Law / Kuwait

Kuwait

4 of 8 named instruments researched to a stage, across four of the six areas of law we track: 3 in force and 1 enacted but not yet in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 1
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law1 instrument, 1 enacted but not yet in force

Research summary (241 words)

Kuwait's data-protection posture is a CITRA (Communications and Information Technology Regulatory Authority) regulation, most recently Decision No. 26 of 2024 (amending or superseding an earlier Decision reported variously as No. 42 of 2021), not a comprehensive statute, and it applies only to CITRA-licensed telecommunications and information-technology service providers, not to the private sector generally.

Coverage here is deliberately thin and its confidence low: the regulation's cited PDF at citra.gov.kw returns only a PDF.js viewer interface, made of the reader's own menu, toolbar and dialog strings, with none of the regulation's own article text extracted, and no alternate primary-source mirror is located.

Every substantive finding below is therefore secondary sourced, drawn from converging legal-commentary trackers, and not confirmed against the regulation's own text; no verbatim quotation of an operative article is available, so no data-subject-rights procedure, cross-border-transfer rule, defined list of sensitive categories, or enforcement and penalty structure beyond CITRA's role as regulator is established here, one way or the other.

A DataGuidance-sourced commentary states directly that biometric data is "Not applicable" under Kuwait's current framework; the more likely reading, by analogy to Qatar and Bahrain in this batch, is that this reports the absence of a distinct heightened category for biometric data rather than the absence of any coverage at all, since the same secondary sources report an unqualified consent duty for personal data generally that would ordinarily reach an identifying biometric characteristic, but there is no primary-source confirmation either way.

Comprehensive regime

CITRA Data Privacy Protection Regulation

CITRA Decision No. 26 of 2024 (amending or superseding Decision No. 42 of 2021)secondary legal-commentary trackers (Michalsons, Al Tamimi, DataGuidance/glaco.com, Securiti, Chambers)

Commencement not set. Binds private bodies.

What this law does

Kuwait has no cross-sector data-protection statute. This regulation, issued by CITRA, applies only to CITRA-licensed telecommunications and information-technology service providers.

Per secondary sources, it requires explicit consent before collecting or processing personal data, with no category-specific qualification, a legal-guardian consent requirement for minors under 18, requires breach notification to CITRA reportedly within 72 hours, and requires appropriate technical and organizational security measures.

A DataGuidance-sourced commentary states that biometric data is "Not applicable" under Kuwait's current framework; read alongside the general, unqualified consent duty, the more likely reading is the same pattern found in Qatar and Bahrain in this batch, no distinct heightened category for biometric data, rather than biometric data falling outside the regulation's personal-data coverage altogether, but neither reading was confirmed against the regulation's own primary text: the regulation's cited PDF returns only a PDF.js viewer interface, with none of its article text extracted, and no working alternate primary-source mirror was found.

No data-subject-rights procedure (access, deletion, correction, or portability), cross-border-transfer rule, defined list of sensitive categories beyond the reported biometric commentary above, or the regulation's own enforcement and penalty structure is established here; every one of those remains unconfirmed rather than absent. No effective date is recorded here because no primary source confirming one was read; secondary trackers report 19 February 2024.

What it requires

Scraping law1 instrument, 1 in force

Research summary (176 words)

Kuwait has no scraping-specific statute.

Article 37 of the Electronic Transactions Law (Law No. 20 of 2014) criminalises illegitimately logging in to an electronic data processing system, preventing access to it, damaging it, or obtaining credit-card or other electronic-card numbers from it, with imprisonment of up to three years and a fine of between five thousand and twenty thousand Kuwaiti dinars; on a plain reading, none of those four acts describes a scraper reading a public, unauthenticated page without defeating a security measure.

Two further named leads for this topic, the Cybercrime Law (Law No. 63 of 2015 on Combating Information Technology Crimes) and the Copyright Law (Law No. 75 of 2019 on Copyright and Related Rights), are not addressed here: the only located copy of the Cybercrime Law requires a paid subscription that shows its title and table of contents but not its articles, and the only located copy of the Copyright Law is an Official Gazette scan whose extracted text is too corrupted, with letters missing from ordinary words, to support a quoted provision.

Computer misuse

Electronic Transactions Law, Unauthorised Access to an Electronic Data Processing System

Electronic Transactions Law (Law No. 20 of 2014), art. 37, unauthorised access to electronic data processing systemOfficial English translation of the Electronic Transactions Law (Law No. 20 of 2014), Kuwait Direct Investment Promotion Authority (KDIPA)

In force. Binds public and private bodies.

