Skip to content
これは参考訳です。英語版が正式かつ法的拘束力を持つ公式バージョンです。 英語版を表示
Middle EastMEDIUM coverage

Kuwait — CITRA Data Privacy Protection Regulation + E-Commerce/Cybercrime Laws + National AI Strategy: AI Compliance Requirements

Kuwait has NO single comprehensive personal-data-protection law — data-protection obligations are split across three instruments. (1) CITRA Administrative Decision No. 26 of 2024, the Data Privacy Protection Regulation (DPPR, effective 2024-02-19), requires consent before collecting/processing personal data, restricts cross-border transfers, and mandates breach notification to CITRA within 72 hours — but its scope is LIMITED to telecommunications service providers/licensees regulated by CITRA, not all organizations. (2) Law No. 20 of 2014 (the E-Commerce Law) separately prohibits illegal data collection without consent for electronic transactions generally. (3) Law No. 63 of 2015 (the Cybercrime Law) criminalizes unauthorized data access/disclosure. Kuwait launched a National AI Strategy (aligned with Vision 2035/"New Kuwait") that is, as of 2026, a policy framework under development (CITRA/CAIT, a proposed unified AI oversight model) rather than binding standalone AI legislation.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

February 19, 2024

Maximum Penalty

No single figure — varies by instrument: DPPR/CITRA sanctions per CITRA's establishing law (fines reported in the KWD 500-20,000 range plus imprisonment 1-5 years for telecom-sector breaches); E-Commerce Law (No. 20/2014) up to 3 years imprisonment + fine no less than KWD 5,000; Cybercrime Law (No. 63/2015) 6 months-10 years imprisonment + fines up to KWD 20,000.

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Establish Lawful Basis for AI Data Processing (CITRA DPPR + E-Commerce Law)

High Priority

CITRA's Data Privacy Protection Regulation (Administrative Decision No. 26/2024) requires telecom-sector service providers/licensees to obtain consent before collecting or processing personal data; Kuwait's E-Commerce Law (No. 20/2014) separately prohibits illegal data collection without consent for electronic transactions generally. AI systems must document consent or other legal basis before processing Kuwaiti residents' data; explicit consent is expected for sensitive personal data (health, biometric, financial) used in AI systems.

CITRA Administrative Decision No. 26 of 2024 (DPPR); Law No. 20 of 2014 (E-Commerce Law)

CITRA 72-Hour Breach Notification (Telecom Sector)

Medium Priority

CITRA-licensed telecommunications service providers must notify CITRA of a personal-data breach within 72 hours under the Data Privacy Protection Regulation.

CITRA Administrative Decision No. 26 of 2024 (DPPR)

Align AI Systems with Kuwait National AI Strategy (Vision 2035)

Lower Priority

Kuwait's National AI Strategy is a policy framework (developed under CITRA/CAIT and aligned with Vision 2035) setting out AI governance principles for organizations operating in Kuwait: transparency, fairness, accountability, security, and human oversight. AI systems in priority sectors (healthcare, finance, logistics, education, energy, judiciary) face enhanced governance expectations, but as of 2026 this is a recommended baseline, not binding standalone AI legislation.

Kuwait National AI Strategy (CITRA/CAIT, Vision 2035-aligned) — policy framework, not yet binding legislation.

Recent Regulatory Guidance

guidance2024-06

Kuwait National AI Strategy — AI Governance Framework (Vision 2035)

Kuwait's National AI Strategy is a national framework (developed under CITRA/CAIT and aligned with Vision 2035) setting out AI governance principles for organizations operating in Kuwait — transparency and explainability to affected individuals, human oversight for consequential AI decisions in priority sectors (healthcare, finance, judiciary, energy, logistics, education), documented AI governance frameworks, and alignment with CITRA data-protection and security requirements. As of 2026 it is a strategy/policy framework (a High-Level Steering Committee and unified AI oversight model are proposed), not yet binding standalone AI legislation; treat these as recommended baselines rather than enforceable obligations.

Frequently Asked Questions

Does Kuwait — CITRA Data Privacy Protection Regulation + E-Commerce/Cybercrime Laws + National AI Strategy apply to my business?

Kuwait has NO single comprehensive personal-data-protection law — data-protection obligations are split across three instruments. (1) CITRA Administrative Decision No. 26 of 2024, the Data Privacy Protection Regulation (DPPR, effective 2024-02-19),… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Kuwait — CITRA Data Privacy Protection Regulation + E-Commerce/Cybercrime Laws + National AI Strategy is: No single figure — varies by instrument: DPPR/CITRA sanctions per CITRA's establishing law (fines reported in the KWD 500-20,000 range plus imprisonment 1-5 years for telecom-sector breaches); E-Commerce Law (No. 20/2014) up to 3 years imprisonment + fine no less than KWD 5,000; Cybercrime Law (No. 63/2015) 6 months-10 years imprisonment + fines up to KWD 20,000.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Kuwait — CITRA Data Privacy Protection Regulation + E-Commerce/Cybercrime Laws + National AI Strategy?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.citra.gov.kw

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan