Cloud regions and data residency by market — Morocco, MENA and Europe
Where a workload physically runs decides which law applies to it. This page lists the AWS, Azure, Google Cloud and Oracle regions available per market, and what the local regime requires — including the markets where the honest answer is that no in-country region exists.
Reviewed
The Morocco answer, plainly
Morocco has one in-country hyperscaler region: OCI af-casablanca-1. Everything else runs from Europe — most commonly eu-west-3, eu-south-2, francecentral — which is a genuine trade-off rather than a detail, because Law 05-20 on cybersecurity and its implementing decrees require operators of vital infrastructure to host sensitive data and critical information systems on Moroccan territory (Bank Al-Maghrib treats credit institutions as vital operators), and separately Article 43 of Law 09-08 requires prior CNDP authorisation for any transfer of personal data to a country the CNDP has not recognised as offering adequate protection.
In practice regulated Moroccan buyers pair a local or sovereign host with a European region rather than choosing one or the other. The French-language detail lives on Souveraineté des données; the legal text is summarised at Loi 09-08.
Regions by market
Region codes only. We do not publish latency figures: nothing here measures round-trip time, and it depends on your carrier and peering rather than on distance.
| Market | AWS | Azure | Google Cloud | Oracle | In country? | Applicable regime |
|---|---|---|---|---|---|---|
| Morocco | eu-west-3 eu-south-2 | francecentral spaincentral | europe-southwest1 | af-casablanca-1 | Yes | CNDP |
| Algeria | eu-west-3 eu-south-1 | France Central | europe-west9 | — | No | ANPDP |
| Austria | eu-central-1 | austriaeast | europe-west3 | eu-frankfurt-1 | Yes | DSB |
| Bahrain | me-south-1 | — | — | — | Yes | PDPA |
| Belgium | — | belgiumcentral | europe-west1 | — | Yes | GBA / APD |
| Canada | ca-central-1 ca-west-1 | canadacentral canadaeast | northamerica-northeast1 northamerica-northeast2 | ca-toronto-1 ca-montreal-1 | Yes | OPC |
| Egypt | me-south-1 me-central-1 eu-south-1 | UAE North | me-central1 | — | No | PDPC |
| France | eu-west-3 | francecentral francesouth | europe-west9 | eu-paris-1 eu-marseille-1 | Yes | CNIL |
| Germany | eu-central-1 eusc-de-east-1 | germanywestcentral germanynorth | europe-west3 europe-west10 | eu-frankfurt-1 | Yes | BfDI |
| Ireland | eu-west-1 | northeurope | europe-west2 europe-west1 | — | Yes | DPC |
| Italy | eu-south-1 | italynorth | europe-west8 europe-west12 | eu-milan-1 | Yes | Garante |
| Jordan | me-south-1 me-central-1 | UAE North Qatar Central | — | — | No | Ministry of Digital Economy and Entrepreneurship (personal data protection unit), overseen by the Personal Data Protection Council chaired by the Minister of Digital Economy and Entrepreneurship |
| Kuwait | me-central-1 me-south-1 | uaenorth | me-central2 | — | No | CITRA |
| Netherlands | — | westeurope | europe-west4 | eu-amsterdam-1 | Yes | AP |
| Oman | me-central-1 me-south-1 | uaenorth | me-central2 | — | No | MTCIT |
| Poland | eu-central-1 | polandcentral | europe-central2 | eu-frankfurt-1 | Yes | PUODO (office: UODO) |
| Portugal | eu-south-2 eu-west-1 | spaincentral | europe-southwest1 | eu-madrid-1 | No | CNPD |
| Qatar | — | qatarcentral | me-central1 | — | Yes | NCSA |
| Saudi Arabia | — | — | me-central2 | me-riyadh-1 me-jeddah-1 | Yes | SDAIA |
| Spain | eu-south-2 | spaincentral | europe-southwest1 | eu-madrid-1 | Yes | AEPD |
| Sweden | eu-north-1 | swedencentral swedensouth | europe-north2 | eu-stockholm-1 | Yes | IMY |
| Switzerland | eu-central-2 | switzerlandnorth switzerlandwest | europe-west6 | eu-zurich-1 | Yes | EDÖB (FDPIC) |
| Tunisia | eu-south-1 eu-west-3 | France Central | europe-west9 | — | No | INPDP |
| United Arab Emirates | me-central-1 | uaenorth uaecentral | — | me-dubai-1 me-abudhabi-1 | Yes | Federal Authority for Artificial Intelligence and Data |
| United Kingdom | eu-west-2 | uksouth ukwest | europe-west2 | uk-london-1 uk-cardiff-1 | Yes | ICO |
| United States | us-east-1 us-east-2 us-west-1 us-west-2 us-gov-west-1 us-gov-east-1 | eastus eastus2 centralus southcentralus westus2 westus3 usgovvirginia usgovarizona | us-central1 us-east1 us-east4 us-west1 us-west2 us-south1 | us-ashburn-1 us-phoenix-1 us-chicago-1 us-sanjose-1 | Yes | No national data protection authority. Enforcement is distributed: the Federal Trade Commission under Section 5 (unfair or deceptive practices), the HHS Office for Civil Rights for HIPAA, state attorneys general for state privacy statutes, and the California Privacy Protection Agency — the only dedicated state privacy regulator. |
What residency actually requires
“Data residency” is used loosely to mean three different obligations, and only one of them is about geography. The first is a genuine localisation rule: certain data must sit on servers inside the country, full stop. Morocco applies this to operators of vital infrastructure under Law 05-20, and the UAE applies it to health data generated in-country.
The second is a transfer condition. The data may leave, but only under a legal mechanism — an adequacy finding, contractual safeguards, or a regulator’s prior authorisation. Article 43 of Morocco’s Law 09-08 works this way, as does Chapter V of the GDPR across Europe.
The third is a sectoral hosting condition that has nothing to do with borders: France requires health data to sit with an HDS-certified host, and Germany’s BSI C5 attestation is routinely demanded of cloud providers serving regulated buyers. A provider can satisfy all three at once, or fail one while meeting the others — which is why “we host in the EU” is not by itself an answer to a compliance question.
The practical consequence for architecture is that the region decision is usually made per workload rather than per company. Read the per-market detail on Morocco, the Middle East or Europe, or the legal summaries at GDPR.