Use Frontier AI And
Keep Your Data Sovereign
for PDPL-Compliance
Use OpenAI, Claude or Gemini under Saudi and UAE data protection law with the Mavs AI runtime control layer for data sovereignty.

What PDPL Asks of You
and How Everyday Prompts Become Breaches

01 — Keep personal data inside the country.
SAR 5M max penalty, doubled on repeatPersonal data can leave Saudi Arabia or the UAE only under strict conditions: the destination country must be approved by the regulator, or the transfer must be covered by a contract that protects the data, and you must assess the risk first. UAE sector rules go further: health data may not be stored or processed outside the UAE, and the Central Bank requires customer and transaction data to stay in the country. Risk: Every prompt to a model hosted abroad is a cross-border transfer. On a public LLM there is no contract behind it. On the enterprise tool there is, but it cannot tell you which personal data left in which prompt. Either way, you cannot show a regulator what left or where it went.
02 — Respect purpose limitation and data minimisation.
SAR 5M max penalty, doubled on repeatPurpose limitation means personal data can be processed only for the specific purpose the person was told about when it was collected. Data minimisation means you may use only as much of it as that purpose requires. Anything more needs a fresh legal basis. Risk: A customer record collected to service an account was not collected to be summarised by a third-party model. When an employee pastes the whole record into a chat app, the data is processed for a purpose the customer never agreed to, and far more of it than the task needed.
03 — Honour requests to see, correct or destroy data.
30 days to respondAnyone whose data you hold can ask to see it, have it corrected, or have it destroyed. You have a fixed time to respond, and the regulator can act on any failure. Risk: Once personal data reaches a third-party LLM, it sits in chat history and vendor logs you cannot search or delete. You can destroy the record on your own systems and still be unable to honour the request.
04 — Demonstrate technical safeguards on personal data.
SAR 3M and up to 2 years' imprisonment for unlawful disclosure of sensitive dataPersonal data must be protected by security controls you can show the regulator: encryption, access control, logging, monitoring and retention limits. Health, financial and biometric data carry the heaviest penalties when those controls fail. Risk: Sending real personal data to an LLM fails this twice. It leaves the reach of your controls, then sits in the provider's caches and logs where none of your safeguards apply. A clinician asking a model about a real patient has taken the record outside every control you could show.
05 — Respond to breaches inside the clock.
72 hours to notify SDAIAIf personal data is breached, Saudi Arabia requires you to notify SDAIA within 72 hours and the affected individuals without undue delay. The UAE requires notification to the Data Office as soon as you become aware. The notification has to say what data was exposed and whose. Risk: AI chat tools keep no record of which personal data left in which prompt. Without per-prompt logs, establishing the scope of a breach means asking employees what they typed.
Residency Is Where Data Sits
Sovereignty Is Who Controls It

Three Pillars of the Mavs AI Control Layer for PDPL Compliance
SYNTHETIC SUBSTITUTION
AT THE PROMPT BOUNDARY
Sensitive data in the prompt is replaced with realistic synthetic stand-ins: a name for a name, an ID for an ID. The model answers as it would have with the real data, and the real values are restored before the user reads it. The provider sees only the synthetic version.

A PRIVATE TENANT
HOSTED IN YOUR COUNTRY
Real values, substitution mappings and the Mavs engine run in a private tenant in the country you choose. Only the synthetic prompt crosses the border, so residency and sovereignty hold for every model your teams use.

GOVERNANCE
AND AUDIT TRAIL
Guardrails act on the sensitive data inside a prompt rather than blocking the prompt, and you set them per team. Every prompt, substitution and response is logged immutably, so when the regulator asks how a transfer was controlled, the answer is in your own log.

