Kuwait
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Kuwait has no single privacy law. The telecoms regulator's rules fill the gap, and they reach anyone running a website or app for people in Kuwait. Ordinary personal data can go abroad if you tell the person first and they agree. But medical records, court files, DNA and criminal fingerprints, and anything sensitive a company holds must sit on servers inside Kuwait.
Data governance in Kuwait
The eight things that decide how you handle data about people in Kuwait. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The rules reach a foreign company with no office in Kuwait. The telecoms regulator's privacy rules apply to anyone who runs a website, a smart application or a cloud service and who collects or handles personal data about people in Kuwait, wherever the handling actually happens. There is no size or revenue floor to duck under. If your company sits outside Kuwait you are expected to record who your local contact is, alongside your data protection officer.
The Data Privacy Protection Regulation defines a 'Communications and Information Technology Service Provider' to include a person who 'operates a website, smart application or cloud computing services, collects or processes personal data or directs another party that collects and processes personal data on its behalf'. Article 1 extends the regulation to processing 'whether processed inside or outside the State of Kuwait' where it is linked to sending advertising or marketing material, or to monitoring the behaviour and tendencies of the people concerned. Article 7 requires the record of processing activities to name 'the service provider and its representative if it is outside Kuwait and the data protection officer'. There is no registration threshold and no exemption for small firms. Two carve-outs exist: purely personal or family use by an individual, and security authorities acting for crime prevention, investigation or prosecution.
Sources
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Data Privacy Protection Regulation v1.8, Definitions and Articles 1 and 2 (scope)
citra.gov.kw
“Such regulation apply to all public and private sectors service providers who collect, process and store personal data and user related content in whole or in part, either permanently or temporarily using automated means or any other means that are part of a data storage system, whether processed inside or outside the State of Kuwait”
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Data Privacy Protection Regulation v1.8, Article 7(4)(a) — record must name the provider's representative if it sits outside Kuwait
citra.gov.kw
Link checked 18 August 2026
Where the data is allowed to live
It depends entirely on how sensitive the data is. Kuwait sorts all data into four tiers. Tiers one and two, which cover names, contact details, civil identity numbers and similar, can go abroad once you have told the person and obtained their written agreement. Tiers three and four cannot leave at all. That ban is absolute: not permanently, not temporarily, not for any purpose.
Tier three is far broader than most people expect. It captures medical records, court and lawsuit files, legal opinions from law firms, criminal fingerprints and DNA fingerprints, and also a company's own meeting minutes, business plans and internal project reports. Tier four covers encryption keys, political and international-relations documents, and military or state-security material. The Cloud Computing Regulatory Framework forbids storing or hosting any of it outside Kuwait. Separate rules point the same way for specific groups: private-sector and public-sector cloud users are both told not to place tier three or four personal data, or government data, on a provider's data centre outside Kuwait; public cloud may not be used for tier three at all, only private or hybrid cloud with the tier-three part kept inside Kuwait; and tier two data may go on a public cloud only if it is encrypted with keys held solely by the customer. Sector by sector: HEALTH is effectively closed, because medical records are tier three. LEGAL AND PROFESSIONAL FILES are closed for the same reason. GOVERNMENT is closed for tier three and four, and defence and security bodies are exempt from the classification scheme altogether and set their own rules. BANKING AND PAYMENTS are conditional rather than closed, but the Central Bank must approve any cloud arrangement touching sensitive data at least one month before signing, and that duty catches branches of foreign banks even when the contract was signed by the group abroad. TELECOMS carry a statutory confidentiality duty over calls and private communications. SECURITIES, INSURANCE, EDUCATION, MAPPING and GAMBLING: no separate storage-location rule was found on the regulators' own sites as at 18 August 2026, so the general cloud tiers are what binds them. Gambling is in any event unlawful in Kuwait.
