Requirements
What the regulation expects

PDPL, Implementing Regulation and transfer rules
Security of personal data and transfer outside the Kingdom are where key custody shows up in legal scoping.
Security measures for personal data
Controllers must apply the security measures necessary to protect personal data. Encryption with customer-held keys is a technical measure, not a legal shortcut.
Transfer outside the Kingdom
Cross-border transfer and disclosure are restricted and risk-assessed. Key location attestation is an input to that assessment.
Evidence for counsel and assessors
Deployment topology, key location attestation and audit trail supplied as inputs, not as a substitute for legal analysis.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
On-premise or in-country vault with enforced access policy and tamper-evident trail of every key access.
Learn moreMicrosoft 365 DKE
Outer key held where the entity decides so the SaaS host cannot unilaterally decrypt.
Learn moreAWS XKS / HYOK patterns
Keys outside the cloud provider as an input to transfer risk assessment.
Learn moreKey themes
Where independent key control fits
Read SDAIA article text before committing to bid wording. Product claims stop at architecture and evidence; transfer adequacy is a legal call.
Security of personal data
Encryption with customer-held keys, enforced access control and a tamper-evident trail of every access to key material.
Transfer outside the Kingdom
Key inside the Kingdom, ciphertext in a global cloud. Supply key location attestation and topology to the customer's transfer risk assessment. Do not treat this as automatic legal compliance.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
