KUWAIT
N/A
Pillar Domestic data policies |
Indicator Framework for data protection
Lack of comprehensive legal framework for data protection
Kuwait does not have a comprehensive legal framework governing all personal data; instead, it relies on sectoral regulation. Law No. 20 of 2014 on Electronic Transactions contains provisions related to data privacy and the protection of electronic records, documents, and information associated with civil, commercial, or administrative transactions conducted wholly or partially through electronic means, and applies to private companies, government authorities, public institutions, non-governmental organisations, and their employees. Additionally, Law No. 63 of 2015 on Combating Cyber Crimes imposes severe penalties for the unlawful tampering with or acquisition of personal or governmental data. In addition, Administrative Decision No. 26 of 2024, issued by the Communications and Telecommunications Regulatory Authority (CITRA), establishes obligations concerning data protection for telecommunications service providers and related industry sectors that collect, process, or store personal data, in whole or in part.
Coverage Horizontal
KUWAIT
Since October 2013
Pillar Domestic data policies |
Indicator Minimum period for data retention
Anti-Money Laundering/Combating the Financing of Terrorism Law 106 of 2013
قانون رقم 85 لسنة 2013 بالموافقة على انضمام دولة الكويت إلى االتفاقية الدولية لقمع تمويل اإلرهاب
قانون رقم 85 لسنة 2013 بالموافقة على انضمام دولة الكويت إلى االتفاقية الدولية لقمع تمويل اإلرهاب
Banks and other financial institutions are required by the Anti-Money Laundering/Combating the Financing of Terrorism Law 106 of 2013 to retain a copy of transaction data for five years.
Coverage Banking and financial services
KUWAIT
Since February 2024
Pillar Domestic data policies |
Indicator Requirement to perform a Data Protection Impact Assessment (DPIA) or have a data protection officer (DPO)
Kuwait Administrative Decision No. 26 of 2024 Concerning the Issuance of the Data Privacy Protection Regulation
قرار 26 بشأن إصدار لائحة حماية خصوصية البيانات
قرار 26 بشأن إصدار لائحة حماية خصوصية البيانات
Pursuant to Art. 6 of the Data Privacy Protection Regulation, telecommunications service providers are required to furnish the Communications and Telecommunications Regulatory Authority (CITRA) with the contact details of their designated data protection officer when notifying data breaches. Nevertheless, the Regulation does not expressly stipulate the procedures or obligations pertaining to the appointment of data protection officers as such.
Coverage Telecommunications sector
KUWAIT
N/A
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for copyright infringement
Lack of intermediary liability framework in place for copyright infringements
A basic legal framework on intermediary liability for copyright infringement is absent in Kuwait's law and jurisprudence.
Coverage Internet intermediaries
KUWAIT
N/A
Pillar Intermediary liability |
Indicator Safe harbour for intermediaries for any activity other than copyright infringement
Lack of intermediary liability framework in place for any activity other than copyright infringement
A basic legal framework on intermediary liability beyond copyright infringement is absent in Kuwait's law and jurisprudence.
Coverage Internet intermediaries
KUWAIT
Reported in 2021, last reported in 2025
Pillar Intermediary liability |
Indicator User identity requirement
Identity requirement for SIM cards
It is reported that Kuwait’s SIM registration policy requires mobile network operators to collect and retain users’ personal data together with verifiable proof of identity.
Coverage Mobile network operators
Sources
KUWAIT
Since February 2016
Pillar Intermediary liability |
Indicator Monitoring requirement
Law No. 8 of 2016 regarding the regulation of electronic media
In accordance with Art. 17 of Law No. 8, the manager in control of a website or electronic media outlet is responsible for any prohibited or violating content on the respective website or electronic media outlet/platform under the law. Therefore, the manager is responsible for observing accuracy and credibility in all publications of news, information or data. Electronic media is defined in Art. 1 as “activity which includes the publication or transmission of materials, activities or media services of electronic content that are produced, developed, updated, circulated, transmitted, published or penetrating it through the international information net (the internet) or any other communications net.”
Coverage Electronic media
Sources
- https://web.archive.org/web/20230407041517/https://elaw.media.gov.kw/Files/Rules/139.pdf
- https://web.archive.org/web/20220128000735/https://www.kuwaittimes.com/law-no-8-of-2016-regarding-the-regulation-of-electronic-media/
- https://web.archive.org/web/20230327012009/https://www.tamimi.com/law-update-articles/kuwait-applies-electronic-media-law/
- Show more...
