Data Protection and Privacy 2025

KUWAIT Law and Practice Contributed by: Alex Saleh, Asad Ahmad, Mohammad Al Awadhi and Liana Rashid, GLA & Company

KWD20,000, or either of these penalties. This provision also covers data related to clients’ bank accounts (Article 3). Additionally, the law applies to individuals who deliberately modify or destroy electronic medical documents related to medical tests, diagnoses, care or treatment, using the internet or other information technology. Those found guilty of such actions face imprisonment for up to three years and a fine of between KWD3,000 and KWD10,000, or either of these penalties (Article 3). 1.4 Data Protection Fines in Practice Kuwait data protection regulators do not make public the details of administrative proceedings, or the history of fines imposed on entities/indi - viduals that violate applicable data protection regulations. 1.5 AI Regulation To date, Kuwait has not issued any dedicated AI legislation. That said, the authors do expect Kuwait to issue new regulations in the near future upon completion of the Google Cloud project. 1.6 Interplay Between AI and Data Protection Regulations This is not applicable, given that Kuwait has not issued any dedicated data protection legislation addressing AI issues.

telecommunications sector (specifically, those licensed by CITRA). Additionally, CITRA repealed the Data Classification Policy under Decision No 34 of 2024, which previously categorised data into four levels for processing and transfer guid - ance. 2.2 Recent Case Law To date, there have been no notable ongoing litigation cases regarding enforcement of data protection laws and regulations in Kuwait. 2.3 Collective Redress Mechanisms This topic is not applicable. 3. Data Regulation on IoT Providers, Data Holders and Data Processing Services 3.1 Objectives and Scope of Data Regulation The DPPR applies exclusively to individuals and entities serving as providers within the telecom - munications sector and holding licences issued by CITRA (“Licensees”; see 1.1 Overview of Data and Privacy-Related Laws ). The E-Transactions Law applies to private com - panies, government authorities, public institu - tions and non-governmental organisations, and to their employees. The Cybercrime Law applies to every identifiable natural person. The Cloud Computing Regulatory Framework (v2.4) issued by CITRA applies to all cloud service providers licensed by CITRA with data centres in Kuwait. Although the Framework gov - erns the licensing and other obligations of these cloud service providers, it also places obliga -

2. Privacy Litigation 2.1 General Overview

Please refer to 1.1 Overview of Data and Priva- cy-Related Laws , outlining the recent amend - ments to the DPPR under Decision No 26 of 2024, which have narrowed its scope and apply only to service providers and licensees in the

275 CHAMBERS.COM

Powered by