Banking Law And Critical Data Infrastructure Protection Kuwait .
Banking Law and Critical Data Infrastructure Protection in Kuwait
1. Introduction
Kuwait does not regulate banking cybersecurity and critical-data protection through one single “Critical Information Infrastructure Act.” Instead, protection is achieved through a layered regulatory system.
The principal layers are:
- Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Regulation of Banking Business;
- Central Bank of Kuwait regulations and supervisory instructions;
- CBK Cybersecurity Framework (2020) and the newer Cyber & Operational Resilience Framework (CORF);
- Electronic Transactions Law No. 20 of 2014;
- Cybercrime Law No. 63 of 2015;
- CITRA Law No. 37 of 2014, as amended;
- CITRA Data Privacy Protection Regulations;
- legislation and regulations concerning credit information;
- the National Cybersecurity Centre framework and cybersecurity controls; and
- sector-specific requirements for electronic-payment and e-money providers.
This means that a Kuwaiti bank's information-security obligations are simultaneously banking-regulatory, cybersecurity, data-protection, electronic-transactions and criminal-law obligations.
Recent Kuwaiti practice has also moved from traditional cybersecurity compliance toward operational resilience—the ability to anticipate, withstand, recover from and adapt to cyber and operational disruption. The CBK's current CORF describes this as a resilience-first, maturity-oriented regulatory model.
2. Constitutional and Legal Foundation
The starting point is the Kuwaiti legal system and the state's interest in financial and economic stability.
The Central Bank of Kuwait was established under Law No. 32 of 1968. Article 15 sets out the CBK's core objectives, including monetary stability, credit policy and supervision of Kuwait's banking system.
The CBK therefore occupies a position substantially different from an ordinary financial regulator: its statutory mandate is connected to the stability and integrity of the national financial system.
This becomes particularly important when banking systems are treated as critical national infrastructure.
3. Law No. 32 of 1968 — The Principal Banking Law
A. Purpose
Law No. 32 of 1968 is the foundation of Kuwait's banking regulatory system.
It establishes the CBK and provides the legal basis for:
- licensing and regulation of banks;
- supervision of banking activity;
- monetary and credit policy;
- banking information and reporting;
- internal controls;
- financial stability;
- regulatory intervention; and
- supervisory instructions issued by the CBK.
The official CBK source confirms that the law was subsequently amended, including by Decree-Law No. 130 of 1977.
B. Supervisory authority
Article 15 is particularly important because it assigns the CBK responsibility for supervising Kuwait's banking system.
The CBK explains that its supervision sector follows implementation of Chapter III of Law No. 32/1968 and the instructions issued under it, with the objective of safeguarding the stability and integrity of the banking and financial system and protecting customers' money.
Thus, cybersecurity can be viewed as part of prudential banking supervision, even when the original 1968 legislation obviously predates modern cyber threats.
4. Confidentiality of Banking Information
One of the most important connections between banking law and data protection is banking secrecy/confidentiality.
The CBK's regulations expressly include:
instructions concerning banks' maintenance of the confidentiality of information and data concerning their customers.
This appears among the CBK's instructions for conventional banks.
The statutory framework also regulates information supplied by banks to the CBK. Under Article 82, information supplied to the Central Bank is generally confidential, subject to specified exceptions, including certain regulatory information exchanges with other central banks and banking supervisors.
Practical significance
For a bank, confidential information may include:
- account information;
- balances;
- transaction history;
- customer identification information;
- credit information;
- payment information;
- authentication information;
- electronic banking records;
- corporate banking information; and
- other information obtained through the banking relationship.
Therefore, unauthorised access is not merely an IT-security issue—it can become a breach of banking-regulatory duties and potentially a criminal offence.
5. Electronic Payments and Banking Infrastructure
The significance of cybersecurity becomes particularly obvious in electronic payment systems.
The CBK introduced updated Instructions for Regulating Electronic Payment of Funds in May 2023 under the framework of Law No. 20 of 2014 on Electronic Transactions. These regulations place electronic-payment activity under CBK oversight.
