Skip to content
All resources
Compliance·6 min read·

NCA ECC and PDPL: what they mean for the software you buy and build

If you run technology in Saudi Arabia, two names come up in almost every serious procurement conversation: the NCA's Essential Cybersecurity Controls and the Personal Data Protection Law. Neither is something to bolt on at the end. Here's a practical view of what they are and how to hold a vendor to them.

NCA ECC, briefly

The Essential Cybersecurity Controls are the National Cybersecurity Authority's baseline for protecting information and technology assets. They cover governance, defence, resilience, and third-party and cloud security, among other areas.

For software, the practical effect is that security has to be designed in and demonstrable: access controls, audit trails, secure operations, and clear ownership of who is responsible for what.

PDPL, briefly

The Personal Data Protection Law governs how personal data is collected, used, stored, and shared. It sets expectations around lawful basis, transparency, data-subject rights, and where and how data is handled.

For a system that touches personal data — and most enterprise systems do — that means being deliberate about what you collect, keeping it separate and secure, and being able to honour requests to access or delete it.

What to ask a vendor

  • How is our data kept separate from other customers'?
  • Can data reside in-Kingdom, and how is that guaranteed?
  • What access controls and audit trails exist, and can we see them?
  • How are personal-data rights (access, correction, deletion) handled?
  • Is security designed in and reviewed, or reacted to after incidents?
  • Where formal certification is needed, what is in place today?

A word on 'compliant'

Be cautious with vendors who claim blanket 'compliance' or wave certification badges without specifics. Alignment to a standard and formal certification against it are different things. A trustworthy partner will tell you plainly what is already in place and what they would put in place with you.

THE TAKEAWAY

Treat NCA ECC and PDPL as design inputs, not paperwork. Ask specific questions about data separation, residency, access, audit, and personal-data rights — and be wary of unspecific compliance claims.

Want to talk it through?

We're happy to be a sounding board, whether or not it turns into a project.