Kuwait Data Privacy Protection Regulation (KDPPR, 2021 - CMA Directive)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
KDPPR - Breach Notification - Article 5 - 72 Hour - Incident Response - CITRA
Kuwait KDPPR Article 5 + supplementary CITRA Incident Reporting Guidelines mandate breach notification regime. Personal Data breach defined as breach of security leading to accidental or unlawful destruction + loss + alteration + unauthorised disclosure of + access to Personal Data. Notification to CITRA Data Privacy Office within 72 hours of becoming aware (similar to GDPR Article 33) + earlier where high-risk. Notification to affected Data Subjects without undue delay where likely to result in high risk to rights and freedoms (compromise of credentials + financial data + Sensitive Personal Data + risk of identity theft + fraud + reputational harm). Notifications include: nature + categories + approximate number of affected Subjects + likely consequences + measures taken or proposed + contact for queries. Records of all breaches whether notified or not. Incident response playbook + tabl
- Incident response playbook
- Breach notification log (CITRA and Subjects)
- Tabletop exercise records
- Coordination with Kuwait NCSC and MoI
- 72-hour notification evidence
- Breach risk assessment criteria
- Late or no CITRA notification
- No Data Subject notification when high-risk
- Incomplete incident records
- No tabletop exercises
- No NCSC liaison
KDPPR - Cross-Border Transfer - Data Localisation - Cloud First Policy - Class A B C D - Articles 6-7
Kuwait KDPPR Articles 6-7 cross-border transfer regime + Cloud Computing localisation. Transfer of Personal Data outside Kuwait permitted only where: (1) destination jurisdiction provides adequate level of protection (CITRA may publish list); (2) standard contractual clauses + binding corporate rules acceptable to CITRA; (3) explicit informed consent of Data Subject + Sensitive Personal Data require written informed consent; (4) necessity for contract performance + vital interests + public interest. CITRA notification + approval may be required for systematic transfers + large volumes + Sensitive Personal Data. CITRA Cloud First Policy (2017 + updated 2021) classifies cloud workloads into: Class A (publicly available data + can use foreign cloud) + Class B (internal data + Kuwait or GCC cloud preferred) + Class C (confidential + national cloud required) + Class D (highly sensitive + gove
- Cross-border transfer inventory
- CITRA-approved SCCs or BCRs
- Cloud First classification per workload
- CITRA approval evidence for Class C/D
- Sovereignty assessment for higher classifications
- Transfer without lawful basis
- No Cloud First classification
- Class C/D in foreign cloud
- No CITRA approval for systematic transfers
KDPPR - DPO - Training - ROPA - PIA - Complaints - Audit - CITRA
Kuwait KDPPR Articles 3-7 governance + accountability obligations. Data Protection Officer (DPO) or Equivalent Role designation - mandatory for: (1) telecommunications operators + ICT licensees processing large volumes of Personal Data; (2) public sector bodies; (3) controllers processing Sensitive Personal Data at scale. DPO qualifications + reporting independence + executive engagement + CITRA liaison. Training and Awareness: annual mandatory training for all personnel handling Personal Data + role-based deep training for IT + security + customer-facing staff + DPO + executives + Board. Records of Processing Activities (ROPA): maintained for each processing operation including categories + purposes + recipients + transfers + retention + security. Privacy Impact Assessments (PIA): mandatory for high-risk processing + new systems + cross-border transfers + cloud migrations + Sensitive Pe
- DPO designation records
- Training records (annual + role-based)
- ROPA per processing operation
- PIA reports
- Complaints handling log
- Independent audit reports
- CITRA engagement records
- No DPO designated
- Training not delivered
- ROPA incomplete or absent
- No PIAs for high-risk
- No independent audit
- Poor CITRA cooperation
KDPPR - Data Processor - Vendor Management - Contracts - Subprocessor - Cloud
Kuwait KDPPR Articles 4 + 7 data processor + third-party vendor obligations. Controllers must conduct due diligence on Processors + cloud providers + ensure: (1) Documented contracts specifying purposes + scope + categories of Personal Data + duration + obligations of Processor including security + sub-processing + Data Subject support + audit rights + breach notification + return or deletion at end of contract; (2) Processors process only on Controller documented instructions; (3) Processors maintain confidentiality + security commensurate with KDPPR Articles 4-5; (4) Sub-processors only with prior written authorisation from Controller + flow-down contractual obligations; (5) Cloud providers categorised per Cloud First Policy + meet sovereignty for higher-classification workloads; (6) Cross-border transfers by Processor follow KDPPR Article 6 lawful bases; (7) Joint Controllership where
- Processor contracts (KDPPR-compliant clauses)
- Subprocessor authorisation register
- Cloud provider classification
- Vendor security assessments
- Audit reports
- Termination + return + deletion evidence
- Processors without contract
- Subprocessors without authorisation
- Cloud providers not classified
- No vendor audits
- Missing return/deletion at termination
KDPPR - Data Subject Rights - Access - Correction - Erasure - Object - Restriction - Portability
Kuwait KDPPR Article 3 Data Subject Rights (modeled on GDPR Articles 12-22 + GCC convergence): (1) Right to Information about processing including identity of Controller + Processor + purposes + lawful basis + recipients + retention; (2) Right of Access to own Personal Data + free first copy + reasonable subsequent fee; (3) Right to Correction of inaccurate or incomplete data; (4) Right to Erasure (Right to be Forgotten) when no longer necessary + consent withdrawn + unlawful processing + legal obligation; (5) Right to Object to processing including direct marketing + profiling; (6) Right to Restriction of Processing during dispute or accuracy verification; (7) Right to Withdrawal of Consent at any time as easily as it was given; (8) Right to Data Portability for data provided by Data Subject in structured machine-readable format. Response within reasonable timeframe (typically 30 days).