The regulatory requirements address, among other matters:
- governance;
- risk management;
- AML/CFT;
- cybersecurity;
- business continuity;
- customer protection; and
- safety and stability of payment systems.
The CBK also issued minimum cybersecurity and business-continuity requirements for e-payment service providers and e-money service providers.
Why this matters for critical infrastructure
A payment system is not merely a database. It is a system whose disruption can affect:
Bank → Payment network → Clearing/settlement → Customer → Government/business transactions
Consequently, compromise of a payment platform can produce systemic consequences.
6. Kuwait's Banking Sector as Critical National Infrastructure
Kuwait's cybersecurity policy has expressly recognised the banking sector as part of critical national infrastructure.
The CBK's cybersecurity materials explain that Kuwait's National Cybersecurity Strategy identifies the banking sector as critical national infrastructure and that the CBK therefore developed cybersecurity requirements specifically for regulated banking entities.
This produces an important legal concept:
Critical infrastructure protection is broader than personal-data protection.
For example:
| Issue | Primary concern |
|---|---|
| Personal data breach | Privacy/confidentiality |
| Bank-account breach | Confidentiality + financial security |
| Payment-system attack | Integrity + availability + financial stability |
| Ransomware against bank | Availability + operational resilience |
| Attack on clearing system | Systemic financial risk |
| Destruction of banking databases | Integrity + continuity |
| Cyberattack on national payment infrastructure | National/critical infrastructure security |
Thus, CIA—Confidentiality, Integrity and Availability—becomes central to banking infrastructure protection.
7. CBK Cybersecurity Framework 2020
The CBK introduced its Cybersecurity Framework (CSF) in 2020.
The framework applies to regulated entities in the banking sector and was designed to improve cybersecurity across:
- systems;
- operations;
- infrastructure;
- information; and
- data.
The CBK subsequently reported implementation by Kuwaiti banks and major sector players such as KNET and CI-NET.
The framework moved banking cybersecurity away from simply having an IT department toward institution-wide governance and risk management.
Key areas include
1. Governance
Senior management and boards have responsibility for cybersecurity governance.
2. Risk management
Banks must identify, assess and manage cyber risks.
3. Security controls
Technical and organisational safeguards must protect systems and information.
4. Incident management
Banks need mechanisms to detect, respond to and recover from security incidents.
5. Business continuity
Critical banking services must continue despite disruption.
6. Data security
Important records and sensitive information must be protected against unauthorised access, alteration or destruction.
7. Third-party risk
Outsourcing and technology providers create additional risks that must be controlled.
8. Cyber & Operational Resilience Framework — CORF
A particularly important contemporary development is the CBK's Cyber & Operational Resilience Framework (CORF).
The CBK describes CORF as the next stage after the 2020 Cybersecurity Framework.
Its philosophy is no longer simply:
“Prevent cyberattack.”
Instead, it asks whether the regulated entity can:
anticipate → withstand → respond → recover → adapt
to cyber and operational disruption.
This is important for critical infrastructure because perfect prevention is impossible.
A bank therefore has to demonstrate not only security controls but also resilience.
Example
Suppose ransomware compromises a bank's primary data centre.
A mature resilience regime asks:
- Was the attack detected?
- Were critical systems isolated?
- Could customers still access essential services?
- Was the backup environment protected?
- Was the backup actually recoverable?
- Was the CBK notified where required?
- Was the incident properly investigated?
- Were customers protected from financial loss?
- How quickly was normal service restored?
- Did the bank modify its controls afterward?
This is the difference between cybersecurity and cyber resilience.
9. Electronic Transactions Law No. 20 of 2014
The Electronic Transactions Law No. 20 of 2014 provides the broader legal basis for electronic transactions and electronic records.
It is important for banking because modern banking involves:
- electronic contracts;
- electronic signatures;
- electronic records;
- online payment;
- digital authentication;
- electronic communications.
The CBK's e-payment framework expressly operates under the Electronic Transactions Law.
Consequently, electronic banking security is not governed exclusively by banking legislation.
10. Cybercrime Law No. 63 of 2015
The Law No. 63 of 2015 on Combating Information Technology Crimes is another central element.
It criminalises various forms of unlawful conduct involving information technology.
