Guide

CITRA Data Classification and Data Residency Rules for Cloud in Kuwait

CITRA’s cloud framework keeps tier 3 and 4 data inside Kuwait, but the policy that defined those tiers was repealed in February 2024, and CITRA’s privacy regulation binds its licensees only. Per Chambers 2026 there is no general localisation rule for private companies, though government data, the framework itself, sector rules and contracts can still require local hosting.

Last verified Written by the Rukn engineering team

Key takeaways

  • Where the framework applies to you, tiers 3 and 4 (sensitive and highly sensitive) must not be stored outside Kuwait, even temporarily.
  • CITRA repealed the Data Classification Policy in February 2024, so the tier rules are now less clear for private companies.
  • The privacy regulation (Decision No. 26 of 2024) applies to CITRA licensees, not to every business.
  • Google (2023) and Microsoft (2025) have announced Kuwait cloud regions without launch dates. Kuwait was not in Google’s live region list when we checked.
  • Keep sensitive stores and encryption keys in Kuwait, and if the framework binds you, treat identifiable customer data as in-country too (Art. 4.2.1.1.3).

CITRA's Data Classification Policy sorted data into four tiers, and its Cloud Computing Regulatory Framework keeps tiers 3 and 4 inside Kuwait. Two things changed in 2024. CITRA repealed the classification policy in February 2024, and its privacy regulation, as amended by Decision No. 26 of 2024, binds CITRA licensees only. This guide sets out who each rule binds, which data it names, and where each kind of data can be hosted today.

This is a technical guide, not legal advice. Facts were last checked against the sources listed at the end on 27 September 2026.

The three documents people mean by "CITRA cloud rules"

In Kuwait, "CITRA rules" on hosting usually means one of three documents from the Communication and Information Technology Regulatory Authority (CITRA):

DocumentWhat it doesStatus on 27 September 2026
Cloud Computing Regulatory Framework, v2.4Licenses cloud providers, sets residency, breach and contract rulesStill published on CITRA's website. Law firms describe it as applying to licensed providers with data centres in Kuwait and to certain subscribers
Data Classification Policy, v2.3Defines the four data tiers the framework relies onRepealed in February 2024, according to GLA & Company in the Chambers 2026 guide. The PDF is still downloadable from CITRA
Data Privacy Protection Regulation (as amended by Decision No. 26 of 2024)Consent, transparency, breach noticeIn force, but only for CITRA licensees, according to DLA Piper and Chambers

The tiers still appear in the framework's text, but the policy that defined them has been repealed. Chambers' contributors write that after the repeal, the framework for data storage and transfers "has become less clear".

The four data tiers, as CITRA defined them

The repealed policy asked data owners to sort data into at least four tiers. Definitions come from the policy (v2.3); hosting rules come from the framework (v2.4).

TierCITRA's labelExamples CITRA givesHosting rule in the framework
1Public dataPublished laws and policies, self-service forms, public website contentMay use providers outside Kuwait (Art. 3.1.4.1)
2Private insensitive dataName, job title, employer, email, Civil ID number, gender, age, qualifications, phone numbers, addressPublic cloud allowed if encryption requirements are met and only the customer holds the keys (Art. 3.1.4.2)
3Private sensitive dataMeeting minutes, business plans, internal project reports, court files, legal opinions, medical records, criminal and DNA fingerprintsPrivate or hybrid cloud only (Art. 3.1.4.3). Not outside Kuwait. Hybrid is allowed if the tier 3 data stays inside Kuwait (Art. 3.2.1.2.2)
4Highly sensitive dataEncryption keys, political documents and international negotiations, military or state-security informationNot outside Kuwait for any purpose, temporarily or permanently (Art. 4.2.1.1.1). The policy also calls for the highest encryption and protection

Chambers 2026 summarises the old policy as allowing tier 3 data in hybrid clouds "both inside and outside Kuwait". The framework text (Art. 3.2.1.2.2) requires the tier 3 part of a hybrid setup to stay in Kuwait, and that is the reading we follow.

Two details change how you design:

  • The Civil ID number is tier 2, not tier 3. Under the policy's own examples, a customer table with names, phone numbers and Civil ID numbers was tier 2, and Art. 3.1.4.2 allows tier 2 in a public cloud if it is encrypted and only you hold the keys. Art. 4.2.1.1.3 (below) complicates this for anyone the framework binds.
  • Encryption keys are tier 4. If you apply the tiers conservatively, the keys that protect your tier 3 data belong in Kuwait, even when the ciphertext sits somewhere else.