- Rights request handling SLAs and logs
- Access response templates
- Withdrawal of consent mechanism
- Portability format documentation
- CITRA complaint escalation procedure
- Identity verification policy
- No specific handling for KDPPR rights
- Withdrawal of consent harder than giving
- Long response times
- No portability format
- Missing CITRA escalation path
KDPPR - Lawful Basis - Consent - Notice - Transparency - Data Minimisation - Retention
Kuwait KDPPR Articles 3-4 lawful basis for processing Personal Data including: (1) Express written consent of Data Subject; (2) Performance of contract with Data Subject; (3) Compliance with legal obligations; (4) Vital interests of Data Subject; (5) Public interest; (6) Legitimate interests not overridden by Data Subject fundamental rights. Sensitive Personal Data (health + biometric + financial + religious + ethnicity + criminal record) requires explicit separate written consent. Consent must be specific + informed + free + unambiguous + withdrawable. Privacy notices must be transparent + plain Arabic + cover purposes + categories + recipients + retention + Data Subject rights + complaint mechanism + CITRA escalation. Data Minimisation - only collect what is necessary for declared purposes. Retention - delete or anonymise when purpose fulfilled unless legal obligation. Purpose Limitati
- Privacy notices in Arabic
- Consent records (granular and withdrawable)
- Lawful basis register
- Retention schedule
- Data minimisation policy
- Sensitive data explicit consent records
- Bundled consent without granularity
- Privacy notice not in Arabic
- No retention schedule
- Sensitive data not separately consented
- Purpose creep without new consent
KDPPR - Scope - Application - CITRA - Resolution 26 of 2021 - Telecommunications - ICT - Cloud - Articles 1-3
Kuwait Data Privacy Protection Regulation (KDPPR) issued by Communications and Information Technology Regulatory Authority (CITRA) Resolution No. 26 of 2021. Sector-specific directive (NOT comprehensive national data protection statute - Kuwait still drafting general data protection law). Scope: applies to telecommunications operators + Internet Service Providers (ISPs) + ICT licensed entities + cloud computing providers + government bodies + public services that process Personal Data through telecommunications + ICT infrastructure within or accessible from State of Kuwait. CITRA itself the regulator established under Law No. 37 of 2014 + Amiri Decree No. 26 of 2014. KDPPR aligned with international standards (GDPR-inspired but lighter touch) + considered transitional regulation pending broader national law. Article 1 purpose + Article 2 definitions (Personal Data + Data Subject + Data C
- Applicability assessment
- CITRA licensee register
- Cloud First classification matrix
- Sector-specific scope memo
- Personal data inventory
- Regulatory engagement records
- Failure to identify all CITRA-licensed entities in scope
- Cloud workloads unclassified per Cloud First Policy
- Missing CITRA registration
- Treating KDPPR same as GDPR without Kuwait-specific provisions
KDPPR - Security Controls - Encryption - Access - Logging - Articles 4-5
Kuwait KDPPR Articles 4-5 mandate appropriate technical + organisational security measures proportionate to risk + nature of Personal Data + processing operations. Required controls include: encryption at rest + in transit for Personal Data + Sensitive Personal Data + cardholder data + credentials; role-based access control + least privilege + segregation of duties + privileged access management; multi-factor authentication for administrative access + remote access + cloud admin consoles; comprehensive logging of access + processing + administrative actions + retention of logs for at least 1 year; security monitoring + SIEM + intrusion detection + anomaly detection; vulnerability management + patching + penetration testing; data loss prevention; secure software development lifecycle; physical security; backup + business continuity; ongoing security training + awareness. CITRA may audit +
- Encryption configuration evidence (at rest and in transit)
- RBAC + PAM records
- MFA enforcement evidence
- SIEM and IDS deployment
- Pen-test reports
- Patching SLA evidence
- Security training records
- Unencrypted Personal Data at rest or in transit
- No MFA for admin
- Insufficient logging retention
- No vulnerability management programme
- No security training
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.