If you sell to Gulf customers from a Chinese back office — or to Chinese customers from Dubai — you are running two data-protection regimes at once. Teams usually discover this after the storefront is live. Here is what differs in practice.
1. Who has to approve the transfer
PIPL treats any export of personal information out of China as a regulated act. You need one of: a CAC security assessment, CAC standard contractual clauses filed with the regulator, or a certification. The route depends on volume and sensitivity — and the thresholds have moved, so confirm the current numbers rather than a blog post’s.
Saudi PDPL and the UAE PDPL do not require a government assessment for every transfer, but they do require a lawful basis, and they constrain onward transfer to third parties. In Saudi Arabia, the regulator’s rules distinguish transfers to jurisdictions with “adequate” protection from everything else.
Practical consequence: the same architecture does not automatically satisfy both. Map the data flows first; decide the mechanism second.
2. What counts as valid consent
Both regimes allow consent as a basis. The difference is how specific it must be.
- Bundled consent buried in checkout terms rarely survives scrutiny in either market.
- Marketing pixels, retargeting and call recording are separate purposes and, in our experience, need separate, unbundled consent in both jurisdictions.
- Children’s data attracts heavier treatment under both regimes — relevant if you sell toys, education or family services.
3. What “adequate protection” means in the contract
Draft the privacy notice in the language the customer actually reads — Arabic for Gulf retail, Chinese for mainland consumers, English as the operating language. A single English notice translated literally into Arabic tends to read as evasive, which is a trust problem before it is a legal one.
Checklist before you launch:
- Data-flow map with destination, purpose and retention for each flow.
- Transfer mechanism chosen and documented (not assumed).
- Unbundled consent for marketing and analytics.
- Notices in the language of the customer, reviewed by a native speaker.
- Internal playbook for data-subject requests — who receives, who decides, who responds within the deadline.
4. The sequencing mistake
The most expensive pattern we see: launch first, retrofit the data posture afterwards. Retrofit means rebuilding consent flows, re-papering processors and sometimes re-performing campaigns whose leads were collected on a basis that no longer holds.
Do the mapping during scoping, before creative is briefed. It costs a fraction of the repair.
This briefing is general information, not legal advice. Transfer mechanisms and thresholds change — confirm the current position before you rely on them.