Security & compliance · Saudi Arabia
Edrak and the National Data Management Office
The NDMO sets how data is governed, classified and protected in the Kingdom, and the PDPL sets the rules for personal data. Edrak works from your systems of record, so the governance you already have keeps applying.
- NDMO
- National regulator for data. Sets data management, governance and personal data protection standards.
- Applies to
- Government entities and, through the PDPL, any organisation processing personal data of residents of the Kingdom.
- Where Edrak stands
- Edrak maps its data handling to the NDMO standards and the PDPL and shares that mapping. We act as a processor under your instructions; the controller obligations remain yours.
The NDMO standards
The National Data Management and Personal Data Protection Standards cover fifteen domains. These four shape how an AI platform has to behave.
Governance
Data governance and classification
Ownership, stewardship and the national classification scheme: public, internal, confidential, secret.
PDPL
Personal Data Protection Law
Lawful basis, purpose limitation, individual rights and breach notification for personal data.
Quality
Data quality and metadata
Standards for accuracy, completeness and documented lineage.
Sharing
Data sharing and open data
Conditions under which data may move between entities and outside the Kingdom.
How Edrak supports your NDMO obligations
The obligations are yours. Edrak is built to make meeting them straightforward, and to be clear about what stays on your side.
Data governance
Edrak: Works from your systems of record, so ownership, classification and quality stay where your data office defines them.
You: Data classification, ownership and quality standards.
Data classification
Edrak: Routing and deployment rules are set per classification level, so restricted data never reaches a model or location you have not approved.
You: Classifying data under the national scheme.
Purpose and minimisation
Edrak: Each workflow declares what data it reads and why. Edrak retrieves only what the step needs and does not retain personal data beyond the workflow unless you configure it to.
You: Defining lawful purposes and the retention your policies allow.
Individual rights
Edrak: Records show where personal data was read or written, so access, correction and deletion requests can be traced through every workflow.
You: Receiving and fulfilling requests within statutory timelines.
Cross-border transfers
Edrak: Deployment options keep data in-country. Model routing lets you stop personal data leaving your boundary while still using hosted models for other work.
You: Assessing transfer conditions and approving any exceptions.
Records
Edrak: Every action, decision and outcome is logged: who asked, which model ran, what it touched, what came back.
You: Retention periods and lineage documentation.
For your security and compliance teams
We share a requirement-by-requirement mapping to the NDMO frameworks, a data-flow diagram for your deployment option, and our security overview, under NDA. We also answer questionnaire items directly.
Talk to our teamThe NDMO issues requirements and guidance; it does not certify vendors. This page describes how Edrak's controls support your obligations. Edrak does not claim compliance or certification on your behalf. Confirm applicability with your compliance team.

