Skip to the content
Global Data RulesData governance rules, country by country

Kuwait

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: HighEnforcement: Dormant

Kuwait has no single privacy law. The telecoms regulator's rules fill the gap, and they reach anyone running a website or app for people in Kuwait. Ordinary personal data can go abroad if you tell the person first and they agree. But medical records, court files, DNA and criminal fingerprints, and anything sensitive a company holds must sit on servers inside Kuwait.

Data governance in Kuwait

The eight things that decide how you handle data about people in Kuwait. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The rules reach a foreign company with no office in Kuwait. The telecoms regulator's privacy rules apply to anyone who runs a website, a smart application or a cloud service and who collects or handles personal data about people in Kuwait, wherever the handling actually happens. There is no size or revenue floor to duck under. If your company sits outside Kuwait you are expected to record who your local contact is, alongside your data protection officer.

High confidenceNational rulesAppoint a local representativeAppoint a data protection officer

Where the data is allowed to live

It depends entirely on how sensitive the data is. Kuwait sorts all data into four tiers. Tiers one and two, which cover names, contact details, civil identity numbers and similar, can go abroad once you have told the person and obtained their written agreement. Tiers three and four cannot leave at all. That ban is absolute: not permanently, not temporarily, not for any purpose.

High confidenceDepends on your industryNo — it stays putNot allowedHealth dataCriminal justice dataGenetic dataGovernment-restricted data

Sending data out of the country

For the data that is allowed to travel, the gate is the individual, not the government. There is no approved-country list, no banned-country list and no standard contract to sign. You classify the data, tell the person you intend to send it out of Kuwait, and get their written agreement saying why it is going and who is receiving it. For tier three and tier four data no paperwork helps, because the answer is simply no.

High confidenceNo restrictionExplicit consentPut a transfer safeguard in placeTell people what you do

The regulator, and whether it actually acts

On paper the Communication and Information Technology Regulatory Authority, known as CITRA, and it can fine up to one million Kuwaiti dinars per breach, roughly three and a quarter million US dollars. In practice it is a busy telecoms regulator and a silent privacy regulator. It issued regulatory decisions as recently as June 2026, but we found no published privacy fine, no register of licensed cloud providers and no enforcement notice under the privacy rules. The Central Bank of Kuwait is the one authority visibly punishing firms.

Medium confidenceDormantFixed maximum fine

How long you must keep it — and when to delete it

There is a firm ceiling and several firm floors, and they collide. The ceiling: you must destroy someone's personal data once your contract with them ends, or earlier if they withdraw consent or ask you to. The floors: payment and electronic money firms must keep records for ten years after the relationship ends, money-laundering records run five years, and investment firms keep complaint and business-continuity records five years. Kuwait gives no rule for resolving the clash.

High confidenceDelete data after a periodKeep data for a minimum period

If something goes wrong

Count the clocks, because there are at least four and the fastest is one hour. If a leak harms a large number of users you have 24 hours to tell the regulator, the affected users and the police. Every other personal data breach gets 72 hours to the regulator and 72 hours to the affected person. Cloud providers get 72 hours to warn their customers. And if you are supervised by the Central Bank, a serious incident must be reported within one hour of discovery.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that ruin weekends. First, a child in Kuwait is anyone under 18, and you need the guardian's explicit consent. Second, the ban on sending data abroad also swallows your own business plans, meeting minutes and internal project reports, because Kuwait puts them in the same box as medical records. Third, if you host that box you need a Kuwaiti licence and a data centre physically in Kuwait. Fourth, you owe a round-the-clock contact person. Fifth, the police get told about big leaks.

High confidenceGet a parent's consent for childrenKeep the data in the countryRegister or notifyAppoint a data protection officerDo not hand data to foreign authorities on demand

What's changing next

Nothing is scheduled to commence on a fixed date in the next twelve months, but three things are queued. A replacement privacy regulation has been sitting finished since a public consultation closed in October 2023 and could be issued at any time. A guide on adopting artificial intelligence closed consultation in April 2026. A regulation on the rights of telecoms and technology users closed consultation in June 2026. Banks are absorbing a new Central Bank resilience framework issued in December 2025.