Sources
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Cloud Computing Regulatory Framework v2.4, Article 4.2.1.1 — residency and transfer of subscriber data
citra.gov.kw
“Subscribers of cloud computing services must ensure that no data or content is hosted or stored, in which the data classification policy and chapter three on data classification of this framework does not allow it to be hosted or stored outside the State of Kuwait for any purpose, or in any form, whether temporarily or permanently”
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Cloud Computing Regulatory Framework v2.4, Article 3.2.1.2.2 — duty on private-sector cloud users
citra.gov.kw
“Obligation not to store or host personal data of individuals or government entities data which they have that fall within the third and fourth level of data classification on the data center and cloud computing environment of the cloud computing service provider who are outside the State of Kuwait.”
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Data Classification Policy v2.3 — the four tiers, including medical records, court files and DNA fingerprints in tier three
citra.gov.kw
Link checked 18 August 2026
- Official sourceCentral Bank of KuwaitCyber and Operational Resilience Framework v1.0, Article 7.2.1.3 and 7.2.1.4 — Central Bank approval for cloud, including foreign bank branches
cbk.gov.kw
“Regulated Entities shall seek approval from CBK at least one month prior to signing any cloud based outsourcing agreements”
Link checked 18 August 2026
Sending data out of the country
For the data that is allowed to travel, the gate is the individual, not the government. There is no approved-country list, no banned-country list and no standard contract to sign. You classify the data, tell the person you intend to send it out of Kuwait, and get their written agreement saying why it is going and who is receiving it. For tier three and tier four data no paperwork helps, because the answer is simply no.
The Data Privacy Protection Regulation requires the provider to 'Notify the data owner in case the service provider intends to transfer his personal data out of Kuwait in accordance with the data classification policy issued by CITRA'. The Cloud Computing Regulatory Framework adds a prior-consent duty on the provider before content is moved or processed abroad, and the Cloud Service Providers rules require written consent explaining the reasons and naming the recipient. Kuwait therefore does not operate an allowlist or a blocklist of destination countries: there is no list to be populated, and no country-level assessment is made. Two other conditions bite in practice. First, the receiving cloud provider must be registered or licensed by the regulator before any content moves to a public, hybrid or community cloud. Second, licensed providers must disclose to the regulator both their data-centre locations inside Kuwait and every country where they run data centres that touch Kuwaiti subscribers' content.
Sources
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Cloud Computing Regulatory Framework v2.4, Article 8.1.2 — written consent before data is copied abroad
citra.gov.kw
“Obtain a written consent from their subscribers before transferring or copying their data outside the State of Kuwait, explaining the reasons, and specifying the party to which the data is to be copied or transferred as long as it does not fall within the third and fourth level of data classification.”
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Data Privacy Protection Regulation v1.8, Article 6(10) — notify the person before sending their data out of Kuwait
citra.gov.kw
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Cloud Computing Regulatory Framework v2.4, Articles 4.2.1.2 and 4.2.1.3 — provider must be licensed and must disclose the countries where its data centres sit
citra.gov.kw
Link checked 18 August 2026
The regulator, and whether it actually acts
On paper the Communication and Information Technology Regulatory Authority, known as CITRA, and it can fine up to one million Kuwaiti dinars per breach, roughly three and a quarter million US dollars. In practice it is a busy telecoms regulator and a silent privacy regulator. It issued regulatory decisions as recently as June 2026, but we found no published privacy fine, no register of licensed cloud providers and no enforcement notice under the privacy rules. The Central Bank of Kuwait is the one authority visibly punishing firms.
Evidence that CITRA is genuinely staffed and working: its regulatory-decisions register lists 73 decisions with the most recent dated 8 June 2026, and its public-consultation register shows consultations closing in April and June 2026. So this is not an empty chair. Evidence that the privacy layer is dormant: cloud service provider licensing does not appear anywhere in CITRA's published list of licensing services; its cybersecurity pages still headline a national strategy covering 2017 to 2020 and controls written for the coronavirus period; a revised privacy regulation went out to public consultation on 10 August 2023 and, three years later, the version published on CITRA's own site is still v1.8; and no decision in the public register concerns personal data. By contrast the Central Bank of Kuwait publishes a running list of penalties, with actions against local banks, exchange companies and electronic payment providers dated October and November 2025, and it released a 389-page Cyber and Operational Resilience Framework on 3 December 2025. The Capital Markets Authority and the Insurance Regulatory Unit are also visibly active, the latter publishing decisions and news through May 2026, but neither imposes a data-location rule of its own. Reading the whole picture: if you are a bank you face a real regulator; if you are anyone else, the privacy rules currently depend on your own discipline.