One Control Layer For Every Way
Your Enterprise Uses AI
How we Ride?
PDPL Is About Keeping Control of the Data
The usual fixes give up either the data or the model. Mavs AI helps you keep both.
| Requirement | Self-hosted model | Provider-hosted model in-region | Other AI-DLP guardrails | Mavs AI |
|---|---|---|---|---|
Personal data stays in the country | ||||
Model reasons with full context | ||||
Choice of frontier model | ||||
Audit evidence per prompt | ||||
Deleting a customer's data on request | ||||
What it costs you |
| Requirement | Mavs AI | Self-hosted model | Provider-hosted model in-region | Other AI-DLP guardrails |
|---|---|---|---|---|
Personal data stays in the country | ||||
Model reasons with full context | ||||
Choice of frontier model | ||||
Audit evidence per prompt | ||||
Deleting a customer's data on request | ||||
What it costs you |
Frequently Asked Questions
Which laws does this page cover?
The Saudi Personal Data Protection Law, enforced by SDAIA and in force since September 2023, and the UAE's Federal Decree-Law No. 45 of 2021, overseen by the UAE Data Office. Qatar (Law No. 13 of 2016), Bahrain (Law No. 30 of 2018) and Oman (Royal Decree 6/2022) follow the same pattern: purpose limitation, individual rights, and restrictions on moving personal data out of the country. Mavs applies the same control regardless of which one you answer to.
Is sending a prompt to a model hosted abroad a cross-border transfer?
Yes, if the prompt contains personal data. The Saudi Transfer Regulations and UAE Articles 22 and 23 apply to the act of transferring, not to where the data is stored afterwards. A prompt with a National ID or Emirates ID in it is a transfer the moment it leaves your network.
Where does Mavs run?
In a private tenant hosted in the GCC, or inside your own VPC or private environment. The risk engine, your policies, the substitution mappings and the audit log stay in that tenant. Only the synthetic prompt goes to the model.
Does the model provider still receive personal data?
No. Personal and sensitive values are replaced with synthetic stand-ins before the prompt leaves your environment. The provider receives a prompt that reads naturally and contains no real personal data, so there is nothing for it to retain, log or train on.
Does it work with OpenAI, Claude and Gemini hosted outside the region?
Yes. That is the point. Your teams use the frontier models they want, hosted wherever the provider hosts them, and the data that reaches those models is synthetic.
Does Mavs recognise national ID numbers and other local identifiers?
Yes. Saudi National ID and Iqama numbers, Emirates ID, Qatar ID, Bahrain CPR and Omani civil numbers, along with IBANs, phone numbers, names, addresses, dates and amounts. Mavs reads the prompt as language rather than matching patterns, so it also finds sensitive values that have no fixed format.
Does this cover health and banking data under UAE sector rules?
The same mechanism applies. Health records and transaction data are substituted before the prompt leaves the UAE, and every prompt is logged. Mavs supplies two things a regulator asks for: enforced controls on what leaves, and evidence of every event. Your broader obligations under Federal Law No. 2 of 2019 and the Central Bank standards remain yours.
Can Mavs AI help us with intellectual property and other business-sensitive data?
Yes. Deal codenames, unannounced pricing, bid figures, unreleased roadmap, product designs and key account lists are not personal data, so pattern-based tools do not see them. Mavs reads the prompt as language, judges what is sensitive in the context of your business, and substitutes those values the same way it does personal data. A fund can have a frontier model summarise a term sheet without the counterparty names leaving the country.
How is this different from waiting for a sovereign model?
An in-region model keeps the data in the country, but it is a bet on a smaller set of models at a higher price, and the provider is still inside your data path. Mavs keeps the data in the country and lets you use any model. Where you already run an in-region model, Mavs adds the per-prompt policy and audit layer on top.
Does Mavs sign a data processing agreement?
Yes. Our standard DPA covers processor obligations under the Saudi PDPL and the UAE Decree-Law, sub-processor controls, breach cooperation, and confirmation that customer data is not used for training.
How is Mavs deployed, and how long does it take?
Mavs is a runtime control layer over API, hosted in a private tenant in the country you choose or within your own environment. For employees, Mavs Secure Chat runs in the browser with nothing to install, and sign-in goes through your existing identity provider. For apps and agents, integration is via API. Most enterprises are live within a few hours.

