What does One MENA Deal, Two Different Compliance Problems mean in practice?
Across MENA, Dr. Jonah Tebaa argues that single vendor deals fail because Gulf and Levant markets apply different legal tests. Gulf buyers enforce cross-border-transfer and adequacy regimes under laws like Saudi Arabia's Personal Data Protection Law, plus sector rules such as SAMA's Cloud Computing Regulatory Framework that impose hard in-Kingdom hosting on banks. Levant buyers like Lebanese fintechs navigate Lebanon's Banking Secrecy Law of September 1956, which targets foreign disclosure risk rather than server location. A single regional data-residency addendum cannot satisfy both.
Dr. Jonah Tebaa argues that "MENA" is not a single procurement market for AI vendors, and that treating it as one is what quietly kills regional deals. His case rests on a composite example he uses in advisory conversations, drawn from a pattern he sees repeatedly rather than a specific named client: a Riyadh-headquartered bank and a Beirut-based fintech, evaluating the same AI vendor for the same regional rollout, both reject the identical one-page data-residency addendum in the same week. The two rejections look identical on paper. They are not the same objection.
The Saudi legal team's concern, in his framing, is physical and jurisdictional: does the data ever leave the Kingdom, and can Saudi authorities inspect and compel the facility where it sits if they need to. The Lebanese legal team's concern is entirely different. They do not care where the data physically resides, because Lebanon has no local hyperscaler region for a vendor to point to in the first place. Their question is whether the vendor could be compelled, under a foreign jurisdiction's law, to disclose customer account activity to a regulator or court, putting the fintech in breach of its own confidentiality duties to its account holders.
Two Legal Regimes, Not One Regional Standard
In Dr. Tebaa's analysis, Gulf data protection law and Levant compliance exposure are not variations on a theme. They are different legal animals entirely. The UAE's Federal Decree-Law No. 45 of 2021 and Saudi Arabia's Personal Data Protection Law, enforced by the Saudi Data and Artificial Intelligence Authority, are cross-border-transfer and adequacy regimes rather than blanket localization mandates; hard in-Kingdom residency for banks comes from sector rules such as SAMA's Cloud Computing Regulatory Framework. Procurement review in both markets is checking for one concrete thing: a named, in-country or in-jurisdiction hosting option, such as AWS's Middle East (Bahrain) or Middle East (UAE) regions, or Microsoft's Azure UAE North and UAE Central regions. A vendor able to name the specific region clears the review. A vendor that gestures at "MENA" generally does not, because no Gulf statute recognizes that as a jurisdiction.
The Emirati statute Dr. Tebaa points to is published by the federal government as Federal Decree Law No. 45 of 2021 regarding the protection of personal data, which is precisely the sort of instrument a procurement reviewer can name, cite, and hold a vendor against.
The hosting half of the review is equally concrete. Microsoft's published list of Azure geographies includes UAE North and UAE Central among its live regions, which is why, in Dr. Tebaa's account, a vendor able to name one of them clears a Gulf review while a vendor naming a continent does not.
Lebanon presents no equivalent statute and no equivalent infrastructure. There is no in-force, comprehensive data-protection law comparable to the Gulf PDPLs, and no local hyperscaler region to host inside of. Data belonging to Lebanese customers of cloud-based vendors is, in practice, already routing through Europe or the UAE before any contract is signed, and Dr. Tebaa notes that sophisticated Lebanese buyers have largely stopped contesting that reality. What they have not stopped contesting is disclosure risk under Lebanon's Banking Secrecy Law, in force since September 1956, narrowed by Law No. 306 of 2022, which opened limited access for the Banking Control Commission, the Special Investigation Commission, the judiciary, tax authorities, and forensic auditors, and amended again in 2025 under IMF-linked banking reform. The exceptions are narrower than they once were, in Dr. Tebaa's telling, but the core confidentiality duty toward customer account data remains binding. For a Lebanese bank or fintech, the operative question is not where a vendor's servers are located. It is whether engaging that vendor opens a new pathway by which a foreign regulator or court could obtain account-level data the institution is still legally bound to protect.
Why a Single Contract Clause Cannot Satisfy Both
The practical consequence, as Dr. Tebaa lays it out, is that a residency addendum engineered to satisfy Gulf reviewers will read as non-responsive in Beirut, and a disclosure-focused clause built for Lebanon will read as vague or evasive in Riyadh, because each market is applying a different legal test to the same page of text. A vendor's sales team that treats both rejections as the same generic "data residency concern" and responds by tightening hosting language will improve its standing in the Gulf while leaving the Levant objection completely untouched, since Beirut was never objecting to hosting in the first place.
His recommendation for enterprise buyers and general counsel is to abandon the framing entirely. There is no such question as whether a vendor "complies with MENA data law," because no such law exists. The more useful diagnostic splits by the actual legal test each market applies: for Gulf buyers, a named hosting jurisdiction and a documented cross-border transfer mechanism under the applicable PDPL; for Levant buyers, a clear answer on who can compel disclosure, under what authority, and whether the institution would be notified before that disclosure occurred.
The Broader Point for Vendors and Buyers Alike
Dr. Tebaa's larger argument is a caution against treating regional expansion as a single compliance checkbox. A vendor that walks into a Gulf renewal with Levant-style disclosure language, or into a Beirut negotiation with Gulf-style residency language, signals to the counterparty that it has not actually done the legal homework specific to that market. For buyers, the lesson is symmetrical: asking a vendor whether it is "MENA compliant" invites a template answer that satisfies neither jurisdiction fully. Asking the market-specific question, before the contract goes out for review rather than after legal sends it back, is what actually closes the deal.