Sources
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)CITRA register of regulatory decisions — 73 decisions, most recent 8 June 2026
citra.gov.kw
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)CITRA public consultations register — draft Data Privacy Protection Regulation consulted 10 August 2023 to 10 October 2023, never issued
citra.gov.kw
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Law No. 37 of 2014 establishing CITRA, as amended by Law No. 98 of 2015, Article 64.6 — administrative fine of up to one million Kuwaiti dinars per violation
citra.gov.kw
Link checked 18 August 2026
- Official sourceCentral Bank of KuwaitCentral Bank of Kuwait penalties register — actions against banks, exchange companies and e-payment providers, October and November 2025
cbk.gov.kw
Link checked 18 August 2026
- Official sourceInsurance Regulatory Unit, State of KuwaitInsurance Regulatory Unit — decisions and announcements published through May 2026
iru.gov.kw
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a firm ceiling and several firm floors, and they collide. The ceiling: you must destroy someone's personal data once your contract with them ends, or earlier if they withdraw consent or ask you to. The floors: payment and electronic money firms must keep records for ten years after the relationship ends, money-laundering records run five years, and investment firms keep complaint and business-continuity records five years. Kuwait gives no rule for resolving the clash.
Ceiling. The Data Privacy Protection Regulation requires the provider to 'Destroy personal data in its possession once the contractual relationship with the data owner has expired, or during the contract term if the data owner so requests', and separately to delete the data where consent is withdrawn, where the data is no longer needed for the service, or where the person is no longer using the service. Withdrawal of consent triggers a duty to destroy the data from hardware and from logs, and to keep no duplicates. Floors. Payment, electronic money and payment infrastructure firms supervised by the Central Bank must keep all electronic documents, records and data for not less than ten years from the end of the contractual relationship. Anti-money-laundering documentation must be kept for at least five years from the end of the customer relationship. Investment and securities firms licensed by the Capital Markets Authority keep complaint records five years, and business-continuity records five years from when they stop being used. How the clash resolves. Nothing in the privacy regulation says the retention floors override the deletion duty, and nothing in the financial rules says the reverse. In practice the specific financial obligations are the safer master, because they carry a supervisor who fines. This is a genuine gap, not a simplification.
Sources
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Data Privacy Protection Regulation v1.8, Articles 6(12) and 6(21) — destroy data at the end of the relationship
citra.gov.kw
“Destroy personal data in its possession once the contractual relationship with the data owner has expired, or during the contract term if the data owner so requests.”
Link checked 18 August 2026
- Official sourceCentral Bank of KuwaitCircular No. 2/BS, IBS, FS, IFS, ES, PS/524/2023, Instructions for Regulating the Electronic Payment of Funds, Article 23 — ten-year retention
cbk.gov.kw
“Maintain all the electronic documents, records and data related to the activity for a period of no less than 10 years from the date of termination of the contractual relationship.”
Link checked 18 August 2026
- Official sourceCentral Bank of KuwaitCentral Bank of Kuwait, e-payment supervisory instructions — five-year minimum for anti-money-laundering documentation
cbk.gov.kw
“All documentation, data, and information, whether on the transactions executed or those gathered in line with due diligence measures must be maintained for 5 years minimum of the date of end of business with the customer”
Link checked 18 August 2026
- Official sourceCapital Markets Authority, State of KuwaitCapital Markets Authority Executive Bylaw, Module 6 (Policies and Procedures of Licensed Persons), Articles on complaint and business-continuity records — five years
cma.gov.kw
Link checked 18 August 2026
If something goes wrong
Count the clocks, because there are at least four and the fastest is one hour. If a leak harms a large number of users you have 24 hours to tell the regulator, the affected users and the police. Every other personal data breach gets 72 hours to the regulator and 72 hours to the affected person. Cloud providers get 72 hours to warn their customers. And if you are supervised by the Central Bank, a serious incident must be reported within one hour of discovery.
