Middle East
SAP Business One cloud hosting across the GCC and the wider Middle East.
- United Arab Emirates
- Saudi Arabia
- Qatar
- Bahrain
- Kuwait
- Oman
Support: 24/7 support in English and Arabic, with engineers in the Gulf time zone.
Overview
Our home market and where the company started, headquartered in Dubai. The Gulf has moved fast on data protection: the UAE, Saudi Arabia, Qatar, Bahrain and Oman all now have national privacy law, and the financial regulators layer their own cybersecurity frameworks on top. We deploy into in country cloud regions so residency is a design decision rather than a compromise.
Markets served
- United Arab Emirates
- Saudi Arabia
- Qatar
- Bahrain
- Kuwait
- Oman
- Jordan
- Egypt
- Lebanon
- Iraq
Data can be pinned to a single in country region (Dubai, Abu Dhabi, Doha, Riyadh or Bahrain), with backups and disaster recovery copies kept in country or in a region you nominate. Where a regulator requires primary data to stay onshore, we deploy so that it does, and we tell you in writing which components sit where.
Microsoft Azure
UAE & Qatar
AWS
UAE & Bahrain
Huawei Cloud
UAE, Saudi Arabia & Turkey
UAE Federal Decree Law No. 45 of 2021 (PDPL)
What it governs
The UAE's federal personal data protection law: lawful basis, data subject rights, breach notification and controls on cross border transfer.
How we support it
In country deployment in Azure UAE North/Central or AWS UAE, encryption in transit and at rest, access logging, and breach detection and notification support on the infrastructure we manage.
DIFC Data Protection Law No. 5 of 2020
What it governs
Applies to entities in the Dubai International Financial Centre. GDPR aligned, with its own transfer and accountability requirements.
How we support it
Residency options that keep data within an approved jurisdiction, plus the processing records, security documentation and audit evidence a DIFC entity needs from its processor.
ADGM Data Protection Regulations 2021
What it governs
The Abu Dhabi Global Market equivalent, again closely modelled on GDPR.
How we support it
Abu Dhabi regional deployment, documented technical and organisational measures, and processor side records of processing.
Saudi Personal Data Protection Law (SDAIA PDPL)
What it governs
Saudi Arabia's national privacy law and its implementing regulations, including conditions on transferring personal data outside the Kingdom.
How we support it
Deployment into Saudi cloud regions so personal data can remain in Kingdom, with transfer controls and documentation where a transfer is permitted and necessary.
Saudi NCA Essential Cybersecurity Controls (ECC)
What it governs
The National Cybersecurity Authority's baseline controls for organisations operating in Saudi Arabia.
How we support it
Infrastructure hardening, identity and access management, logging, vulnerability management and incident response aligned to the ECC control families we operate.
SAMA Cyber Security Framework
What it governs
The Saudi Central Bank's framework, mandatory for regulated financial institutions and their service providers.
How we support it
Third party assurance evidence, segregated environments, tested business continuity, and the monitoring and reporting a SAMA regulated customer must be able to demonstrate.
Qatar Law No. 13 of 2016 (PDPPL)
What it governs
Qatar's personal data privacy protection law, with breach notification duties.
How we support it
Azure Qatar Central deployment for in country residency, encryption, access control and breach notification support.
Bahrain Law No. 30 of 2018 (PDPL)
What it governs
Bahrain's personal data protection law, including restrictions on transfers abroad.
How we support it
AWS Middle East (Bahrain) deployment, documented safeguards and processor obligations recorded in the agreement.
Oman Royal Decree 6/2022 (PDPL)
What it governs
Oman's personal data protection law and its executive regulations.
How we support it
Regional deployment options, consent and rights handling support, and infrastructure side security controls.
Egypt Law No. 151 of 2020 and Jordan Law No. 24 of 2023
What it governs
The Egyptian and Jordanian personal data protection laws, both with licensing and transfer conditions.