Importantly for banking, the legislation covers unlawful activities involving electronic information and specifically reaches information relating to customers' bank accounts.
The law addresses conduct such as:
- unauthorised access;
- unlawful use of information systems;
- alteration or destruction of electronic data;
- electronic forgery;
- misuse of electronic signatures;
- attacks involving electronic systems;
- unlawful access to credit-card data; and
- electronic fraud.
Banking relevance
A cyberattack against a bank can therefore produce two parallel consequences:
Regulatory consequence
CBK cybersecurity and supervisory requirements.
Criminal consequence
Cybercrime prosecution under Law No. 63/2015.
11. Protection of Credit Information
Another important component is Law No. 9 of 2019 concerning the Exchange of Credit Information and its implementing regulations.
Credit information is particularly sensitive because it combines:
- financial information;
- identity information;
- credit history;
- repayment behaviour; and
- information useful for determining creditworthiness.
Kuwait's current data-protection framework identifies Law No. 9 of 2019 as one of the principal sources governing data protection in the country.
Banks therefore need to distinguish between:
ordinary customer data → personal-data protection
and
credit information → additional sector-specific credit-information requirements.
12. CITRA and Data Protection
The Communications and Information Technology Regulatory Authority (CITRA) was established under Law No. 37 of 2014, as amended by Law No. 98 of 2015.
CITRA has also developed data/privacy-related regulations.
Current legal commentary identifies, among the relevant instruments, CITRA Resolution No. 26 of 2024 concerning Data Privacy Protection Regulations and the Cloud Computing Regulatory Framework.
This creates an important compliance question for banks:
Where does banking regulation end and general data regulation begin?
The answer is: they overlap.
A bank may simultaneously have obligations under:
- CBK banking regulations;
- CBK cybersecurity requirements;
- electronic-payment rules;
- credit-information legislation;
- CITRA rules where applicable;
- cybersecurity legislation;
- Electronic Transactions Law; and
- Cybercrime Law.
13. National Cybersecurity Centre
Kuwait established the National Cyber Security Centre (NCSC) under Decree No. 37 of 2022.
Recent Kuwaiti legal materials identify the NCSC as an important national cybersecurity authority, particularly for governmental cybersecurity matters. They also identify subsequent national cybersecurity frameworks and controls.
The 2026 legal landscape therefore reflects a multi-regulator model rather than one universal data-protection authority.
This is significant because Kuwait currently does not have a single regulator exercising comprehensive jurisdiction over all data-protection matters.
14. Critical Data Infrastructure — What Must Be Protected?
A useful way of understanding Kuwaiti banking infrastructure is to divide it into layers.
Layer 1 — Customer data
- name;
- identification information;
- account details;
- transaction history;
- contact information.
Layer 2 — Banking applications
- mobile banking;
- internet banking;
- core banking;
- loan systems;
- treasury systems.
Layer 3 — Payment infrastructure
- card systems;
- electronic-payment platforms;
- payment gateways;
- clearing systems;
- settlement systems.
Layer 4 — Communications infrastructure
- bank networks;
- secure connections;
- data centres;
- cloud infrastructure;
- telecommunications links.
Layer 5 — National financial infrastructure
- central-bank systems;
- payment/settlement infrastructure;
- financial information networks;
- major national financial service providers.
An attack becomes progressively more serious as it moves from individual data → bank → payment network → financial system.
15. Confidentiality, Integrity and Availability
The legal significance of critical data infrastructure can be understood through the CIA triad.
A. Confidentiality
Information must not be disclosed to unauthorised persons.
Example:
A bank employee accesses a customer's account information without authorisation.
Possible implications:
- breach of banking confidentiality;
- data-protection violation;
- internal disciplinary action;
- regulatory consequences;
- potentially criminal consequences depending on conduct.
B. Integrity
Information must not be improperly modified.
Example:
A hacker changes the beneficiary account number for a corporate transfer.
The primary issue is no longer simply confidentiality—the integrity of the payment instruction has been compromised.
C. Availability
Critical systems must remain available.
Example:
A ransomware attack takes down a bank's core banking system.
