Presented byRegister now

Advertise with us

Fintech

Why Smart Payment Companies in MENA Build Locally

Data residency, not features or pricing, now decides which payment companies win in MENA.

Karim El-Sayed·08 Sept 2026·3 min read
K

Karim El-Sayed Karim El-Sayed covers company news, policy and regulation across the UAE and wider MENA for Anecdoted, with a focus on how new rules and licences reshape how startups operate. karim@anecdoted.com

Why Smart Payment Companies in MENA Build Locally

Companies entering Middle East payments can usually settle pricing, confirm merchant demand, and line up an acquirer. Then someone asks where transaction data will physically live, and the timeline changes. Geography now outweighs features in MENA payment expansion.

Regulators across the Gulf and North Africa have settled on a single principle: payment data belongs inside the country that produced it. The Qatar Central Bank forbids licensed payment service providers from processing or storing data abroad, including offshore clouds. Saudi Arabia's SAMA rules and Personal Data Protection Law require domestic processing of Saudi personal data. The UAE and Egypt have frameworks pointing the same direction.

The boom behind the rules is real. Electronic payments hit 85% of Saudi retail payments in 2025, up from 79% a year earlier, across 14.6 billion transactions. Qatar's electronic payment value reached QR106.8 billion in July 2026, a 40% year-on-year jump, with Fawran doubling in value over twelve months. The MENA digital payment market is projected to grow from about $275 billion in 2026 to $462 billion by 2031.

A well-funded company's first instinct is to build from scratch. A native build typically takes two to three years before a single live transaction, before acquirer onboarding and PCI DSS certification. In a market growing at 40% a year, that means arriving late. The alternative is a white-label platform deployed under your own brand and in your own environment.

Two Akurateco clients show how deployment models matter in practice. TESS Payments, a Qatar PSP serving Doha Bank, QNB, Qatar Development Bank, and Qatar Fintech Hub, needed technical capability to secure a QCB license, but needed a license to justify local infrastructure. It launched on Akurateco's SaaS platform, used that to support licensing and PCI DSS, then migrated to dedicated on-premises infrastructure on Microsoft Azure inside Qatar. Transactions were synchronised across both environments, so merchants saw no disruption.

The routing is local as well. Apple Pay and Google Pay cards flow through NAPS/QPay to QMP and Fawran. International cards go through CyberSource and Mastercard Payment Gateway Services into Doha Bank, Commercial Bank of Qatar, and QNB. That is a Qatari payment topology, not a generic gateway with a Qatari label.

DineroPay, a licensed Saudi PSP, chose the opposite route: on-premises from day one. It deployed on Oracle Cloud Infrastructure set to SAMA's storage and encryption rules and achieved SAMA certification there. Saudi mobile demand is the present, not a forecast. DineroPay needed Apple Pay, Google Pay, network tokenisation, and BNPL options Tabby and Tamara alongside cards. Tokenisation lifts approval rates but requires controlled infrastructure. A native build would have consumed the period when the market was dividing; a pre-integrated local deployment compressed it.

Four questions decide the call. Does your license require it? A domestic PSP license in Qatar or Saudi Arabia effectively does; agents acting under another license may not. How many markets are you serving? One regulated market rewards on-premises. Fifteen punish it. What sequencing constraint matters? If demonstrated capability has to precede licensing, SaaS first and on-premises second is the only workable order. Who owns migration risk? Moving live merchants later is the highest-risk stage; dual-running and transaction synchronisation should be planned before launch, not improvised after.

Localisation looks like an added cost from outside the market. From inside, it works as a barrier to entry that compounds. The same rules that slow one entrant now keep its competitors outside, and that makes the location of data the core strategic choice rather than a compliance detail.