Your gaming platform can live almost anywhere in the EEA. A replicated copy of the regulatory data cannot: the MGA wants it on a known, inspectable server in Malta.
This is one of the requirements that catches operators out when they move their platform to the cloud or to a data centre outside Malta. The licence does not force you to host everything on the island, but it does require that the regulatory data generated under your Maltese licence is replicated, in close to real time, to a server physically located in Malta that the Malta Gaming Authority can inspect. The query “iGaming replication server in Malta” is usually a compliance team or a hosting lead trying to work out exactly what that server has to be and who builds it. This article answers that. Sirap supplies and supports the on-premise and Malta-hosted infrastructure behind it, and works with operators here on exactly this requirement.
What does the MGA actually require?
In short: if your live platform is hosted outside Malta, a replica of the regulatory data has to be hosted inside Malta, and the Authority has to be able to reach it. The MGA’s guidelines on technical infrastructure set out that a licensee using a data centre or cloud outside Malta for its critical components must maintain real-time replication of the data generated under the Maltese licence to a Maltese data centre. The operator has to tell the MGA where that replication server physically sits, down to the data centre, rack and IP addresses, describe the secured connection from the live servers, and describe what data is replicated and how frequently, including any time lag between the master and the Malta copy. Crucially, the MGA must be able to inspect that server, physically and electronically, on a routine or ad-hoc basis, with immediate and unrestricted access.
The practical consequence people miss: this is fundamentally a requirement for a known, located, inspectable machine in Malta. That is why it is an infrastructure question, not only a software one, and why a generic cloud region elsewhere does not satisfy it. (Always confirm the current detail against the MGA’s own technical-infrastructure guidelines, which are updated from time to time; this article explains the shape of the requirement, not a substitute for the latest text or your compliance advice.)
What data has to be replicated?
The replication is about the regulatory record, not your whole estate. In practice the data that has to reach the Malta server is the player details, the financial transactions and the game-play transactions generated under the Maltese licence. That is the information the MGA needs to be able to audit independently of your live platform, which is the entire point of holding a copy where the regulator, not just the operator, can get to it. It means the Malta server is typically a database server, sized for that regulatory dataset and its growth, rather than a copy of every system you run.
Is this a cloud-provider job, or a server in Malta?
This is the question behind the search, and the honest answer runs against the instinct. Moving your master platform to the cloud is fine and common, but it does not remove the Malta-replica requirement, it is the very thing that triggers it. The replica has to be on a server the MGA can identify by rack and IP and physically inspect, so “just use another cloud region” generally does not meet the obligation unless that environment gives you a known, inspectable, Malta-located footprint you can hand the Authority. For most operators the clean answer is a dedicated replication server in a Malta data centre, or on-premise, that you control and can point an inspector at. The master in the cloud, the mandated replica on a Maltese box, is the standard shape.
The distinction that trips people up: replication is not backup
It is worth being precise, because the two get conflated and they solve different problems. A backup is a point-in-time copy you restore from after something goes wrong. Replication is a continuously updated live copy that tracks the master closely, so at any moment the Malta server reflects what the platform holds. The MGA requirement is for replication, a current mirror it can inspect, not a nightly backup. You still want backups as well, of the Malta replica included, but a backup on its own does not satisfy the rule, and a replica on its own is not a disaster-recovery strategy. They are complementary, and a sound design has both.
What server does the Malta replica actually run on?
It does not need to be exotic. A regulatory replication target is a database and storage workload, not a GPU server, so the typical fit is a dependable dual-socket rackmount with fast, resilient storage, sized to the regulatory dataset and its growth. We build these on a Supermicro X13 1U/2U rackmount server, configured to the data volume and the availability you want, located in a Malta data centre or on-premise. Where the operator wants the replica itself to be resilient at the storage layer, we run it on a DataCore mirrored pool so a single server failing does not take the regulatory copy offline. The hardware is deliberately proportionate; the engineering is in getting the replication, the security and the inspectability right.
Where does the replication itself happen? Three options
“Replication” is a function, and it can live at three different layers. The right one depends on your platform and how you want to run the Malta copy.
Database-native replication
The most common approach for this requirement. The platform’s database (MySQL, PostgreSQL, MSSQL or similar) streams its changes to a replica instance running on the Malta server, in real time or near it. It is well understood, it keeps the replicated dataset in exactly the regulatory shape the MGA expects, and the time lag is measurable and reportable, which is precisely what the Authority asks you to document.
Storage-level replication with DataCore
If you want the resilience at the storage layer rather than tying it to one database engine, DataCore can replicate or mirror the underlying volumes between nodes, synchronously or asynchronously. This suits operators who want the Malta copy to be highly available in its own right, and who run a mix of systems rather than a single database.
Workload replication and DR with Acronis
Where the operator wants the Malta server to double as a disaster-recovery target, not only a regulatory mirror, Acronis provides continuous replication of whole workloads with orchestrated failover. The appeal is one platform covering the regulatory copy, the backups and a tested recovery plan. The point to keep straight is that Acronis runs on the Malta server we provide; it is the replication and DR layer, not a substitute for the located, inspectable box the MGA requires.
What about the connection and the MGA’s access?
Two things beyond the box itself decide whether a deployment actually passes. The first is the link from the live platform to the Malta replica: it has to be secure, and you have to be able to describe the protocols protecting it and the replication frequency and lag. The second is the Authority’s access: the MGA has to be able to inspect the replication server physically and electronically, with immediate and unrestricted access, which means the location, the access procedure and the documentation have to be in place before an inspection, not improvised during one. We set the server up so those answers exist, the physical location and rack are documented, the connection is secured and described, and the access path for the regulator is defined.
How Sirap builds it
We treat this as one job with a compliance shape, not a server sale. That means sizing the Supermicro replica to the regulatory dataset and its growth, choosing the replication layer with you (database-native, DataCore or Acronis) to match your platform and resilience goals, designing the secured connection from the live environment, and making sure the physical location, documentation and MGA access path are ready for inspection. We add Eaton power protection so the regulatory copy is not the thing that goes down in an outage, and we support all of it from Malta, which for a licensee means a local partner who can be on site when the Authority is. We supply the infrastructure and the build; your compliance team and the MGA own the regulatory sign-off.
The takeaway
An MGA replication server is a modest, well-built database and storage server in Malta, kept as a live, secured, inspectable copy of your player, financial and game-play data, with the replication done at whichever layer fits your platform. The cloud is fine for your master; the replica is the part that stays in Malta, on hardware you can point an inspector at. Get the server sizing, the replication method, the secured link and the access documentation right, and what looks like a compliance headache becomes a standard piece of infrastructure.
Featured Products in this article
-

Supermicro AS-3015TR-I4 Edge GPU Tower
Read more -

Supermicro AS-1116R-FN4 Short Depth Server
Read more -

Supermicro AS-E300-14GR Compact Edge Server
Read more -

Supermicro X13 4U Universal GPU SuperServer
Read more -

Supermicro X14 5U NVIDIA GPU Server
Read more -

Supermicro X13 4U Storage Server
Read more -

Supermicro X13 1U/2U Rackmount Server
Read more -

Supermicro X13 Super Workstation
Read more
Kurt Paris
With an MSc in Software Engineering, and over 15 years in IT Management, Kurt Paris leads technology strategy at Sirap. Zebra Technologies, Domino and Cisco-certified, he helps Maltese businesses build resilient storage & backup infrastructure, Machine Vision & AutoID Automation