What this law does

Article 37 criminalises, for any person, deliberately and illegitimately logging in to an electronic data processing system, preventing access to it, causing it damage, or obtaining credit-card or other electronic-card numbers from it to steal funds, alongside separate clauses on unlicensed electronic-authentication services and forged or defective electronic signatures.

The offence carries imprisonment of up to three years and a fine of between five thousand and twenty thousand Kuwaiti dinars, or either penalty. The public prosecution alone has jurisdiction to investigate and pursue the offence, so it creates no private civil claim. Article 46 ties the law's own commencement to the date of its publication in the Official Gazette rather than to the date it was signed, and the source read for this entry carries only the signing date.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (955 words)

Kuwait's one located standalone security-baseline instrument is the Data Classification Policy (version 2.3), issued by the Communication and Information Technology Regulatory Authority (CITRA) and listed among CITRA's own 'Regulations and Decisions' with a listing date of 16 June 2022.

The policy describes its own scope as a methodology for data classification for the public and private sectors, and directs 'the data owner', any individual, government entity, or private company that owns data and has authority to process it, to classify all digital data it holds into at least four sensitivity tiers (Public Data, Private Insensitive Data, Private Sensitive Data, and Highly Sensitive Data), with entities of a security or military nature excluded from the four-tier scheme and free to classify their own data as they see fit.

Once classified, the data owner must encrypt Tier 3 and Tier 4 data during transmission between locations, maintain a unified data catalog with metadata standards, and ensure Tier 3 and Tier 4 data is transferred off or removed from a data center's or server's storage before that equipment is decommissioned.

The policy also assigns roles: senior management must form a data classification team headed by the entity's Director of Information Security and Director of Information Technology alongside the departments that own data, direct employees to report any breach of the policy immediately, and record breaches with corrective action taken; CITRA's own role is to issue related guidelines, monitor public and private sector compliance, and coordinate with the Central Agency for Information Technology (CAIT) for quarterly compliance reporting from government entities.

No penalty, civil or criminal, for a private sector data owner's non-compliance appears anywhere in the policy's own text, so the instrument, read in full, stands as researched but toothless on its own; whether CITRA's general regulatory or licensing power under its establishment law (Law No. 37 of 2014, as amended by Law No. 98 of 2015) separately supplies a sanction was not independently traced.

CITRA's 'Laws and Regulations' index lists further resolutions and decisions across additional pages beyond the one read here; the visible page, sorted newest first back to March 2022, names no other title suggesting a product-security, vulnerability-reporting, or further baseline-security regulation beyond the Data Classification Policy. Whether an earlier or later regulation on an unread page carries one could not be confirmed and is recorded here as a gap, not as a finding that none exists.

CITRA separately runs a 'Cybersecurity and Emergency Response' programme naming a National Cybersecurity Strategy for the State of Kuwait (2017-2020), a set of pandemic era circulars (a security policy for operating electronic applications during the COVID-19 emergency, security controls for remote work during the pandemic, a joint initiative with Cisco Systems to secure government remote work), and a general 'application security service'; none of these reads as a currently binding, generally applicable regulation, and no product-security or incident-reporting duty running to a private business on any clock was found among them.

The Central Bank of Kuwait (CBK) separately operates a Cyber and Operational Resilience Framework (CORF), which CBK's own page describes as the next evolution from the 'foundational cybersecurity compliance' its earlier Cybersecurity Framework (2020) established, moving to a 'Resilience-first' and 'Maturity-oriented' regulatory model from 2025.

It binds CBK's own 'Regulated Entities': Kuwaiti banks (conventional, Islamic, and specialized) and foreign bank branches, finance companies, investment companies, exchange companies, credit information companies, and e-payment companies, providers, and operators.

None of those bound-party classes, a licensed bank or a licensed financial services provider, is an activity this corpus's vocabulary can currently express, so this regime is recorded here rather than raised against a declared activity, the same treatment this profile gives DORA's financial entities and New York's Department of Financial Services Part 500 covered entities.

CORF's own operative text, as distinct from the CBK page describing it, was not located at a reachable URL, and a 'Penalties' item CBK's supervision navigation lists alongside CORF was not independently read.

