Skip to the content
Global Data RulesData governance rules, country by country

Kuwait

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Kuwait — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Dormant

Kuwait has no single privacy law. The telecoms regulator's rules fill the gap. They apply to anyone running a website or app for people in Kuwait. You can send ordinary personal data abroad if you tell the person first and they agree. But some data must sit on servers inside Kuwait. That covers medical records, court files, DNA and criminal fingerprints, and anything sensitive a company holds.

Data governance in Kuwait

The eight things that decide how you handle data about people in Kuwait. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The rules reach a foreign company with no office in Kuwait. They apply to anyone who runs a website, a smart application or a cloud service. If you collect or handle personal data about people in Kuwait, you are covered. It does not matter where you do the work. There is no size or revenue floor to duck under. If your company sits outside Kuwait, you must record who your local contact is, alongside your data protection officer.

What you have to do here:
Appoint a representative · Appoint a data protection officer

Where the data is allowed to live

It depends on how sensitive the data is. Kuwait sorts all data into four tiers. Tiers one and two cover names, contact details, civil identity numbers and similar. You can send those abroad once you tell the person and get their written agreement. Tiers three and four cannot leave at all. That ban is absolute. Not permanently, not temporarily, not for any purpose.

What to do: Plan for a database inside Kuwait: this data is not allowed to leave.

Sending data out of the country

For data that is allowed to travel, the person decides, not the government. There is no approved-country list, no banned-country list and no standard contract to sign. You classify the data. You tell the person you intend to send it out of Kuwait. You get their written agreement saying why it is going and who is receiving it. For tier three and tier four data no paperwork helps. The answer is simply no.

What you have to do here:
Put a transfer safeguard in place · Tell people what you do
Ways to send data out:
Explicit consent

The regulator, and whether it actually acts

On paper it is the Communication and Information Technology Regulatory Authority, known as CITRA. It can fine up to one million Kuwaiti dinars per breach, roughly three and a quarter million US dollars. But it acts as a busy telecoms regulator and a silent privacy regulator. It issued regulatory decisions as recently as June 2026. We found no published privacy fine, no register of licensed cloud providers and no enforcement notice under the privacy rules. The Central Bank of Kuwait is the one authority visibly punishing firms.

What it costs if you get it wrong:
Fixed maximum fine
Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

There is a firm ceiling and several firm floors, and they collide. The ceiling: you must destroy someone's personal data once your contract with them ends. You must destroy it earlier if they withdraw consent or ask you to. The floors: payment and electronic money firms must keep records for ten years after the relationship ends. Money-laundering records run for five years. Investment firms keep complaint and business-continuity records for five years. Kuwait gives no rule for resolving the clash.

What you have to do here:
Delete data after a period · Keep data for a minimum period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count the clocks, because there are at least four and the fastest is one hour. If a leak harms a large number of users you have 24 hours to tell the regulator, the affected users and the police. Every other personal data breach gets 72 hours to the regulator and 72 hours to the affected person. Cloud providers get 72 hours to warn their customers. And if you are supervised by the Central Bank, a serious incident must be reported within one hour of discovery.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that ruin weekends. First, a child in Kuwait is anyone under 18, and you need the guardian's explicit consent. Second, the ban on sending data abroad also swallows your own business plans, meeting minutes and internal project reports. Kuwait puts them in the same box as medical records. Third, if you host that box you need a Kuwaiti licence and a data centre physically in Kuwait. Fourth, you owe a round-the-clock contact person. Fifth, the police get told about big leaks.

What you have to do here:
Get a parent's consent for children · Appoint a data protection officer · Do not hand data to foreign authorities on demand

What's changing next

Nothing starts on a fixed date in the next twelve months. But three things are queued. A replacement privacy regulation has been sitting finished since a public consultation closed in October 2023. It could be issued at any time. A guide on adopting artificial intelligence closed consultation in April 2026. A regulation on the rights of telecoms and technology users closed consultation in June 2026. Banks are absorbing the Central Bank's new resilience rulebook, issued in December 2025.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Cloud Service Providers Regulations and Commitments (لوائح والتزامات مزودي الخدمات السحابية) and Cloud First Policy · CITRA Cloud Service Providers Regulations and Commitments, version 1.7, read with the Cloud First Policy · Licence condition

In forceNo — it stays put

No cloud provider may contract with the Kuwaiti public sector, or host sensitive data for anyone, without CITRA permission. To host the sensitive tiers it must own a data centre inside Kuwait. We found no published list of licensed providers, so treat the approval route as untested.