Even if no customer information is stolen, the event can still be a major operational and systemic risk.
This is why CORF's resilience approach is particularly significant.
16. Business Continuity and Disaster Recovery
Critical banking infrastructure cannot rely only on firewalls and antivirus software.
A bank should have:
- backup systems;
- disaster recovery sites;
- recovery-time objectives;
- recovery-point objectives;
- tested restoration procedures;
- incident-response teams;
- crisis-management procedures;
- alternative communication channels;
- system redundancy; and
- periodic resilience testing.
The CBK's e-payment cybersecurity requirements specifically combine cybersecurity with business continuity, demonstrating that the two are treated as interconnected regulatory requirements.
17. Outsourcing and Cloud Computing
Modern banks frequently rely on:
- cloud providers;
- payment processors;
- fintech companies;
- managed security providers;
- software vendors;
- telecommunications providers.
This creates the problem of third-party cyber risk.
A bank cannot simply argue:
“The data was compromised by our cloud provider, therefore we are not responsible.”
From a regulatory perspective, outsourcing does not necessarily eliminate the bank's responsibility to manage its risks.
Cloud computing therefore becomes particularly important because a breach of a third-party provider can affect multiple banks simultaneously.
Kuwait's current legal framework includes a Cloud Computing Regulatory Framework among its data-protection/cybersecurity instruments.
18. Incident Response
A serious banking cyber incident should trigger a structured response:
Stage 1 — Detection
Identify suspicious activity.
Stage 2 — Containment
Prevent further compromise.
Stage 3 — Investigation
Determine:
- what happened;
- when it happened;
- which systems were affected;
- whether data was accessed;
- whether transactions were manipulated.
Stage 4 — Regulatory notification
Where required, the relevant regulator must be notified.
Stage 5 — Recovery
Restore systems securely.
Stage 6 — Post-incident review
Identify the control failure and prevent recurrence.
The regulatory philosophy increasingly treats resilience as a continuing governance responsibility rather than a one-time technical exercise.
19. Case Law
A. Important qualification
Kuwaiti banking and cybersecurity case law is not as extensively published in English as UK, US or EU case law.
The official Kuwaiti Ministry of Justice provides mechanisms for obtaining Court of Cassation judgments, but many individual decisions are not readily available through an English-language public database.
Therefore, it would be misleading to invent or overstate a Kuwaiti Court of Cassation precedent specifically holding that “bank X breached critical infrastructure law.”
The better approach is to distinguish direct banking/cybersecurity precedents from illustrative cybercrime jurisprudence.
Case 1: Attorney General v. Sara Al-Drees
Court: Kuwaiti Criminal Court / Court of First Instance
Subject: Cybercrime law and online communications
Year: 2016
Sara Al-Drees was prosecuted in connection with tweets, with charges involving the Cybercrime Law together with other communications/publication provisions. The proceedings were observed by international organisations, and the publicly available case materials identify the cybercrime legislation as part of the prosecution.
The case is relevant because it demonstrates that Kuwait's Cybercrime Law can operate alongside older criminal, communications and publication legislation.
Legal significance
The case illustrates the breadth of cyber legislation: the fact that conduct occurs electronically does not necessarily mean that only the Cybercrime Law applies.
Other substantive laws may be applied through electronic means.
Limitation
This is not a banking case. It should therefore be cited as an example of Kuwaiti judicial application of cybercrime legislation, rather than as authority concerning bank cybersecurity.
20. Al-Drees and the Principle of Electronic Conduct
The Al-Drees litigation is nevertheless valuable for understanding a fundamental proposition:
Traditional legal offences can acquire an electronic dimension through the use of information networks or technology.
This principle is highly relevant to banking.
For example:
Traditional fraud + electronic network = electronic financial fraud.
Traditional forgery + electronic document = electronic forgery.
Traditional unauthorised access + banking database = cybercrime/data-security offence.
Traditional disclosure of confidential information + electronic transmission = potentially a technology-enabled confidentiality breach.
21. Cybercrime Law and Bank Accounts
The Cybercrime Law is especially relevant to banking because its provisions expressly encompass data connected with customers' bank accounts.
