirements and controls issued by the Ministry of Health and the Saudi Health Council. That is where sector-specific obligations live, and it is the reason a general-purpose data-protection answer is not sufficient for a health deployment.
- Access to Health Data restricted to the minimum number of employees
- Role-based access control with a complete audit trail
- Ministry of Health and Saudi Health Council controls incorporated by reference
- Encryption in transit and at rest
- Retention aligned to SFDA's minimum five-year rule for PPM records
So why offer on-premise at all
Because hosting location is frequently a condition in the tender even where it is not a condition in the law. Procurement teams write requirements from internal policy, from cybersecurity guidance, and from a preference for keeping clinical systems inside their own estate. A product that cannot meet that condition is excluded before its features are ever assessed.
iAssets runs cloud or fully on-premise, and is deployed on-premise today inside a Saudi health cluster. We would rather win that requirement by meeting it than by misdescribing the law that surrounds it.
- Cloud or fully on-premise deployment
- Deployed on-premise inside the Tabuk Health Cluster
- Role-based access control and complete audit trail
- Arabic and English throughout, including reports
- Integration with existing HIS and ERP systems
FAQ
Does Saudi law require health data to be hosted inside the Kingdom?
No. This is the most common misconception in this market. The Personal Data Protection Law contains no residency provision — it permits transfer outside the Kingdom subject to conditions — and the National Cybersecurity Authority removed its hosting mandates in 2024. Hosting location is frequently a procurement condition, which is a different thing, and worth distinguishing when you are reading a tender.
What are the conditions for transferring health data abroad?
Three. The transfer must not prejudice national security or the Kingdom's vital interests; there must be an adequate level of protection for the data outside the Kingdom, no less than the level provided by the Law; and the transfer must be limited to the minimum amount of personal data needed. It is an adequacy-and-minimisation test rather than a prohibition.
Is health data treated differently under PDPL?
Yes. Health Data is named explicitly within Sensitive Data, and is defined as any personal data related to an individual's health condition or to health services they received. The Law also restricts access to health data, including medical files, to the minimum number of employees or workers — which for a maintenance system means role-based access has to be genuine rather than nominal.
What are the penalties for mishandling sensitive data?
Criminal rather than administrative. Disclosure or publication of sensitive data in violation of the Law carries imprisonment of up to two years, a fine of up to three million Saudi riyals, or both. The Law also applies extraterritorially to the processing of data relating to individuals residing in the Kingdom, so a vendor hosting outside Saudi Arabia is not outside its scope by virtue of location.
Does a CMMS hold health data?
It can, and that should be designed for rather than assumed away. Work orders, technician notes and device histories can carry context that touches an individual's care. The safer posture is to treat the system as in scope: restrict access by role, keep a complete audit trail, and keep clinical context out of maintenance records where it is not needed for the work.
Where do sector-specific health rules come from?
The Implementing Regulation incorporates by reference the requirements and controls issued by the Ministry of Health and the Saudi Health Council. That is why a generic data-protection answer is not sufficient for a health deployment — the general law sets the frame, and the health authorities fill in the detail that applies to your facility.
Can iAssets be deployed entirely on-premise?
Yes, and it is deployed on-premise today inside a Saudi health cluster. We support cloud or fully on-premise, with role-based access control, a complete audit trail, encryption in transit and at rest, and integration with existing HIS and ERP systems. We would rather meet a hosting requirement than argue it away, but we will also tell you plainly when it is a tender condition rather than a legal one.
Put your maintenance evidence beyond dispute
Talk to the Intrazero team about iAssets — the CMMS running the Tabuk Health Cluster — with Arabic and English interfaces and cloud or on-premise hosting.
Talk to the Intrazero team about iAssets — the CMMS running the Tabuk Health Cluster — with Arabic and English interfaces and cloud or on-premise hosting.
Schedule a Platform Demo
Experience the ecosystem. Complete the form below to align your demo with the right product specialists.