# Country Compliance Guides

Jurisdiction-by-jurisdiction answers — what each country's data protection law specifically requires, and how Cyber Crucible's architecture addresses it. Gulf, Africa, Europe and UK.

# Does Cyber Crucible comply with Saudi Arabia's PDPL?

**Short answer:** Cyber Crucible has reviewed its operations against Saudi Arabia's Personal Data Protection Law, uses SDAIA-approved Standard Contractual Clauses for any transfer of Saudi-origin personal data, and can be deployed entirely inside the Kingdom with zero cross-border flow. It collects only system and security telemetry — never file contents, documents, email, or communications.

## What the law requires

PDPL took effect 14 September 2023 with a grace period to 14 September 2024. Saudi Arabia maintains among the strongest localization preferences in the Gulf, and the Saudi Data & AI Authority (SDAIA) supervises. Transfers out of the Kingdom require a recognized safeguard plus, in most cases, a Transfer Risk Assessment.

## What specifically applies here

- **SDAIA pre-approved SCCs** are used for any transfer of Saudi-origin personal data to the United States, adopted without modification apart from required fields, and extended to any onward sub-processor.
- **A Transfer Risk Assessment** has been completed following SDAIA's structured guidance — data flows, destination legal regime, controls, residual risk, documented mitigations.
- **Processor role** — Cyber Crucible normally acts as processor under a written DPA; the Saudi customer is controller.
- **Article 33 local representative** — as processor, that obligation sits with you as controller.

## The cleanest route

Given the localization preference, the fully on-premises air-gapped deployment is the strongest answer: all backend management inside your own physically secured racks, zero outbound telemetry. Where nothing crosses the border, transfer obligations do not arise.

> SCCs and the TRA available from **dpo@cybercrucible.com**. Status at time of writing — confirm current requirements with local counsel.

# Does Cyber Crucible comply with UAE data protection law?

**Short answer:** Yes, under the same architecture — minimal collection, local processing, and deployment options where data never leaves the country. One UAE-specific point matters: if your entity sits in DIFC or ADGM, a different regime applies than the federal law.

## What the law requires

UAE Federal Decree-Law No. 45 of 2021 establishes the federal personal data protection framework. It permits a broader range of lawful bases than the more consent-centric Gulf regimes, and takes a risk-based, safeguards-oriented approach to cross-border transfer rather than strict localization. Implementation has depended on Executive Regulations — an area that has moved, so confirm the current position.

## The free zone question

**This catches people out.** The DIFC (Dubai International Financial Centre) and ADGM (Abu Dhabi Global Market) operate their own data protection regimes, separate from the federal law. If your entity is established in either, the applicable rules and supervisory authority differ.

Establish which framework governs you before assessing any vendor — the answer changes what you need to evidence.

## What specifically applies here

- **Lawful basis flexibility** — the broader range of bases means legitimate-interest-style reasoning for security processing is generally more workable than in consent-centric regimes.
- **Transfer safeguards** — regional staging keeps processing within the UAE; air-gapped deployment removes transfer entirely.
- **Processor role** under a written DPA, on your documented instructions.

> Status at time of writing — confirm current requirements, including Executive Regulations and free-zone applicability, with local counsel.

# Does Cyber Crucible comply with Bahrain's data protection law?

**Short answer:** Yes. Bahrain's law is heavily GDPR-inspired with extraterritorial reach, so the same controls that satisfy GDPR apply — minimal collection, documented processor role, strong security safeguards, and controlled transfer.

## What the law requires

Bahrain has had a standalone data protection law in force since 2019. It is often cited as among the clearest and most mature in the Gulf, with strong data subject rights, explicit accountability obligations, and **extraterritorial application** — meaning it can reach vendors outside Bahrain processing Bahraini residents' data.

## What specifically applies here

The extraterritorial reach is the point worth noting. It means the question isn't only whether *you* comply, but whether your vendors do.

- **Accountability** — the excluded-data list (no keys, credentials, tokens, or content) is explicit and documented rather than described in generalities, which is exactly what accountability obligations expect.
- **Data subject rights** — narrow in practice here, because behavioural telemetry is pseudonymized and content is never collected, so the volume of personal data subject to rights requests is minimal.
- **Transfer** — regional staging or air-gapped deployment.

## Why GDPR alignment helps

Because Bahrain's law tracks GDPR closely, the GDPR mapping applies almost directly. If your organization has already done GDPR vendor assessment work, most of it carries over.

> Status at time of writing — confirm with local counsel.

