GCC data residency for call centres: where call audio and transcripts can be stored

By Adnan Bassem — Founder, InfoDriven (Dubai). Building Arabic-first speech recognition for GCC call centers.Published June 10, 2026

ComplianceLast updated: June 10, 2026

Where can call recordings be stored, country by country?

Here is the practitioner's map as of mid-2026. Treat it as a planning baseline, not legal advice — executive regulations in several states are still evolving, and sector regulators override the general rule.

  • Saudi Arabia — PDPL (Royal Decree M/19 of 2021, amended by M/148 of 2023, SDAIA enforcement since 14 September 2024): cross-border transfer permitted to adequate jurisdictions (EU treated as adequate for most use cases) or with SDAIA-approved safeguards; in-Kingdom processing expected for SAMA-regulated sensitive workloads, health, and government/NCA-classified data
  • UAE onshore — federal PDPL (Federal Decree-Law 45 of 2021): transfers permitted with adequacy or contractual safeguards; health data under Federal Law No. 2 of 2019 generally must stay in-UAE; government procurement often mandates in-region processing
  • UAE DIFC — DP Law No. 5 of 2020 (GDPR-aligned): EU jurisdictions adequate in most cases; transfers elsewhere need appropriate safeguards
  • UAE ADGM — DP Regulations 2021: same pattern as DIFC — EU adequacy in most cases, safeguards otherwise
  • Qatar — Law No. 13 of 2016 on personal data privacy protection: transfer permitted subject to the law's protection requirements; financial-sector and government workloads commonly procure in-country or QFC-aligned arrangements — confirm current regulator guidance with counsel
  • Kuwait — no single comprehensive data-protection statute; CITRA's data-privacy regulatory framework governs telecom and cloud service providers, and conservative practice keeps regulated-sector data in-country or in approved clouds — counsel review recommended
  • Bahrain — Personal Data Protection Law (Law No. 30 of 2018, in force 2019): transfer permitted to jurisdictions deemed adequate or with authorisation/safeguards; Bahrain actively courts cloud hosting and is comparatively transfer-friendly
  • Oman — Personal Data Protection Law (Royal Decree 6/2022, with subsequent executive regulations): transfer permitted with conditions including consent and protection-level requirements — check the current executive-regulation detail with counsel

What transfer mechanisms actually work for KSA and UAE traffic?

The two largest markets carry most call-centre volume, so get these two right first. For Saudi controllers, the post-M/148 regime offers three workable routes: transfer to an adequate jurisdiction (the EU has been treated as adequate under the implementing regulations for most use cases), SDAIA-approved contractual safeguards, or explicit consent — with the first being the lowest-friction for ongoing operational flows like transcription. For UAE controllers, DIFC and ADGM both treat the EU as adequate in most cases, and the federal PDPL accepts contractual safeguards in a DPA.

In both countries the general rule has carve-outs that decide architecture: SAMA-regulated banking workloads and NCA-classified data in Saudi Arabia, health data under UAE Federal Law No. 2 of 2019, and government procurements in both. The mistake teams make is designing one residency answer for the whole call estate. Segment first — general support, regulated financial calls, health-adjacent calls, government contracts — then assign each segment a posture and a transfer mechanism. A record of processing activities that shows this segmentation is exactly what a SDAIA or UAE Data Office inquiry, or an enterprise procurement review, wants to see.

Why EU hosting plus GCC worker nodes is a workable pattern

The architecture CallScribe runs is worth describing because it generalises. All processing runs on private infrastructure hosted in Hetzner EU (Germany and Finland), with optional GCC-resident worker nodes connected via Tailscale — and no audio or transcripts are sent to US-based third-party APIs during transcription. That single design decision resolves three recurring objections at once.

First, EU hosting rides the adequacy rails: the EU is the jurisdiction GCC transfer regimes most consistently treat as acceptable, so the default posture needs only a DPA rather than bespoke approvals. Second, GCC-resident worker nodes mean that when a workload does require in-country processing — a SAMA bank, a UAE health provider, a government contract — the heavy compute can run on nodes physically in the Kingdom or the Emirates while the control plane stays consistent. Third, the absence of US third-party APIs in the transcription path removes the hardest question in GCC procurement reviews: "which foreign cloud AI service sees our customers' voices?" The answer "none" shortens security questionnaires considerably. Contrast this with per-minute US cloud ASR APIs, where audio transits US infrastructure by design — workable for some traffic, but a non-starter for the regulated segments.

When do you need in-country or on-premise processing?

