Security & compliance · Saudi Arabia

Edrak and the National Data Management Office

The NDMO sets how data is governed, classified and protected in the Kingdom, and the PDPL sets the rules for personal data. Edrak works from your systems of record, so the governance you already have keeps applying.

NDMO
National regulator for data. Sets data management, governance and personal data protection standards.
Applies to
Government entities and, through the PDPL, any organisation processing personal data of residents of the Kingdom.
Where Edrak stands
Edrak maps its data handling to the NDMO standards and the PDPL and shares that mapping. We act as a processor under your instructions; the controller obligations remain yours.

The NDMO standards

The National Data Management and Personal Data Protection Standards cover fifteen domains. These four shape how an AI platform has to behave.

  • Governance

    Data governance and classification

    Ownership, stewardship and the national classification scheme: public, internal, confidential, secret.

  • PDPL

    Personal Data Protection Law

    Lawful basis, purpose limitation, individual rights and breach notification for personal data.

  • Quality

    Data quality and metadata

    Standards for accuracy, completeness and documented lineage.

  • Sharing

    Data sharing and open data

    Conditions under which data may move between entities and outside the Kingdom.

How Edrak supports your NDMO obligations

The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.

  • Data governance

    Edrak: Works from your systems of record, so ownership, classification and quality stay where your data office defines them.

    You: Data classification, ownership and quality standards.

  • Data classification

    Edrak: Routing and deployment rules are set per classification level, so restricted data never reaches a model or location you have not approved.

    You: Classifying data under the national scheme.

  • Purpose and minimisation

    Edrak: Each workflow declares what data it reads and why. Edrak retrieves only what the step needs and does not retain personal data beyond the workflow unless you configure it to.

    You: Defining lawful purposes and the retention your policies allow.

  • Individual rights

    Edrak: Records show where personal data was read or written, so access, correction and deletion requests can be traced through every workflow.

    You: Receiving and fulfilling requests within statutory timelines.

  • Cross-border transfers

    Edrak: Deployment options keep data in-country. Model routing lets you stop personal data leaving your boundary while still using hosted models for other work.

    You: Assessing transfer conditions and approving any exceptions.

  • Records

    Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.

    You: Retention periods and lineage documentation.

For your security and compliance teams

We share a requirement-by-requirement mapping to the NDMO frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.

Talk to our team

The NDMO issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Confirm applicability with your compliance team.