Skip to content
Regulation Guide
🇰🇼

Kuwait Data Protection Compliance Guide

Kuwait has no single data protection law. It has three instruments, criminal penalties, and no data protection authority — which changes what compliance means here.

3 Instruments

Instead of One Law

Up to 3 Years

Imprisonment Exposure

None

National Data Authority

Overview

Kuwait is the GCC state without an omnibus data protection statute, and that absence is routinely misread as an absence of obligation. It isn't. Three instruments carry the weight instead. Law No. 20 of 2014 on Electronic Transactions — the e-commerce law — prohibits collecting or processing information without the consent of the person concerned, and requires that personal data be kept accurate and protected. Law No. 63 of 2015 on Combating Information Technology Crimes covers unauthorised access to data. And CITRA's Data Protection Regulation No. 26 of 2024, which replaced No. 42 of 2021, sets consent, transparency and breach-notification duties on licensed service providers. What makes Kuwait different in practice is not the standard but the enforcement route: there is no national data protection authority to open a file, negotiate remediation, or issue an administrative fine first. The consent obligation sits in a criminal statute, so the exposure is prosecution rather than a regulator's letter.

Key Requirements

Consent Before Collection

The Electronic Transactions Law prohibits collecting or processing information without the consent of the person concerned. This applies to your store whether or not you hold a CITRA licence.

Full Disclosure at the Point of Consent

CITRA's 2024 regulation requires explicit consent given with full disclosure of the conditions and obligations attached — not a bare notice that data is collected.

Accuracy and Updating

Personal data must be verified and kept current. Stale records are a compliance problem, not just a data-quality one.

Protective Measures

Apply real security controls. The cybercrime law makes unauthorised access to data a serious offence, which puts your safeguards in the frame when a breach happens.

A Route to Modify or Delete

Tell users how to request modification or deletion of their data, and make that route work.

24-Hour Breach Notification

Licensed service providers must report a data breach to CITRA within 24 hours. If there is any chance the definition reaches you, build for 24 hours rather than 72.

Penalties for Non-Compliance

Kuwait's penalties are criminal rather than administrative, which is the practical difference from every other Gulf regime.

Electronic Transactions Law

Up to three years' imprisonment and a fine of not less than KWD 5,000 for unlawful collection or processing.

Cybercrime Law

Up to ten years' imprisonment and fines of KWD 5,000 to KWD 20,000 for unauthorised access to data.

CITRA Measures

For licensed service providers, CITRA can act under the powers in its establishing law, including against the licence itself.

No Administrative First Step

There is no national data protection authority to issue a warning and a remediation window. The route runs through prosecutors, so there is no early, cheap stage to fix things in.

How Arqam360 Helps

Consent Before Any Collection

Trackers are blocked until the visitor chooses, so no personal data is collected before the consent the Electronic Transactions Law requires exists.

Disclosure That Is Actually Read

Each category states what it collects and why, in Arabic and English, which is what a full-disclosure standard is asking for.

Modify or Delete, Self-Service

Visitors can reopen their choices and withdraw at any time, and data-subject requests have somewhere to land.

A Record You Can Produce

Timestamped consent logs, exportable. With no regulator to mediate, contemporaneous evidence is what you have.

Enforcement Timeline

2014

Electronic Transactions Law

Law No. 20 of 2014 and its Executive Regulations (Decision No. 48 of 2014) introduce a consent requirement for collecting and processing information — Kuwait's closest thing to a general data protection rule.

2015

Cybercrime Law

Law No. 63 of 2015 on Combating Information Technology Crimes makes unauthorised access to data a serious criminal offence, with penalties well above the e-commerce law's.

2024

CITRA Regulation No. 26

CITRA's Data Protection Regulation No. 26 of 2024 replaces No. 42 of 2021, tightening consent, transparency and breach reporting for licensed service providers — and leaving its own scope contested.

Check What Your Site Collects Before Consent

Scan your site free. See which trackers collect visitor data before anyone agrees to it — the thing Kuwait's consent rule is actually about.

Run a Free Scan

Last updated:

FAQ

Kuwait Data Protection FAQ

Straight answers about a framework that has no single law to point at.

Not an omnibus one, and no national data protection authority. Three instruments do the work instead: the Electronic Transactions Law No. 20 of 2014, the Cybercrime Law No. 63 of 2015, and CITRA's Data Protection Regulation No. 26 of 2024. The absence of a single statute is not an absence of obligation — the consent requirement is real and sits in a criminal law.

Get Consent Right in Kuwait

Consent before collection, disclosed per purpose, in Arabic and English, with a record you can produce. Free forever on one domain.