Medium confidenceIn forceRegulator guideline

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Cloud Service Providers Regulations and Commitments (لوائح والتزامات مزودي الخدمات السحابية) and Cloud First Policy

Licence condition · CITRA Cloud Service Providers Regulations and Commitments, version 1.7, read with the Cloud First Policy

In forceNo — it stays put

No cloud provider may contract with the Kuwaiti public sector, or host sensitive data for anyone, without CITRA permission, and to host the sensitive tiers it must own a data centre inside Kuwait. We found no published list of licensed providers, so treat the approval route as untested.

In force since 20 September 2021But only enforceable from 20 March 2022

Enforced by Communication and Information Technology Regulatory Authority

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Government sign-off needed

Medium confidence
Banking

Cyber and Operational Resilience Framework (CORF)

Regulator directive · Central Bank of Kuwait, Cyber and Operational Resilience Framework for All Local Banks and Financial Institutions, version 1.0

In forceYes, with paperwork

The Central Bank's 389-page resilience framework, issued in December 2025, is the only Kuwaiti instrument with European-style privacy principles and a real enforcer behind it. It does not ban sending data abroad, but it requires the Central Bank's approval a month before any cloud deal touching customer data.

In force since 3 December 2025

Enforced by Central Bank of Kuwait

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence
Payments

Instructions for Regulating the Electronic Payment of Funds

Regulator directive · Central Bank of Kuwait Circular No. 2/BS, IBS, FS, IFS, ES, PS/524/2023

In forceYes, with paperwork

Payment, electronic money and payment infrastructure firms must keep every record for ten years after the relationship ends and must get the Central Bank's written approval before putting anything material on a cloud service. There is no rule forcing payment data to stay in Kuwait.

In force since 1 January 2023

Enforced by Central Bank of Kuwait

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Data Privacy Protection Regulation (لائحة حماية خصوصية البيانات)

Directly binding regulation · CITRA Data Privacy Protection Regulation, version 1.8, issued under Law No. 37 of 2014 as amended by Law No. 98 of 2015

In forceYes, with paperwork

Kuwait's closest thing to a general privacy law. It is a telecoms regulator's rulebook, not an act of parliament, and it binds anyone running a website, app or cloud service that handles data about people in Kuwait. Consent is the main legal basis, a child is anyone under 18, and breaches must be reported within 72 hours or 24 hours if large.

In force since 22 June 2021But only enforceable from 22 June 2022

Enforced by Communication and Information Technology Regulatory Authority

Transfer model: No restriction · Accepted routes: Explicit consent

High confidence

Cloud Computing Regulatory Framework (الإطار التنظيمي للحوسبة السحابية)

Directly binding regulation · CITRA Cloud Computing Regulatory Framework, version 2.4, Chapters 3 and 4

In forceNo — it stays put

The hard wall. Any data Kuwait classes as tier three or tier four, which includes medical records, court files, DNA and criminal fingerprints, encryption keys, state security material and even a firm's own business plans, may not be hosted or stored outside Kuwait at all.

In force since 20 September 2021But only enforceable from 20 March 2022

Enforced by Communication and Information Technology Regulatory Authority

Transfer model: Not allowed

High confidence

Data Classification Policy (سياسة تصنيف البيانات)

Government policy document · CITRA Data Classification Policy, version 2.3, listed on CITRA's regulatory register dated 16 June 2022

In forceYes, with paperwork

The rule that decides everything else. Every organisation in Kuwait, public or private, must sort its data into four sensitivity tiers, and the tier decides whether the data may leave the country. Defence and security bodies are exempt and classify as they choose.

In force since 16 June 2022

Enforced by Communication and Information Technology Regulatory Authority

Transfer model: No restriction · Accepted routes: Explicit consent

High confidence

Who you would hear from

  • الهيئة العامة للاتصالات وتقنية المعلومات (سيترا)

    Telecommunications and information technology, including the data privacy, data classification and cloud computing rulebooks. Can fine up to one million Kuwaiti dinars per violation.

