Skip to content

Evidence request lists

Kuwait Data Privacy Protection Regulation (KDPPR, 2021 - CMA Directive)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

KDPPR - Breach Notification - Article 5 - 72 Hour - Incident Response - CITRA

KDPPR-Breach-Notification-Article-5-Incident-Response-CITRA-Affected-Subjects-72-Hour
Kuwait KDPPR Breach Notification + Article 5 + Incident Response + CITRA + 72-Hour

Kuwait KDPPR Article 5 + supplementary CITRA Incident Reporting Guidelines mandate breach notification regime. Personal Data breach defined as breach of security leading to accidental or unlawful destruction + loss + alteration + unauthorised disclosure of + access to Personal Data. Notification to CITRA Data Privacy Office within 72 hours of becoming aware (similar to GDPR Article 33) + earlier where high-risk. Notification to affected Data Subjects without undue delay where likely to result in high risk to rights and freedoms (compromise of credentials + financial data + Sensitive Personal Data + risk of identity theft + fraud + reputational harm). Notifications include: nature + categories + approximate number of affected Subjects + likely consequences + measures taken or proposed + contact for queries. Records of all breaches whether notified or not. Incident response playbook + tabl

Artefacts an auditor will ask for
  • Incident response playbook
  • Breach notification log (CITRA and Subjects)
  • Tabletop exercise records
  • Coordination with Kuwait NCSC and MoI
  • 72-hour notification evidence
  • Breach risk assessment criteria
Where this commonly fails
  • Late or no CITRA notification
  • No Data Subject notification when high-risk
  • Incomplete incident records
  • No tabletop exercises
  • No NCSC liaison

KDPPR - Cross-Border Transfer - Data Localisation - Cloud First Policy - Class A B C D - Articles 6-7

KDPPR-Cross-Border-Transfer-Data-Localisation-Cloud-First-Policy-Article-6-7-CITRA-Approval
Kuwait KDPPR Cross-Border Transfer + Data Localisation + Cloud First Policy + CITRA Approval

Kuwait KDPPR Articles 6-7 cross-border transfer regime + Cloud Computing localisation. Transfer of Personal Data outside Kuwait permitted only where: (1) destination jurisdiction provides adequate level of protection (CITRA may publish list); (2) standard contractual clauses + binding corporate rules acceptable to CITRA; (3) explicit informed consent of Data Subject + Sensitive Personal Data require written informed consent; (4) necessity for contract performance + vital interests + public interest. CITRA notification + approval may be required for systematic transfers + large volumes + Sensitive Personal Data. CITRA Cloud First Policy (2017 + updated 2021) classifies cloud workloads into: Class A (publicly available data + can use foreign cloud) + Class B (internal data + Kuwait or GCC cloud preferred) + Class C (confidential + national cloud required) + Class D (highly sensitive + gove

Artefacts an auditor will ask for
  • Cross-border transfer inventory
  • CITRA-approved SCCs or BCRs
  • Cloud First classification per workload
  • CITRA approval evidence for Class C/D
  • Sovereignty assessment for higher classifications
Where this commonly fails
  • Transfer without lawful basis
  • No Cloud First classification
  • Class C/D in foreign cloud
  • No CITRA approval for systematic transfers

KDPPR - DPO - Training - ROPA - PIA - Complaints - Audit - CITRA

KDPPR-DPO-Training-Awareness-Records-Of-Processing-PIA-Customer-Complaints-Review-Audit-CITRA-Engagement
Kuwait KDPPR DPO + Training + ROPA + PIA + Customer Complaints + Independent Audit + CITRA

Kuwait KDPPR Articles 3-7 governance + accountability obligations. Data Protection Officer (DPO) or Equivalent Role designation - mandatory for: (1) telecommunications operators + ICT licensees processing large volumes of Personal Data; (2) public sector bodies; (3) controllers processing Sensitive Personal Data at scale. DPO qualifications + reporting independence + executive engagement + CITRA liaison. Training and Awareness: annual mandatory training for all personnel handling Personal Data + role-based deep training for IT + security + customer-facing staff + DPO + executives + Board. Records of Processing Activities (ROPA): maintained for each processing operation including categories + purposes + recipients + transfers + retention + security. Privacy Impact Assessments (PIA): mandatory for high-risk processing + new systems + cross-border transfers + cloud migrations + Sensitive Pe

