Key facts
| Qatar context | Qatar PDPPL (Law No. 13 of 2016) is the personal data baseline; NCSA issues security guidance |
| Data plane | GCC region-locked plane (me-central-1, UAE); EU, APAC, US planes available |
| Deployment models | In-region cloud, private endpoint in your VPC, on-prem, air-gapped |
| Identity and access | SAML 2.0 / OIDC SSO, SCIM, workspace/role/resource RBAC on Enterprise |
| Key custody | BYOK via AWS KMS, Azure Key Vault, HashiCorp Vault or on-prem HSM |
| Audit | Audit log export to SIEM; region-locked log storage |
| Compliance posture | SOC 2 Type II and ISO 27001 readiness in progress (not yet certified); GDPR and PDPL alignment |
| SLA | 99.9% uptime on paid plans; Enterprise 4-hour support SLA — see /legal/sla |
TL;DR
- Map every store — inference, embeddings, logs, backups — to a region before signing.
- List subprocessors and upstream model providers with locations; require change notification.
- Verify failover keeps traffic in-jurisdiction rather than routing to a default global pair.
- Define deletion and export procedures, then test them during the pilot.
- Align the DPA with PDPPL obligations and any QFC or sector-specific rules.
How it works, step by step
- Identify the regulator and regime for each workload, including QFC and sector rules.
- Request the store-by-store residency map and a network diagram from the vendor.
- Cross-check the subprocessor list against the map and flag out-of-region dependencies.
- Ask how failover and disaster recovery preserve regional commitments.
- Review DPA terms: breach notification, audit rights, deletion, transfer mechanisms.
- Run a pilot with test data and verify configuration, audit export and deletion.
- File the evidence pack and schedule an annual review.
Original data
Try it yourself
Open the AI data residency checklist →
Checklist part one: architecture
- Is the inference endpoint in the selected region, and is that enforced by configuration you can export?
- Where are embeddings and vector indexes stored?
- Do audit and application logs stay in-region, or replicate to a central stack?
- Are backups encrypted and region-locked?
- Is there any path — model routing, moderation, analytics — to an out-of-region service?
Plugsky's region selection applies to the workspace data plane; validate each item against your chosen tier, since on-prem shifts the answer entirely. Assign an owner and a review date for each item, or the checklist becomes a document instead of a control.
Checklist part two: governance
Residency is one control among several. Confirm how the vendor supports PDPPL obligations: data subject access and deletion, consent records where applicable, retention limits, breach notification, and security measures. Review the DPA, subprocessor list and audit-export capabilities. Your own governance then decides where AI may be used, what may be processed, and who approves exceptions.
Checklist part three: operations
Operational items decide whether commitments survive reality. Ask for the failover runbook, the deletion runbook, escalation paths and the support SLA. Plugsky publishes a 4-hour Enterprise support SLA and a legal SLA with uptime commitments at /legal/sla. Test the escalation path during the pilot — it is easier to repair a process than a contract. Record the outcome and revisit the checklist annually.
Common pitfalls
- Accepting a global endpoint with regional pricing.
- Forgetting model upstreams in subprocessor mapping.
- No deletion path for embeddings created during evaluation.
- Assuming failover is region-safe without seeing the design.
- Treating the DPA as a substitute for architectural evidence.
Honest comparison
| Capability | Plugsky | Hyperscaler AI platform | Building in-house |
|---|---|---|---|
| Qatar-adjacent residency | GCC region-locked plane | Regional services for some products | Your data centre |
| Deployment range | Cloud, VPC, on-prem, air-gapped | Shared cloud with dedicated options | You own the stack |
| Subprocessor transparency | Published list with change notification | Per-service subprocessor pages | You vet every supplier |
| Identity controls | SSO/SCIM and RBAC on Enterprise | Mature IAM integration | You build it |
| Audit export | SIEM connectors | Native cloud audit | Custom |
| Certifications | SOC 2 / ISO 27001 readiness in progress | Completed audits in many regions | Your own programme |
Frequently asked questions
Which Qatar law applies to AI data processing?
The PDPPL (Law No. 13 of 2016) is the baseline, with NCSA guidance and QFC rules in the financial centre. Confirm your specific obligations with Qatari counsel.
Does Plugsky host in Qatar?
Plugsky provides a GCC region-locked plane. Ask the enterprise team for the current facility mapping before relying on a specific in-country location.
What evidence proves residency?
A configuration export for the selected region, a store map, sample audit events, and written failover behavior. Combine them with the DPA.
How do we handle cross-border transfers?
Document the data categories, destination regions and legal mechanism. The vendor supplies the architecture facts; legal sufficiency is your counsel's assessment.
Can sensitive workloads run on-prem?
Yes — on-prem and air-gapped tiers run open-weight models behind your firewall with the same OpenAI-compatible API.
What support is included on Enterprise?
Enterprise includes a named engineer and a 4-hour support SLA; uptime commitments and credits are documented at /legal/sla.
How does billing work for private deployments?
Private deployments are quoted per engagement. See the live pricing page for self-serve plans and contact the enterprise team for a scoped proposal.