Clock one: 24 hours. Where personal data held by a licensee is wrongly disclosed or accessed by a third party and the disclosure harms a large number of users, notice must go to CITRA, to end users and to law enforcement agencies as soon as possible and within 24 hours of the licensee reasonably concluding there has been a breach. Note that it runs to three recipients at once, including the police, which is unusual. Clock two: 72 hours to CITRA for any personal data breach, with a prescribed content list covering the nature of the breach, how much data leaked, who was affected, the security levels breached, the data protection officer's contact route, likely consequences and the remedy taken. Clock three: 72 hours to the affected individual, unless strong technical protections were already applied to the affected data and follow-up steps have removed the risk. Clock four, for financial firms only: high-severity incidents to the Central Bank within one hour of discovery with progress updates every four hours, medium severity within four hours with daily updates, and low severity consolidated monthly. Overlap is the trap. A single breach at a Kuwaiti bank's cloud-hosted customer platform can trigger the one-hour bank clock, the 24-hour large-scale clock, the 72-hour regulator clock and the 72-hour individual clock, all from the same moment of discovery.
Sources
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Data Privacy Protection Regulation v1.8, Article 6(26) — 24 hours where a leak harms a large number of users
citra.gov.kw
“the licensee shall notify CITRA, end users and law enforcement agencies as soon as possible and in no more than 24 hours after the licensee reasonably determines that there has been a violation of this disclosure or access.”
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Data Privacy Protection Regulation v1.8, Articles 8 and 9 — 72 hours to the regulator and 72 hours to the individual
citra.gov.kw
“The service provider shall, within a period not exceeding 72 hours following its knowledge of the incident, provide a notification of any breach incident of personal data to CITRA.”
Link checked 18 August 2026
- Official sourceCentral Bank of KuwaitCyber and Operational Resilience Framework v1.0, Article 8.2.2.1 — one-hour and four-hour reporting to the Central Bank
cbk.gov.kw
“Medium severity incidents shall be reported within (4) hours of discovery; and High severity incidents shall be reported within (1) hour of discovery.”
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Cloud Computing Regulatory Framework v2.4, Article 4.2.2.1 — cloud provider must warn subscribers within 72 hours
citra.gov.kw
Link checked 18 August 2026
What catches people out
Five things that ruin weekends. First, a child in Kuwait is anyone under 18, and you need the guardian's explicit consent. Second, the ban on sending data abroad also swallows your own business plans, meeting minutes and internal project reports, because Kuwait puts them in the same box as medical records. Third, if you host that box you need a Kuwaiti licence and a data centre physically in Kuwait. Fourth, you owe a round-the-clock contact person. Fifth, the police get told about big leaks.
One. The Data Privacy Protection Regulation requires 'explicit consent of the guardian of a child whose age is less than 18 years', with reasonable efforts and available technology used to verify age. There is no lower digital-consent age as in Europe, and the regulator says it will set the mechanism for obtaining the guardian's consent, which it has not published. Two. Tier three of the Data Classification Policy is not limited to personal data. It expressly lists 'Minutes of meeting and business plans' and 'Internal project reports' alongside medical records and DNA fingerprints. Since tier three may not be hosted outside Kuwait for any purpose, a routine group intranet or an overseas project management tool can breach the rule. Three. A cloud provider wanting to host tier three or four data must be licensed by CITRA, must prove it owns a licensed data centre located inside Kuwait, must renew annually, and is prohibited from providing services before the licence issues. Contracts signed by an unlicensed provider are stated to be void. Four. The privacy regulation demands internal systems to receive and handle access, correction and deletion requests 'around the clock', and 24-hour availability of the data protection officer. Five. The 24-hour large-breach notice goes to law enforcement agencies, not only to the regulator, which changes how an incident should be handled from the first minute. A sixth point for completeness: the cloud framework tells providers that where they are subject to a foreign country's judicial laws, they must not hand a subscriber's content to any domestic or foreign government or public authority, which sits awkwardly with overseas disclosure orders.
Sources
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Data Privacy Protection Regulation v1.8, Article 5(5) — guardian consent below 18
citra.gov.kw
“Obtain an explicit consent of the guardian of a child whose age is less than 18 years.”