How we support it
Deployment and transfer arrangements designed against the applicable conditions, with documentation you can put in front of a regulator.
| Regulation | What it governs | How we support it |
|---|---|---|
| UAE Federal Decree Law No. 45 of 2021 (PDPL) | The UAE's federal personal data protection law: lawful basis, data subject rights, breach notification and controls on cross border transfer. | In country deployment in Azure UAE North/Central or AWS UAE, encryption in transit and at rest, access logging, and breach detection and notification support on the infrastructure we manage. |
| DIFC Data Protection Law No. 5 of 2020 | Applies to entities in the Dubai International Financial Centre. GDPR aligned, with its own transfer and accountability requirements. | Residency options that keep data within an approved jurisdiction, plus the processing records, security documentation and audit evidence a DIFC entity needs from its processor. |
| ADGM Data Protection Regulations 2021 | The Abu Dhabi Global Market equivalent, again closely modelled on GDPR. | Abu Dhabi regional deployment, documented technical and organisational measures, and processor side records of processing. |
| Saudi Personal Data Protection Law (SDAIA PDPL) | Saudi Arabia's national privacy law and its implementing regulations, including conditions on transferring personal data outside the Kingdom. | Deployment into Saudi cloud regions so personal data can remain in Kingdom, with transfer controls and documentation where a transfer is permitted and necessary. |
| Saudi NCA Essential Cybersecurity Controls (ECC) | The National Cybersecurity Authority's baseline controls for organisations operating in Saudi Arabia. | Infrastructure hardening, identity and access management, logging, vulnerability management and incident response aligned to the ECC control families we operate. |
| SAMA Cyber Security Framework | The Saudi Central Bank's framework, mandatory for regulated financial institutions and their service providers. | Third party assurance evidence, segregated environments, tested business continuity, and the monitoring and reporting a SAMA regulated customer must be able to demonstrate. |
| Qatar Law No. 13 of 2016 (PDPPL) | Qatar's personal data privacy protection law, with breach notification duties. | Azure Qatar Central deployment for in country residency, encryption, access control and breach notification support. |
| Bahrain Law No. 30 of 2018 (PDPL) | Bahrain's personal data protection law, including restrictions on transfers abroad. | AWS Middle East (Bahrain) deployment, documented safeguards and processor obligations recorded in the agreement. |
| Oman Royal Decree 6/2022 (PDPL) | Oman's personal data protection law and its executive regulations. | Regional deployment options, consent and rights handling support, and infrastructure side security controls. |
| Egypt Law No. 151 of 2020 and Jordan Law No. 24 of 2023 | The Egyptian and Jordanian personal data protection laws, both with licensing and transfer conditions. | Deployment and transfer arrangements designed against the applicable conditions, with documentation you can put in front of a regulator. |
Compliance is shared between provider and customer. We provide the infrastructure controls, evidence and documentation on our side of that line: residency, encryption, access control, backup, monitoring and incident response. Your obligations as data controller remain yours. This page is general information, not legal advice; confirm your specific obligations with your own counsel.
Services available here
Move to the cloud, the right way.
Let's talk about your SAP environment, your security and your growth plan. Migration with minimal disruption is what we do.
Common questions
Can our data stay inside the UAE?
Yes. We deploy in Azure UAE North (Dubai), Azure UAE Central (Abu Dhabi), or AWS Middle East (UAE), with the option to keep backups and disaster recovery copies in country as well. We also document which components are hosted in each region.
Can you host SAP Business One inside Saudi Arabia?
Yes. We host SAP Business One on Huawei Cloud infrastructure in Saudi Arabia, enabling customer data and personal data to remain in the Kingdom in line with applicable local data residency requirements, including the SDAIA PDPL. For SAMA regulated customers, we also provide the relevant third party assurance evidence required by the regulator for service providers.
Is Arabic support available?
Yes. Support runs 24/7 in English and Arabic, from engineers in the Gulf time zone rather than a follow the sun desk that hands your ticket on at midnight.
Which regulations apply if we operate in a UAE free zone?
DIFC and ADGM entities fall under their own GDPR aligned data protection regimes rather than the federal PDPL. Both are covered in the table above, and the practical difference is mostly in transfer conditions and accountability records, which we provide either way.