54east / Insights / Sovereignty audit
Sovereignty audit · Whitepaper
Why a cloud region isn’t a jurisdiction
A region tells you where the disks spin. It does not tell you who can compel the operator, who holds the keys, who sees the logs, or what you walk away with if the contract ends.
Data residency and AI procurement for Abu Dhabi institutions
A region tells you where the disks spin. It does not tell you who can compel the operator, who holds the keys, who sees the logs on a support ticket, or what you walk away with if the contract ends. Winning institutions own the system. A region code is not ownership.
The map, as it actually is
Azure, AWS, Oracle and Alibaba advertise UAE regions. Google Cloud does not. IBM Cloud does not. “In-region” is not a market-wide default, and it is not a jurisdiction.azure-regions aws-uae oracle alibaba gcp ibm
Microsoft Azure has two UAE regions, both launched in June 2019:azure-2019 azure-regions
- UAE North — Dubai. Generally available. Availability zones. Programmatic name `uaenorth`.
- UAE Central — Abu Dhabi. Restricted paired region for UAE North. Programmatic name `uaecentral`. Not a generally available production region for every subscription.
AWS operates Middle East (UAE), API name `me-central-1`, generally available 29 August 2022. AWS does not publish a city. Do not invent one.aws-uae aws-history
Oracle Cloud lists UAE East (Dubai) `me-dubai-1` and UAE Central (Abu Dhabi) `me-abudhabi-1`.oracle Alibaba Cloud has advertised UAE (Dubai) `me-east-1` since November 2016.alibaba
Google Cloud still has no UAE region as of August 2026. Official Middle East compute regions: Doha `me-central1`; Dammam `me-central2` (access restricted); Tel Aviv `me-west1`. Dubai and Fujairah appear as network-edge and interconnect/colocation points — Equinix DX1 in Dubai is interconnect, not a compute/storage region. That is not in-country residency. Do not treat Doha or Dammam as UAE.gcp gcp-locations gcp-dammam gcp-edge gcp-interconnect
IBM Cloud’s public region table does not list a UAE region. IBM Services did open managed data centres in Dubai and Abu Dhabi in January 2020, for hybrid and managed workloads — not a public IBM Cloud region.ibm ibm-services-2020
For a Gulf institution evaluating an AI system — a ministry, a bank, a hospital group, a national energy company — ticking “hosted in the UAE” is where diligence starts. Not where it ends.
Region is the vendor’s construct. Sovereignty is yours.
A cloud region is a physical and legal construct the vendor chose. Sovereignty, in the sense that matters to a ministry or a regulated institution, is a set of guarantees the customer chose. They overlap. The overlap is partial. The gap stays invisible until an incident, an audit, or a change of ownership forces it into view.
Four questions separate a defensible deployment from a well-marketed regional one.
1. Who can be compelled, and under which law?
A UAE data centre operated by a US-headquartered hyperscaler does not, by itself, take the parent outside US legal process. The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) amended the Stored Communications Act so that a provider subject to US jurisdiction must disclose communications and records in its possession, custody, or control, “regardless of whether such communication, record, or other information is located within or outside of the United States.” Location of disks is not the test. Control is.cloud-act sca-2713
This is exposure, not automatic disclosure. Warrants or court orders are still required. Providers may raise foreign-law comity challenges. Customer-managed keys and confidential compute can make the provider practically unable to read the payload without the customer. They reduce practical access. They do not, by themselves, take a US parent outside US process.ms-cloud-act lockbox
Microsoft’s own UAE compliance language is residency, failover, and disaster recovery — DESC CSP certification of the two UAE regions included. It is not a statutory carve-out from process against a US parent.desc
No UAE statute found extinguishes that process merely because the disks sit in Dubai or Abu Dhabi. UAE transfer and sector rules regulate outbound movement from UAE controllers. That is a different legal question. Do not collapse them.
2. Who holds the keys?
Encryption at rest is standard. Who controls the key-management service is not. If the vendor’s global KMS sits outside the country, “in-region storage” is compatible with a key custodian who is not.
Customer-managed keys, held in-country, that the institution can revoke unilaterally, are a different guarantee from “your data is encrypted.” Ask which legal entity operates the HSM. Ask whether a local partner holds a copy “for support.” Ask whether the institution can shred access without a vendor ticket.
3. Who can see it during operations?
Global support models route tickets to whichever engineer is on shift, wherever they are. A resident-data sentence is hollow if a production issue sends a screen-share or a log dump through a support team outside the jurisdiction. This is rarely volunteered. It has to be asked, named in the contract, and logged with geographic origin.
