Key takeaways
- Where the framework applies to you, tiers 3 and 4 (sensitive and highly sensitive) must not be stored outside Kuwait, even temporarily.
- CITRA repealed the Data Classification Policy in February 2024, so the tier rules are now less clear for private companies.
- The privacy regulation (Decision No. 26 of 2024) applies to CITRA licensees, not to every business.
- Google (2023) and Microsoft (2025) have announced Kuwait cloud regions without launch dates. Kuwait was not in Google’s live region list when we checked.
- Keep sensitive stores and encryption keys in Kuwait, and if the framework binds you, treat identifiable customer data as in-country too (Art. 4.2.1.1.3).
CITRA's Data Classification Policy sorted data into four tiers, and its Cloud Computing Regulatory Framework keeps tiers 3 and 4 inside Kuwait. Two things changed in 2024. CITRA repealed the classification policy in February 2024, and its privacy regulation, as amended by Decision No. 26 of 2024, binds CITRA licensees only. This guide sets out who each rule binds, which data it names, and where each kind of data can be hosted today.
This is a technical guide, not legal advice. Facts were last checked against the sources listed at the end on 27 September 2026.
The three documents people mean by "CITRA cloud rules"
In Kuwait, "CITRA rules" on hosting usually means one of three documents from the Communication and Information Technology Regulatory Authority (CITRA):
| Document | What it does | Status on 27 September 2026 |
|---|---|---|
| Cloud Computing Regulatory Framework, v2.4 | Licenses cloud providers, sets residency, breach and contract rules | Still published on CITRA's website. Law firms describe it as applying to licensed providers with data centres in Kuwait and to certain subscribers |
| Data Classification Policy, v2.3 | Defines the four data tiers the framework relies on | Repealed in February 2024, according to GLA & Company in the Chambers 2026 guide. The PDF is still downloadable from CITRA |
| Data Privacy Protection Regulation (as amended by Decision No. 26 of 2024) | Consent, transparency, breach notice | In force, but only for CITRA licensees, according to DLA Piper and Chambers |
The tiers still appear in the framework's text, but the policy that defined them has been repealed. Chambers' contributors write that after the repeal, the framework for data storage and transfers "has become less clear".
The four data tiers, as CITRA defined them
The repealed policy asked data owners to sort data into at least four tiers. Definitions come from the policy (v2.3); hosting rules come from the framework (v2.4).
| Tier | CITRA's label | Examples CITRA gives | Hosting rule in the framework |
|---|---|---|---|
| 1 | Public data | Published laws and policies, self-service forms, public website content | May use providers outside Kuwait (Art. 3.1.4.1) |
| 2 | Private insensitive data | Name, job title, employer, email, Civil ID number, gender, age, qualifications, phone numbers, address | Public cloud allowed if encryption requirements are met and only the customer holds the keys (Art. 3.1.4.2) |
| 3 | Private sensitive data | Meeting minutes, business plans, internal project reports, court files, legal opinions, medical records, criminal and DNA fingerprints | Private or hybrid cloud only (Art. 3.1.4.3). Not outside Kuwait. Hybrid is allowed if the tier 3 data stays inside Kuwait (Art. 3.2.1.2.2) |
| 4 | Highly sensitive data | Encryption keys, political documents and international negotiations, military or state-security information | Not outside Kuwait for any purpose, temporarily or permanently (Art. 4.2.1.1.1). The policy also calls for the highest encryption and protection |
Chambers 2026 summarises the old policy as allowing tier 3 data in hybrid clouds "both inside and outside Kuwait". The framework text (Art. 3.2.1.2.2) requires the tier 3 part of a hybrid setup to stay in Kuwait, and that is the reading we follow.
Two details change how you design:
- The Civil ID number is tier 2, not tier 3. Under the policy's own examples, a customer table with names, phone numbers and Civil ID numbers was tier 2, and Art. 3.1.4.2 allows tier 2 in a public cloud if it is encrypted and only you hold the keys. Art. 4.2.1.1.3 (below) complicates this for anyone the framework binds.
- Encryption keys are tier 4. If you apply the tiers conservatively, the keys that protect your tier 3 data belong in Kuwait, even when the ciphertext sits somewhere else.
What the framework asks of subscribers
The framework also sets duties for customers ("subscribers"). Its preamble says its clauses bind "all parties concerned with using cloud computing services, unless otherwise stated". Its scope clause (Art. 1.4) names all public-sector subscribers, plus private-sector subscribers who host government data, and Chapter 3 lists duties for private and business subscribers as well. Under the framework text:
- Subscribers classify their own data and choose protection to match (Art. 3.2.1).
