Regulation explainerGeographic Expansion

Data residency in Saudi Arabia and the UAE: what SaaS providers must settle first

Saudi Arabia and the UAE both regulate personal data and how it leaves the country, but they do it through different regimes. Saudi Arabia has one national law with separate transfer rules; the UAE has a federal law alongside separate regimes in the DIFC and ADGM financial free zones. Which rules bite depends on where your customer is established and what sector it is in, so map that before choosing a hosting region.

Reviewed 7 min read

On this page
  1. Why Gulf buyers ask for in-country hosting
  2. The data-protection regimes a Gulf SaaS deal can touch
  3. Mapping obligations by where the customer sits
  4. Architecture decisions to settle before customer data moves
  5. Sequencing hosting with the entity and the first contracts
  6. Questions and answers
  7. Sources

Why Gulf buyers ask for in-country hosting

The request usually comes in procurement, not from a regulator. A bank's security questionnaire asks where data is stored and who can reach it; a government-related buyer's contract specifies hosting inside the country. Behind those questions sit three things: national data-protection laws with transfer restrictions, sector regulators who set their own outsourcing and cloud conditions, and the customer's own risk appetite.

Separating the three matters. A law may allow a transfer with the right safeguards while a customer's contract still forbids it, and a contract term can be negotiated where a statutory duty cannot. ColdAI's expansion work treats hosting as something that must satisfy local data-localisation requirements before customer data moves, so this mapping happens early7.

The data-protection regimes a Gulf SaaS deal can touch

Personal Data Protection Law (Saudi Arabia)

Saudi Arabia

Applies whenPersonal data of individuals in the Kingdom is processed. The law was issued in September 2021 and is administered by the Saudi Data and AI Authority (SDAIA), which runs a national register and breach-notification and complaints services1.

  • Establish a lawful basis for processing and honour data-subject rights.
  • Register where the register applies to you and notify breaches through SDAIA's platform1.
  • Follow the implementing regulations, including the separate transfer rules below.

Regulation on Personal Data Transfer outside the Kingdom

Saudi Arabia

Applies whenPersonal data is stored, disclosed or accessed outside Saudi Arabia; commentary on SDAIA's framework lists remote access as one of the forms of transfer to assess2.

  • Transfer to countries SDAIA finds adequate or, until and unless an adequacy list applies, under safeguards such as standard contractual clauses or binding rules2.
  • Carry out a transfer risk assessment when relying on safeguards, or when transferring sensitive data continuously or at scale2.

UAE Federal Personal Data Protection Law (PDPL)

UAE (onshore)

Applies whenIssued as Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, it covers personal data processed in the UAE or about people in the UAE, with the UAE Data Office as federal regulator3. It excludes government data, health and banking data governed by their own laws, and free zones with their own data-protection laws such as the DIFC and ADGM4.

  • Process on a lawful basis and meet controller and processor duties3.
  • Transfer abroad to adequate jurisdictions or on another permitted basis, such as contractual safeguards or explicit consent4.
  • Check the status of the executive regulations, which were still pending when the commentary cited here was published4.

DIFC Data Protection Law

Dubai International Financial Centre

Applies whenDIFC Law No. 5 of 2020 applies where the controller or processor is incorporated in the DIFC, or processes personal data in the DIFC5. The law has been amended since it commenced, so work from the current consolidated text5.

  • Comply with the DIFC law and its Data Protection Regulations, not the federal law5.
  • Confirm the current consolidated text with DIFC counsel before relying on any provision.

ADGM Data Protection Regulations

Abu Dhabi Global Market

Applies whenThe ADGM Data Protection Regulations 2021 apply where the entity is established in ADGM6. The regime is supervised by the ADGM Office of Data Protection, which keeps a register of data controllers6.

  • Register as a data controller where required and meet the regulations' controller duties6.
  • Transfer outside ADGM to jurisdictions designated as adequate or under the safeguards the regulations allow6.

Mapping obligations by where the customer sits

Question to settleCustomer in Saudi ArabiaCustomer in onshore UAECustomer in the DIFC or ADGM
Primary data-protection regimeSaudi PDPL and its implementing and transfer regulationsFederal PDPL, unless a sector law displaces itThe free zone's own law and regulations
Regulator to name in contractsSDAIAUAE Data OfficeDIFC Commissioner or ADGM Office of Data Protection
Basis for hosting or access abroadAdequacy or safeguards plus a risk assessment where requiredAdequacy or another permitted basis; detail depends on executive regulationsAdequate jurisdiction or permitted safeguards under the free-zone rules
Sector overlay to ask aboutFinancial regulator and national cybersecurity requirements for regulated or government-related buyersHealth and banking data under their own federal lawsFinancial-services regulator's outsourcing expectations for licensed firms
Likely contract demandIn-country region for regulated and government-related buyersVaries by sector; often a UAE regionOften acceptable abroad with safeguards, subject to the firm's own regulator

A planning aid only, not a statement of what any particular customer or regulator requires. Sector overlays depend on the customer's licence; ask the customer which framework it must evidence and get it in writing.

