Data center licensing requirements in Saudi Arabia involve more than one approval. A customer-facing facility will generally require CST registration, while the investor must also complete the correct corporate setup, obtain site and construction permits, and assess separate cloud, telecommunications, cybersecurity and personal data obligations before launch.
Saudi Arabia has introduced a dedicated regulatory framework for data center services as part of its wider development of cloud computing, artificial intelligence and digital infrastructure.
For an investor, however, a data center is not simply an information technology business. It is also a physical development that depends on land, electricity, cooling, telecommunications connectivity, safety systems and environmental controls.
The approval pathway must therefore cover three connected questions:
- Who will own and operate the Saudi business?
- Where and how will the facility be built?
- Which services will the operator sell to customers?
Answering those questions early helps the investor identify the correct authorities and avoid designing a facility around the wrong regulatory assumptions.
What does a “data center license” in Saudi Arabia actually mean?
Data center licensing in Saudi Arabia means the combined process of registering the facility with CST, establishing the operating company, securing site and municipal approvals, and complying with any separate cloud, telecom, cybersecurity and PDPL rules. The exact pathway depends on what the facility will host and sell.
The term “data center license” can be misleading because Saudi Arabia does not issue one approval that covers the entire project.
The Communications, Space and Technology Commission, or CST, operates a sector-specific registration framework for providers that offer data center services to customers. Other authorities remain responsible for investment registration, company formation, construction, safety, environmental compliance and personal data protection.
A CST registration therefore does not replace a building permit, commercial registration or cloud computing registration.
Does every data center require CST registration?
The CST Data Center Services Regulations entered into force on 1 January 2024 and apply to data center service providers operating in Saudi Arabia. CST describes the relevant beneficiaries as wholesale or retail providers that offer data center services to other parties in the Kingdom.
This distinction matters.
A company that sells colocation, hosting or other data center services to customers will generally fall within the CST framework. Colocation means that customers place their own servers or other equipment inside the operator’s facility and pay for space, power, cooling, connectivity and related support.
A facility used only to run the owner’s internal business systems may stand in a different position. The company should still confirm the position against the actual use of the facility because group arrangements, managed services or services supplied to affiliates can affect the analysis.
How do the CST registration categories work?
CST lists the following data center registration categories:
| Category | Practical meaning |
| Qualifying | Applies to a data center that remains under development. |
| Limited | An operational category assessed under the applicable CST requirements. |
| Standard | An operational category requiring the relevant technical and operational evidence. |
| Advanced | A higher operational category under the CST framework. |
CST expressly states that the Qualifying category applies to data centers under development. It also requires a separate registration for each facility according to its classification and stage of development.
The categories should not be treated as marketing descriptions. They form part of the regulatory registration process. The investor should review the current technical criteria before finalising the design, certification strategy or customer promises.
A facility may begin in the Qualifying category while construction continues and later move into the appropriate operational category. The operator should plan that transition rather than waiting until the facility is ready to open.
Which authorities regulate a Saudi data center project?
A typical project can involve several authorities. Their roles are different, and approval from one authority does not replace approval from another.
| Regulatory layer | Main authority | Main question |
| Foreign investment | Ministry of Investment, or MISA | Can the foreign investor register for the proposed activities? |
| Company establishment | Ministry of Commerce and Saudi Business Center | Has the operating company been incorporated with the correct activities? |
| Data center services | CST | Must each facility be registered, and under which category? |
| Building and municipal approvals | Municipality through Balady | Can the site be built, occupied and used for the activity? |
| Safety approvals | General Directorate of Civil Defense | Does the facility satisfy the applicable fire and safety requirements? |
| Data protection | SDAIA | How will the operator process and protect personal data? |
| Cybersecurity | CST and, where applicable, NCA | Which cybersecurity controls apply to the operator and its customers? |
| Environmental compliance | National Center for Environmental Compliance | Does the project require an environmental permit or assessment? |
The approval matrix can change where the project sits in a special economic zone, serves government entities, supports critical national infrastructure or includes regulated cloud, financial, health or telecommunications services.
What corporate approvals does a foreign investor need?
A foreign investor should begin with the Investment Law, issued under Royal Decree No. M/19 of 1446H, published in August 2024 and effective from February 2025. Its Implementing Regulations were issued by Ministerial Decision No. 1086 dated 7 February 2025.
The Investment Law replaced the former Foreign Investment Law and moved Saudi Arabia from the previous foreign-investment licence model to a unified MISA registration system. It also provides for equal treatment of local and foreign investors in similar circumstances, subject to restricted or prohibited activities and other applicable laws.
Read also: MISA License Explained for Foreign Investors
After completing the relevant MISA process, the investor must establish the Saudi operating entity and obtain its commercial registration under the Companies Law, issued under Royal Decree No. M/132 of 1443H and effective from 19 January 2023.
