Blog · Compliance

UAE data residency and local cloud hosting.

A practical look at keeping data inside the UAE — what the regulation actually requires, which providers run in-country, and how to architect for it without losing the convenience of a modern cloud stack.

By Darkstar Technologies editorialPublished Last reviewed Reading time 6 min
Abu Dhabi skyline at dusk — illustrating UAE in-country cloud infrastructure
Cover artwork: Darkstar Technologies
Why it matters

In-country data is becoming the default, not the exception.

For a long time, UAE businesses defaulted to hyperscaler regions in Europe or the US. That tradeoff is shifting. Federal Decree-Law No. 45 of 2021 — the UAE Personal Data Protection Law — together with sector rules from the Central Bank, TDRA, ADGM and DIFC, and the language inside government tenders have all moved in the same direction: personal, financial and health data should live inside the UAE, on infrastructure the country can reach.

Where to host

The in-country cloud options.

01

Oracle Cloud — Abu Dhabi region

Two in-country availability domains operated under UAE jurisdiction. Strong fit for regulated workloads, government tenders and Oracle-heavy ERP estates that need keys, backups and replicas to stay inside the UAE.

02

Microsoft Azure — UAE North & UAE Central

Two paired regions inside the UAE (Dubai and Abu Dhabi). Broadest service catalogue of any in-country provider — Postgres, SQL, AKS, OpenAI, Key Vault — useful when teams already standardise on Microsoft 365 and Entra.

03

AWS — Middle East (UAE) Region

Three availability zones in the UAE with the usual AWS service depth — RDS, S3, Lambda, Bedrock. Pairs well with workloads that want managed services without rebuilding on Microsoft or Oracle stacks.

04

G42 Cloud / Core42

UAE-owned sovereign cloud with deep ties to local regulators and a strong AI compute footprint. Right call when a tender or regulator explicitly requires Emirati-owned infrastructure.

The regulation

What actually constrains the architecture.

Federal Decree-Law 45 (PDPL)

The UAE Personal Data Protection Law sets the baseline. Cross-border transfers are restricted unless the destination country has an adequate regime or specific safeguards are in place.

ADGM & DIFC

Both financial free zones run their own data protection regimes modelled on GDPR. Most regulated entities licensed in ADGM or DIFC need to keep core records in-jurisdiction.

Sector regulators

TDRA, Central Bank, Department of Health Abu Dhabi and Dubai Health Authority each carry sector-specific data localisation requirements — health, finance and telecoms typically must stay in the UAE.

Government tenders

Federal and Abu Dhabi government RFPs increasingly require all data — primary, backups and disaster recovery — to remain inside the UAE on approved infrastructure.

How we architect for it

Four rules behind every UAE-resident build.

01

Pin the data plane in-country

Primary database, object storage, backups and read replicas all provisioned in a UAE region. No silent failover to EU or US regions during incidents.

02

Keep keys local

Encryption keys held in a UAE-resident KMS or HSM — Azure Key Vault UAE, AWS KMS Middle East, or Oracle Vault Abu Dhabi. Export of key material disabled.

03

Edge globally, store locally

Use a global CDN for static assets and caching, but route authenticated and personal-data requests back to UAE origins. Cache TTLs tuned so personal data never lives at the edge.

04

Document the third parties

Every SaaS in the stack — analytics, email, payments, AI APIs — mapped to where it actually stores data. Replace or carve out anything that sends personal data outside approved jurisdictions.

Need a UAE-resident stack? Let's map it.

Describe the system, the bottleneck, or the ambition. We will tell you — precisely — how we would build it.