For example, unlawful manipulation or destruction of electronic banking records can attract serious criminal consequences, while unauthorised access to payment-card information is separately addressed.
This is important because the law protects not merely the physical bank but the electronic information environment through which banking is conducted.
22. Relationship Between Banking Regulation and Criminal Law
Consider the following hypothetical.
Scenario
A bank's employee secretly accesses 500 customer accounts and downloads their information.
There may be several legal dimensions:
Banking law
The conduct may violate banking confidentiality and internal-control requirements.
Data protection
The processing/access may violate applicable privacy requirements.
Cybercrime law
Unauthorised access or misuse of electronic information may constitute an offence.
Employment law
The employee may face disciplinary consequences.
Civil law
Affected customers may potentially have claims depending on the circumstances and applicable law.
Regulatory law
The bank may face supervisory consequences for inadequate controls.
Thus, one cyber incident can generate multiple legal causes and regulatory responses simultaneously.
23. Banking Law vs Critical Infrastructure Law
A useful examination distinction is:
| Banking Law | Critical Infrastructure Protection |
|---|---|
| Protects banking system and financial stability | Protects systems essential to national/economic functioning |
| Regulated principally by CBK | Involves national cybersecurity institutions and sector regulators |
| Focus on banks and financial institutions | Broader infrastructure ecosystem |
| Prudential supervision | National/systemic resilience |
| Customer/account protection | System continuity and national security |
| Capital/liquidity/governance | Cybersecurity, resilience, continuity |
| Banking secrecy | Confidentiality, integrity and availability |
| Payment-system safety | Protection of critical financial infrastructure |
The two areas overlap substantially because banking systems themselves may constitute critical infrastructure.
24. Regulatory Responsibility — Who Does What?
Central Bank of Kuwait
Primary sector regulator for banks and many financial/payment activities.
Its responsibilities include:
- banking supervision;
- financial stability;
- cybersecurity requirements;
- electronic-payment regulation;
- operational resilience.
CITRA
Regulates communications and information-technology matters under its establishing legislation and has issued data/privacy and cloud-related regulations.
National Cybersecurity Centre
Provides national-level cybersecurity governance and controls, particularly concerning government and national cybersecurity architecture.
Criminal authorities
Enforce the Cybercrime Law and other criminal legislation when cyber incidents constitute offences.
25. Major Legal Principles
From the Kuwaiti framework, several principles can be derived.
Principle 1 — Cybersecurity is part of banking supervision
Cybersecurity is no longer merely a technical function.
It is connected to the CBK's statutory responsibility for banking stability.
Principle 2 — Banking data is specially protected
Customer banking information is subject to confidentiality obligations and additional sector-specific requirements.
Principle 3 — Critical infrastructure requires resilience
The objective is not simply to prevent attacks but to ensure that essential banking services can survive and recover from disruption.
Principle 4 — Multiple laws can apply simultaneously
A single incident may invoke:
- banking law;
- cybercrime law;
- electronic-transactions law;
- data-protection rules;
- credit-information law; and
- contractual/civil obligations.
Principle 5 — Payment systems are particularly sensitive
Because payment systems are interconnected, their compromise can create consequences beyond an individual bank.
26. Hypothetical Case Study
Facts
A cybercriminal obtains an employee's credentials at a Kuwaiti bank.
The criminal:
- enters the bank's internal network;
- accesses customer accounts;
- changes beneficiary details;
- transfers KWD 2 million;
- deletes transaction logs; and
- encrypts part of the bank's database.
Legal analysis
A. Unauthorised access
The attacker has interfered with an electronic information system.
Cybercrime Law becomes relevant.
B. Customer data
The attacker accessed banking information.
Banking confidentiality and data-protection obligations are implicated.
C. Payment manipulation
Changing beneficiary details compromises the integrity of the payment system.
D. Destruction of records
Deletion of logs compromises evidence and data integrity.
E. Ransomware
Encryption of the database creates an availability and resilience problem.
F. Bank's regulatory responsibility
The CBK may examine whether the bank had:
- appropriate authentication;
- access controls;
- monitoring;
- incident detection;
- segregation of duties;
- backup systems;
- business continuity;
- incident-response procedures.