Artefacts an auditor will ask for
  • DPO designation records
  • Training records (annual + role-based)
  • ROPA per processing operation
  • PIA reports
  • Complaints handling log
  • Independent audit reports
  • CITRA engagement records
Where this commonly fails
  • No DPO designated
  • Training not delivered
  • ROPA incomplete or absent
  • No PIAs for high-risk
  • No independent audit
  • Poor CITRA cooperation

KDPPR - Data Processor - Vendor Management - Contracts - Subprocessor - Cloud

KDPPR-Data-Processor-Vendor-Management-Contractual-Obligations-Subprocessor-Article-4-7-Cloud
Kuwait KDPPR Data Processor + Vendor Management + Contractual Obligations + Subprocessor

Kuwait KDPPR Articles 4 + 7 data processor + third-party vendor obligations. Controllers must conduct due diligence on Processors + cloud providers + ensure: (1) Documented contracts specifying purposes + scope + categories of Personal Data + duration + obligations of Processor including security + sub-processing + Data Subject support + audit rights + breach notification + return or deletion at end of contract; (2) Processors process only on Controller documented instructions; (3) Processors maintain confidentiality + security commensurate with KDPPR Articles 4-5; (4) Sub-processors only with prior written authorisation from Controller + flow-down contractual obligations; (5) Cloud providers categorised per Cloud First Policy + meet sovereignty for higher-classification workloads; (6) Cross-border transfers by Processor follow KDPPR Article 6 lawful bases; (7) Joint Controllership where

Artefacts an auditor will ask for
  • Processor contracts (KDPPR-compliant clauses)
  • Subprocessor authorisation register
  • Cloud provider classification
  • Vendor security assessments
  • Audit reports
  • Termination + return + deletion evidence
Where this commonly fails
  • Processors without contract
  • Subprocessors without authorisation
  • Cloud providers not classified
  • No vendor audits
  • Missing return/deletion at termination

KDPPR - Data Subject Rights - Access - Correction - Erasure - Object - Restriction - Portability

KDPPR-Data-Subject-Rights-Access-Correction-Erasure-Object-Restriction-Portability-Withdrawal-Article-3
Kuwait KDPPR Data Subject Rights + Access + Correction + Erasure + Withdrawal of Consent

Kuwait KDPPR Article 3 Data Subject Rights (modeled on GDPR Articles 12-22 + GCC convergence): (1) Right to Information about processing including identity of Controller + Processor + purposes + lawful basis + recipients + retention; (2) Right of Access to own Personal Data + free first copy + reasonable subsequent fee; (3) Right to Correction of inaccurate or incomplete data; (4) Right to Erasure (Right to be Forgotten) when no longer necessary + consent withdrawn + unlawful processing + legal obligation; (5) Right to Object to processing including direct marketing + profiling; (6) Right to Restriction of Processing during dispute or accuracy verification; (7) Right to Withdrawal of Consent at any time as easily as it was given; (8) Right to Data Portability for data provided by Data Subject in structured machine-readable format. Response within reasonable timeframe (typically 30 days).

Artefacts an auditor will ask for
  • Rights request handling SLAs and logs
  • Access response templates
  • Withdrawal of consent mechanism
  • Portability format documentation
  • CITRA complaint escalation procedure
  • Identity verification policy
Where this commonly fails
  • No specific handling for KDPPR rights
  • Withdrawal of consent harder than giving
  • Long response times
  • No portability format
  • Missing CITRA escalation path

KDPPR - Lawful Basis - Consent - Notice - Transparency - Data Minimisation - Retention

KDPPR-Lawful-Basis-Consent-Notice-Transparency-Data-Minimisation-Retention-Privacy-Notices
Kuwait KDPPR Lawful Basis + Consent + Notice + Transparency + Data Minimisation + Retention