What the framework asks of subscribers

The framework also sets duties for customers ("subscribers"). Its preamble says its clauses bind "all parties concerned with using cloud computing services, unless otherwise stated". Its scope clause (Art. 1.4) names all public-sector subscribers, plus private-sector subscribers who host government data, and Chapter 3 lists duties for private and business subscribers as well. Under the framework text:

  • Subscribers classify their own data and choose protection to match (Art. 3.2.1).
  • Private-sector subscribers must not host individuals' personal data or government data in tiers 3 or 4 with a provider outside Kuwait (Art. 3.2.1.2.2).
  • Tier 3 and tier 4 data must not be hosted or stored outside Kuwait "for any purpose, or in any form, whether temporarily or permanently" (Art. 4.2.1.1). That covers backups, replicas and log exports, not just the primary database.
  • The same article also lists "personal data of individuals held with government agencies, private sector companies, or service providers, as stipulated in article 4.1.4" (Art. 4.2.1.1.3). Art. 4.1.4 requires "clear and explicit written permission" before personal data is used to infer identity. This sits awkwardly with Art. 3.1.4.1, which lets data below tier 3 go abroad. If the framework binds you, keep identifiable customer data in Kuwait unless counsel advises otherwise.
  • Subscribers must not put their content in a public, hybrid or community cloud unless the provider is registered and licensed by CITRA (Art. 4.2.1.2). CITRA's English text says "shared content", but the Arabic original (محتوى مشترِك) reads as the subscriber's content.
  • Your data stays your property. The provider may not view, modify, move or delete it without the owner's permission (Art. 3.1.2).

What changed in 2024

February 2024: the classification policy was repealed

GLA & Company's Chambers guide, last updated 10 March 2026, reports that CITRA repealed the Data Classification Policy in February 2024. The authors write that Kuwaiti law "does not generally address data localisation requirements, especially after the repeal". In their view, storing and transferring sensitive data is now governed mainly by the consent provisions of Law No. 20 of 2014 on Electronic Transactions.

They list two sector rules that still touch where records are kept:

  • Healthcare facilities must keep a register and database of patient information (Article 60 of Law No. 70 of 2020 on the Medical Profession).
  • Private-sector employers must keep a file for each employee (Article 80 of Law No. 6 of 2010 on Labour in the Private Sector).

The privacy regulation binds CITRA licensees only

DLA Piper's Kuwait entry says the Data Privacy Protection Regulation applies to "individuals and entities operating as service providers within the telecommunications sector and holding licenses issued by CITRA". Chambers, which cites the regulation as amended by Decision No. 26 of 2024, says the same. It is not a general data protection law for every business.

One nuance: DLA Piper notes that the regulation's definition of a service provider is broad and mentions websites, smart applications and cloud services. If you are unsure whether you hold a CITRA licence, ask counsel.

For licensees, DLA Piper summarises the main duties:

  • Publish service information and terms in easy language, in Arabic and English.
  • State why data is collected, and get consent.
  • Disclose any transfer of personal data to foreign countries, naming them.
  • Delete a user's data when they withdraw consent.
  • Report a personal data breach to CITRA and affected users within 24 hours. Telling users is not required if appropriate protection measures were effectively applied to the affected data.

What still applies to every business

The Electronic Transactions Law (No. 20 of 2014) applies to private companies, government bodies and NGOs. DLA Piper summarises its core rule: do not collect or process personal information unlawfully, or without the person's consent. The Cybercrime Law (No. 63 of 2015) penalises unlawful access to, and disclosure of, personal and government data. DLA Piper also notes that Kuwait has no national data protection authority and no registration requirement.

Which rules apply to you: a scope check

Your situationWhat the sources say appliesA sensible engineering stance
Government ministry or agencyCloud framework applies directly (Art. 1.4)Keep tier 3 and 4 data in Kuwait with a CITRA-licensed provider
Private company holding government data (a contractor)Cloud framework applies (Art. 1.4)Same as government. Isolate the government data from your other systems
CITRA-licensed telecom, ISP or cloud providerCloud framework plus the privacy regulationBuild 24-hour breach reporting and transfer disclosures into operations
Private SME with no government dataElectronic Transactions Law and Cybercrime Law. No general localisation rule, per Chambers. The framework's private-subscriber duties (Art. 3.2.1.2) may still reach youConsent, purpose and access control first. Consider local hosting for medical, legal and HR files
Online store selling to Kuwaiti consumersAs above, plus Decree-Law 10/2026 on digital commerceSee our Decree-Law 10/2026 website checklist

Contracts can be stricter than the law. If a bank, ministry or large customer writes "data stays in Kuwait" into your contract, that clause governs your architecture whatever the regulation says.