    Genuinely staffed and working as a telecoms regulator: 73 regulatory decisions on its public register, the most recent dated 8 June 2026, and public consultations closing in April and June 2026. But dormant on privacy: no published data protection fine or enforcement notice, no public register of licensed cloud providers, cloud licensing absent from its published list of licensing services, and its cybersecurity pages still headline the 2017 to 2020 national strategy. A revised privacy regulation consulted on in August 2023 has still not been issued.

  • بنك الكويت المركزي

    Banks, finance and investment companies, exchange companies, electronic payment and electronic money providers. Cyber resilience, cloud approval, incident reporting and record retention.

    The one visibly active enforcer. Publishes a running penalties register with actions against local banks, exchange companies and e-payment providers dated October and November 2025, and issued a 389-page resilience framework on 3 December 2025.

  • هيئة أسواق المال

    Securities activities, licensed persons, investment funds. Record retention and information security policies, but no data-location rule of its own.

    Active. Its executive bylaw modules carry 2026 revision dates.

  • وحدة تنظيم التأمين

    Insurance and reinsurance companies and intermediaries under Law No. 125 of 2019. No insurance-specific data storage rule was found.

    Active. Publishes resolutions and announcements, including a decision in April 2026 and financial reporting in May 2026.

  • الجهاز المركزي لتكنولوجيا المعلومات

    Named in the Data Classification Policy as the body supervising implementation of CITRA's regulations and policies, and the recipient of every organisation's quarterly classification reports.

    Could not verify. Its own website did not respond from our network on 18 August 2026, so we have no evidence either way about whether it collects the quarterly reports the policy requires. This is an unverified gap, not a finding that the agency is inactive.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact commencement dates of the Data Privacy Protection Regulation, the Cloud Computing Regulatory Framework and the Cloud Service Providers rules.

    CITRA publishes these as undated scanned documents carrying only a version number. The cloud framework says it comes into force 30 days after publication in the official gazette, with a six-month grace period, but we could not reach Kuwait Al-Youm, the official gazette, from our network. The dates recorded here are inferred from the scan dates on CITRA's own files (June 2021 for the privacy regulation, September 2021 for the cloud documents) and should be treated as approximate.

  • Whether Kuwait has enacted, or is drafting, a general personal data protection statute.

    No Kuwaiti government site we could reach publishes a bill or a draft. The Kuwaiti government portal returned an access error and the gazette site did not respond. CITRA's consultation register shows only a revised privacy regulation from 2023, which is a regulator instrument rather than a statute.

  • Whether CITRA has ever issued a decision, fine or public warning under the Data Privacy Protection Regulation.

    Its public register of 73 regulatory decisions contains none on personal data, but the register may not cover individual enforcement actions. Absence of evidence, not evidence of absence.

  • Whether any cloud service provider currently holds the CITRA licence needed to host tier three and tier four data.

    No register of licensed or registered cloud providers was found on CITRA's site, and cloud licensing is not listed among its published licensing services. This matters because the rules say a provider without the licence may not serve the public or private sector at all.

  • Health sector rules issued by the Ministry of Health.

    The Ministry of Health website did not respond from our network on 18 August 2026. The health position stated here rests on the classification of medical records as tier three, which is verified, rather than on any ministry instrument, which we could not check.

  • Any compliance deadline or transition period attached to the Central Bank's Cyber and Operational Resilience Framework.

    The published framework gives a release date of 3 December 2025 but we found no stated implementation deadline in the document or on the framework's page. Treat it as binding now.

  • The constitutional and parliamentary position, including the dissolution of the National Assembly and law-making by decree.

    Reported widely but not verifiable on any Kuwaiti government domain reachable from our network. It is recorded as background in the eighth answer and should not be relied on.

  • Sector-specific storage rules for insurance, securities, education, mapping and geospatial data.

    We checked the Capital Markets Authority executive bylaw and the Insurance Regulatory Unit site and found no data-location requirement, but we could not review every circular. Recorded as 'no rule found, checked 18 August 2026', not as 'there is no rule'.

  • The precise article number in Law No. 37 of 2014 that makes telephone calls and private communications confidential.

    CITRA's English-labelled copy of the law is in fact the Arabic text, and the extracted layout does not reliably preserve article numbering. The confidentiality provision is present in the text; the numbering is not asserted.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Kuwait versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.