# Does Cyber Crucible comply with Qatar's data protection law?

**Short answer:** Yes. Qatar's regime is more consent-centric than its neighbours, which makes minimal collection especially valuable — the less personal data processed, the smaller the consent burden.

## What the law requires

Qatar has had a standalone data protection law in force since 2017, making it one of the earliest in the region. It maintains a stricter, consent-centric model compared with the UAE's broader set of lawful bases, alongside a risk-based approach to transfer safeguards.

## Why consent-centricity favours this architecture

In a consent-centric regime, every category of personal data you process is a category you may need a basis to process. That makes *not collecting* materially more valuable than protecting well.

Cyber Crucible never collects encryption keys, credentials, session tokens, or file contents. Behavioural telemetry is pseudonymized where it could identify an individual, and telemetry sources are configurable so you can narrow collection further.

The result is that the consent surface for the security tool itself is unusually small.

## Transfer

Regional staging keeps processing close to or within the jurisdiction; air-gapped deployment eliminates cross-border flow entirely.

> Status at time of writing — confirm with local counsel.

# Does Cyber Crucible comply with Oman's data protection law?

**Short answer:** Yes — and Oman is the most time-sensitive jurisdiction in the Gulf right now. Oman's personal data protection law reaches full effect on **5 February 2026**, following a two-year grace period, so vendor stacks that were compliant-by-default are now in scope.

## What the law requires

Oman's law closely mirrors GDPR principles while incorporating local requirements around consent and data handling. The two-year grace period ends 5 February 2026, at which point full compliance is expected.

## Why this matters for vendor selection now

Grace periods create a predictable pattern: organizations defer vendor review until the deadline approaches, then discover that a security tool continuously exporting endpoint telemetry to another jurisdiction is difficult to justify under the new regime.

If you are reviewing your stack against the February 2026 date, the questions worth asking any endpoint vendor are:

1. What personal data does it collect, specifically and enumerated?
2. Where is that data processed, and can that be kept in Oman?
3. What is the transfer mechanism if it leaves?
4. Can it operate with no outbound telemetry at all?

Cyber Crucible's answers are: enumerated exclusions (no keys, credentials, tokens, or content); processing is local to the endpoint; regional staging available; and yes — the air-gapped deployment produces zero outbound telemetry.

> Status at time of writing — confirm the current position and any extension with local counsel.

# Kuwait has no comprehensive data protection law — what does that mean for vendor selection?

**Short answer:** Kuwait has taken a targeted sectoral approach rather than enacting a comprehensive national data protection law, with CITRA regulation governing how the telecom and IT sectors handle user content. That makes data sovereignty a commercial and security decision rather than a compliance obligation — but the decision still matters.

## The current position

Kuwait remains the notable exception among major Gulf states in having no comprehensive national personal data protection law. Instead, CITRA regulation addresses user content handling in telecom and IT specifically.

## Why "no law" is not the same as "no risk"

Three reasons organizations in Kuwait still weigh this carefully:

1. **Sectoral rules still apply.** If you operate in telecom or IT, CITRA requirements are live obligations.
2. **Counterparties impose terms.** Multinational partners, insurers, and customers frequently require GDPR-equivalent handling contractually, regardless of local law.
3. **Regulation tends to arrive.** Every other GCC state has now enacted a comprehensive law. Selecting vendors that already meet stricter regimes avoids a forced migration later.

## The practical position

Because Cyber Crucible never collects keys, credentials, tokens, or content, and can be deployed fully air-gapped, it satisfies the strictest regimes in the region. Choosing it in Kuwait is choosing not to have this problem when the law changes.

> Status at time of writing — confirm current sectoral requirements with local counsel.

# Does Cyber Crucible comply with Kenya's Data Protection Act?

**Short answer:** Yes. Kenya's Data Protection Act 2019 restricts cross-border transfer to countries with appropriate safeguards, and applies a stricter rule to sensitive personal data. Cyber Crucible does not collect sensitive personal data at all, and can be deployed so that no data leaves Kenya.

## What the law requires

Sections 48 and 49 of the Data Protection Act 2019 prohibit transferring personal data to a country lacking appropriate data security safeguards, with several permitted bases including adequacy.

**The stricter rule that matters:** transfer of *sensitive* personal data is permitted only where the data subject has consented **and** appropriate safeguards exist. Both conditions, not either.

## Why the sensitive-data rule is the key point

That dual requirement is difficult to satisfy operationally — obtaining and evidencing individual consent for every affected data subject, on an ongoing basis, for a security tool.