In force since 20 September 2021Enforced from 20 March 2022

Enforced by Communication and Information Technology Regulatory Authority

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.
Banking

Cloud and outsourcing rules (Banking)

Official name: Cyber and Operational Resilience Framework (CORF) · Central Bank of Kuwait, Cyber and Operational Resilience Framework for All Local Banks and Financial Institutions, version 1.0 · Regulator directive

In forceYes, with paperwork

The Central Bank's 389-page resilience rulebook was issued in December 2025. It is the only Kuwaiti rulebook with European-style privacy principles and a real enforcer behind it. It does not ban sending data abroad. But it requires the Central Bank's approval a month before any cloud deal touching customer data.

In force since 3 December 2025

Enforced by Central Bank of Kuwait

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Payments

Cloud and outsourcing rules (Payments)

Official name: Instructions for Regulating the Electronic Payment of Funds · Central Bank of Kuwait Circular No. 2/BS, IBS, FS, IFS, ES, PS/524/2023 · Regulator directive

In forceYes, with paperwork

Payment, electronic money and payment infrastructure firms must keep every record for ten years after the relationship ends. They must also get the Central Bank's written approval before putting anything material on a cloud service. There is no rule forcing payment data to stay in Kuwait.

In force since 1 January 2023

Enforced by Central Bank of Kuwait

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Applies to every company3 rules

These bind you whatever business you are in, once the country's rules reach you.

Cloud and outsourcing rules

Official name: Data Privacy Protection Regulation (لائحة حماية خصوصية البيانات) · CITRA Data Privacy Protection Regulation, version 1.8, issued under Law No. 37 of 2014 as amended by Law No. 98 of 2015 · Directly binding regulation

In forceYes, with paperwork

This is Kuwait's closest thing to a general privacy law. It is a telecoms regulator's rulebook, not an act of parliament. It binds anyone running a website, app or cloud service that handles data about people in Kuwait. Consent is the main legal basis. A child is anyone under 18. You must report a breach within 72 hours, or within 24 hours if it is large.

In force since 22 June 2021Enforced from 22 June 2022

Enforced by Communication and Information Technology Regulatory Authority

How this country controls where data goes: No restriction · Accepted routes: Explicit consent

Personal data must stay in the country

Official name: Cloud Computing Regulatory Framework (الإطار التنظيمي للحوسبة السحابية) · CITRA Cloud Computing Regulatory Framework, version 2.4, Chapters 3 and 4 · Directly binding regulation

In forceNo — it stays put

Some data may never leave Kuwait. Anything Kuwait classes as tier three or tier four may not be hosted or stored outside the country at all. That covers medical records, court files, DNA and criminal fingerprints, encryption keys, state security material, and even a firm's own business plans.

In force since 20 September 2021Enforced from 20 March 2022

Enforced by Communication and Information Technology Regulatory Authority

How this country controls where data goes: Not allowed

State and security data rules

Official name: Data Classification Policy (سياسة تصنيف البيانات) · CITRA Data Classification Policy, version 2.3, listed on CITRA's regulatory register dated 16 June 2022 · Government policy document

In forceYes, with paperwork

This is the rule that decides everything else. Every organisation in Kuwait, public or private, must sort its data into four sensitivity tiers. The tier decides whether the data may leave the country. Defence and security bodies are exempt and classify as they choose.

In force since 16 June 2022

Enforced by Communication and Information Technology Regulatory Authority

How this country controls where data goes: No restriction · Accepted routes: Explicit consent

Who you would hear from

  • الهيئة العامة للاتصالات وتقنية المعلومات (سيترا)

    Telecommunications and information technology, including the data privacy, data classification and cloud computing rulebooks. Can fine up to one million Kuwaiti dinars per violation.