The company’s registered activities should match its real business model. A data center project may involve several distinct activities, including:
- owning and operating the physical facility;
- leasing racks or technical space;
- providing hosting services;
- managing servers or infrastructure;
- providing cloud computing;
- selling telecommunications connectivity;
- leasing equipment; and
- Offering system integration or technical support.
A broad information technology description may not cover every service that the company intends to invoice.
The corporate structure also matters. One company may own the building while another operates the data center or sells cloud services. In that case, each entity must hold the registrations and contractual rights that correspond to its actual role.
Which site and construction permits must be obtained?
Before construction begins, the project normally requires land-use confirmation and a building permit.
The Balady process allows the owner or its representative to appoint an approved engineering office, submit the required designs and apply for the building permit. After construction, the owner applies for an occupancy certificate through the same municipal system.
The investor should not sign a long-term lease or acquire land before confirming that the site can support the intended use.
Read also: Construction in KSA
Site due diligence should examine:
- permitted land use;
- electrical capacity and connection conditions;
- fiber access and route diversity;
- cooling and water requirements;
- generator and fuel-storage arrangements;
- access for construction and maintenance;
- expansion rights;
- environmental constraints;
- Civil Defense requirements; and
- The route to the occupancy and commercial licenses.
Power and connectivity require particular attention. A site may be legally available but commercially unsuitable if the required electricity capacity or diverse network connections cannot be delivered on the project timetable.
The legal team should review the lease, utility arrangements and construction contracts together. A land agreement should not require the investor to proceed where essential regulatory or utility conditions remain unavailable.
How does the CST data center registration process work?
CST provides an electronic registration service through its business portal. The applicant submits the facility information and supporting documents required for the relevant category. CST currently lists the registration service as free.
Registration is facility-specific. A registration for a Riyadh data center does not automatically cover a separate facility in Jeddah, Dammam or another location.
The information submitted to CST should match:
- the facility’s development stage;
- the technical design;
- the operator’s legal entity;
- the services offered to customers;
- the intended operational category; and
- the supporting certifications or technical evidence.
Technical certification and CST registration serve different purposes. A recognised facility certificate may support the application, but it does not replace the regulatory registration.
The investor should therefore determine the intended category during design and construction. Waiting until the building is complete can reveal gaps between the built facility and the evidence required for its intended registration.
Does data center registration cover cloud computing services?
No. Operating a data center and providing cloud computing are separate activities.
A data center operator provides the physical environment in which equipment operates. This normally includes space, power, cooling, physical security and access to connectivity.
A cloud provider supplies computing resources or software through the internet. Cloud services may include:
- infrastructure as a service, where customers obtain virtual computing, storage or network resources;
- platform as a service, where customers use a managed environment to build or run applications; and
- Software as a service, where customers access complete software applications online.
CST explains these service models separately from the physical facility layer.
Where the Saudi company sells cloud services, it must assess the separate Cloud Computing Services Provisioning Regulations and CST registration process. CST uses a qualifying route and Classes A, B and C, with different facility and operational evidence applying to the available classes.
An operator may therefore require both:
- registration for the physical data center; and
- Registration for the cloud services supplied from that facility.
The distinction depends on what the company actually promises and supplies to customers, not only on the wording used in its commercial registration.
Read also: Digital Economy in Saudi Arabia: Opportunities for Foreign Investors
When is a telecommunications license also required?
Many data centers buy connectivity from telecommunications operators that already hold the necessary CST licenses. Simply purchasing connectivity does not normally turn the data center into a telecommunications provider.
A separate question arises where the operator itself plans to establish or operate telecommunications infrastructure, resell regulated connectivity, provide public network services or supply wholesale infrastructure to other service providers.
CST maintains separate licensing frameworks for telecommunications and infrastructure services. For example, an infrastructure wholesale services license can authorize a provider to establish, own, operate and maintain telecommunications infrastructure for supply to other licensed providers.
The customer contract should describe the service accurately. Calling a regulated network service an “additional data center service” does not remove the licensing issue.
Which cybersecurity rules apply to a data center operator?
A registered data center provider should first examine CST’s Cybersecurity Regulatory Framework for service providers in the communications and information technology sector. CST states that the framework mainly concerns organizations licensed, registered or otherwise regulated by CST.
Read also: Impact of Saudi Cybersecurity Laws on Businesses
Cybersecurity compliance should form part of the project from the design stage. It can affect:
- physical and logical access;
- network separation;
- privileged accounts;
- vulnerability management;
- incident response;
- monitoring;
- backup and recovery;
- subcontractors; and
- business continuity.
The National Cybersecurity Authority’s Essential Cybersecurity Controls may also apply. They apply directly to government entities and private organizations that own, operate or host Critical National Infrastructure. The NCA encourages other organizations to use the controls as a cybersecurity benchmark.
This means that not every private data center automatically requires an NCA certification. The operator should complete an applicability assessment based on its customers, hosted systems and regulatory status.
Customer contracts should also divide security responsibilities clearly. The operator may control physical access and facility security while the customer remains responsible for its applications, user accounts and data configuration.
How does the PDPL affect data center services?