- Private-sector subscribers must not host individuals' personal data or government data in tiers 3 or 4 with a provider outside Kuwait (Art. 3.2.1.2.2).
- Tier 3 and tier 4 data must not be hosted or stored outside Kuwait "for any purpose, or in any form, whether temporarily or permanently" (Art. 4.2.1.1). That covers backups, replicas and log exports, not just the primary database.
- The same article also lists "personal data of individuals held with government agencies, private sector companies, or service providers, as stipulated in article 4.1.4" (Art. 4.2.1.1.3). Art. 4.1.4 requires "clear and explicit written permission" before personal data is used to infer identity. This sits awkwardly with Art. 3.1.4.1, which lets data below tier 3 go abroad. If the framework binds you, keep identifiable customer data in Kuwait unless counsel advises otherwise.
- Subscribers must not put their content in a public, hybrid or community cloud unless the provider is registered and licensed by CITRA (Art. 4.2.1.2). CITRA's English text says "shared content", but the Arabic original (محتوى مشترِك) reads as the subscriber's content.
- Your data stays your property. The provider may not view, modify, move or delete it without the owner's permission (Art. 3.1.2).
What changed in 2024
February 2024: the classification policy was repealed
GLA & Company's Chambers guide, last updated 10 March 2026, reports that CITRA repealed the Data Classification Policy in February 2024. The authors write that Kuwaiti law "does not generally address data localisation requirements, especially after the repeal". In their view, storing and transferring sensitive data is now governed mainly by the consent provisions of Law No. 20 of 2014 on Electronic Transactions.
They list two sector rules that still touch where records are kept:
- Healthcare facilities must keep a register and database of patient information (Article 60 of Law No. 70 of 2020 on the Medical Profession).
- Private-sector employers must keep a file for each employee (Article 80 of Law No. 6 of 2010 on Labour in the Private Sector).
The privacy regulation binds CITRA licensees only
DLA Piper's Kuwait entry says the Data Privacy Protection Regulation applies to "individuals and entities operating as service providers within the telecommunications sector and holding licenses issued by CITRA". Chambers, which cites the regulation as amended by Decision No. 26 of 2024, says the same. It is not a general data protection law for every business.
One nuance: DLA Piper notes that the regulation's definition of a service provider is broad and mentions websites, smart applications and cloud services. If you are unsure whether you hold a CITRA licence, ask counsel.
For licensees, DLA Piper summarises the main duties:
- Publish service information and terms in easy language, in Arabic and English.
- State why data is collected, and get consent.
- Disclose any transfer of personal data to foreign countries, naming them.
- Delete a user's data when they withdraw consent.
- Report a personal data breach to CITRA and affected users within 24 hours. Telling users is not required if appropriate protection measures were effectively applied to the affected data.
What still applies to every business
The Electronic Transactions Law (No. 20 of 2014) applies to private companies, government bodies and NGOs. DLA Piper summarises its core rule: do not collect or process personal information unlawfully, or without the person's consent. The Cybercrime Law (No. 63 of 2015) penalises unlawful access to, and disclosure of, personal and government data. DLA Piper also notes that Kuwait has no national data protection authority and no registration requirement.
Which rules apply to you: a scope check
| Your situation | What the sources say applies | A sensible engineering stance |
|---|---|---|
| Government ministry or agency | Cloud framework applies directly (Art. 1.4) | Keep tier 3 and 4 data in Kuwait with a CITRA-licensed provider |
| Private company holding government data (a contractor) | Cloud framework applies (Art. 1.4) | Same as government. Isolate the government data from your other systems |
| CITRA-licensed telecom, ISP or cloud provider | Cloud framework plus the privacy regulation | Build 24-hour breach reporting and transfer disclosures into operations |
| Private SME with no government data | Electronic Transactions Law and Cybercrime Law. No general localisation rule, per Chambers. The framework's private-subscriber duties (Art. 3.2.1.2) may still reach you | Consent, purpose and access control first. Consider local hosting for medical, legal and HR files |
| Online store selling to Kuwaiti consumers | As above, plus Decree-Law 10/2026 on digital commerce | See our Decree-Law 10/2026 website checklist |
Contracts can be stricter than the law. If a bank, ministry or large customer writes "data stays in Kuwait" into your contract, that clause governs your architecture whatever the regulation says.