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Data Classification Policy v2.3, tier three examples — includes meeting minutes, business plans, internal project reports, medical records and DNA fingerprints
citra.gov.kw
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Cloud Service Providers Regulations and Commitments v1.7, Licensing Procedure — licence plus a data centre inside Kuwait
citra.gov.kw
“Service Providers are prohibited from providing cloud services to the public or private sectors prior to obtain this license.”
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Cloud Computing Regulatory Framework v2.4, Article 4.3.3 — provider must not hand content to a foreign government or public authority
citra.gov.kw
Link checked 18 August 2026
What's changing next
Nothing is scheduled to commence on a fixed date in the next twelve months, but three things are queued. A replacement privacy regulation has been sitting finished since a public consultation closed in October 2023 and could be issued at any time. A guide on adopting artificial intelligence closed consultation in April 2026. A regulation on the rights of telecoms and technology users closed consultation in June 2026. Banks are absorbing a new Central Bank resilience framework issued in December 2025.
Dormant switches matter more here than pending law, and Kuwait has four of them. First, the cloud framework states outright that CITRA may amend its chapters and articles 'without prior notice', so the residency rules can change overnight with no consultation at all. Second, the same framework lets CITRA declare accreditation plans and standards mandatory by decision. Third, the classification policy invites the regulator to issue a Data Classification and Handling Procedure Guide, which would change what falls into the untransferable tiers. Fourth, the revised privacy regulation consulted on in August 2023 has never been published, so the current version can be replaced without further notice. On the financial side the Central Bank's Cyber and Operational Resilience Framework version 1.0 was released on 3 December 2025 and replaces the 2020 Cybersecurity Framework; we could not find a published compliance deadline for it, so treat it as already binding. One piece of constitutional context: Kuwait's National Assembly was dissolved in 2024 and legislation is being made by decree, which means a general data protection statute could appear without any parliamentary process. We could not verify that point on a Kuwaiti government site from our network, so treat it as background rather than fact.
Sources
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)CITRA public consultations register — draft Data Privacy Protection Regulation (2023), artificial intelligence adoption guide (closed 20 April 2026), telecoms and IT user rights regulation (closed 6 June 2026)
citra.gov.kw
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Cloud Computing Regulatory Framework v2.4, Article 9.2.3 — the regulator may amend the framework without prior notice
citra.gov.kw
“Amendment to the chapters and articles of this framework without prior notice.”
Link checked 18 August 2026
- Official sourceCentral Bank of KuwaitCentral Bank of Kuwait — Cyber and Operational Resilience Framework, version 1.0 released 3 December 2025
cbk.gov.kw
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud Service Providers Regulations and Commitments (لوائح والتزامات مزودي الخدمات السحابية) and Cloud First Policy
Licence condition · CITRA Cloud Service Providers Regulations and Commitments, version 1.7, read with the Cloud First Policy
No cloud provider may contract with the Kuwaiti public sector, or host sensitive data for anyone, without CITRA permission, and to host the sensitive tiers it must own a data centre inside Kuwait. We found no published list of licensed providers, so treat the approval route as untested.
Enforced by Communication and Information Technology Regulatory Authority
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyProviders hosting tier one or two data must register with CITRA; providers hosting tier three or four must hold a full licence, renewed annually.
- Keep the data in the countryA licensed provider must own a data centre licensed in Kuwait and physically located inside Kuwait's borders.
- Independent auditMust disclose to CITRA every data centre location inside Kuwait and every country where it runs data centres touching Kuwaiti subscribers.
What it costs if you get it wrong
- Fixed maximum fine: KD 1,000,000 per violation — about $3 millionProviding cloud services without the required registration or licence.
- Order to stopContracts with subscribers are stated to be void where the provider fails to obtain a licence.
Sources
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Cloud Service Providers Regulations and Commitments v1.7, Registration, Permission and Licensing Procedures
citra.gov.kw
“Cloud service providers wishing to host Tier 3 and Tier 4 data are required to provide CITRA with information, identifications, certificates, and documents ... Service Providers are prohibited from providing cloud services to the public or private sectors prior to obtain this license.”
