KUWAIT Law and Practice Contributed by: Alex Saleh, Asad Ahmad, Mohammad Al Awadhi and Liana Rashid, GLA & Company
1. Legal and Regulatory Framework 1.1 Overview of Data and Privacy- Related Laws Legislation Currently in Place The Electronic Transactions Law under Law No 20 of 2014 (the “E-Transactions Law”) and its Implementing Regulations under Decision No 48 of 2014 (the “Regulations”) currently regulate the protection of private and public data of elec - tronic records such as signatures, documents and payments. The E-Transactions Law applies to electronic records, documents and information linked to civil, commercial or administrative transactions conducted via electronic methods, either in part or in full. An electronic record resulting from these transactions comprises data or informa - tion that is produced, stored, extracted or cop - ied, either entirely or partially, using electronic means on an electronic medium. In addition, the Cybercrime Law under Law No 63 of 2015 imposes fines and penalties in rela - tion to the illegal dealing or possession of per - sonal and governmental data. New Developments Regarding Data Privacy Protection Regulation The latest amendments to Law No 42 of 2021 pertaining to the Data Privacy Protection Regu - lation (DPPR) were made under Decision No 26 of 2024, and have notably narrowed the legal framework of the DPPR, which now only applies to individuals and entities operating as service providers and licensees in the telecommunica - tions sector (“Licensees”), possessing licences issued by the Kuwait Telecommunications and Information Technology Regulatory Authority (CITRA). The DPPR defines Licensees as entities
or individuals that provide telecommunications services to the public, or that manage, estab - lish or operate telecommunications networks or provide internet services for telecommunications purposes. In addition, the DPPR creates data protection obligations for Licensees engaged in the activities of collecting, processing or storing personal data – as well as the conditions neces - sary to engage in such activities. Moreover, the DPPR applies to actions involved in data storage, collection and processing per - formed inside or outside Kuwait. The CITRA regulations grant Licensees’ prospective and existing customers the right to withdraw their consent to any form of use of their personal data; upon the customer’s request, the Licen - sees must accordingly dispose of and destroy all the associated user’s data in their possession. However, it is important to note that the regula - tions do not apply to the respective state securi - ty authorities that hold data for the sole purpose of monitoring and maintaining peace, controlling existing and prospective crimes, and preventing external and internal threats to public security. Furthermore, CITRA has repealed the Data Clas - sification Policy under Decision No 34 of 2024, which previously classified data into four distinct levels to provide guidance to entities that pro - cess, store and transfer data. That said, the authors do not expect the current data protection landscape to remain this way. The authors understand that the Kuwaiti govern - ment has decided to narrow the scope of the DPPR due to the Google Cloud project, which was initiated in Kuwait in January 2024. The Google Cloud project in Kuwait is a collaboration between Google and the Kuwaiti government to build three data centres and a local office.
272 CHAMBERS.COM
Powered by FlippingBook