4. What happens on exit?
Can the institution retrieve model weights, prompts, fine-tuning data, and audit logs in a usable, vendor-neutral format if it terminates the vendor? Or does “your data” in the contract mean the raw inputs, while the trained artefacts and the operational history stay with the vendor as their IP?
A system that cannot be extracted was never owned. Exit terms are contract. They are not a PDPL statutory condition, and they are not a region code.
Your statute is not the same as the institution next door
This paper is written for Abu Dhabi institutions, including ministries. Do not read one federal personal-data statute onto every reader. The law splits.
Ministries and government data
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) does not apply to government data, to governmental entities which control or process personal data, or to personal data held by security and judicial authorities. That is Article 2(2)(a)–(c), not a drafting footnote.pdpl ita-pdpl
A ministry is not a PDPL controller. Classified and government data are outside PDPL. Do not use PDPL as the residency or transfer hook for public institutions.
Government and ministry cloud buying sits under the UAE Information Assurance Standard (Cyber Security Council), the National Cloud Security Policy issued by the Council — mandatory for UAE government and critical-infrastructure entities when buying and using cloud, including knowing data location and acceptable legal jurisdiction — and any sector overlay the entity actually sits under. Those are the instruments. PDPL is not.ia ia-tdra ncsp
Banks
For CBUAE-licensed banks, Circular C 14/2021 (Outsourcing Regulation for Banks) requires Board or Board-committee approval, and Central Bank non-objection, for material outsourcing. Not every cloud or AI vendor is material outsourcing as a class.c14 c14-nob
The 2021 Enabling Technologies Guidelines (CBUAE with SCA, DFSA and FSRA) treat a cloud arrangement as material when disruption or a security or confidentiality breach may materially affect operations, risk management, legal compliance, or the confidentiality or integrity of personal data. They hold the governing body accountable for AI outcomes. Language is “should.”enabling
The February 2026 Guidance Note on consumer protection and responsible adoption of AI/ML makes board- and senior-management accountability for AI explicit. Licensed financial institutions “should not employ AI models that they have no control over.” It is guidance, issued 2026, not the 2021 outsourcing circular.ai-note ai-gov ai-tp
PDPL Article 2(2)(f) carves out bank and credit personal data governed by other legislation. Do not run a bank’s core diligence through PDPL as if it were the residency statute.
Health
Health records are largely outside PDPL. Article 2(2)(e) excludes health personal data the protection and processing of which is governed by other legislation.pdpl ita-pdpl
The controlling federal instrument is Federal Law No. 2 of 2019 concerning information and communication technology in health fields. Article 13: it is not permissible to store, process, generate or transfer health data related to health services provided in the UAE outside the State except by a resolution of the Health Authority in coordination with the Ministry. Ministerial Resolution No. 51 of 2021 lists limited export cases. That is an in-country default. PDPL is not a residency law, and Article 2(2)(e) takes health data out of PDPL. The health instruments occupy their own lane. They do not sit as a stricter version of the same statute.health-law ita-health
Abu Dhabi entities also sit under the Department of Health’s ADHICS standard, first issued in 2019 — before PDPL. Dubai entities sit under DHA’s Policy for Data and Health Information Protection and Confidentiality (DHA/HRS/HISHD/PP-11), issue date 10 August 2022, effective 10 October 2022 — after PDPL. The DHA policy reads itself with Federal Law 2/2019 and PDPL. An AI vendor that “meets PDPL” has not met the health-data localisation bar or the emirate technical standard.dha
Free zones
ADGM and DIFC each operate their own data-protection regimes, distinct from federal law and from each other. PDPL Article 2(2)(g) carves out companies and establishments in free zones that are subject to their own personal-data regulations.pdpl
- DIFC: Data Protection Law No. 5 of 2020, amended by DIFC Laws Amendment Law No. 1 of 2025 (enacted 8 July 2025, in force 15 July 2025). Own commissioner, own adequacy list, own standard clauses.difc difc-2025
- ADGM: Data Protection Regulations 2021, enacted 14 February 2021. Independent Office of Data Protection. Own standard clauses.adgm adgm-odp
A mainland-plus-free-zone group — common for banks, and not rare for government-adjacent entities — is not one residency question. It is two or three, each with a different regulator.
Private-sector personal data on the mainland
For in-scope mainland personal data, PDPL is the transfer test. Name it correctly.