KUWAIT
Since June 2015, entry into force in July 2015
Pillar Intermediary liability |
Indicator Monitoring requirement
Law No. 63 of 2015 regarding Anti-Information Technology Crime
Art. 4.4 of Law No. 63 of 2015 on Anti-Information Technology Crime prescribes imprisonment and a fine for anyone who establishes a website, publishes, produces, prepares, creates, sends, or stores information or data intended to be used, distributed, or displayed via the Internet or an information technology device in a manner that harms public morality, or who manages a location for such purposes. This requirement in practice can act as a monitoring requirement.
Coverage Horizontal
KUWAIT
N/A
Pillar Telecom infrastructure & competition |
Indicator Functional/accounting separation for operators with significant market power
Lack of mandatory functional separation for dominant network operators
It is reported that Kuwait does not compel operators with significant market power (SMP) to adopt functional separation; however, compliance with accounting separation is mandatory.
Coverage Telecommunications sector
KUWAIT
Since May 2014
Pillar Telecom infrastructure & competition |
Indicator Licensing restrictions to operate in the telecom market
Law No. 37 of 2014 on the Establishment of Communication and Information Technology Regulatory Authority
قانون رقم 37 لسنة 2014 بإنشاء هيئة تنظيم الاتصالات وتقنية المعلومات
قانون رقم 37 لسنة 2014 بإنشاء هيئة تنظيم الاتصالات وتقنية المعلومات
Under Law No. 37 of 2014 on the Telecommunications and Information Technology Regulatory Commission, the Communication and Information Technology Regulatory Authority (CITRA) issues licenses to telecom service providers. Under Art. 59, the CITRA employees have the power to request and examine licenses, books, registers, documents, and all papers related to the telecommunication activity; Examine and inspect any telecommunication devices, telecommunication installations, or any other facilities associated with providing telecommunication service or establishing, operating or owning telecommunication network; Review any additional information or documents in any form they might be related to the provision of telecommunication services. It is reported that "although Kuwait’s telecommunications industry is technically open to private investment, in practice, the government maintains extensive ownership in the sector and controls licensing and infrastructure development. It is reported that Kuwait’s telecommunications law gives authorities sweeping power to revoke licenses and block content, with little judicial oversight."
Coverage Telecommunications sector
Sources
- https://web.archive.org/web/20220319204215/https://citra.gov.kw/sites/en/LawofCITRA/Law%20No.%2037-%202014.pdf
- https://web.archive.org/web/20231108030000/https://ustr.gov/sites/default/files/files/reports/2021/2021NTE.pdf
- https://web.archive.org/web/20240615044454/https://kdipa.gov.kw/wp-content/uploads/2022/08/%D9%82%D8%A7%D9%86%D9%88%D9%86-37-%D9%84%D8%B3%D9%86%D9%87-2014-%D9%85%D8%B9-%D8%A7%D9%84%D8%AA%D8%B9%D8%AF%D...
- https://web.archive.org/web/20251210212622/https://ustr.gov/sites/default/files/2024%20NTE%20Report.pdf
- Show more...
KUWAIT
Reported in 2024
Pillar Telecom infrastructure & competition |
Indicator Licensing restrictions to operate in the telecom market
Reported minimum capital requirement for telecom licences
It is reported that a minimum capital threshold is required for the acquisition of a telecommunications licence in Kuwait.
Coverage Telecommunications sector
KUWAIT
N/A
Pillar Telecom infrastructure & competition |
Indicator Signature of the WTO Telecom Reference Paper
Lack of appendment of WTO Telecom Reference Paper to schedule of commitments
Kuwait has not appended the World Trade Organization (WTO) Telecom Reference Paper to its schedule of commitments.
Coverage Telecommunications sector
KUWAIT
Reported in 2018, last reported in 2024
Pillar Telecom infrastructure & competition |
Indicator Presence of an independent telecom authority
Presence of an independent telecom authority
It is reported that the Communication and Information Technology Regulatory Authority (CITRA), the executive authority for the supervision and administration of services in the telecommunications sector, is independent from the government in the decision-making process.
Coverage Telecommunications sector
Sources
- https://web.archive.org/web/20251209180508/https://app.gen5.digital/tracker/country-cards/Kuwait
- https://web.archive.org/web/20231129160641/https://www.citra.gov.kw/sites/en/Pages/AboutUs.aspx
- https://web.archive.org/web/20220126163822/https://www.ilo.org/dyn/natlex/natlex4.detail?p_lang=en&p_isn=99822&p_country=KWT&p_count=311
- https://web.archive.org/web/20250310122455/https://datahub.itu.int/data/?i=100088&s=3109&e=KWT
- Show more...