Cyber Crucible sidesteps it: **no sensitive personal data is collected.** Not biometric, health, or genetic data; not data revealing racial or ethnic origin, religious belief, or political opinion. Telemetry describes system behaviour and security events, not personal attributes.

Where behavioural telemetry could indirectly identify an individual, identifiers are pseudonymized or masked.

## Transfer

Regional staging keeps processing within Kenya. The air-gapped deployment produces zero outbound telemetry, so sections 48–49 are not engaged.

> Status at time of writing — confirm with local counsel.

# Does Cyber Crucible meet Nigeria's data localization requirement?

**Short answer:** Yes — and this is the jurisdiction where the architecture matters most. Nigeria's Data Protection Act 2023 imposes a data localization requirement: personal data of Nigerian citizens must be stored within Nigeria. Cyber Crucible's on-premises deployment keeps everything inside your own infrastructure, in-country, with zero outbound telemetry.

## What the law requires

Sections 41–43 of the Nigeria Data Protection Act 2023 set conditions for cross-border transfer, including destination-country safeguards and data subject consent. Beyond those conditions, **Nigeria imposes a localization requirement** — personal data of Nigerian citizens must be stored within Nigeria. Sectoral rules in financial services add further localization obligations.

## Why most security vendors struggle here

This is the clearest example of a rule that cloud-dependent endpoint security cannot satisfy by design. A tool whose architecture is "collect telemetry on the endpoint, ship it to our cloud for analysis" is, structurally, moving personal data out of Nigeria as a condition of functioning. Contractual safeguards don't resolve a storage-location requirement.

## Why this architecture does satisfy it

- **Analysis is local.** Threat evaluation and interdiction happen on the endpoint in typically under 200 milliseconds. No cloud round trip is required for protection.
- **Backend can be fully in-country.** The on-premises model runs all management software inside your own physically secured racks.
- **Zero outbound telemetry** in the air-gapped configuration — nothing leaves, so nothing is stored abroad.
- **Less to localize anyway** — keys, credentials, tokens, and file contents are never collected in the first place.

> Status at time of writing — confirm current requirements, including financial-sector rules, with local counsel.

# Does Cyber Crucible comply with South Africa's POPIA?

**Short answer:** Yes. POPIA restricts cross-border transfer unless the destination offers substantively similar protection or the data subject consents. Cyber Crucible minimizes what is processed to begin with, and can be deployed so no transfer occurs.

## What the law requires

South Africa's Protection of Personal Information Act (2013) prohibits transferring personal information outside the country without the data subject's consent, or unless the recipient jurisdiction is subject to a law providing substantively similar protection.

## What specifically applies here

The "substantively similar protection" test is an assessment you must be able to evidence. Two things make that assessment simpler:

1. **The scope is small.** Encryption keys, credentials, session tokens, and file contents are never collected. What remains is behavioural telemetry, pseudonymized where it could identify an individual.
2. **Contractual protections** — processing occurs under a written DPA with security, confidentiality, and breach notification terms, extended to any sub-processor.

## Or avoid the test entirely

Regional staging keeps processing in South Africa. The air-gapped deployment produces no outbound flow at all, in which case the transfer provisions are simply not engaged — usually a faster path than evidencing adequacy.

> Status at time of writing — confirm with local counsel.

# Does Cyber Crucible comply with Egypt's data protection law?

**Short answer:** Yes. Egypt requires prior approval for cross-border transfers of personal data — a materially higher bar than contractual safeguards. Cyber Crucible can be deployed so that no transfer occurs, removing the approval requirement rather than navigating it.

## What the law requires

Egypt's data protection framework requires **prior approval** for transfers of personal data outside the country. That is a permission-based model rather than a safeguards-based one: you cannot simply put contractual protections in place and proceed.

## Why the approval model changes vendor selection

Under a safeguards model, a vendor with strong contractual terms is workable. Under an approval model, every cross-border flow is an administrative process with timing, discretion, and renewal risk attached.

A security tool that continuously exports telemetry creates an ongoing flow requiring that approval to remain valid. If approval lapses or conditions change, the tool's normal operation becomes a compliance problem.

## The straightforward answer

The air-gapped on-premises deployment produces zero outbound telemetry — nothing is transferred, so no approval is required. Regional staging keeps processing local where a hybrid model is preferred.

The categories most likely to attract regulatory attention — keys, credentials, tokens, file contents — are never collected regardless of deployment.

> Status at time of writing — confirm current requirements and approval procedure with local counsel.

