CITRA Data Privacy Protection Regulation
Kuwait has no cross-sector data-protection statute. This regulation, issued by CITRA, applies only to CITRA-licensed telecommunications and information-technology service providers.
Per secondary sources, it requires explicit consent before collecting or processing personal data, with no category-specific qualification, a legal-guardian consent requirement for minors under 18, requires breach notification to CITRA reportedly within 72 hours, and requires appropriate technical and organizational security measures.
A DataGuidance-sourced commentary states that biometric data is "Not applicable" under Kuwait's current framework; read alongside the general, unqualified consent duty, the more likely reading is the same pattern found in Qatar and Bahrain in this batch, no distinct heightened category for biometric data, rather than biometric data falling outside the regulation's personal-data coverage altogether, but neither reading was confirmed against the regulation's own primary text in this research pass: every attempt to fetch it returned a PDF.js viewer shell rather than extracted text, and no working alternate primary-source mirror was found.
No effective date is recorded here because no primary source confirming one was read; secondary trackers report 19 February 2024.