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)CITRA Cloud First Policy — government entities must consider cloud first, within the classification tiers
citra.gov.kw
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)CITRA published list of licensing services — cloud service provider licensing does not appear on it, checked 18 August 2026
citra.gov.kw
Link checked 18 August 2026
Cyber and Operational Resilience Framework (CORF)
Regulator directive · Central Bank of Kuwait, Cyber and Operational Resilience Framework for All Local Banks and Financial Institutions, version 1.0
The Central Bank's 389-page resilience framework, issued in December 2025, is the only Kuwaiti instrument with European-style privacy principles and a real enforcer behind it. It does not ban sending data abroad, but it requires the Central Bank's approval a month before any cloud deal touching customer data.
Enforced by Central Bank of Kuwait
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Report cyber incidents — within 1 hourHigh severity to the Central Bank within one hour of discovery, updates every four hours. Medium severity within four hours, daily updates. Low severity consolidated monthly.
- Report breaches to the regulator — within 1 hour
- Tell affected peopleWithout undue delay where the breach is likely to create a high risk to the person.
- Put a transfer safeguard in placeCentral Bank approval at least one month before signing any cloud outsourcing agreement touching sensitive data, including where a foreign bank's branch relies on a group contract.
- Assess high-risk projects — 2 yearsPrivacy impact assessment every two years or on significant change, reviewed annually.
- Secure the data
- Keep logs
- Written vendor contract
- Let people delete their dataRight to be forgotten written into the framework's privacy principles.
What it costs if you get it wrong
- Fixed maximum fineSupervisory penalties published on the Central Bank's penalties register.
- Order to stopSupervisory direction against a regulated entity.
Sources
- Official sourceCentral Bank of KuwaitCyber and Operational Resilience Framework v1.0, Articles 5.11.2, 7.2.1 and 8.2.2
cbk.gov.kw
“Regulated Entities shall seek approval from CBK at least one month prior to signing any cloud based outsourcing agreements, regarding the use of infrastructure-as-a-service (IaaS), platform-as-a-service (PaaS), and software-as-a-service (SaaS) products which directly or indirectly interact with systems involving sensitive data”
Link checked 18 August 2026
- Official sourceCentral Bank of KuwaitCentral Bank of Kuwait — Cyber and Operational Resilience Framework page
cbk.gov.kw
Link checked 18 August 2026
- Official sourceCentral Bank of KuwaitCentral Bank of Kuwait penalties register — evidence the supervisor issues decisions
cbk.gov.kw
Link checked 18 August 2026
Instructions for Regulating the Electronic Payment of Funds
Regulator directive · Central Bank of Kuwait Circular No. 2/BS, IBS, FS, IFS, ES, PS/524/2023
Payment, electronic money and payment infrastructure firms must keep every record for ten years after the relationship ends and must get the Central Bank's written approval before putting anything material on a cloud service. There is no rule forcing payment data to stay in Kuwait.
Enforced by Central Bank of Kuwait
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep data for a minimum period — 10 yearsTen years from the end of the contractual relationship, for all electronic documents, records and data.
- Put a transfer safeguard in placePrior written Central Bank approval before outsourcing to a cloud provider or to any third party with significant operational impact.
- Secure the data
- Report cyber incidentsSystem failures reported to the Central Bank under the firm's incident process.
- Register or notifyCentral Bank approval also required before opening a branch or subsidiary outside Kuwait.
What it costs if you get it wrong
- Fixed maximum finePenalties published on the Central Bank penalties register against e-payment service providers, most recently October and November 2025.
- Loss of your licenceBreach of the e-payment licensing conditions.
Sources
- Official sourceCentral Bank of KuwaitCircular No. 2/BS, IBS, FS, IFS, ES, PS/524/2023, Articles 23 and 28
cbk.gov.kw
“Obtain CBK's prior written approval for outsourcing a third party to provide services with a significant operational impact, or a cloud service provider for any of the E-Payment, E-money or E-Payment system operation activities.”
Link checked 18 August 2026
- Official sourceCentral Bank of KuwaitCentral Bank of Kuwait penalties register — penalties against e-payment service providers, 13 October 2025
cbk.gov.kw
Link checked 18 August 2026
Applies to every company3 rules
These bind you whatever business you are in, once the country's rules reach you.