# Does Cyber Crucible comply with Ghana's Data Protection Act?

**Short answer:** Yes, and Ghana is comparatively straightforward. Ghana is notable among African jurisdictions for **not** imposing additional requirements on cross-border transfer beyond its general data protection obligations — so the standard controls apply without a special transfer regime.

## What the law requires

Ghana has an established data protection framework with a supervisory authority. Analysis of African jurisdictions consistently identifies Ghana as the exception: unlike most of its neighbours, it does not layer additional conditions specifically onto cross-border data sharing.

That does not mean transfer is unregulated — general obligations around lawful processing, security, and data subject rights still apply. It means there is no separate approval or adequacy hurdle to clear.

## What specifically applies here

With the transfer question simplified, the assessment reduces to the ordinary ones:

- **What is collected?** System and security telemetry only. No keys, credentials, tokens, or content.
- **How is it secured?** TLS 1.3 in transit, per-agent JWE payload encryption, encryption at rest, role-based access.
- **Who is responsible?** Cyber Crucible acts as processor under a written DPA on your documented instructions.

## Still worth considering sovereignty

Even without a transfer restriction, in-country or air-gapped deployment remains available — and organizations serving regional customers often prefer it, since neighbouring jurisdictions are considerably stricter.

> Status at time of writing — confirm with local counsel.

# Does Cyber Crucible meet Zambia's data localization requirement?

**Short answer:** Yes. Zambia's Data Protection Act requires controllers to process and store personal and sensitive personal data on a data centre or server **within Zambia**. Cyber Crucible's on-premises deployment satisfies this directly — the backend runs inside your own infrastructure, in-country.

## What the law requires

Part X of Zambia's Data Protection Act regulates cross-border transfer, and Section 70 obliges a data controller to process and store personal and sensitive personal data on a data centre or server located within Zambia.

This is a **storage location mandate**, not a safeguards test. Contractual protections do not satisfy it.

## Why this eliminates most cloud-based security tools

A vendor whose product requires shipping endpoint telemetry to a cloud region outside Zambia cannot meet Section 70 by improving its contracts or encryption. The requirement is about *where the data physically sits*.

## Why this architecture satisfies it

- **On-premises backend** — all management software runs on servers you control, inside Zambia.
- **Local analysis** — threat evaluation and interdiction occur on the endpoint itself, so protection never depends on an out-of-country service.
- **Zero outbound telemetry** in the air-gapped configuration.
- **Minimal scope** — keys, credentials, tokens, and content are never collected, so the volume of personal data subject to Section 70 is small to begin with.

> Status at time of writing — confirm with local counsel, including any sector-specific rules.

# Does Cyber Crucible comply with Rwanda's data protection law?

**Short answer:** Yes. Rwanda's data protection law is supervised by the National Cyber Security Authority, and sector-specific rules add localization obligations — notably for licensed banks, which must maintain primary data within Rwanda. The on-premises deployment satisfies both.

## What the law requires

Rwanda enacted a data protection law with the **National Cyber Security Authority (NCSA)** designated as supervisory authority; its data protection office launched in March 2022.

Alongside the general law, sectoral regulation adds localization: cyber security regulation requires banks licensed by the Central Bank to maintain primary data within Rwandan territory.

## Why the sectoral rule matters most

For financial services in Rwanda, the banking localization requirement is usually the binding constraint — stricter and more specific than the general data protection provisions. A security product deployed across a bank's endpoints processes data that falls within it.

## What specifically applies here

- **On-premises deployment** keeps primary data within Rwanda, satisfying the localization requirement directly.
- **Local analysis** means protection does not depend on any out-of-country service.
- **Supervisory alignment** — with NCSA as both cyber security and data protection authority, being able to evidence *what* a security tool collects, in enumerated terms, is unusually useful.

> Status at time of writing — confirm current general and sectoral requirements with local counsel.

# Does Cyber Crucible comply with Morocco's data protection law?

**Short answer:** Yes. Morocco's Law No. 09-08 and its implementing decree govern personal data processing, supervised by the CNDP. The same controls apply — minimal collection, documented processor role, strong safeguards, and in-country or air-gapped deployment where preferred.

## What the law requires

Morocco's framework rests on **Law No. 09-08** on the protection of individuals with regard to the processing of personal data, together with implementing **Decree No. 2-09-165**. The **CNDP** (Commission Nationale de contrôle de la protection des Données à caractère Personnel) is the supervisory authority, and is active in international cooperation on emerging issues including AI.