Kuwait KDPPR Articles 3-4 lawful basis for processing Personal Data including: (1) Express written consent of Data Subject; (2) Performance of contract with Data Subject; (3) Compliance with legal obligations; (4) Vital interests of Data Subject; (5) Public interest; (6) Legitimate interests not overridden by Data Subject fundamental rights. Sensitive Personal Data (health + biometric + financial + religious + ethnicity + criminal record) requires explicit separate written consent. Consent must be specific + informed + free + unambiguous + withdrawable. Privacy notices must be transparent + plain Arabic + cover purposes + categories + recipients + retention + Data Subject rights + complaint mechanism + CITRA escalation. Data Minimisation - only collect what is necessary for declared purposes. Retention - delete or anonymise when purpose fulfilled unless legal obligation. Purpose Limitati

Artefacts an auditor will ask for
  • Privacy notices in Arabic
  • Consent records (granular and withdrawable)
  • Lawful basis register
  • Retention schedule
  • Data minimisation policy
  • Sensitive data explicit consent records
Where this commonly fails
  • Bundled consent without granularity
  • Privacy notice not in Arabic
  • No retention schedule
  • Sensitive data not separately consented
  • Purpose creep without new consent

KDPPR - Scope - Application - CITRA - Resolution 26 of 2021 - Telecommunications - ICT - Cloud - Articles 1-3

KDPPR-Scope-Application-CITRA-Resolution-26-2021-Telecommunications-ICT-Cloud-Public-Services-Article-1-3
Kuwait KDPPR Scope and Application + CITRA Resolution 26 of 2021 + Telecommunications + ICT + Cloud

Kuwait Data Privacy Protection Regulation (KDPPR) issued by Communications and Information Technology Regulatory Authority (CITRA) Resolution No. 26 of 2021. Sector-specific directive (NOT comprehensive national data protection statute - Kuwait still drafting general data protection law). Scope: applies to telecommunications operators + Internet Service Providers (ISPs) + ICT licensed entities + cloud computing providers + government bodies + public services that process Personal Data through telecommunications + ICT infrastructure within or accessible from State of Kuwait. CITRA itself the regulator established under Law No. 37 of 2014 + Amiri Decree No. 26 of 2014. KDPPR aligned with international standards (GDPR-inspired but lighter touch) + considered transitional regulation pending broader national law. Article 1 purpose + Article 2 definitions (Personal Data + Data Subject + Data C

Artefacts an auditor will ask for
  • Applicability assessment
  • CITRA licensee register
  • Cloud First classification matrix
  • Sector-specific scope memo
  • Personal data inventory
  • Regulatory engagement records
Where this commonly fails
  • Failure to identify all CITRA-licensed entities in scope
  • Cloud workloads unclassified per Cloud First Policy
  • Missing CITRA registration
  • Treating KDPPR same as GDPR without Kuwait-specific provisions

KDPPR - Security Controls - Encryption - Access - Logging - Articles 4-5

KDPPR-Information-Security-Controls-Encryption-Access-Control-Logging-Monitoring-Article-4-5
Kuwait KDPPR Information Security Controls + Encryption + Access Control + Logging + Monitoring

Kuwait KDPPR Articles 4-5 mandate appropriate technical + organisational security measures proportionate to risk + nature of Personal Data + processing operations. Required controls include: encryption at rest + in transit for Personal Data + Sensitive Personal Data + cardholder data + credentials; role-based access control + least privilege + segregation of duties + privileged access management; multi-factor authentication for administrative access + remote access + cloud admin consoles; comprehensive logging of access + processing + administrative actions + retention of logs for at least 1 year; security monitoring + SIEM + intrusion detection + anomaly detection; vulnerability management + patching + penetration testing; data loss prevention; secure software development lifecycle; physical security; backup + business continuity; ongoing security training + awareness. CITRA may audit +

Artefacts an auditor will ask for
  • Encryption configuration evidence (at rest and in transit)
  • RBAC + PAM records
  • MFA enforcement evidence
  • SIEM and IDS deployment
  • Pen-test reports
  • Patching SLA evidence
  • Security training records
Where this commonly fails
  • Unencrypted Personal Data at rest or in transit
  • No MFA for admin
  • Insufficient logging retention
  • No vulnerability management programme
  • No security training
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.