Most cloud strategy advice is written for a world where you can put data anywhere you like. In Saudi Arabia, that assumption falls apart on day one. Get the order of decisions wrong here and you can find yourself re-architecting a system you’ve already built.
Start with the data, not the provider.
Saudi regulation constrains where certain data can live and be processed. PDPL, sector rules from SAMA and the NCA, and government data-classification requirements all weigh in. So the right first question isn’t “AWS, Azure, Google, or Oracle?” It’s “what data do we hold, how is it classified, and where is it legally allowed to live?” The big providers now run local regions inside the Kingdom precisely because this matters: the Saudi cloud market is growing fast (research-firm estimates put it around $5bn in 2025 heading toward roughly $14bn by 2030), and the hyperscalers have stood up in-Kingdom regions specifically for data residency (MarketsandMarkets). Designing as if they don’t is a costly mistake.
Classify before you migrate.
Not all data carries the same weight. Sweeping everything into the strictest bucket is wasteful. Treating regulated data casually is dangerous. A clear classification, say public, internal, confidential, regulated, tells you what can go to a global region, what has to stay in-Kingdom, and what needs sovereign-grade controls. Picture the decision flowing out of the data itself, not out of a logo you picked first.
flowchart TD
A(["Start with the data, not the provider"]) --> B{"How is this data classified?"}
B -->|"Public or internal"| C(["A global region is fine"])
B -->|"Confidential"| D{"Does a regulator require residency?"}
D -->|"No"| C
D -->|"Yes"| E(["Keep it in-Kingdom"])
B -->|"Regulated"| E
Then pick an architecture that fits the constraints.
- In-Kingdom regions for regulated and sensitive workloads where residency is mandatory. Sovereign cloud isn’t a niche Saudi concern, either: Gartner forecasts worldwide sovereign cloud IaaS spending will total around $80bn in 2026 (Gartner), so the tooling and patterns are maturing quickly.
- Hybrid where some systems have to stay on-premise or in a local data centre while others move to public cloud.
- Multi-cloud only where it genuinely lowers risk. It adds real operational complexity, so don’t reach for it just to avoid lock-in on paper.
Don’t forget the boring operational reality.
Cloud isn’t automatically cheaper, and un-governed cloud spend grows fast. You need cost controls, a security posture lined up with NCA expectations, and the in-house skills, or a partner, to actually run it. And the migration itself should be incremental and reversible, not one high-stakes cutover you can’t walk back.
The organizations that get this right treat cloud as a series of deliberate, compliance-aware decisions. Not a default destination everything gets shoved toward.
Planning a cloud migration in the Kingdom? SDCG designs cloud strategies that start with data residency and Saudi regulatory reality. We’re vendor-neutral across AWS, Azure, Google, and Oracle, because we don’t resell any of them and earn nothing on what you choose. Book a free 30-minute review.
Sources
- MarketsandMarkets, Saudi Arabia cloud computing market
- Gartner, worldwide sovereign cloud IaaS spending to total $80 billion in 2026