## What specifically applies here

Morocco's regime is among the more established in North Africa, with a functioning authority and notification/authorization procedures that vary by processing type. Practical implications for vendor assessment:

- **Enumerate what is collected.** Cyber Crucible's excluded-data list is explicit — no keys, credentials, tokens, or content — which supports notification accuracy.
- **Processor role** under a written DPA on documented instructions.
- **Transfer** — regional staging or air-gapped deployment; the latter removes the question.

## For organizations operating across the Maghreb

Requirements differ considerably between Morocco, Tunisia, Algeria, and Libya. Selecting a vendor that meets the strictest applicable regime — rather than assessing each separately — is usually the lower-effort path.

> Status at time of writing — confirm with local counsel.

# What are the data protection requirements in Libya?

**Short answer:** Libya has not yet developed comprehensive data protection regulations. That makes data sovereignty a commercial, security, and counterparty decision rather than a local compliance obligation — but for organizations handling sensitive operations, it remains a decision worth making deliberately.

## The current position

Libya has yet to enact a comprehensive data protection framework. There is no equivalent to Saudi PDPL, Morocco's Law 09-08, or Nigeria's NDPA.

## Why sovereignty still matters without a local law

**1. Counterparties impose requirements.** International partners, insurers, multinational customers, and funders routinely require GDPR-equivalent handling by contract regardless of local law. Meeting the stricter standard avoids renegotiating later.

**2. Sensitive sectors carry their own risk.** Energy, telecommunications, finance, and government operations attract attention independent of privacy legislation. Where a security tool sends telemetry — and who can compel access to it there — is a genuine operational question.

**3. Regulation tends to follow.** Neighbouring jurisdictions across North Africa have enacted or updated frameworks. Vendor decisions made now will still be in place when Libya's position changes.

## The practical position

Because Cyber Crucible never collects keys, credentials, tokens, or content, and can run fully air-gapped with zero outbound telemetry, it satisfies the strictest regimes in the region. In Libya that is a choice rather than an obligation — but it is one that ages well.

> Status at time of writing — confirm the current legislative position with local counsel before relying on it.

# Does Cyber Crucible comply with GDPR?

**Short answer:** Yes, by design rather than by policy. Content, credentials, encryption keys, and session tokens are never collected; analysis happens on the endpoint; Cyber Crucible acts as processor under a written DPA; and deployment options keep personal data inside the EU — or inside your own building.

## Mapping to GDPR principles

- **Data minimization (Art. 5)** — the excluded-data list is enumerated, not described in generalities. Telemetry is limited to what threat detection requires and is configurable.
- **Integrity and confidentiality (Art. 5, 32)** — TLS 1.3 in transit, per-agent JWE payload encryption, encryption at rest, role-based access control, key rotation, audit logging.
- **Processor obligations (Art. 28)** — written DPA specifying scope; processing only on documented instructions; sub-processors bound to equivalent terms.
- **Transfers (Chapter V)** — EU regional staging, or air-gapped deployment that eliminates transfer entirely.
- **Data protection by design (Art. 25)** — the strongest claim available: the highest-risk categories are not protected by policy, they are never collected.

## Pseudonymization

Where behavioural telemetry could indirectly identify an individual, identifiers are pseudonymized or masked — a safeguard GDPR explicitly recognizes.

## What this does not do

It does not make your organization GDPR compliant. Your obligations depend on your own processing purposes, lawful bases, notices, and records. What it removes is a common difficulty: a security vendor continuously exporting personal data to a third country.

# Does Cyber Crucible comply with UK GDPR?

**Short answer:** Yes. UK GDPR and the Data Protection Act 2018 track EU GDPR closely, so the same mapping applies — minimal collection, processor role under a written DPA, strong technical safeguards, and deployment options that keep data in the UK or entirely on your premises.

## What applies

Following the UK's departure from the EU, UK GDPR operates alongside the Data Protection Act 2018, supervised by the Information Commissioner's Office (ICO). The principles, lawful bases, and processor obligations closely mirror EU GDPR.

## Where organizations should pay attention

- **International transfers** use the UK's own mechanisms — the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, rather than EU SCCs alone.
- **Dual compliance** — organizations operating in both the UK and EU must satisfy both regimes, though the practical controls overlap almost entirely.

## What specifically applies here

The assessment is the same as for EU GDPR, and the answers are the same:

- Keys, credentials, tokens, and file contents are never collected.
- Analysis occurs on the endpoint; protection does not require data to move.
- UK regional staging, or air-gapped deployment that removes transfer entirely.
- Processor role under a written DPA with sub-processors bound to equivalent terms.

> For the appropriate transfer instrument for your circumstances, contact **dpo@cybercrucible.com**. Status at time of writing — confirm current ICO guidance with counsel.