Data Privacy Protection Regulation (لائحة حماية خصوصية البيانات)
Directly binding regulation · CITRA Data Privacy Protection Regulation, version 1.8, issued under Law No. 37 of 2014 as amended by Law No. 98 of 2015
Kuwait's closest thing to a general privacy law. It is a telecoms regulator's rulebook, not an act of parliament, and it binds anyone running a website, app or cloud service that handles data about people in Kuwait. Consent is the main legal basis, a child is anyone under 18, and breaches must be reported within 72 hours or 24 hours if large.
Enforced by Communication and Information Technology Regulatory Authority
Transfer model: No restriction · Accepted routes: Explicit consent
What it makes you do
- Get consent
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Secure the data
- Keep records of processing
- Appoint a data protection officerContactable 24 hours a day, and internal systems for handling access, correction and deletion requests must run around the clock.
- Appoint a local representativeRecord of processing must name the provider's representative where the provider sits outside Kuwait.
- Get a parent's consent for children — applies at: under 18
- Report breaches to the regulator — within 72 hours
- Tell affected people — within 72 hours
- Report cyber incidents — within 24 hoursWhere a wrongful disclosure harms a large number of users, notice goes to CITRA, to end users and to law enforcement within 24 hours.
- Written vendor contract
- Delete data after a period
- Put a transfer safeguard in place
What it costs if you get it wrong
- Fixed maximum fine: KD 1,000,000 per violation — about $3 millionAny breach of a CITRA regulation. Doubled on repetition, or twice the value of the damage caused, whichever is greater.
- Loss of your licenceBreach by a licensed communications or IT service provider.
Sources
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Data Privacy Protection Regulation v1.8 — full text as published by CITRA
citra.gov.kw
“The service provider shall, within a period not exceeding 72 hours following its knowledge of the incident, provide a notification of any breach incident of personal data to CITRA.”
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Law No. 37 of 2014 establishing CITRA as amended by Law No. 98 of 2015, Article 64.6 — fine up to one million Kuwaiti dinars per violation
citra.gov.kw
Link checked 18 August 2026
Cloud Computing Regulatory Framework (الإطار التنظيمي للحوسبة السحابية)
Directly binding regulation · CITRA Cloud Computing Regulatory Framework, version 2.4, Chapters 3 and 4
The hard wall. Any data Kuwait classes as tier three or tier four, which includes medical records, court files, DNA and criminal fingerprints, encryption keys, state security material and even a firm's own business plans, may not be hosted or stored outside Kuwait at all.
Enforced by Communication and Information Technology Regulatory Authority
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryTier three and tier four data may not be hosted or stored outside Kuwait for any purpose, temporarily or permanently.
- Secure the dataTier three data may only sit on a private or hybrid cloud; tier two may sit on a public cloud only if encrypted with keys held solely by the customer.
- Put a transfer safeguard in placeFor tier one and tier two data, prior written consent naming the recipient and the reason.
- Tell affected people — within 72 hoursCloud provider must warn its subscribers of a security breach or data leak within 72 hours.
- Do not hand data to foreign authorities on demandA provider subject to a foreign country's judicial laws must not hand subscriber content to any domestic or foreign government or public authority.
What it costs if you get it wrong
- Fixed maximum fine: KD 1,000,000 per violation — about $3 millionBreach of the framework, under the CITRA establishment law.
Sources
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Cloud Computing Regulatory Framework v2.4, Articles 3.1.4, 3.2.1.2.2, 3.2.1.3.2 and 4.2.1.1
citra.gov.kw
“Subscribers of cloud computing services must ensure that no data or content is hosted or stored, in which the data classification policy and chapter three on data classification of this framework does not allow it to be hosted or stored outside the State of Kuwait for any purpose, or in any form, whether temporarily or permanently”
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Data Classification Policy v2.3 — definition of the four tiers
citra.gov.kw
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)CITRA regulatory framework document register listing the Data Classification Policy, 16 June 2022
citra.gov.kw
Link checked 18 August 2026
Data Classification Policy (سياسة تصنيف البيانات)
Government policy document · CITRA Data Classification Policy, version 2.3, listed on CITRA's regulatory register dated 16 June 2022
The rule that decides everything else. Every organisation in Kuwait, public or private, must sort its data into four sensitivity tiers, and the tier decides whether the data may leave the country. Defence and security bodies are exempt and classify as they choose.
