Banking Law And Payment Card Network Regulation Kuwait .
Banking Law and Payment Card Network Regulation in Kuwait
1. Introduction
Payment card network regulation in Kuwait concerns the legal and regulatory framework governing credit cards, debit cards, prepaid cards, card-processing systems, payment gateways, acquiring services, electronic payments and the networks connecting customers, merchants, banks and payment-service providers.
A typical card transaction involves several parties:
Cardholder → Merchant → Acquiring Bank/Processor → Card Network → Issuing Bank
International networks such as Visa and Mastercard can form part of this infrastructure, while Kuwaiti banks and domestic payment infrastructure operate within the regulatory framework supervised principally by the Central Bank of Kuwait (CBK).
Kuwait does not regulate payment-card networks through one self-contained "Payment Card Network Act." Instead, the framework is built from banking legislation, CBK regulations and instructions, electronic-transactions law, consumer-protection requirements, cybersecurity obligations, anti-money-laundering rules and contractual arrangements between issuers, acquirers, merchants, processors and network operators.
2. Central Bank of Kuwait as Principal Regulator
The principal banking statute is Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business, as amended.
The CBK's regulatory role is particularly important because card payments involve:
- regulated banks;
- customer funds;
- clearing and settlement;
- electronic payment systems;
- operational resilience;
- fraud prevention;
- cybersecurity; and
- systemic financial stability.
A payment-card business therefore cannot be analysed simply as a private contract between a bank and its customer.
It forms part of Kuwait's regulated financial infrastructure.
3. CBK Payment-Service Regulation
Kuwait has developed a more specific regulatory framework for electronic payment of funds and payment-service providers.
The framework addresses entities involved in activities such as:
- payment services;
- electronic payment systems;
- payment gateways;
- electronic-money-related activities;
- payment processing; and
- related financial technology.
Depending upon its precise business model, a payment company may require CBK registration, licensing or other regulatory authorization.
This is important for card networks because a company cannot necessarily avoid financial regulation merely by describing itself as a "technology platform."
The regulator looks at the substance of the activity.
4. Structure of a Card Transaction
Suppose a customer purchases a laptop in Kuwait for:
KD 500
using a credit card.
The transaction might operate as follows:
- Customer presents card credentials.
- Merchant sends authorization request.
- Merchant's acquiring bank or processor forwards it.
- Card network routes the request.
- Issuing bank approves or declines it.
- Authorization returns to merchant.
- Clearing takes place.
- Settlement follows.
- Merchant receives funds after applicable charges.
Different legal relationships therefore exist simultaneously.
There may be:
Cardholder ↔ Issuing Bank
Merchant ↔ Acquiring Bank
Acquirer ↔ Network
Issuer ↔ Network
Processor ↔ Bank
Each relationship may have different contractual and regulatory consequences.
5. Card Issuing Regulation
A Kuwaiti bank issuing cards must comply with the regulatory requirements applicable to banking and consumer-facing financial products.
For a credit card, important issues include:
- credit assessment;
- credit limits;
- fees;
- disclosure;
- repayment obligations;
- unauthorized transactions;
- customer complaints;
- card cancellation;
- fraud monitoring; and
- responsible treatment of customers.
A card is therefore both a payment instrument and, where credit is extended, a credit product.
Debit cards are somewhat different because payment ordinarily comes from money already available in the customer's account.
6. Acquiring Services
The acquirer provides card-payment acceptance services to merchants.
For example:
Kuwaiti retailer → acquiring bank → card network → customer's bank
The acquiring agreement normally addresses:
- merchant fees;
- settlement periods;
- chargebacks;
- prohibited transactions;
- security requirements;
- fraud monitoring;
- card-data protection;
- termination;
- reserves; and
- disputed transactions.
Banks must also consider whether merchants present heightened risks involving fraud, money laundering or prohibited business activities.
7. Payment Card Networks
A card network provides infrastructure and rules connecting participants.
Network rules may cover:
- authorization;
- clearing;
- settlement;
- card acceptance;
- technical standards;
- dispute procedures;
- chargebacks;
- fraud controls;
- tokenization;
- authentication; and
- merchant requirements.
But private network rules do not override mandatory Kuwaiti law or CBK requirements.
A contractual provision saying:
"Network rules are final in every circumstance"
cannot necessarily exclude mandatory regulatory, judicial or consumer-protection requirements applicable in Kuwait.
8. Electronic Transactions Law
Kuwait Law No. 20 of 2014 concerning Electronic Transactions is important to digital payment arrangements.
Modern card transactions frequently involve:
- electronic instructions;
- digital records;
- authentication credentials;
- electronic communications; and
- electronically generated evidence.
Consequently, the legal recognition and evidential treatment of electronic records becomes important where customers or merchants dispute transactions.
For example, litigation may require determination of whether a particular electronic transaction was actually authorized.
9. Authentication and Fraud Prevention
Card-network regulation increasingly focuses on whether the transaction was genuinely initiated or authorized by the customer.
Banks and processors therefore employ controls such as:
- PIN authentication;
- one-time passwords;
- transaction alerts;
- device identification;
- fraud-scoring systems;
- tokenization; and
- multi-factor authentication.
Consider:
Customer normally spends KD 50–100 per transaction.