Architecture decisions to settle before customer data moves

These are the choices that regulators, customers and counsel will all ask about. Settle them in writing for each customer segment.

  1. Choose the hosting region per segment

    Decide which customers must be served from an in-country region and which can be served from an existing region with safeguards. Check that the cloud services you depend on, including managed AI models, are actually available in that region, because a missing service often forces a transfer by the back door.

    Output
    Region matrix by customer segment
    Owner
    Platform lead
  2. Decide who holds the encryption keys

    Choose between provider-managed keys, keys you manage in-region, or customer-held keys. Key location is a common customer question, and it shapes whether staff abroad can read data at all.

    Output
    Key-management design
    Owner
    Security lead
  3. Design support and engineering access

    Because remote access from abroad may count as a transfer in Saudi Arabia, define who can reach production data from where, under what approval, and how that access is logged. Follow-the-sun support models often need redesign here.

    Output
    Access policy and logging plan
    Owner
    Engineering and support leads
  4. List every sub-processor and where it processes

    Include monitoring, error tracking, email delivery, analytics and AI inference providers. Each one that processes personal data abroad needs a transfer basis or must be replaced for in-country customers.

    Output
    Sub-processor register with locations
    Owner
    Privacy lead
  5. Write the data-flow record and transfer assessments

    Document what personal data flows where and on what basis, and complete the risk assessments the applicable regime requires. This record is what counsel reviews and what customers ask to see.

    Output
    Data-flow map and assessments
    Owner
    Privacy lead with local counsel

Sequencing hosting with the entity and the first contracts

Hosting, the local entity and customer contracts depend on each other, so the order matters. Map the regimes and segment your customers first; then decide the hosting design; then let counsel draft the data-processing terms around a design that already exists. Signing a contract that promises in-country hosting before the region is live, or moving data before the transfer basis is documented, creates obligations the product cannot yet meet.

The entity question interacts too. Contracting through a free-zone company changes which data-protection regime governs your own processing, though not the regime your customer answers to. Record that choice in your market entry regulatory register alongside licences and employment obligations, so one sequence covers all three.

Questions and answers

Does the Saudi PDPL require all personal data to stay in Saudi Arabia?

Not as a blanket rule. The transfer regulation allows transfers to jurisdictions SDAIA finds adequate or under safeguards such as standard contractual clauses, with risk assessments in some cases. In practice, regulated and government-related customers often require in-country hosting through their contracts or sector rules, which can be stricter than the law itself. Confirm both layers with Saudi counsel.

Does the UAE federal data protection law apply in the DIFC and ADGM?

Generally not. Commentary on the UAE's federal data-protection law notes that it excludes free zones with their own data-protection laws, naming the DIFC and ADGM, which have their own laws, regulators and transfer rules. A company with customers in both onshore UAE and a free zone may therefore need to meet two regimes, so map customers by where they are established.

Can our support team outside the region access customer data hosted in-country?

Possibly, but treat it as a transfer question. Commentary on Saudi Arabia's framework lists remote access among the forms of transfer to assess, and many customer contracts restrict access by location. Design a controlled access route with approvals and logging, document the transfer basis, and agree the model with the customer before relying on it.

Do we need a local entity before hosting data in the Gulf?

Not necessarily for hosting itself; cloud regions can usually be contracted from abroad. The entity question is driven by customer contracting, licences and employment. However, the entity you contract through can change which data-protection regime governs your own processing, so decide hosting and structure together with counsel rather than one after the other.

Which rules apply to AI model inference on Gulf customer data?

The same personal data rules apply to inference as to storage: if prompts or outputs contain personal data and the model runs abroad, that is processing abroad. Check whether the model you use is available in the chosen region, record the inference provider as a sub-processor, and include model logs and fine-tuning data in the data-flow map.

Sources

  1. National Data Governance Platform: personal data protection services — Saudi Data and AI Authority (SDAIA) · checked 10 October 2026
  2. Update on Saudi Arabia's cross border data transfers: understanding the New Risk Assessment Guidelines — Clyde & Co · checked 10 October 2026
  3. Data protection laws — The UAE Government portal (u.ae) · checked 10 October 2026
  4. UAE Personal Data Protection Law – FAQs — Simmons & Simmons · checked 10 October 2026
  5. Data Protection Law DIFC Law No. 5 of 2020 — Dubai International Financial Centre · checked 10 October 2026
  6. ADGM Office of Data Protection — Abu Dhabi Global Market · checked 10 October 2026
  7. Geographic Expansion: who does what between ColdAI and local advisers — ColdAI

More in Geographic Expansion

Back to Geographic Expansion

Next step

Gulf prospects asking where their data will live?

Send your current hosting regions, sub-processor list and the questions your Gulf prospects have asked. We will map which regimes apply by customer segment and the hosting decisions to settle with local counsel.

Map your Gulf hosting questions