Doing Business In..._2026

KUWAIT Law and Practice Contributed by: Sam Habbas, Luis Cunha, Hisham Al-Quraan and Mustafa Sayed, ASAR – Al Ruwayeh & Partners

8. Data Protection 8.1 Applicable Regulations Data protection considerations and restrictions are addressed in various laws of Kuwait, including: • the Kuwaiti Constitution; • the Electronic Transactions Law (the “ET Law”); • Law No 37 of 2014 on the Establishment of the Communications and Information Technology Regulatory Authority (CITRA); • the Evidence Law; • the Right to Access Information Law and its imple - menting regulations; • Law No 9 of 2019, Concerning the Exchange of Credit Information and its implementing regula - tions; • various resolutions/regulations issued by CITRA, such as: (a) CITRA Resolution No 26 of 2024 on the Regu - lations of Data Privacy Protection (DPR); and (b) the Cloud Computing Regulatory Framework (“Cloud Regulations”) issued by CITRA; • Decree No 37 of 2022 regarding the establishment of the National Cyber Security Center (NCSC); and • various resolutions/regulations issued by the NCSC, such as: (a) Resolution No 35 of 2023, “Concerning the National Framework for Cybersecurity Govern - ance”; (b) Resolution No 1 of 2025, “Concerning the National Framework for Cybersecurity Govern - ance”; and (c) Resolution No 2 of 2026 “Concerning the National Controls for Cybersecurity.”With respect to data protection generally, the ET Law applies to all records and information recorded electronically relating to civil, com - mercial and administrative transactions, unless the parties agree otherwise. Regarding the collection, use and disposal of personal infor - mation, the ET Law provides that, except as otherwise authorised, all government and pri - vate entities may not unduly or illegally disclose any personal data documented in electronic form unless and until it has been agreed to by the data subject. These restrictions on the col - lection, use and disposal of personal data and

items that may be considered as personal data are further expanded upon in the provisions of the DPR and the Cloud Regulations. However, the DPR and Cloud Regulations are more spe - cific in the application and considered sectoral resolutions that apply only to regulated entities which are operating in the telecommunications sector (mobile network operators, ISPs, cloud service providers, etc). 8.2 Geographical Scope Companies that are doing business “in” Kuwait are typically required to abide by Kuwaiti laws, regard - less of whether or not they have a physical presence in Kuwait; such laws include the ET Law. While this is decided on a case-by-case basis, the likelihood of the foreign entity being subject to Kuwait’s laws increas - es according to the strength of the link between the activities of the foreign entity and Kuwait. Having not - ed this, there are restrictions on the export of certain government and sensitive information (although these points are currently being looked into and new reforms are expected). 8.3 Role and Authority of the Data Protection Agency There is no particular agency in Kuwait that is specifi - cally charged with and dedicated to enforcing Kuwaiti data protection rules. The agency that may have juris - diction will depend on the specific data protection rules that are being contravened. For instance, CITRA would be the authority in charge of overseeing the application of the DPR and Cloud Regulations when it is related to a company which is licensed by CITRA to conduct telecommunication services, while the Cen - tral Bank of Kuwait would be the primary authority in relation to entities which it may regulate (such as banks).

9. Looking Forward 9.1 Upcoming Legal Reforms

With respect to business reforms in 2026 and beyond, it is expected that a number of reforms will be issued to facilitate foreign parties seeking to do business directly in Kuwait. Perhaps the most significant of

569 CHAMBERS.COM

Powered by