Mapping each tier to a hosting option
Even with the policy repealed, the four tiers remain the most useful vocabulary for a data inventory in Kuwait, because the framework still refers to them. It is the first step in our digital transformation guide for SMEs.
| Tier | Typical system in a Kuwaiti business | Hosting pattern |
|---|---|---|
| 1 | Marketing website, published price lists, public docs | Any region, served through a CDN |
| 2 | CRM contacts, lead forms, newsletter lists, order history | Nearest hyperscaler region, encrypted with keys you hold outside the provider, ideally in Kuwait. If the framework binds you, see Art. 4.2.1.1.3 above |
| 3 | Patient records, HR files, legal files, board papers, internal reports | In Kuwait: a CITRA-licensed local cloud, your own data centre, or provider hardware installed in Kuwait |
| 4 | Encryption keys, government or security data | In Kuwait only, with keys held in-country |
A split architecture, step by step
- Inventory first. List every data store: databases, object buckets, search indexes, analytics exports, backups and logs.
- Label each store by tier. Put the tier in resource tags and in the schema documentation, so reviews can check it.
- Keep stateless tiers anywhere. Web front ends, CDNs and tier 1 content can run in the nearest region for speed.
- Pin tier 3 and 4 stores in Kuwait. Access them from the application over a private connection rather than copying them out.
- Watch the side doors. Cross-region backup, disaster-recovery replicas, error trackers and log shippers are the usual way sensitive data leaves a country without anyone deciding it should. Third-party tools count too: a WhatsApp bot or AI assistant may send message content abroad, so check where it processes data before you plan WhatsApp AI agents.
- Hold the keys locally. A key management setup inside Kuwait matches the framework's tier 4 treatment of keys.
Cloud regions in and near Kuwait (checked 27 September 2026)
| Provider | Kuwait status | What exists today |
|---|---|---|
| Google Cloud | Region announced on 24 January 2023, with no launch date given. Kuwait does not appear in Google's Compute Engine list of regions and zones | Nearest Middle East regions: Doha (me-central1) and Dammam (me-central2) |
| Microsoft Azure | Microsoft announced its intent to establish an AI-powered Azure region on 6 March 2025, in a partnership signed with CAIT and CITRA. No launch timescale was given | No Kuwait launch date. Choose the nearest Gulf region from Microsoft's current region list and design to move later |
| AWS | Its September 2024 Kuwait announcement was Outposts hardware, not a region | Outposts hardware can be installed in Kuwaiti data centres and connects to the nearest AWS Region. Ask AWS which form factors (1U or 2U servers, 42U racks) are offered locally |
| CITRA-licensed local providers | CITRA licenses providers that host tier 3 and 4 data in Kuwaiti data centres (Art. 2.4) | CITRA publishes a register of licensed cloud providers. On 27 September 2026 it listed 13 companies, including Zain, Wataniya, Gulfnet and QualityNet. The page shows 2025 expiry dates and may not be current, so ask each provider for its current licence |
Do not plan a launch around an unannounced region date. Design for portability (containers, infrastructure as code, standard database engines), so a later move to a Kuwait region is a migration, not a rebuild.
Contract terms to insist on
Chapter 6 of the framework lists what a cloud contract and SLA must cover. It is a useful checklist even if the framework does not bind you:
- Provider identity, business address and full contact details.
- The services and their permitted uses, fees, payment terms and termination.
- Data ownership stays with you, and data is used only to provide the service, not for advertising without consent.
- Security obligations and breach steps. Under the framework, providers notify subscribers within 72 hours of becoming aware of a breach (Art. 4.2.2.1).
- Subcontracting, with final responsibility on the provider.
- Business continuity with a tested disaster recovery plan.
- Exit: a copy of your content in a usable format, deletion on request, or transfer to a new provider.
Before any data leaves Kuwait, the framework also expects the provider to tell you in advance and get your consent (Art. 4.2.1.4). If you are choosing between a Kuwaiti team and one abroad, residency and contract jurisdiction belong in that decision. We cover both in local agency vs offshore developer.
Where Rukn fits
We design cloud architecture and migrations for businesses in Kuwait, and we can plan a split architecture that keeps sensitive stores in-country and everything else close to users. If you want your data mapped to hosting before a migration, see our cloud architecture and migration service in Kuwait.
We re-check this page against the sources and update the "last verified" date when anything moves.
Frequently asked questions
Does Kuwait have a data localisation law?
Not a general one for private companies, according to the Chambers 2026 guide, especially since CITRA repealed its Data Classification Policy in February 2024. CITRA’s Cloud Computing Regulatory Framework still keeps tier 3 and tier 4 data inside Kuwait for public bodies and companies holding government data, and its Chapter 3 also bars private subscribers from hosting individuals’ tier 3 and 4 personal data abroad (Art. 3.2.1.2.2). Sector rules and contracts can also require local hosting. This is a technical summary, not legal advice.
Does Kuwait have a personal data protection law?