G. Critical infrastructure dimension
If the incident materially disrupts a system important to Kuwait's financial infrastructure, it becomes more than an ordinary data breach.
It may represent a systemic operational-resilience event.
27. Key Challenges in Kuwait
1. Fragmented legal framework
Kuwait does not have one comprehensive statute governing every aspect of data protection and critical infrastructure.
Current legal analysis describes the system as distributed among several laws and regulators.
2. Overlapping regulators
Banks may need to consider requirements from:
- CBK;
- CITRA;
- NCSC; and
- other governmental authorities.
3. Rapid technological change
The 1968 banking statute could not have anticipated:
- cloud banking;
- mobile banking;
- AI;
- ransomware;
- APIs;
- cryptocurrency;
- open banking;
- sophisticated phishing;
- supply-chain attacks.
Consequently, much of the modern regime is implemented through regulatory instructions and cybersecurity frameworks rather than through the original statute itself.
4. Cross-border data
International banks and cloud providers raise difficult questions concerning:
- data transfers;
- foreign regulators;
- cloud locations;
- confidentiality;
- supervisory access.
5. Third-party risk
A bank may be operationally dependent on external technology providers.
A cyberattack on one provider could therefore affect several banks simultaneously.
28. Critical Evaluation
Kuwait has developed a relatively sophisticated sector-specific approach to banking cybersecurity.
Strengths
First, the CBK has direct supervisory authority over banks.
Second, Kuwait recognised the banking sector as critical national infrastructure.
Third, the 2020 cybersecurity framework created sector-specific cybersecurity expectations.
Fourth, the newer CORF shifts the focus toward operational resilience.
Fifth, electronic-payment providers are subject to explicit cybersecurity and business-continuity requirements.
Sixth, cybercrime legislation provides criminal protection against unauthorised access, manipulation and electronic financial offences.
Weaknesses/challenges
The principal weakness is fragmentation.
Rather than one comprehensive data/critical-infrastructure statute, obligations are distributed across different laws, regulators and sectoral instruments.
Current 2026 legal commentary expressly notes that Kuwait does not have a single overarching data-protection regulator.
29. Conclusion
The Kuwaiti approach can be summarised as follows:
Law No. 32/1968
↓
CBK banking supervision
↓
Bank confidentiality + internal controls
↓
Cybersecurity Framework 2020
↓
Electronic-payment cybersecurity requirements
↓
Cybercrime Law No. 63/2015
↓
CITRA/data privacy framework
↓
National Cybersecurity Centre
↓
CBK Cyber & Operational Resilience Framework
↓
Protection of Kuwait's critical financial infrastructure
The central legal idea is that a modern bank is simultaneously a financial institution, a data custodian and an operator of critical digital infrastructure.
Accordingly, protecting Kuwaiti banks requires more than protecting money. The law and regulatory framework increasingly seek to protect the confidentiality, integrity, availability and resilience of the digital systems on which the Kuwaiti financial system depends. The CBK's move from the 2020 cybersecurity framework to CORF is especially significant because it places resilience and recovery alongside prevention.
Key authorities to cite in an academic answer
- Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and Regulation of Banking Business.
- CBK Instructions for Conventional Banks, particularly customer-information confidentiality and internal-control requirements.
- CBK Cybersecurity Framework 2020.
- CBK Cyber & Operational Resilience Framework (CORF).
- Instructions for Regulating Electronic Payment of Funds, 2023.
- Law No. 20 of 2014 on Electronic Transactions.
- Law No. 63 of 2015 on Combating Information Technology Crimes.
- Law No. 9 of 2019 concerning Exchange of Credit Information.
- Law No. 37 of 2014 establishing CITRA, as amended by Law No. 98 of 2015.
- CITRA Resolution No. 26 of 2024 on Data Privacy Protection Regulations.
- Decree No. 37 of 2022 establishing the National Cybersecurity Centre.
- Attorney General v. Sara Al-Drees / Sara Al-Drees cybercrime proceedings — useful as an illustrative cybercrime case, although not a banking case.

comments