Kuwait's Cybercrime Law (Law No. 63 of 2015 on Combating Cybercrimes) is already this jurisdiction's scraping topic instrument for its unauthorized access offences. Its table of contents lists only two chapters, Definitions (Article 1) and Offences and Penalties (Articles 2 through 21), with no separate chapter of operator facing duties, confirming no additional security topic provision sits inside it beyond what the scraping topic already holds.

The Electronic Transactions Law (Law No. 20 of 2014, as later amended by Decree Law No. 148 of 2025), also already the scraping topic's instrument for its own unauthorized access provision, runs eight chapters; its only security adjacent language sits in Chapter Seven, 'Privacy and Data Protection' (Articles 32 through 36), where Article 36 requires the bodies holding the personal data Article 32 registers to take the appropriate measure to protect that personal data and information against loss, damage, disclosure, replacement with incorrect data or information, or addition of untrue information, a controller's safeguards clause addressed to personal data inside a privacy chapter rather than a standalone security duty, the same shape as General Data Protection Regulation (GDPR) Article 32, so it belongs with this jurisdiction's privacy row rather than being filed here a second time.

The same Law's electronic payment chapter (Article 31) gives the Central Bank authority to issue instructions to banking and financial institutions on electronic payment regulation, consistent with the statutory root of CBK's CORF and its predecessor Cybersecurity Framework named above.

CITRA's own Data Privacy Protection Regulation, already this jurisdiction's privacy topic instrument, could not be independently re-read here to check for a further, separable security duty beyond its data protection safeguards clause: its PDF returned no extractable text when read, a known extraction limit rather than evidence the document does not exist, so that check from the topic checklist's sixth dimension was not completed.

Security baseline statutes

Data Classification Policy

Data Classification Policy, version 2.3 (Communication and Information Technology Regulatory Authority, listed 16 June 2022)Official PDF text, Communication and Information Technology Regulatory Authority (CITRA) legal references library, read in full

In force since 16 June 2022. Binds public and private bodies.

What this law does

This policy outlines a methodology for data classification for the public and private sectors. The data owner shall classify their data into at least four levels. Entities of a security or military nature of the country are excluded from adherence to the classification levels specified in this policy, and they have the option to classify their data as they see appropriate.

The data owner must encrypt all classified data that falls under Tier 3 and Tier 4 during transmission from one government entity to another, or when transmitted between different physical geographical locations of government entities; this applies to the private sector as well.

The data owner must ensure that all data classified according to the third and fourth levels are transferred or removed from data centers and servers before the disposition of the equipment of data centers and servers hosting the data. The data owner is required to create and maintain a data catalog which should include the metadata information and standards for its data in a unified format. This catalog should also be updated periodically.

The entity or company must form a data classification team headed by the senior management or their representatives, with the membership of each of the director of information security department, the director of the information technology department, in addition to the directors of the various departments who own data, whether the data is personal and pertains to subscribers or it is the entity or company data.

Directing the entity's employees to immediately report any breach in the implementation of this policy. Record breaches and take corrective actions. Issue policies and guidelines related to information and communication technology. Monitor the public and private sectors entities in implementing the policies and guidelines issued by the authority to ensure compliance.

Request periodic reports from the Central Agency for Information and Technology (CAIT) to analyze and measure the compliance and implementation of government entities with this policy. No penalty, civil or criminal, for non-compliance appears anywhere in the policy's own text.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (227 words)

Kuwait has no press-publisher neighbouring right, no mandatory platform-to-publisher bargaining regime, and no hot-news or misappropriation doctrine distinct from ordinary copyright law.

The general copyright framework, Law No. 75 of 2019 on Copyright and Related Rights, art. 31, permits quotation of passages from a published work in another work, consistent with fair practice, non-substantial in extent and to the extent justified by the purpose, with the source and author's name cited, and states that this reaches press summaries taken from newspapers and periodicals.

Article 31 separately permits, without the author's permission, transferring or copying newspaper and periodical articles on current topics (or broadcast works of a similar character) with clear source and author attribution where known, and permits newspapers, periodicals, and broadcasting entities to publish excerpts from an author's lawfully available works and published articles on matters of current public interest without permission or compensation, subject to source attribution, unless the author prohibited this at the time of publication.

Neighbouring rights under the same law, read elsewhere in its text, run to performers rather than to a print or online news publisher, so no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates was located. No provision addressing a machine-readable text-and-data-mining reservation, or the status of a hyperlink as a communication to the public, was located in the reviewed text.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.