Not a general one. According to DLA Piper, Kuwait has no national data protection authority and no registration requirement. CITRA’s Data Privacy Protection Regulation (Decision No. 26 of 2024) binds CITRA licensees only. For other businesses, the Electronic Transactions Law (No. 20 of 2014) prohibits collecting or processing personal data unlawfully or without consent, and the Cybercrime Law (No. 63 of 2015) penalises unlawful access and disclosure. This is a technical summary, not legal advice.
What are CITRA’s four data classification levels?
Tier 1 is public data such as published laws. Tier 2 is private insensitive data such as names, emails and Civil ID numbers. Tier 3 is private sensitive data such as medical records, legal files and business plans. Tier 4 is highly sensitive data such as encryption keys and state-security information. The policy defining them was repealed in February 2024, but the cloud framework still refers to them.
Does CITRA Decision 26 of 2024 apply to my company?
Only if your company holds a licence from CITRA, according to DLA Piper and Chambers. The regulation covers telecom-sector service providers licensed by CITRA. Its definition of a service provider mentions websites, apps and cloud services, so check with counsel if you are unsure. Most private companies are instead covered by the Electronic Transactions Law (No. 20 of 2014) and the Cybercrime Law (No. 63 of 2015).
Can I host Kuwaiti customer data on AWS or Azure outside Kuwait?
For most private companies with no government data, the sources report no general ban, provided you meet consent and security duties. Under the cloud framework, data below tier 3 may use providers abroad (Art. 3.1.4.1), but Art. 4.2.1.1.3 also lists individuals’ personal data held by private companies among data that should not leave Kuwait. If the framework binds you, get legal advice before moving personal data offshore. Backups and replicas count as storage.
Is there a Google Cloud or Azure region in Kuwait?
Google announced a Kuwait region in January 2023, but Kuwait was not in its list of live regions on 27 September 2026. The nearest are Doha and Dammam. Microsoft announced its intent to establish an Azure region in Kuwait in March 2025, with no launch timescale. AWS has made its Outposts hardware available for installation in Kuwaiti data centres since September 2024.
Sources
We checked the facts on this page against these sources on 27 September 2026.
- CITRA: Cloud Computing Regulatory Framework, v2.4 (PDF)
- CITRA: Data Classification Policy, v2.3 (PDF, repealed in February 2024)
- CITRA: Cloud computing service providers licensed by CITRA
- DLA Piper: Data protection laws in Kuwait
- Chambers Global Practice Guides: Data Protection & Privacy 2026, Kuwait (GLA & Company)
- Google Cloud blog: Bringing a new Google Cloud region to Kuwait (24 January 2023)
- Google Cloud: Compute Engine regions and zones
- Microsoft: Microsoft strengthens partnership with Kuwait government, announces intent to establish AI-powered Azure region (6 March 2025)
- AWS: Announcing availability of AWS Outposts in Kuwait (September 2024)
Rukn is an independent software company. We are not affiliated with, endorsed by or a partner of Communication and Information Technology Regulatory Authority (CITRA), Google Cloud, Microsoft Azure, and Amazon Web Services, and we receive no referral fees. Names and trademarks belong to their owners and are used only to describe compatibility.
Related reading
- Kuwait Decree-Law No. 10 of 2026: the website and app checklist, article by articleDecree-Law No. 10 of 2026, Kuwait's digital commerce law, applies one month after its executive regulations are published (Art. 45), and as of 27 September 2026 we could not find them. What your store must build is already fixed in the text: seller disclosures, all-in prices, an Arabic e-invoice, 14-day withdrawal, CBK-licensed payments and 5-year records.
- Kuwait agency vs offshore developer: the real cost and riskAn offshore developer can quote less per hour and add people faster. A Kuwait-based agency usually costs more up front but reduces risks specific to Kuwait: KNET onboarding, Arabic invoices once the digital commerce law applies, Arabic copy, data that may need to stay in Kuwait, and a contract you can enforce in Kuwaiti courts.
- Digital Transformation for Small Business in Kuwait: A 90-Day Starter PathFor a small business in Kuwait, digital transformation means moving the few processes that touch money, customers and government paperwork onto connected digital tools, one step at a time. A realistic first cycle takes about 90 days: foundations first, then payments and customer channels, then one automated workflow.
- WhatsApp AI agent for business: what it can do, what it cannot, and the rulesA WhatsApp AI agent for business reads customers' typed messages, answers from a knowledge base the business controls, and hands the chat to a person when it should. Since 15 January 2026, Meta's terms bar AI Providers from offering general-purpose AI assistants as the main product. In our reading, AI a business uses to serve its own customers is a different use, though Meta decides what counts.
Want this built for your business?
Rukn designs and builds web, mobile, cloud, WhatsApp and AI systems for businesses in Kuwait. Tell us what you need and we reply within 24 hours with a plan, timeline and quote.