    Staffed and working as a telecoms regulator. Its public register holds 73 regulatory decisions, the most recent dated 8 June 2026. Public consultations closed in April and June 2026. But quiet on privacy. No published data protection fine or enforcement notice. No public register of licensed cloud providers. Cloud licensing is absent from its published list of licensing services. Its cybersecurity pages still lead with the 2017 to 2020 national strategy. A revised privacy regulation consulted on in August 2023 has still not been issued.

  • بنك الكويت المركزي

    Banks, finance and investment companies, exchange companies, electronic payment and electronic money providers. Cyber resilience, cloud approval, incident reporting and record retention.

    The one visibly active enforcer. It publishes a running penalties register, with actions against local banks, exchange companies and electronic payment providers dated October and November 2025. It issued a 389-page resilience rulebook on 3 December 2025.

  • هيئة أسواق المال

    Securities activities, licensed persons, investment funds. Record retention and information security policies, but no data-location rule of its own.

    Active. Its executive bylaw modules carry 2026 revision dates.

  • وحدة تنظيم التأمين

    Insurance and reinsurance companies and intermediaries under Law No. 125 of 2019. No insurance-specific data storage rule was found.

    Active. Publishes resolutions and announcements, including a decision in April 2026 and financial reporting in May 2026.

  • الجهاز المركزي لتكنولوجيا المعلومات

    Named in the Data Classification Policy as the body supervising implementation of CITRA's regulations and policies, and the recipient of every organisation's quarterly classification reports.

    We could not verify what this agency does. We have no evidence either way on whether it collects the quarterly reports the policy requires. Treat this as unchecked, not as a sign that the agency is inactive.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact commencement dates of the Data Privacy Protection Regulation, the Cloud Computing Regulatory Framework and the Cloud Service Providers rules.

    CITRA publishes these as undated scanned documents carrying only a version number. The cloud rules say they come into force 30 days after publication in the official gazette, with a six-month grace period. We could not confirm the date in Kuwait Al-Youm, the official gazette. The dates recorded here come from the scan dates on CITRA's own files: June 2021 for the privacy regulation, September 2021 for the cloud documents. Treat them as approximate.

  • Whether Kuwait has enacted, or is drafting, a general personal data protection statute.

    We found no bill and no draft on any Kuwaiti government site. CITRA's consultation register shows only a revised privacy regulation from 2023. That is a regulator's rulebook, not a law passed by parliament. If a general privacy law matters to your plans, check with Kuwaiti counsel.

  • Whether CITRA has ever issued a decision, fine or public warning under the Data Privacy Protection Regulation.

    CITRA's public register of 73 regulatory decisions contains none about personal data. The register may not cover individual enforcement actions. We found no privacy fine, but that does not prove there has never been one.

  • Whether any cloud service provider currently holds the CITRA licence needed to host tier three and tier four data.

    We found no register of licensed or registered cloud providers on CITRA's site. Cloud licensing is not listed among its published licensing services. This matters, because the rules say a provider without the licence may not serve the public or private sector at all. Ask any provider to show you its licence.

  • Health sector rules issued by the Ministry of Health.

    We could not check the Ministry of Health's own rules. The health position here rests on medical records being tier three, which is confirmed. If you work in health, check with the ministry before you rely on this.

  • Any compliance deadline or transition period attached to the Central Bank's Cyber and Operational Resilience Framework.

    The published document gives a release date of 3 December 2025. We found no compliance deadline in the document or on its page. Treat it as binding now.

  • The constitutional and parliamentary position, including the dissolution of the National Assembly and law-making by decree.

    This is reported widely, but we could not confirm it on any Kuwaiti government website. It is recorded as background in the eighth answer. Do not rely on it.

  • Sector-specific storage rules for insurance, securities, education, mapping and geospatial data.

    We checked the Capital Markets Authority executive bylaw and the Insurance Regulatory Unit site and found no rule about where data must be held. We could not review every circular. This is a 'no rule found on 18 August 2026', not proof that no rule exists.

  • The precise article number in Law No. 37 of 2014 that makes telephone calls and private communications confidential.

    CITRA's English-labelled copy of the law is in fact the Arabic text. The extracted layout does not reliably preserve article numbering. The confidentiality rule is present in the text. We do not assert the article number.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.