Three triggers reliably push a workload out of the EU-default posture. Sector mandates: SAMA-regulated financial calls in Saudi Arabia, health data under UAE Federal Law No. 2 of 2019, and analogous health and banking rules emerging in the other states. Classification regimes: Saudi NDMO data-classification rules require certain government-handled personal data to remain in-Kingdom, and UAE federal or emirate-level deployments often procure G-Cloud or approved-cloud residency. Contractual requirements: BPO master service agreements increasingly pass through the end-client's residency obligations, so a Riyadh BPO serving a Saudi bank inherits the bank's in-Kingdom expectations regardless of the BPO's own preferences.

When a trigger fires, the options ladder is: GCC-resident worker nodes (processing in-country, managed service), in-country deployment via approved cloud partners (NCA-approved in KSA, G-Cloud/G42 patterns in the UAE), or full on-premise deployment in your own datacenter — CallScribe offers enterprise on-premise as a separate engagement for exactly these cases. Each rung costs more and moves slower than the one below it, so use the cheapest rung that satisfies the actual obligation rather than defaulting to on-premise out of caution.

Practical residency decisions for a GCC call-centre architecture

Pulling it together into a decision sequence: inventory your call categories and the countries whose residents appear on the calls; identify the controllers and their regimes (six states, plus DIFC and ADGM as separate regimes inside the UAE); segment categories into "general" (EU-default workable), "regulated" (in-country processing), and "uncertain" (counsel review); then choose a vendor architecture that can serve all three segments without splitting your tooling.

Two final practitioner notes. Backups and disaster-recovery copies count — a compliant primary region with backups replicating to a non-compliant one is a transfer, and it is the detail audits find. And residency is necessary but not sufficient: a recording stored in the right country with no access logging, no retention enforcement, and no deletion workflow still fails the data-protection laws that motivated the residency requirement in the first place. Where this article states the general rule for the smaller four states, confirm the current executive-regulation position with counsel before committing an architecture — Qatar, Kuwait, Bahrain, and Oman are all actively developing their enforcement practice.

Sources

  1. Saudi PDPL, Royal Decree M/19 of 1443H (2021), amended by Royal Decree M/148 of 1444H (2023); SDAIA implementing regulations (2023)
  2. UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
  3. DIFC Data Protection Law No. 5 of 2020; ADGM Data Protection Regulations 2021
  4. UAE Federal Law No. 2 of 2019 on the Use of ICT in Health Fields, Article 13 (in-UAE health-data storage)
  5. Qatar Law No. 13 of 2016 on the protection of personal data privacy
  6. Bahrain Personal Data Protection Law, Law No. 30 of 2018
  7. Oman Personal Data Protection Law, Royal Decree 6/2022
  8. Kuwait CITRA data-privacy regulatory framework for telecom and cloud providers
  9. CallScribe processing architecture: Hetzner EU hosting with optional GCC-resident worker nodes via Tailscale (callscribe.ae/llms.txt)

Frequently asked questions

Does any GCC country require all call recordings to stay in-country?

No GCC state imposes a blanket localisation rule for all call recordings. The mandates are sectoral: UAE health data under Federal Law No. 2 of 2019, Saudi NDMO-classified government data, SAMA expectations for sensitive banking workloads, and procurement-level requirements in government contracts. General commercial call traffic can usually move cross-border with the right transfer mechanism.

Is EU hosting acceptable for Saudi and UAE call-centre data?

For most general workloads, yes. The EU has been treated as adequate under the KSA PDPL implementing regulations for most use cases, and DIFC and ADGM treat EU jurisdictions as adequate in most cases, with the federal UAE PDPL accepting contractual safeguards. The exceptions are the regulated segments — SAMA-sensitive, health, government — which need in-country options.

Do transcripts have the same residency obligations as the audio?

Yes — a transcript identifying a caller is personal data with the same transfer rules as the recording it came from. Architecturally that means your transcription vendor's processing location matters as much as your recording platform's storage location, including any third-party APIs the vendor calls during transcription.

What about Qatar, Kuwait, Bahrain, and Oman specifically?

All four have data-protection frameworks — Qatar Law 13/2016, Bahrain Law 30/2018, Oman Royal Decree 6/2022, and Kuwait's CITRA regulatory framework — and all regulate cross-border transfer, with enforcement practice still maturing. For regulated-sector workloads in these states, get counsel review of the current executive regulations before committing an architecture; for general traffic, documented safeguards plus a DPA is the standard pattern.

Do backup copies and disaster-recovery replicas count as transfers?

Yes. A backup replicating to another jurisdiction is a cross-border transfer of the same personal data, and it is one of the most common audit findings. Map where every copy lives — primary, replica, backup, vendor sub-processor — and apply the transfer analysis to each.

Test it on your own Arabic calls

Dialect-aware transcription with diarization and sentiment — built for GCC call centers.

Try CallScribe free →

5 min/mo free · No credit card