Enforced by Communication and Information Technology Regulatory Authority
Transfer model: No restriction · Accepted routes: Explicit consent
What it makes you do
- Keep records of processingEvery public and private sector organisation must sort its data into at least four tiers, keep a data catalogue of metadata and refresh it periodically.
- Secure the dataTier three and tier four data must be encrypted whenever it moves between organisations or between physical sites, and must be removed from servers before equipment is disposed of.
- Independent auditA classification team chaired by senior management, plus a named contact who sends quarterly implementation reports to the Central Agency for Information Technology.
What it costs if you get it wrong
- Fixed maximum fine: KD 1,000,000 per violation — about $3 millionBreach of a CITRA policy or regulation.
Sources
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)Data Classification Policy v2.3, Articles 3.1.1 to 3.1.6 and 3.4.1
citra.gov.kw
“Assign a focal point employee to communicate and provide the Central Agency for Information Technology (CAIT) with quarterly reports on the extent of implementation of this policy”
Link checked 18 August 2026
- Official sourceCommunication and Information Technology Regulatory Authority (CITRA)CITRA regulatory register entry for the Data Classification Policy, dated 16 June 2022
citra.gov.kw
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact commencement dates of the Data Privacy Protection Regulation, the Cloud Computing Regulatory Framework and the Cloud Service Providers rules.
CITRA publishes these as undated scanned documents carrying only a version number. The cloud framework says it comes into force 30 days after publication in the official gazette, with a six-month grace period, but we could not reach Kuwait Al-Youm, the official gazette, from our network. The dates recorded here are inferred from the scan dates on CITRA's own files (June 2021 for the privacy regulation, September 2021 for the cloud documents) and should be treated as approximate.
Whether Kuwait has enacted, or is drafting, a general personal data protection statute.
No Kuwaiti government site we could reach publishes a bill or a draft. The Kuwaiti government portal returned an access error and the gazette site did not respond. CITRA's consultation register shows only a revised privacy regulation from 2023, which is a regulator instrument rather than a statute.
Whether CITRA has ever issued a decision, fine or public warning under the Data Privacy Protection Regulation.
Its public register of 73 regulatory decisions contains none on personal data, but the register may not cover individual enforcement actions. Absence of evidence, not evidence of absence.
Whether any cloud service provider currently holds the CITRA licence needed to host tier three and tier four data.
No register of licensed or registered cloud providers was found on CITRA's site, and cloud licensing is not listed among its published licensing services. This matters because the rules say a provider without the licence may not serve the public or private sector at all.
Health sector rules issued by the Ministry of Health.
The Ministry of Health website did not respond from our network on 18 August 2026. The health position stated here rests on the classification of medical records as tier three, which is verified, rather than on any ministry instrument, which we could not check.
Any compliance deadline or transition period attached to the Central Bank's Cyber and Operational Resilience Framework.
The published framework gives a release date of 3 December 2025 but we found no stated implementation deadline in the document or on the framework's page. Treat it as binding now.
The constitutional and parliamentary position, including the dissolution of the National Assembly and law-making by decree.
Reported widely but not verifiable on any Kuwaiti government domain reachable from our network. It is recorded as background in the eighth answer and should not be relied on.
Sector-specific storage rules for insurance, securities, education, mapping and geospatial data.
We checked the Capital Markets Authority executive bylaw and the Insurance Regulatory Unit site and found no data-location requirement, but we could not review every circular. Recorded as 'no rule found, checked 18 August 2026', not as 'there is no rule'.
The precise article number in Law No. 37 of 2014 that makes telephone calls and private communications confidential.
CITRA's English-labelled copy of the law is in fact the Arabic text, and the extracted layout does not reliably preserve article numbering. The confidentiality provision is present in the text; the numbering is not asserted.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Kuwait versus
Compare