Skip to content
All guides

AI at work · 6 min read

Personal data in AI projects: what to check in Saudi Arabia and the UAE

Before customer messages or documents reach an AI model, know what data goes where. The main rules in Saudi Arabia and the UAE, and the questions to ask any AI provider.

ZoolCoder

Why AI projects raise data questions

An AI assistant or document reader works on real data: customer messages, invoices, ID numbers, sometimes health or financial details. That data travels to a model that is often run by another company, sometimes in another country. Data protection law asks who decides that, on what basis, and how the data is protected.

Saudi Arabia: the Personal Data Protection Law

The Personal Data Protection Law (Royal Decree M/19, amended by Royal Decree M/148) is overseen by the Saudi Data and AI Authority (SDAIA). The points that matter most for AI projects:

  • Tell people what you collect and why, and use it only for that purpose.
  • People can ask for a copy of their data, a correction or its deletion, and can withdraw their consent.
  • Sending personal data outside the Kingdom is allowed only under set conditions, such as an adequacy decision or approved safeguards like standard contractual clauses.
  • A breach that may cause harm must be reported to SDAIA within 72 hours of becoming aware of it.
  • SDAIA runs a national register and a tool to check whether you must appoint a data protection officer.

The UAE: federal law and financial free zones

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data covers most of the country, and the UAE Data Office oversees it. It also sets conditions for sending personal data abroad. The two financial free zones have their own rules: the DIFC under its Data Protection Law (DIFC Law No. 5 of 2020), and ADGM under its Data Protection Regulations. Check which regime applies to your company, and check the regulator for the latest implementing rules before you rely on a detail.

Questions to ask any AI provider

  • Which model processes our data, and in which country?
  • Is our data used to train your models? Get the answer in writing.
  • How long are prompts, files and logs kept, and can we delete them?
  • Can names, ID numbers and card numbers be removed before data reaches the model?
  • Who on your side can see our data?
  • If there is a breach, who tells us, and how fast?

Send less, keep less

The safest data is data the model never sees. Send only the fields a task needs, mask ID and card numbers, keep conversation logs only as long as you need them, and let a person approve anything that leaves your company.

Where we can help

We design the data flow with you before we build: what the model sees, where it runs and what is kept. How we handle client data in AI work is set out on our AI page.

Want a second pair of eyes?

Tell us how the work runs today. We reply with the first step worth changing.