Backups in a different region?

Works unless local laws specifically block you doing that which they do for some classes of data in some countries.

Multi-cloud in the same country (if that exists in the country and is far enough apart) maybe.

I wonder what exactly these laws prohibit. Like, does it apply to a fully encrypted cold-copy on Amazon Glacier? If you don't store the encryption key outside of UAE, I'd say this isn't even the same data that gets transferred to the third party, it's just some random blob. But I have no idea if the authorities of that country would agree and if it's even actually enforced for that matter, or if it's one of those laws that actually cause problems only if you follow them.

Do cloud providers even share data center locations so you can assess the "far enough" bit yourself?

You usually get city level location information. Depends on your definition for 'far enough' if that works for you.

me-south-1 is about 250 miles away from me-central-1, but that's not far enough in this instance. Given that, I think city level location information should be good enough.

250 miles is pretty good for weather or not specifically targeted destruction (wildfire / industrial explosions / arson), but it's clearly not enough if your data is in a building targeted in a regional war. Assuming datacenters remain targets in wartime, I think it's fair to assume if one datacenter in any particular country is attacked, all the rest of the datacenters in that country are likely to be attacked, too. In that case, offline storage (tapes and things) in inconspicuous locations might be the way.

Kinda they do? Atleast our company knows the exact location of ours

No - and usually the reason is so they cannot be targeted.

In this case, a local on-prem backup in your office-that-is-not-an-aws-datacenter would've worked and satisfy the law right?

(or an AWS Outpost thingy, assuming those things work even if the mothership is down)

[deleted]