Law / Kuwait

Data Classification Policy

Data Classification Policy, version 2.3 (Communication and Information Technology Regulatory Authority, listed 16 June 2022)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 16 June 2022.

A security baseline statutes rule binding public and private bodies.

As of 17 September 2026.

What it requires

  • This binds a data owner in Kuwait, meaning an individual, government entity, or private company that owns data and has authority to process, amend, copy, or store it; entities of a security or military nature are excluded from this four-tier classification scheme and may classify their own data as they see fit.
  • Classify all digital data you process, store, modify, or transfer into at least four sensitivity tiers (Public Data, Private Insensitive Data, Private Sensitive Data, Highly Sensitive Data) and label it accordingly.
  • Encrypt Tier 3 (Private Sensitive) and Tier 4 (Highly Sensitive) data whenever you transmit it between physical locations.
  • Maintain a unified data catalog with metadata describing your classified data, and review the classification periodically.
  • Transfer or remove Tier 3 and Tier 4 data from a data center's or server's storage before decommissioning that equipment.
  • Form a data classification team including your information security and information technology leads, and direct employees to report immediately any breach of this classification scheme, recording it with the corrective action taken.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

No penalty provision, criminal or administrative, appears anywhere in this policy's own text, which was read in full; CITRA's own described role is compliance monitoring backed by periodic CAIT reporting from government entities, not a sanction.

Who enforces it

Enforcement body

The Communication and Information Technology Regulatory Authority (CITRA), which the policy directs to issue related policies and guidelines and to monitor public and private sector compliance, coordinating with the Central Agency for Information Technology (CAIT) for quarterly compliance reporting from government entities. No penalty clause for non-compliance appears in the policy's own text.

Settledness

As of
17 September 2026
Open questions
Does a penalty for a private sector data owner's non-compliance with this policy exist elsewhere in CITRA's general regulatory or licensing power under Law No. 37 of 2014, as amended by Law No. 98 of 2015?

What it reaches

Obligation class

Security, Governance, Retention

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

This policy outlines a methodology for data classification for the public and private sectors. The data owner shall classify their data into at least four levels. Entities of a security or military nature of the country are excluded from adherence to the classification levels specified in this policy, and they have the option to classify their data as they see appropriate.

The data owner must encrypt all classified data that falls under Tier 3 and Tier 4 during transmission from one government entity to another, or when transmitted between different physical geographical locations of government entities; this applies to the private sector as well.

The data owner must ensure that all data classified according to the third and fourth levels are transferred or removed from data centers and servers before the disposition of the equipment of data centers and servers hosting the data. The data owner is required to create and maintain a data catalog which should include the metadata information and standards for its data in a unified format. This catalog should also be updated periodically.

The entity or company must form a data classification team headed by the senior management or their representatives, with the membership of each of the director of information security department, the director of the information technology department, in addition to the directors of the various departments who own data, whether the data is personal and pertains to subscribers or it is the entity or company data.

Directing the entity's employees to immediately report any breach in the implementation of this policy. Record breaches and take corrective actions. Issue policies and guidelines related to information and communication technology. Monitor the public and private sectors entities in implementing the policies and guidelines issued by the authority to ensure compliance.

Request periodic reports from the Central Agency for Information and Technology (CAIT) to analyze and measure the compliance and implementation of government entities with this policy. No penalty, civil or criminal, for non-compliance appears anywhere in the policy's own text.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official PDF text, Communication and Information Technology Regulatory Authority (CITRA) legal references library, read in full

Back to the example  ·  Lint your app