Kuwait’s Communication and Information Technology Regulatory Authority (CITRA) has approved Resolution No. 42 of 2021, the Data Privacy Protection Regulation, setting out data protection rules for telecommunications and IT service providers licensed in Kuwait.
Key points
- Applies to CITRA-licensed service providers and to those processing personal data through them.
- Requires consent and clear privacy notices before collecting and processing personal data.
- Service providers must implement appropriate technical and organisational security measures.
- Personal data breaches must be notified to CITRA within 72 hours, and to affected users where they are at risk.
- Breaches of the regulation can lead to financial penalties.
Kuwait does not yet have a general data protection law, so this regulation is the main privacy framework for the digital sector. UK suppliers providing hosting, software or managed services to Kuwaiti telecoms and IT providers should expect these requirements to flow down through contracts.
Source: CITRA Resolution No. 42 of 2021 on Data Privacy Protection Regulation (CITRA)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.