The Saudi Personal Data Protection Law, or PDPL, applies where the operator processes personal data.
A data center operator may act as a processor when it stores or manages information on a customer’s instructions. It may act as a controller for its own employee information, customer contacts, access logs, visitor records and security footage.
The contract should reflect the real relationship. Simply calling the operator a “processor” does not settle the issue if it independently decides why or how personal data will be used.
The parties should address:
- processing instructions;
- confidentiality;
- security measures;
- breach cooperation;
- subcontractors;
- data deletion;
- audit rights; and
- assistance with data-subject requests.
The PDPL does not impose one simple rule that all personal data must remain in Saudi Arabia. Instead, transfers outside the Kingdom must satisfy the PDPL and the Regulation on Personal Data Transfer Outside the Kingdom.
Read also: Penalties and Violations Under Saudi Arabia’s Data Protection Law
Available safeguards may include standard contractual clauses, binding common rules or an approved accreditation mechanism. A transfer risk assessment may also be required, including for continuous or widespread transfers of sensitive data.
Remote access also needs attention. Allowing personnel outside Saudi Arabia to access personal data stored in a Saudi facility may amount to a cross-border disclosure or transfer even if the physical server never leaves the Kingdom.
The operator should therefore map where data is stored, where backups are held and from which countries administrators or support teams can access it.
Is an environmental permit required?
Environmental requirements depend on the project’s location, design and potential impact.
The National Center for Environmental Compliance oversees environmental permitting and compliance for facilities with a potential environmental impact. A data center project should assess the position where it includes generators, fuel storage, batteries, large cooling systems, substantial water use or electronic waste.
The assessment should take place during site selection and design, not after construction. Environmental conditions can affect the layout, equipment, operating procedures and project timetable.
What is the recommended approval sequence?
The following sequence gives investors a practical starting point:
- Define the physical facility and every service that the business will sell.
- Prepare a project-specific authority and approval matrix.
- Complete land, power, connectivity and environmental due diligence.
- Complete MISA registration where the project involves a foreign investor.
- Incorporate the Saudi company with the correct commercial activities.
- Obtain the building, municipal, environmental and safety approvals.
- Apply for the appropriate CST data center registration for each facility.
- Assess separate cloud or telecommunications registration requirements.
- Complete the occupancy and operating approvals.
- Finalize the cybersecurity, PDPL and customer-contract framework before launch.
Several applications may run in parallel. However, the company structure, technical design, customer services and regulatory filings must remain consistent.
What mistakes commonly delay data center projects?
A common mistake is treating CST registration as the only approval. It does not replace company establishment, construction, municipal, safety or environmental requirements.
Another is failing to distinguish between colocation and cloud computing. A company may register its physical facility but still lack the separate registration required for the cloud services it intends to sell.
Some investors also commit to a site before confirming power, connectivity, zoning or environmental conditions. These issues can force a redesign or make the location unsuitable.
Cybersecurity and data transfers create further problems when considered too late. A global support model may allow overseas administrators to access Saudi customer data, creating cross-border transfer issues even though the main servers remain in the Kingdom.
Finally, the customer agreement must match the service model. Generic hosting terms may not deal adequately with service continuity, security responsibilities, personal data, access rights, subcontractors, equipment removal and exit support.
Plan the licensing route before committing the project budget
Saudi Arabia provides a structured route for data center investment, but that route involves connected corporate, construction, technology and data-compliance requirements.
The practical value of early legal review is not limited to obtaining registrations. It helps the investor determine whether the proposed site, operating structure, technical design and customer services can work together under the applicable rules.
Before committing to a site, construction timetable or customer launch, investors should confirm which approvals apply to the company, the facility and the services it will sell.
Hamad in Association with Youssry Saleh & Partners advises data center developers and operators on MISA registration, corporate establishment, CST registration, site approvals, cloud and telecommunications requirements, PDPL compliance and customer contracts. Our team can prepare a project-specific licensing roadmap and identify regulatory gaps before they affect the build or launch schedule.
For customized legal consultation, please contact us at info@ahysp.com.
FAQ
CST operates a registration framework rather than one general data center license. A provider offering data center services to customers will generally need to register each facility. Construction, municipal, corporate and other sector approvals remain separate.
CST lists Qualifying, Limited, Standard and Advanced categories. The Qualifying category applies to facilities under development. The appropriate operational category depends on the facility’s stage, technical evidence and the current CST criteria.
Not by itself. Data center registration covers the physical facility and related services. A company offering cloud computing must separately assess CST’s cloud registration requirements and the class that applies to its services.
Foreign investment is generally permitted under the Investment Law, subject to restricted and prohibited activities and other sector requirements. The investor must complete the appropriate MISA registration, establish the Saudi entity and obtain the approvals required for the project.
No single rule requires all data to remain in the Kingdom. However, sector-specific localization rules may apply, and transfers of personal data outside Saudi Arabia must comply with the PDPL, its transfer regulations and any required safeguards or risk assessments.