KUWAIT
Since September 2021
Since June 2022 until February 2024
Since June 2022 until February 2024
Pillar Cross-border data policies |
Indicator Ban to transfer and local processing requirement
Cloud Computing Regulatory Framework
الإطار التنظيمي للحوسبة السحابية
Data Classification Policy
سياسة تصنيف البيانات
الإطار التنظيمي للحوسبة السحابية
Data Classification Policy
سياسة تصنيف البيانات
Pursuant to Arts. 3.2.1.2.2 and 4.2.1.1 of the Cloud Computing Regulatory Framework, private and public entities in Kuwait utilising cloud service providers are required to refrain from storing or hosting Tier 3 or Tier 4 personal data, as defined under the Data Classification Policy, on data centres or cloud computing environments situated outside Kuwait, whether on a temporary or permanent basis. The use of hybrid cloud infrastructure within Kuwait is permitted for Tier 3 data.
The Data Classification Policy defined Tier 3 and Tier 4 data as follows:
- Tier 3 – Private sensitive data: data held by public and private sector organisations, which may include non-sensitive private information capable of identifying individuals and potentially compromising personal privacy if disclosed without authorisation. Examples include: minutes of meetings and business plans; internal project reports; litigation files and court orders and judgments; legal notes and opinions; medical records; DNA information; and criminal fingerprint data.
- Tier 4 – Highly sensitive data: data of an extremely sensitive nature, the unauthorised disclosure of which may cause significant harm to individual privacy. This includes data owned by governmental or private entities, or of national significance, and should be disclosed solely to authorised individuals. Examples include: encryption keys; political documents, international negotiations, or international relations data; and sensitive military or state security information.
This Policy was repealed in February 2024, and therefore there is currently a legal vacuum with regard to definitions of Tier 3 and Tier 4.
The Data Classification Policy defined Tier 3 and Tier 4 data as follows:
- Tier 3 – Private sensitive data: data held by public and private sector organisations, which may include non-sensitive private information capable of identifying individuals and potentially compromising personal privacy if disclosed without authorisation. Examples include: minutes of meetings and business plans; internal project reports; litigation files and court orders and judgments; legal notes and opinions; medical records; DNA information; and criminal fingerprint data.
- Tier 4 – Highly sensitive data: data of an extremely sensitive nature, the unauthorised disclosure of which may cause significant harm to individual privacy. This includes data owned by governmental or private entities, or of national significance, and should be disclosed solely to authorised individuals. Examples include: encryption keys; political documents, international negotiations, or international relations data; and sensitive military or state security information.
This Policy was repealed in February 2024, and therefore there is currently a legal vacuum with regard to definitions of Tier 3 and Tier 4.
Coverage Horizontal
KUWAIT
Since February 2024
Pillar Cross-border data policies |
Indicator Conditional flow regime
Kuwait Administrative Decision No. 26 of 2024 Concerning the Issuance of the Data Privacy Protection Regulation
قرار 26 بشأن إصدار لائحة حماية خصوصية البيانات
قرار 26 بشأن إصدار لائحة حماية خصوصية البيانات
Pursuant to Art. 4 of the Data Privacy Protection Regulation, service providers are obligated to disclose the location of personal data storage, specifying whether such data is retained within or outside Kuwait. In addition, they are required to inform data subjects of any intention to transfer their personal data beyond Kuwait’s borders. This provision applies to both individuals and entities engaged in the provision of public telecommunications services, as well as those responsible for the management, establishment, or operation of telecommunications networks, or the provision of internet services for telecommunications purposes.
Coverage Telecommunications sector
Sources
- https://www.citra.gov.kw/sites/ar/LegalReferences/لائحة%20حماية%20خصوصية%20البيانات.pdf
- https://web.archive.org/web/20250418234347/https://mesferlaw.com/archives/9188
- ttps://web.archive.org/web/20250802004745/https://www.iicom.org/wp-content/uploads/IIC-Whitepaper-Data-Protection-Regimes-in-the-GCC-10-March-2025-review75294981.1-combined_1.pdf
- https://web.archive.org/web/20250802005039/https://practiceguides.chambers.com/practice-guides/comparison/932/15607/24360-24367-24371-24376-24381
- Show more...
