
What happens when compliance keeps your data safe but your business offline? The 2026 attacks on AWS data centres in Bahrain and the UAE highlighted the challenges of balancing regulatory compliance with maintaining uptime. Data residency laws in the UAE, Saudi Arabia, and Bahrain require sensitive information to remain within national borders. When local cloud facilities were attacked and went offline, organisations that stored and backed up all their data strictly in-country found themselves unable to access it.
The main takeaway is that not all data should be treated the same. Some information, like patient records or financial ledgers, is legally bound to stay within the region and requires full in-country backup and disaster recovery. Other data, such as logs or analytics, can be moved across borders if it is strongly encrypted. However, simply moving data overseas during a crisis can create cascading problems, like triggering new compliance checks instead of fixing the outage. To avoid this, organisations should decide in advance which data can cross borders, where backups can be stored, and how failover will work within legal limits before a disruption occurs.
In geopolitically sensitive regions, compliance keeps data safe, but only a resilient architecture ensures uptime.
What if data laws forbid failover?
Imagine a healthcare provider in the UAE storing patient records in a local cloud region to comply with residency laws. If that regional data centre goes offline during a major outage, the company cannot immediately transfer those records to an overseas environment, as patient data is legally required to remain within approved jurisdictions. Teams are then forced to find temporary workarounds, such as relying on limited local backups or manually restoring critical systems, while legal teams review which data can and cannot be moved. During this delay, appointment systems, internal operations, and customer services may slow down. This will affect revenue and customer trust.
Why multi-availability zone setups aren’t enough anymore
In the past, cloud resilience meant handling isolated problems like power outages, server crashes, or rack failures. To address these, cloud providers introduced multi-availability zone (multi-AZ) setups spreading workloads across several data centres within the same region. However, during catastrophic events caused by geopolitical conflict, large-scale infrastructure disruption, or natural disasters, all AZs in a region can fail at once.
In such high-risk environments, resilience means looking beyond a single region. A multi-region data centre setup spreads workloads across different cloud regions, such as the UAE and another international region. In an active-active setup, the application runs in both regions simultaneously, with each handling live user traffic. In an active-passive model, the application runs in one region, while the second region is kept ready as a backup for immediate deployment during an emergency.
Global DNS and traffic management services can automatically reroute users. If one region goes offline, data is continuously copied between regions to keep both up to date. This way, users remain online even if a whole country’s cloud infrastructure fails.
A simple way to plan resilience is to separate workloads into three categories:
Designing a compliant and flexible architecture
In the Gulf, resilience is also about keeping systems running while staying compliant. Services that must stay in-country should run on local data centres, either on-premise or in accredited local facilities. Less sensitive workloads can use global cloud environments if they're encrypted.
Regulatory nuances also matter. Cross-border data movement is governed differently across Gulf countries: some jurisdictions restrict unapproved transfers, while others permit them when specific safeguards are in place. These differences should shape which data centre is chosen and how backups are planned.
"Cloud resilience is no longer measured by where your data resides, but by how well your organisation can recover while remaining compliant. The goal is to build an architecture that protects both operations and trust."
- Premanand Velumani, Associate Director, Strategic Growth, MEA.
Three controls hold steady across the region:
Backups should also only be stored only in approved jurisdictions.
Data must be encrypted in transit and at rest.
Cross-border data movement should be formally governed through contracts.
Dubimed, a UAE-based medical supplies distributor, is one example of a regional business running its operations on locally hosted cloud infrastructure. "Our sales team needs a clear vision of their activities. Zoho CRM provided us with the proper deals, modules, and a mobile app so we can follow up on these deals," says Omar Fouad, Digital Development Lead at Dubimed. CEO Safi Rajab adds, "Zoho gives me the possibility to expand and modify the modules by myself, easy."
A resilience framework for Gulf enterprises
Create a clear disaster recovery (DR) plan that covers every angle:
How regionally hosted platforms reduce exposure
Major cloud providers now offer services in the Gulf. Zoho, for instance, operates its own data centres across several countries to meet regional data protection requirements. In the Middle East, it has facilities in Dubai and Abu Dhabi in the UAE and in Riyadh and Jeddah in Saudi Arabia. This regional infrastructure enables organisations to meet data residency requirements, with primary and secondary data centres in the same country providing protection against single-site failure.
But no setup is perfect. A local data centre is at risk if the whole country runs into trouble. A multi-region setup costs more and can slow things down for users. Regulations make things harder too. Businesses are often unsure if their backups must stay in the country, and getting it wrong can mean fines or rework. Businesses can avoid this by setting clear policies on what data can move, where it can be stored, and which systems need to run in more than one region.
The practical answer for most Gulf organisations is to pick a provider whose regional setup matches local compliance needs without forcing a complex multi-region build of their own. Zoho fits this model. In the UAE, customer data sits in the Dubai data centre with Abu Dhabi as a secondary site. In Saudi Arabia, Riyadh is the primary with Jeddah as secondary. Data stays within the country in both cases, which keeps organisations aligned with national residency rules. If the primary site goes down, the secondary holds the data safely. Customers who need broader disaster recovery beyond this can layer in their own on-premise backup or a secondary tool, within the limits set by local rules.
FAQs
Can I legally transfer data abroad?
Cross-border transfer rules vary across the region. Some Gulf countries require approval before data leaves national borders, while others permit transfers to destinations that provide adequate data protection safeguards. The safest approach is to keep legally restricted data in-country and, where cross-border transfers are allowed, ensure they are covered by strong encryption and clear contractual safeguards.
How do I test my disaster recovery plan?
Test your plan as if a real crisis is unfolding. Regularly simulate a full-region outage and run your failover process from start to finish. Measure how long recovery time is, validate data integrity, and review decisions made under pressure. Use your learnings to updated your process playbook and improve response times. Remember: a disaster recovery plan that hasn't been tested is only theoretical.
Is a multi-availability zone (multi-AZ) deployment enough?
Multi-AZ setups protect against localised failures within a single region, such as power or hardware issues. However, they do not protect against large-scale regional disruptions caused by geopolitical conflict or natural disasters. In high-risk environments, multi-region deployment is often necessary.
Does Zoho support data residency in the Middle East?
Yes. Zoho operates regional data centres in the UAE (Dubai and Abu Dhabi) and in Saudi Arabia (Riyadh and Jeddah), allowing organisations to host data locally in line with national residency requirements.
Can Zoho support a hybrid or multi-region resilience strategy?
Each Zoho customer account is hosted in one country, with a primary and secondary data centre inside that country. For UAE customers, data sits in Dubai and is mirrored to Abu Dhabi. For Saudi customers, it sits in Riyadh and is mirrored to Jeddah. Data does not move between countries, which keeps organisations within residency rules by design. Customers looking for broader cross-region disaster recovery can layer in on-premise backup or a secondary tool, where local rules permit.