
rewrite this content and keep HTML tags as is:
- Resilience a priority after AWS outage
- Overseas laws hinder data transfers
- Focus on using multiple jurisdictions
Amazon Web Services’s disclosure in September that it was unable to restore access to cloud data stored in facilities damaged by conflict has been a “hard lesson” for Gulf businesses, lawyers have told AGBI.
The incident in Bahrain and the UAE has prompted companies to strengthen their data policies. But efforts to protect critical information by storing copies overseas can clash with regional data protection and localisation rules.
“We’re seeing greater attention paid to data resilience and where data and back-up copies are held,” said Rob Flaws, partner and head of Mena tech and innovation at Mishcon de Reya.
“The disclosures are likely to accelerate those conversations, particularly among businesses that depend on continuous access to critical data.”
Companies looking to expand back-ups in other regions or move data out of the jurisdiction would be subject to local laws that protect sensitive information.
For many organisations, transferring data – or maintaining a secondary back-up in an overseas market – is legally viable, but for others, it is not.
Can Gulf companies simply transfer data out of the region?
The short answer is no. While cross-border data transfers are generally permitted in GCC jurisdictions, including the largest markets of Saudi Arabia and the UAE, they are subject to laws ensuring personal data remains protected after it leaves the country, said Sara Paradisi, partner at Rosenblatt Law.
In the UAE, these are the Federal Personal Data Protection Law 2021 and separate legislation governing the DIFC or ADGM offshore zones. In Saudi Arabia, it is the Personal Data Protection Law 2023 or the Saudi Data and AI Authority’s Transfer Regulations 2023.
They stipulate that transfers can take place “where the destination provides an appropriate level of protection, or where specified safeguards apply,” Flaws said.
The DIFC and ADGM regimes recognise a list of “adequate” jurisdictions, including the EU and the UK, with robust data protection laws. They also provide for safeguards, such as contractual clauses for destinations not on the list. But the onshore laws do not.
“Companies cannot assume a crisis automatically provides a legal basis for unrestricted international data transfers,” Paradisi said.
Are some sectors more restricted than others?
Financial services, healthcare, government entities, telecoms, internet of things (IoT) and critical infrastructure operators face heightened obligations regarding data storage and access because they hold sensitive national or personal information.
“They may have less flexibility to move data abroad quickly,” Paradisi said.
Data localisation requirements are “quite rigid”, said a partner at another international law firm in the UAE who chose not to be named.
“However, the attacks on data centres led to serious operational difficulties, so we saw authorities ready to discuss emergency back-up options elsewhere,” they added.
What are the rules around data back-ups overseas?
Technically there may be a difference between migrating data systems to other jurisdictions and creating contingency back-ups, but from a legal perspective the same rules apply. “A back-up stored abroad may constitute a cross-border transfer of personal data,” Paradisi said.
Companies considering back-up infrastructure should assess whether it complies with relevant laws.
There are penalties if not – in the UAE ranging from AED50,000 to AED5 million ($13,600 to $1.36 million) and/or criminal penalties under the Cybercrime Law, Carlos Rahme, senior consultant at Kayrouz & Associates, wrote earlier this year.
What are the best strategies for increasing data resilience?
Organisations should conduct a comprehensive review of data classification, storage and disaster recovery, then build a back-up strategy around the legal and operational requirements of each dataset, Flaws said.
Depending on the regulatory framework, that could mean maintaining a secondary copy in another jurisdiction, using geographically separate data centres within the same country or adopting a multicloud or hybrid approach.
“I expect the focus to be less on finding one ‘safe’ jurisdiction and more on building resilience across multiple jurisdictions,” he said.
How else should companies respond?
They could examine their cloud contracts. Under the shared responsibility model, replicating data to a second region or provider is the customer’s responsibility unless stated otherwise, Flaws said.
Companies must ensure their legal, compliance, cybersecurity, procurement, operational and risk teams work together. “Resilience cannot be treated as purely a technology issue,” Paradisi said.
Data protection laws are well established and exist for good reasons. The AWS disclosures are not an argument against hosting data in the Gulf, Flaws said. “They are an argument for designing resilience into the compliance architecture from day one.”
