Most data protection teams in the Gulf have a register for systems, vendors and transfers. Few have a register for prompts. Yet a single prompt can carry a customer name, a national ID and an account number to a service the organisation never approved.
This article explains why that matters under the Saudi and UAE data protection laws, and how to prepare for the questions an auditor will ask.
Why a prompt is processing, and may be a transfer
Data protection laws define processing broadly. Collecting, recording, using, disclosing and transmitting personal data all count. When an employee pastes a customer complaint into a public AI chat, the organisation discloses that data to a third party. The AI provider then stores and processes it on its own systems.
Three consequences follow.
- The provider acts like a processor, but without a contract. The organisation has no agreement that sets purpose, retention or security for that data.
- The data may cross a border. Many public AI services run in data centres outside the Kingdom and outside the UAE. Both the Saudi PDPL and the UAE regimes restrict transfers of personal data abroad.
- The event may be reportable. If the data is sensitive, the disclosure may meet the test for a breach that must be notified.
The scale is not small. The Verizon 2026 DBIR found that 67% of employees access AI from non-corporate accounts on corporate devices. It also found that shadow AI is the third most common non-malicious insider action in DLP datasets. When the account is personal, the organisation has no contract and no log.
Figure 1. Remove the identifier before the prompt crosses the border. Sample prompt and ID are illustrative.
Saudi PDPL: penalties and active enforcement
The Saudi Personal Data Protection Law was issued by Royal Decree M/19. Its penalties are material, as summarised by DLA Piper:
- Disclosure of sensitive data with intent to harm or for personal benefit: up to 2 years' imprisonment and/or a fine up to SAR 3 million.
- Other violations: administrative fines up to SAR 5 million.
- Fines can be doubled for repeat offenders.
The timing also matters. SDAIA moved to active PDPL enforcement in 2026. The law is no longer only a readiness project. Organisations should expect questions about how they control processing by third parties and transfers abroad. Shadow AI touches both.
For banks and insurers, the PDPL sits beside sector rules. The SAMA Cyber Security Framework expects data leakage protection, logging and third-party security. The NCA Essential Cybersecurity Controls expect asset management, event logging and control of external and cloud services. An auditor may test all of these with the same evidence.
UAE PDPL, DIFC and ADGM
In the UAE, three regimes may apply, depending on where the entity is set up.
- UAE PDPL, Federal Decree-Law 45 of 2021, for onshore entities.
- DIFC Data Protection Law 2020 for entities in the Dubai International Financial Centre.
- ADGM Data Protection Regulations 2021 for entities in Abu Dhabi Global Market.
The details differ, but the themes are shared. Processing must have a lawful basis. Processors must work under set obligations. Transfers abroad need a lawful route. For banks, CBUAE regulations and standards add expectations on outsourcing and third-party controls, consumer data protection and incident reporting. The UAE Information Assurance Regulation adds asset inventory, data classification, monitoring and logging.
A public AI tool used through a personal account meets none of these by default. There is no processor agreement, no transfer assessment and no log.
The eight questions the auditor will ask
Auditors tend to follow the data. Expect questions in this order. The right column shows the evidence that answers each one.
| # | Question | Evidence that answers it |
|---|---|---|
| 1 | Which AI tools do your staff use? | AI app inventory, including extensions and agents, split into corporate and personal accounts |
| 2 | Who used them, and in what role? | User and role attribution from SSO and SCIM |
| 3 | What personal data went into them? | Policy decision log by data class, across prompt, paste and upload |
| 4 | Where did the data go? Was it a transfer abroad? | App inventory joined with your vendor records on where each provider processes data |
| 5 | Which tools are approved, and on what terms? | App classes (sanctioned, tolerated, unsanctioned) and the processor contracts for sanctioned tools |
| 6 | What stopped regulated data from leaving? | Timestamped coach, redact and block decisions, with redaction records by data class |
| 7 | Who approved the exceptions, and when do they end? | Exceptions register with approver and expiry date |
| 8 | How do these controls map to the law, and can you prove the records are unaltered? | Regulator clause map and a signed export with a hash |
Notice what is missing from the right column: a policy document. The policy is where the audit starts. It is not what closes a finding.
How to build the evidence
Build the evidence in the same order as the questions. Each step feeds the next.
- Inventory. Discover every AI app, AI browser extension, agent and MCP server in use. Record whether each session used a corporate or personal account.
- Attribution. Tie each session to a named user and role through SSO and SCIM. Without this, you cannot scope a notification.
- Policy log. Record every decision with a timestamp: allow, coach, redact or block. Set rules per app, per user group and per data class, such as Saudi National ID, Iqama, Emirates ID, IBAN and card number.
- Redaction proof. For each redact decision, keep a record of the data class removed. Keep the class, not the identifier itself. This shows that the identifier did not cross the border.
- Exceptions. Every exception needs an approver and an expiry date. Review the register before each audit.
- Clause map. Map each control to the frameworks that apply to you: PDPL, SAMA CSF, NCA ECC, CBUAE, DIFC or ADGM. Keep the map in plain language.
- Signed export. Export the pack with a hash, so the auditor can check it was not changed. Send the same decisions to your SIEM for day-to-day monitoring.
SentraGuard produces these as an AI Usage Evidence Pack in PDF, CSV and as a SIEM feed, for Splunk, IBM QRadar, Microsoft Sentinel or ArcSight. In on-premise and air-gapped deployments, no data is sent to SOAISEC, which avoids adding a new transfer to answer a transfer question.
Sources
- DLA Piper, Data Protection Laws of the World, Saudi Arabia, enforcement: dlapiperdataprotection.com
- Global Privacy Blog, "Active enforcement of Saudi Arabia privacy regime", May 2026: globalprivacyblog.com
- Verizon 2026 Data Breach Investigations Report, as summarised by Suzu Labs: suzulabs.com
- UAE PDPL (Federal Decree-Law 45 of 2021), DIFC Data Protection Law 2020, ADGM Data Protection Regulations 2021, SAMA Cyber Security Framework, NCA Essential Cybersecurity Controls, CBUAE regulations and standards, UAE Information Assurance Regulation: described in general terms. Check the current official text.