Mapping each tier to a hosting option

Even with the policy repealed, the four tiers remain the most useful vocabulary for a data inventory in Kuwait, because the framework still refers to them. It is the first step in our digital transformation guide for SMEs.

TierTypical system in a Kuwaiti businessHosting pattern
1Marketing website, published price lists, public docsAny region, served through a CDN
2CRM contacts, lead forms, newsletter lists, order historyNearest hyperscaler region, encrypted with keys you hold outside the provider, ideally in Kuwait. If the framework binds you, see Art. 4.2.1.1.3 above
3Patient records, HR files, legal files, board papers, internal reportsIn Kuwait: a CITRA-licensed local cloud, your own data centre, or provider hardware installed in Kuwait
4Encryption keys, government or security dataIn Kuwait only, with keys held in-country

A split architecture, step by step

  1. Inventory first. List every data store: databases, object buckets, search indexes, analytics exports, backups and logs.
  2. Label each store by tier. Put the tier in resource tags and in the schema documentation, so reviews can check it.
  3. Keep stateless tiers anywhere. Web front ends, CDNs and tier 1 content can run in the nearest region for speed.
  4. Pin tier 3 and 4 stores in Kuwait. Access them from the application over a private connection rather than copying them out.
  5. Watch the side doors. Cross-region backup, disaster-recovery replicas, error trackers and log shippers are the usual way sensitive data leaves a country without anyone deciding it should. Third-party tools count too: a WhatsApp bot or AI assistant may send message content abroad, so check where it processes data before you plan WhatsApp AI agents.
  6. Hold the keys locally. A key management setup inside Kuwait matches the framework's tier 4 treatment of keys.

Cloud regions in and near Kuwait (checked 27 September 2026)

ProviderKuwait statusWhat exists today
Google CloudRegion announced on 24 January 2023, with no launch date given. Kuwait does not appear in Google's Compute Engine list of regions and zonesNearest Middle East regions: Doha (me-central1) and Dammam (me-central2)
Microsoft AzureMicrosoft announced its intent to establish an AI-powered Azure region on 6 March 2025, in a partnership signed with CAIT and CITRA. No launch timescale was givenNo Kuwait launch date. Choose the nearest Gulf region from Microsoft's current region list and design to move later
AWSIts September 2024 Kuwait announcement was Outposts hardware, not a regionOutposts hardware can be installed in Kuwaiti data centres and connects to the nearest AWS Region. Ask AWS which form factors (1U or 2U servers, 42U racks) are offered locally
CITRA-licensed local providersCITRA licenses providers that host tier 3 and 4 data in Kuwaiti data centres (Art. 2.4)CITRA publishes a register of licensed cloud providers. On 27 September 2026 it listed 13 companies, including Zain, Wataniya, Gulfnet and QualityNet. The page shows 2025 expiry dates and may not be current, so ask each provider for its current licence

Do not plan a launch around an unannounced region date. Design for portability (containers, infrastructure as code, standard database engines), so a later move to a Kuwait region is a migration, not a rebuild.

Contract terms to insist on

Chapter 6 of the framework lists what a cloud contract and SLA must cover. It is a useful checklist even if the framework does not bind you:

  • Provider identity, business address and full contact details.
  • The services and their permitted uses, fees, payment terms and termination.
  • Data ownership stays with you, and data is used only to provide the service, not for advertising without consent.
  • Security obligations and breach steps. Under the framework, providers notify subscribers within 72 hours of becoming aware of a breach (Art. 4.2.2.1).
  • Subcontracting, with final responsibility on the provider.
  • Business continuity with a tested disaster recovery plan.
  • Exit: a copy of your content in a usable format, deletion on request, or transfer to a new provider.

Before any data leaves Kuwait, the framework also expects the provider to tell you in advance and get your consent (Art. 4.2.1.4). If you are choosing between a Kuwaiti team and one abroad, residency and contract jurisdiction belong in that decision. We cover both in local agency vs offshore developer.

