Data Protection and Privacy 2025

KUWAIT Law and Practice Contributed by: Alex Saleh, Asad Ahmad, Mohammad Al Awadhi and Liana Rashid, GLA & Company

User Right Protection and Regulation of Communications and IT Services (“User Guidelines”) Collection of data Under Article 2, the Licensee must prepare relevant rules and mechanisms for the sale of its service, either through means of electronic transaction or through telephone communica - tion. CITRA must approve the rules and mecha - nisms or any amendments to existing contracts of sale in advance, which includes the relevant data collection and storage. Pursuant to Article 3.16, in the case of any such amendment, the following must occur before any enforcement can take place: • the service user must be notified of the amendment 60 days before the amendment enters into force; and • the subscriber’s written approval or e-signa - ture (using the “Hawyti” application) must be obtained. Under Article 3.3, the Licensee must verify the validity of the personal information provided by the users of said services; such proof of informa - tion (in the form of civil ID, passport or driving licence) may be certified by competent govern - mental bodies. Under Article 3.4, before executing the service contract, the mechanism(s) for cancelling the service and any variation(s) to the contractual terms of service must be clearly stipulated. Under Article 3.6, the Licensee must open an electronic file in which all the information, docu - ments and complaints pertaining to any user(s) are safely stored.

Under Article 2 of the Regulations, the storage and maintenance of electronic records, inclusive of personal data, must preserve their original form, encompassing all associated original data, without compromising the quality or standard of the records. In addition, the storage of electronic records, inclusive of personal data, should align with the policies and agreements established between the parties involved in electronic trans - actions, specifying the duration for retaining and maintaining such records. Data subject rights Article 33 grants specific rights to data subjects concerning their personal data stored in elec - tronic records and processing systems main - tained by Entities. Any person with personal data stored by Entities has the right to request access to, as well as a record of, the data or information maintained by that Entity. Additionally, under Article 36, the data subject has the right to modify or delete their personal data held by any of the Entities, and may also update personal information in the event of changes. Requests for the access, modification or deletion of personal data can only be initiated by the individual to whom the data belongs or by their legal representative (Articles 25–26(1) of the Regulations). Under Article 26(2) of the Regulations, deleting stored personal data or information is only per - missible when correction is deemed necessary; in such cases, the previously stored information must be maintained without any use or handling.

277 CHAMBERS.COM

Powered by