Data Protection and Privacy 2025

KUWAIT Law and Practice Contributed by: Alex Saleh, Asad Ahmad, Mohammad Al Awadhi and Liana Rashid, GLA & Company

Obligations in dealing with information In accordance with the regulations concerning PaaS and SaaS model providers in Article 2, the CSP must describe to the user all information that needs to be collected and inform them as to what information will be collected automatically (as well as where to access and amend such information). Following data collection, the CSP must explain to the user where and how such information may be used. The CSP may not use this information to locate the identity of the user. The CSP must also inform users of any third-party providers that operate certain services on their behalf – and of their privacy policies – for the purpose of maintaining transparency. The CSP commits to not share, dispose of or sell the user’s informa - tion with third parties; however, for purposes of improving the service and customer experience, they may be granted access to the user’s name, address, phone number and email. In any case, the user must be informed of such. The user must be notified immediately of any data relocation to new owners as a result of M&A, liquidation or dissolution. The CSP must be efficient, competent and equipped to detect any fraud, security threats or technical problems. The subscriber has the right to request the amendment or deletion of their personal data available to third parties or to the CSP. The CSP must also provide clear mechanisms to users for communication regarding the privacy policy. SaaS model providers must specify in their pri - vacy policy the targeted age group for the collec - tion of data. If the targeted age group is minors, the consent of their guardian must be obtained.

The service must abide by any relevant child protection laws of the state. 3.4 Regulators and Enforcement Besides CITRA and CAIT, the Electronic and Cyber Crime Combating Department (ECCCD) is a specialised department within the Minis - try of Interior in Kuwait that is responsible for enforcing Kuwait’s cybercrime laws and inves - tigating cyber-related crimes. The ECCCD’s main focus is to protect Kuwait’s economy and national security – along with the well-being of its citizens and residents – by combating cyber - crime and enhancing cybersecurity. The ECCCD is responsible for receiving complaints related to cybercrime, conducting investigations and working with other governmental and non-gov - ernmental organisations to combat cyberthreats. The department is also responsible for raising awareness about cyberthreats and providing guidance on how to stay safe online.

4. Sectoral Issues 4.1 Use of Cookies

Pursuant to the Cloud Computing Regula - tory Framework, a CSP must contain a clause labelled “Cookies” in its privacy policy, which determines the mechanisms of usage when it comes to:

• log-in authentication; • security inferences; • advertisements; and • personal identification.

The CSP may not use this data to locate the identity of the user and must always make avail- able the types of cookies used by it or by exter - nal parties on any platform on which the service operates.

279 CHAMBERS.COM

Powered by