Federal Decree-Law No. 45 of 2021, in force 2 January 2022. Articles 22–23 restrict outbound transfers of personal data: adequacy as approved by the Office, or listed derogations including contract, express consent, contract performance, judicial cooperation, and public interest.pdpl ita-pdpl
PDPL is not a data-residency statute. It regulates how personal data may leave. It does not require it to stay.
Do not describe the transfer regime as fully operational “teeth.” As of mid-2026, executive regulations have not been published. There is no published federal adequacy list. There are no UAEDO-approved standard contractual clauses. Article 29’s regularisation clock runs from issuance of the executive regulations; that clock has not started. Article 26’s administrative sanctions require a separate Cabinet decision.chambers aws-pdpl ita-pdpl
Silent overseas inference or training is a transfer when the payload is in-scope personal data — a prompt that identifies a natural person, a fine-tune set that does. A prompt that does not contain personal data is not a PDPL transfer just because it left the country. Route the question through the data, not through the slide that says “UAE region.”
Five questions before the signature
Institutions evaluating an AI vendor — chatbot, analytics platform, agentic system — can put these in the contract. Marketing language is not an answer.
Hosting. Is inference, storage, and fine-tuning entirely within the UAE, with no fallback routing to an overseas region during outage or peak load? On Azure, the published pair is UAE North ↔ UAE Central. UAE Central is restricted. If that pair is locked for the subscription, an Azure disaster-recovery design may leave the country. Put the pair, and the lock, in the no-overseas-failover clause. Do not accept “UAE geography” as a substitute for naming the region that will actually take the failover.azure-regions
Key custody. Are encryption keys generated, held, and revocable by the institution, independent of the vendor’s global infrastructure?
Access logging. Is there a complete, exportable audit trail of every access — employee, vendor support, automated process — with geographic origin recorded?
Support routing. Is there a contractual guarantee that personnel with data access are UAE-based, or is this left to “reasonable efforts”?
Exit. Does the contract specify, in writing, exactly what is returned on termination — weights, prompts, logs, runbooks — in a vendor-neutral, re-implementable format?
A vendor that cannot answer these in specific contractual terms has not built a sovereign system. They have built a system that happens to run on UAE soil. That is a weaker guarantee.
What to demand, in practice
Benchmark the bid against a shape, not against a slogan.
Dedicated infrastructure, not multi-tenant, where the class of data requires it — the institution’s compute and storage not shared with other customers even inside the same in-country hall. Key management the institution can independently verify, not merely attested in a compliance PDF. Support staffed by a named in-country team the institution has met, with a contractual bar on data-touching work routing elsewhere during an incident. Exit terms that have been run, not only written: an extraction drill that pulls model artefacts and logs in the format the contract promises, before an emergency makes that the first attempt.
Paper-complete exit clauses fail in the drill. A “full audit-log export” missing the field the institution actually needs. Weights that open only in the original vendor’s tooling. Catch that while it is still a contract comment.
None of this is free. Dedicated infrastructure, customer-held keys, and contractually guaranteed in-country support cost more than a multi-tenant enterprise SKU. The honest line for a procurement office is not that sovereignty is costless. It is a named premium for a named risk reduction. That is a defensible budget line. “We chose the cheaper vendor and hoped” is not — particularly if a residency or access incident later becomes a public or regulatory record.
The institutions that get this right are not the ones asking whether the vendor is “in the region.” They are the ones asking who can be compelled, who holds the keys, who can see the logs, and what they walk away with if the relationship ends.
A cloud region is a data point. Sovereignty is a bundle of contractual, technical, and legal guarantees, verified independently of where the servers sit. For a ministry, that bundle is IA, national cloud, and sector overlay. For a bank, CBUAE material-outsourcing and the 2026 AI guidance. For a hospital, Federal Law 2/2019 and the emirate health standard. For in-scope mainland personal data, PDPL Articles 22–23 as a transfer test — not a residency stamp. For a DIFC or ADGM entity, that zone’s own law.
Winning institutions own the system. A region with a local partner’s logo on the slide is not the system.
54east builds in-country for UAE and Saudi institutions, on infrastructure the institution owns at the end of the engagement. Consult, build, train. Then we leave. If a residency or vendor-diligence question is live, start with a briefing.
