Data Protection and Privacy 2025

KUWAIT Law and Practice Contributed by: Alex Saleh, Asad Ahmad, Mohammad Al Awadhi and Liana Rashid, GLA & Company

• specify the purpose for collecting and pro - cessing such personal data, including pro - cessing activities for data transfers. These activities must be conducted using law - ful means and limited to the stated purpose. This applies to personal data or information in electronic records or processing systems con - cerning the professional, social, health or finan - cial status of individuals registered with these Entities. Consent may be obtained or inferred from affirmative actions indicating approval, as outlined in Article 4 of the E-Transactions Law. DPPR and the User Guidelines Licensees have notification obligations, includ - ing informing data subjects about personal data transfers outside Kuwait, pursuant to Article 4 of the DPPR. In addition, Licensees are required to establish and uphold a written privacy policy that elaborates extensively on their procedures concerning the collection and processing of personal data, including transfers as part of the processing activities. This policy should be pub - licly accessible on their website and provided to users and data subjects when entering into service contracts. 5. International Considerations 5.1 Restrictions on International Data Transfers Please see 4.4 Transfer of Personal Data in Asset Deals . 5.2 Government Notifications and Approvals Private Entities covered by the E-Transactions Law typically do not need official approval for international data transfers, unless the data

involves state or government-related informa - tion in Kuwait. Licensees may require approval from CITRA to transfer user data internationally, as indicated through consultations with CITRA. However, there is a lack of specific regulations detailing the mechanisms or conditions for such data transfers. 5.3 Data Localisation Requirements Kuwaiti law does not generally address data localisation requirements, especially after the repeal of the Data Classification Policy. How - ever, certain sector-specific examples, such as healthcare facilities, must maintain a register and database to document patient information in either written or electronic form. The facility’s management is responsible for ensuring the safety of these records, and, if the facility ceases operations or changes activities, it must provide patient files or copies upon request (Article 60 of Law No 70 of 2020 on the Medical Profession). While the law does not provide specific mecha - nisms for data transfers, it is understood from the E-Transactions Law that patient consent is required. Another example of data localisation is found in Article 80 of Law No 6 of 2010 on Labour in the Private Sector (the “Labour Law”), which man - dates that employers must maintain a dedicated file for each employee, containing essential doc - uments such as the work permit, employment contract, civil ID, and records of leave, overtime, work injuries and penalties. Similar to healthcare facilities, this law does not address mechanisms for data transfers but also implies that consent may be required under the E-Transactions Law.

281 CHAMBERS.COM

Powered by