AI at work · 6 min read
Personal data in AI projects: what to check in Saudi Arabia and the UAE
Before customer messages or documents reach an AI model, know what data goes where. The main rules in Saudi Arabia and the UAE, and the questions to ask any AI provider.
ZoolCoder
Why AI projects raise data questions
An AI assistant or document reader works on real data: customer messages, invoices, ID numbers, sometimes health or financial details. That data travels to a model that is often run by another company, sometimes in another country. Data protection law asks who decides that, on what basis, and how the data is protected.
Saudi Arabia: the Personal Data Protection Law
The Personal Data Protection Law (Royal Decree M/19, amended by Royal Decree M/148) is overseen by the Saudi Data and AI Authority (SDAIA). The points that matter most for AI projects:
- Tell people what you collect and why, and use it only for that purpose.
- People can ask for a copy of their data, a correction or its deletion, and can withdraw their consent.
- Sending personal data outside the Kingdom is allowed only under set conditions, such as an adequacy decision or approved safeguards like standard contractual clauses.
- A breach that may cause harm must be reported to SDAIA within 72 hours of becoming aware of it.
- SDAIA runs a national register and a tool to check whether you must appoint a data protection officer.
The UAE: federal law and financial free zones
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data covers most of the country, and the UAE Data Office oversees it. It also sets conditions for sending personal data abroad. The two financial free zones have their own rules: the DIFC under its Data Protection Law (DIFC Law No. 5 of 2020), and ADGM under its Data Protection Regulations. Check which regime applies to your company, and check the regulator for the latest implementing rules before you rely on a detail.
Questions to ask any AI provider
- Which model processes our data, and in which country?
- Is our data used to train your models? Get the answer in writing.
- How long are prompts, files and logs kept, and can we delete them?
- Can names, ID numbers and card numbers be removed before data reaches the model?
- Who on your side can see our data?
- If there is a breach, who tells us, and how fast?
Send less, keep less
The safest data is data the model never sees. Send only the fields a task needs, mask ID and card numbers, keep conversation logs only as long as you need them, and let a person approve anything that leaves your company.
Where we can help
We design the data flow with you before we build: what the model sees, where it runs and what is kept. How we handle client data in AI work is set out on our AI page.