Notes
Notes
- Microsoft Learn, Azure regions list, last updated 29 May 2026. UAE North: Dubai, availability zones, paired with UAE Central (restricted). UAE Central: Abu Dhabi, restricted paired region. https://learn.microsoft.com/en-us/azure/reliability/regions-list
- Microsoft Azure Blog, First Microsoft cloud regions in Middle East now available, 19 June 2019. https://azure.microsoft.com/en-us/blog/first-microsoft-cloud-regions-in-middle-east-now-available/ See also Microsoft MEA News Center, 19 June 2019. https://news.microsoft.com/en-xm/2019/06/19/microsoft-cloud-datacenter-regions-now-available-in-the-uae-to-help-fuel-the-middle-easts-future-economic-ambitions/
- AWS News Blog, Now Open – AWS Region in the United Arab Emirates (UAE). Official name Middle East (UAE); no city published. https://aws.amazon.com/blogs/aws/now-open-aws-region-in-the-united-arab-emirates-uae/
- AWS, AWS Regions and Availability Zones documentation history: `me-central-1` launched 29 August 2022. https://docs.aws.amazon.com/global-infrastructure/latest/regions/doc-history.html
- Oracle Cloud Infrastructure, Regions and Availability Domains: UAE Central (Abu Dhabi) `me-abudhabi-1`; UAE East (Dubai) `me-dubai-1`. https://docs.oracle.com/en-us/iaas/Content/General/Concepts/regions.htm See also https://www.oracle.com/ae/cloud/public-cloud-regions/
- Alibaba Group, Dubai data centre / UAE region announcement, 21 November 2016. Region identifier `me-east-1`. https://www.alibabagroup.com/en-US/document-1491579636423852032
- Google Cloud, Regions and zones. Middle East: `me-central1` Doha; `me-central2` Dammam (restricted); `me-west1` Tel Aviv. No UAE region. https://cloud.google.com/compute/docs/regions-zones
- Google Cloud, Global locations. No UAE compute/storage region. https://cloud.google.com/about/locations
- Google Cloud, Dammam region access. https://cloud.google.com/docs/dammam-region-access
- Google Cloud, Network edge locations — Dubai and Fujairah listed as edge, not regions. https://cloud.google.com/vpc/docs/edge-locations
- Google Cloud, Cloud Interconnect colocation facilities — Dubai Equinix DX1. Interconnect is not residency. https://cloud.google.com/network-connectivity/docs/interconnect/concepts/choosing-colocation-facilities
- IBM Cloud, Kubernetes Service regions and zones. No UAE region in the public table. https://cloud.ibm.com/docs/containers?topic=containers-regions-and-zones
- IBM Services, “IBM Services Introduces Two Data Centers in the UAE to Help Accelerate Customer Journeys to Hybrid Cloud,” 7 January 2020. Dubai and Abu Dhabi managed data centres, not a public IBM Cloud region. https://mea.newsroom.ibm.com/2020-01-07-IBM-Services-Introduces-Two-Data-Centers-in-the-UAE-to-Help-Accelerate-Customer-Journeys-to-Hybrid-Cloud
- Congressional Research Service, Cross-Border Data Sharing Under the CLOUD Act (R45173). https://www.congress.gov/crsexternalproducts/R/PDF/R45173/R45173.5.pdf
- 18 U.S.C. § 2713 (Stored Communications Act, as amended by the CLOUD Act): disclosure of communications and records in the provider’s possession, custody, or control, regardless of location inside or outside the United States. https://www.govinfo.gov/content/pkg/USCODE-2024-title18/pdf/USCODE-2024-title18-partI-chap121-sec2713.pdf
- Microsoft, The CLOUD Act: What It Is – And What It Isn’t. Reach by control, not unfettered access; technical controls can render the provider unable to read data without the customer. https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/CLOUD-Act-What-it-is-and-is-not.pdf
- Microsoft Learn, Customer Lockbox. https://learn.microsoft.com/en-us/azure/security/fundamentals/customer-lockbox-overview
- Microsoft Learn, UAE DESC CSP Security Standard — UAE Central and UAE North. Residency and certification, not immunity from foreign process. https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-uae-desc
- UAE legislation portal, Federal Decree-Law No. 45 of 2021 (Protection of Personal Data). In force 2 January 2022 (Art. 33). Art. 2(2) carve-outs; Arts. 22–23 transfers; Arts. 26, 28–29 sanctions, executive regulations, regularisation clock. https://uaelegislation.gov.ae/en/legislations/1972
- US International Trade Administration, 22 January 2024: PDPL does not apply to government data or processing by government authorities, security and judicial data, personal health data, or personal financial data where other legislation governs; Arts. 22–23 summarised as adequacy or listed derogations. https://www.trade.gov/market-intelligence/united-arab-emirates-allows-cross-border-data-flows-personal-data
