Data Protection and Privacy 2025

KUWAIT Law and Practice Contributed by: Alex Saleh, Asad Ahmad, Mohammad Al Awadhi and Liana Rashid, GLA & Company

3.3 Rights and Obligations Under Applicable Data Regulation The E-Transactions Law Consent

tions on individuals and on public, governmen - tal and private entities in the State of Kuwait who subscribe to cloud services hosting certain types of data. The CITRA Law applies to CITRA, its personnel and licensees. 3.2 Interaction of Data Regulation and Data Protection Kuwait Law No 8 of 2016 on the Regulation of Electronic Media (the “Electronic Media Law”) applies to and regulates various online plat - forms, including: • news agencies; • news services; • websites offering electronic commercial advertisements; and • the digital presence of print newspapers and satellite channels. • electronic publishers; • electronic journalism; However, the law does not apply to person - al domains, websites, outlets or electronic accounts that are not operated by individuals with specialised professional expertise. Notably, the Electronic Media Law specifies that the name of the website or media outlet must not violate public order or morals or be identical to an exist - ing site. Thus, media regulation under Kuwaiti law seems to be restricted to media channels that are not privately owned. On the other hand, the data protection requirements under the E-Transactions Law or the DPPR would apply to both private companies and entities offering services to the public.

Under Article 4, individuals are generally not obliged to deal by electronic means except with their consent, and such consent may be inferred through affirmative conduct indicating approval. Under Article 32, when collecting data (includ - ing personal data and data related to individuals’ professional affairs, social status, health status or financial status), government authorities, public authorities and institutions, companies, non-governmental entities or their employees (“Entities”) are explicitly mandated to secure individuals’ consent and to state the purpose behind collecting such data. Under Articles 32 and 35, Entities must also ensure that consent is obtained when conduct - ing any access, disclosure, sharing or process - ing of the collected data. These activities must be undertaken by lawful means and be limited to the stated purpose provided to data owners. This is a requirement that pertains to personal data or information stored in electronic records or processing systems that relates to the pro - fessional affairs, social status, health status or financial status of individuals that are registered Under Article 35, Entities are required to regu - larly verify and update the accuracy of personal data or information stored on their electronic records or processing systems. They must also implement appropriate measures to safeguard the collected or stored personal data and infor - mation stored on their electronic records or pro - cessing systems. with the Entities. Data protection

276 CHAMBERS.COM

Powered by