CITRA Data Privacy Protection Regulation
CITRA Decision No. 26 of 2024 (amending or superseding Decision No. 42 of 2021)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Commencement not set.
A comprehensive regime rule binding private bodies.
As of 19 September 2026.
What it requires
- An app that is a CITRA-licensed telecommunications or information-technology service provider in Kuwait must, per secondary legal-commentary sources not yet confirmed at primary source, obtain a customer's explicit consent (or a guardian's, for a minor under 18) before collecting or processing personal data, a duty that reaches a voiceprint or faceprint like any other identifying data, since the reported consent requirement carries no category-specific qualification; this is an inference from secondary commentary, not an independently confirmed reading of the regulation's own biometric-data treatment. Kuwait has no general cross-sector personal-data statute, so an app outside CITRA's licensed scope is not currently bound by a dedicated privacy law of this kind.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Kuwait has no cross-sector data-protection statute. This regulation, issued by CITRA, applies only to CITRA-licensed telecommunications and information-technology service providers.
Per secondary sources, it requires explicit consent before collecting or processing personal data, with no category-specific qualification, a legal-guardian consent requirement for minors under 18, requires breach notification to CITRA reportedly within 72 hours, and requires appropriate technical and organizational security measures.
A DataGuidance-sourced commentary states that biometric data is "Not applicable" under Kuwait's current framework; read alongside the general, unqualified consent duty, the more likely reading is the same pattern found in Qatar and Bahrain in this batch, no distinct heightened category for biometric data, rather than biometric data falling outside the regulation's personal-data coverage altogether, but neither reading was confirmed against the regulation's own primary text: the regulation's cited PDF returns only a PDF.js viewer interface, with none of its article text extracted, and no working alternate primary-source mirror was found.
No data-subject-rights procedure (access, deletion, correction, or portability), cross-border-transfer rule, defined list of sensitive categories beyond the reported biometric commentary above, or the regulation's own enforcement and penalty structure is established here; every one of those remains unconfirmed rather than absent. No effective date is recorded here because no primary source confirming one was read; secondary trackers report 19 February 2024.
When LexLint raises it
crawls_webprocesses_biometricsprocesses_voiceprovides_telecom_services
Read the law
secondary legal-commentary trackers (Michalsons, Al Tamimi, DataGuidance/glaco.com, Securiti, Chambers)
the regulation's own text is not reproduced
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.