- Chambers and Partners, Data Protection & Privacy 2026 — UAE: implementing regulations “have yet to be issued.” https://practiceguides.chambers.com/practice-guides/data-protection-privacy-2026/uae/trends-and-developments
- AWS, United Arab Emirates Data Privacy: executive regulations “have not been issued to date”; adequacy list “has not yet been made publicly available.” https://aws.amazon.com/compliance/uaedataprivacy/
- UAE Cyber Security Council, UAE Information Assurance Standard. Framework for government and critical-information-infrastructure entities. https://csc.gov.ae/en/w/uae-information-assurance-standard
- Telecommunications and Digital Government Regulatory Authority, UAE Information Assurance Regulation (v1.1): UAE government entities and TRA-designated critical entities are obligated to implement. https://tdra.gov.ae/-/media/About/regulations-and-ruling/EN/UAE-Information-Assurance-Regulation-v1-1-pdf.ashx
- Pinsent Masons, Security policy supports shift to cloud in the UAE: National Cloud Security Policy issued by the UAE Cyber Security Council; mandatory for UAE government and critical-infrastructure entities (and for CSPs) when buying and using cloud; customers must know data location at all stages and ensure CSPs operate within acceptable legal jurisdiction(s). https://www.pinsentmasons.com/out-law/news/security-policy-supports-shift-cloud-uae
- CBUAE Rulebook, Outsourcing Regulation for Banks, Circular C 14/2021. Board or Board-committee approval for material outsourcing. https://rulebook.centralbank.ae/en/rulebook/outsourcing-regulation-banks
- CBUAE Rulebook, non-objection pack — Board evidence required. https://rulebook.centralbank.ae/en/rulebook/8-non-objection-central-bank
- CBUAE / SCA / DFSA / FSRA, Guidelines for Financial Institutions adopting Enabling Technologies (2021). Cloud §§2.11–2.14, 3.24–3.26; AI §§2.25–2.30, 3.94+. https://assets.adgm.com/download/assets/Guidelines%2Bfor%2BFinancial%2BInstitutions%2Badopting%2BEnabling%2BTechnologies%2B20211107.pdf/43c4106e703111efa313063c8edceeae
- CBUAE, Guidance Note to protect consumers and ensure responsible use of artificial intelligence in the financial sector, press dated 23 February 2026. https://www.centralbank.ae/en/news-and-publications/news-and-insights/press-release/cbuae-issues-guidance-note-to-protect-consumers-and-ensure-responsible-use-of-artificial-intelligence-in-the-financial-sector/ PDF: https://www.centralbank.ae/media/mykn5fue/cbuae-issues-guidance-note-to-protect-consumers-and-ensure-responsible-use-of-artificial-intelligence-in-the-financial-sector-en.pdf
- CBUAE Rulebook, AI governance and accountability. https://rulebook.centralbank.ae/en/rulebook/2-governance-and-accountability
- CBUAE Rulebook, AI outsourcing and third-party risk. https://rulebook.centralbank.ae/en/rulebook/9-outsourcing-and-third-party-risk
- UAE legislation portal, Federal Law No. 2 of 2019 concerning ICT in health fields. Art. 13 in-country default. https://uaelegislation.gov.ae/en/legislations/1209
- US International Trade Administration, UAE regulations limiting cross-border health data flows, including Ministerial Resolution 51/2021. https://www.trade.gov/market-intelligence/united-arab-emirates-regulations-limit-cross-border-health-data-flows
- Dubai Health Authority, Policy for Data and Health Information Protection and Confidentiality, DHA/HRS/HISHD/PP-11, issue date 10/08/2022, effective 10/10/2022. https://www.dha.gov.ae/uploads/082022/Health%20Data%20Protection%20and%20Confidentiality%20PolicyEN2022810559.pdf
- DIFC Commissioner of Data Protection. DIFC Data Protection Law No. 5 of 2020. https://www.difc.com/business/registrars-and-commissioners/commissioner-of-data-protection
- DIFC, enactment of DIFC Laws Amendment Law No. 1 of 2025, 16 July 2025 announcement (enacted 8 July 2025, in force 15 July 2025). https://www.difc.com/whats-on/news/difc-announces-enactment-of-amendments-to-select-difc-legislation-through-difc-law-amendment-law
- ADGM, ADGM enacts its new Data Protection Regulations 2021, 14 February 2021. https://www.adgm.com/media/announcements/adgm-enacts-its-new-data-protection-regulations-2021
- ADGM Office of Data Protection. https://www.adgm.com/operating-in-adgm/office-of-data-protection
Related whitepapers
Start with one decision.
If this paper describes the problem in front of you, the next step is a briefing with the architects.