Law / Kuwait

Kuwait

privacy

Kuwait's data-protection posture is a CITRA (Communications and Information Technology Regulatory Authority) regulation, most recently Decision No. 26 of 2024 (amending or superseding an earlier Decision reported variously as No. 42 of 2021), not a comprehensive statute, and it applies only to CITRA-licensed telecommunications and information-technology service providers, not to the private sector generally.

This document's confidence is low and its coverage is deliberately thin: every attempt to read the regulation's own primary text returned a PDF.js viewer shell rather than extracted text, and no alternate primary-source mirror could be found. Every substantive finding below is therefore secondary-sourced, drawn from converging legal-commentary trackers, not confirmed against the regulation's own text, and no attribute_sources pins are recorded because no verbatim source text was actually read.

A DataGuidance-sourced commentary states directly that biometric data is "Not applicable" under Kuwait's current framework; the more likely reading, by analogy to Qatar and Bahrain in this batch, is that this reports the absence of a distinct heightened category for biometric data rather than the absence of any coverage at all, since the same secondary sources report an unqualified consent duty for personal data generally that would ordinarily reach an identifying biometric characteristic, but this document does not have primary-source confirmation either way.

This document should be revisited once a working primary-source mirror of the CITRA regulation is found.

8 instruments named 1 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

CITRA Data Privacy Protection Regulation

cite CITRA Decision No. 26 of 2024 (amending or superseding Decision No. 42 of 2021) stage IMMINENT commencement not set binds private bodies source secondary legal-commentary trackers (Michalsons, Al Tamimi, DataGuidance/glaco.com, Securiti, Chambers)
What it requires

Kuwait has no cross-sector data-protection statute. This regulation, issued by CITRA, applies only to CITRA-licensed telecommunications and information-technology service providers.

Per secondary sources, it requires explicit consent before collecting or processing personal data, with no category-specific qualification, a legal-guardian consent requirement for minors under 18, requires breach notification to CITRA reportedly within 72 hours, and requires appropriate technical and organizational security measures.

A DataGuidance-sourced commentary states that biometric data is "Not applicable" under Kuwait's current framework; read alongside the general, unqualified consent duty, the more likely reading is the same pattern found in Qatar and Bahrain in this batch, no distinct heightened category for biometric data, rather than biometric data falling outside the regulation's personal-data coverage altogether, but neither reading was confirmed against the regulation's own primary text in this research pass: every attempt to fetch it returned a PDF.js viewer shell rather than extracted text, and no working alternate primary-source mirror was found.

No effective date is recorded here because no primary source confirming one was read; secondary trackers report 19 February 2024.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.