Where Rukn fits

We design cloud architecture and migrations for businesses in Kuwait, and we can plan a split architecture that keeps sensitive stores in-country and everything else close to users. If you want your data mapped to hosting before a migration, see our cloud architecture and migration service in Kuwait.

We re-check this page against the sources and update the "last verified" date when anything moves.

Frequently asked questions

Does Kuwait have a data localisation law?

Not a general one for private companies, according to the Chambers 2026 guide, especially since CITRA repealed its Data Classification Policy in February 2024. CITRA’s Cloud Computing Regulatory Framework still keeps tier 3 and tier 4 data inside Kuwait for public bodies and companies holding government data, and its Chapter 3 also bars private subscribers from hosting individuals’ tier 3 and 4 personal data abroad (Art. 3.2.1.2.2). Sector rules and contracts can also require local hosting. This is a technical summary, not legal advice.

Does Kuwait have a personal data protection law?

Not a general one. According to DLA Piper, Kuwait has no national data protection authority and no registration requirement. CITRA’s Data Privacy Protection Regulation (Decision No. 26 of 2024) binds CITRA licensees only. For other businesses, the Electronic Transactions Law (No. 20 of 2014) prohibits collecting or processing personal data unlawfully or without consent, and the Cybercrime Law (No. 63 of 2015) penalises unlawful access and disclosure. This is a technical summary, not legal advice.

What are CITRA’s four data classification levels?

Tier 1 is public data such as published laws. Tier 2 is private insensitive data such as names, emails and Civil ID numbers. Tier 3 is private sensitive data such as medical records, legal files and business plans. Tier 4 is highly sensitive data such as encryption keys and state-security information. The policy defining them was repealed in February 2024, but the cloud framework still refers to them.

Does CITRA Decision 26 of 2024 apply to my company?

Only if your company holds a licence from CITRA, according to DLA Piper and Chambers. The regulation covers telecom-sector service providers licensed by CITRA. Its definition of a service provider mentions websites, apps and cloud services, so check with counsel if you are unsure. Most private companies are instead covered by the Electronic Transactions Law (No. 20 of 2014) and the Cybercrime Law (No. 63 of 2015).

Can I host Kuwaiti customer data on AWS or Azure outside Kuwait?

For most private companies with no government data, the sources report no general ban, provided you meet consent and security duties. Under the cloud framework, data below tier 3 may use providers abroad (Art. 3.1.4.1), but Art. 4.2.1.1.3 also lists individuals’ personal data held by private companies among data that should not leave Kuwait. If the framework binds you, get legal advice before moving personal data offshore. Backups and replicas count as storage.

Is there a Google Cloud or Azure region in Kuwait?

Google announced a Kuwait region in January 2023, but Kuwait was not in its list of live regions on 27 September 2026. The nearest are Doha and Dammam. Microsoft announced its intent to establish an Azure region in Kuwait in March 2025, with no launch timescale. AWS has made its Outposts hardware available for installation in Kuwaiti data centres since September 2024.

Sources

We checked the facts on this page against these sources on 27 September 2026.

  1. CITRA: Cloud Computing Regulatory Framework, v2.4 (PDF)
  2. CITRA: Data Classification Policy, v2.3 (PDF, repealed in February 2024)
  3. CITRA: Cloud computing service providers licensed by CITRA
  4. DLA Piper: Data protection laws in Kuwait
  5. Chambers Global Practice Guides: Data Protection & Privacy 2026, Kuwait (GLA & Company)
  6. Google Cloud blog: Bringing a new Google Cloud region to Kuwait (24 January 2023)
  7. Google Cloud: Compute Engine regions and zones
  8. Microsoft: Microsoft strengthens partnership with Kuwait government, announces intent to establish AI-powered Azure region (6 March 2025)
  9. AWS: Announcing availability of AWS Outposts in Kuwait (September 2024)

Rukn is an independent software company. We are not affiliated with, endorsed by or a partner of Communication and Information Technology Regulatory Authority (CITRA), Google Cloud, Microsoft Azure, and Amazon Web Services, and we receive no referral fees. Names and trademarks belong to their owners and are used only to describe compatibility.

Want this built for your business?

Rukn designs and builds web, mobile, cloud, WhatsApp and AI systems for businesses in Kuwait. Tell us what you need and we reply within 24 hours with a plan, timeline and quote.