Compliance & responsibilities
Clear responsibilities according to the service, sector and project scope.
Scope before delivery
Requirements depend on the data, sector and each party’s role. The areas below describe the review during project scoping. This page does not establish certification or registration; those claims are published only after evidence is verified.
Data protection PDPL
Define controller and processor roles, purposes and lawful bases, individual rights, retention, and deletion. Review the PDPL, implementing regulations, overseas-transfer regulation, processing agreements, and subprocessors. Registration, DPO, and impact-assessment requirements are assessed for applicability.
Official sourceCybersecurity NCA
Review essential, data, and cloud cybersecurity controls according to the sector and contract. Assess NCNICC for private entities notified by NCA. Cybersecurity service delivery is subject to provider registration and applicable licensing requirements. Certifications and registrations are published only after verifying evidence and scope.
Official sourceHosting & operations CST
Identify hosting providers, operating regions, backups, support, and subprocessors. Assess CST requirements according to the provider role. Saudi-based testing runners may use an overseas platform or AI processing; these flows are documented in the service agreements.
Official sourceInvoicing & payments ZATCA / SAMA
Define ZATCA e-invoicing requirements according to the implemented functions and client phase. Connect payments through licensed providers and assess SAMA and Saudi Payments requirements according to the service role. Technical test reports alone do not establish certification.
Official sourceResponsible marketing COMMERCE / PDPL
Review e-commerce requirements, advertising disclosures, content rights, and accuracy of result claims. Apply relevant direct-marketing consent and withdrawal requirements. Nonessential tracking requires a data-flow and consent review before activation.
Official sourceResponsible AI SDAIA
Define agent knowledge, tools, permissions, and human handoff. Governance is guided by SDAIA AI ethics principles. Health, finance, and government projects require a separate assessment of sector obligations.
Official sourceLet’s understand your next move
Start with your goal. We will discuss the scope and next steps with you.