Suddenly the card records:
KD 4,500 foreign online purchase.
The issuing bank's fraud-monitoring systems may identify this as abnormal activity.
The legal question following a dispute can include whether appropriate authentication and security procedures were followed.
10. Unauthorized Card Transactions
Unauthorized transactions are one of the most significant areas of card-related banking disputes.
Suppose a customer's card credentials are stolen and used to purchase goods.
Questions may include:
- Did the customer authorize the transaction?
- Was the PIN or OTP used?
- Was the customer's device compromised?
- Did the customer disclose security credentials?
- Did the bank follow required security procedures?
- When did the customer report the loss?
- Were transaction alerts issued?
- What does the card agreement provide?
- Are contractual provisions consistent with mandatory law and CBK requirements?
The mere fact that technically correct credentials were used does not always resolve every legal issue surrounding authorization or liability.
11. Chargebacks
A chargeback reverses or challenges a card transaction through the card-payment system.
Possible grounds include:
- unauthorized transaction;
- duplicate transaction;
- goods not delivered;
- incorrect amount;
- cancelled transaction;
- defective transaction;
- processing error; or
- merchant fraud.
The card network may establish detailed procedural rules.
However, network chargeback rights and the customer's underlying legal rights should be distinguished.
Losing a network chargeback does not necessarily mean that every possible contractual or statutory remedy has disappeared.
12. Merchant Fees and Interchange
Payment-card economics frequently involve several charges.
For example:
Customer pays:
KD 100
Merchant may ultimately receive less than KD 100 because the payment chain can include:
- merchant service charge;
- acquiring fee;
- network fee; and
- interchange-related amounts.
Regulatory concerns may arise regarding:
- transparency;
- competition;
- discriminatory treatment;
- merchant restrictions; and
- unfair contractual practices.
Kuwait's approach must be distinguished from the EU's detailed statutory interchange-fee regime. EU interchange caps should not automatically be assumed to apply to Kuwaiti domestic card transactions.
13. Competition Law
Card networks can produce strong network effects.
More cardholders attract more merchants.
More merchants make the network more attractive to cardholders.
This can create substantial market power.
Potential competition-law issues include:
- exclusivity;
- restrictive merchant rules;
- discriminatory access;
- tying arrangements;
- exclusionary practices;
- pricing restrictions; and
- agreements between competing institutions.
Kuwait's competition legislation can therefore become relevant alongside banking regulation.
Competition regulation and CBK regulation address different questions: one focuses particularly on competitive market conduct, while the other focuses heavily on financial regulation, payment-system safety and banking stability.
14. Consumer Protection
Card contracts are frequently standard-form contracts.
Customers generally do not negotiate every provision individually.
Regulatory attention can therefore arise concerning:
- unclear fees;
- hidden charges;
- misleading advertising;
- unilateral amendments;
- excessive contractual exclusions;
- unclear exchange-rate provisions;
- disputed transactions; and
- complaint procedures.
Banks should provide customers with sufficiently clear information about the economic and legal characteristics of card products.
15. Foreign-Currency Transactions
Suppose a Kuwaiti cardholder purchases something for:
US$1,000
The account is denominated in Kuwaiti dinars.
The transaction can involve:
- network exchange-rate calculation;
- bank conversion;
- foreign-transaction fee;
- additional processing charges.
The customer should therefore understand how foreign-currency transactions are calculated.
Disputes can arise when the amount appearing on the statement differs significantly from the amount the customer expected.
16. Anti-Money-Laundering Requirements
Payment networks can potentially be misused for:
- money laundering;
- fraud;
- stolen-card transactions;
- terrorist financing;
- merchant collusion; or
- movement of illicit proceeds.
Kuwait's Law No. 106 of 2013 regarding Anti-Money Laundering and Combating the Financing of Terrorism, together with implementing requirements and CBK supervision, is therefore relevant.
Banks and regulated payment providers may have obligations concerning:
- customer identification;
- transaction monitoring;
- suspicious activity;
- record keeping;
- risk assessment; and
- reporting.
Payment convenience does not eliminate AML/CFT obligations.
17. Cybersecurity
Cybersecurity is central to modern card regulation.
Potential attacks include:
- theft of card numbers;
- account takeover;
- phishing;
- compromised merchant terminals;
- malware;
- payment-gateway breaches;
- credential stuffing; and
- attacks on processors.
A payment-card operator must therefore treat cyber risk as both an information-security problem and a financial regulatory risk.
Banks also need business-continuity and incident-response mechanisms.
18. Outsourcing and Cloud Processing
A Kuwaiti bank might use a foreign technology company for card processing.
For example:
Kuwaiti Bank → international processor → global cloud infrastructure
Outsourcing does not necessarily transfer the bank's regulatory responsibility to the vendor.
The bank may still need appropriate:
- vendor due diligence;
- contractual controls;
- cybersecurity requirements;
- audit/access rights;
- business-continuity planning;
- incident reporting;
- data protections; and
- exit arrangements.
The same principle becomes particularly important where critical payment infrastructure is outsourced.
19. Fintech and Digital Wallets
The traditional card network is increasingly connected with:
- mobile wallets;
- contactless payments;
- tokenized cards;
- QR payments;
- embedded payments;
- digital banking applications; and
- fintech platforms.
For example:
Customer → Mobile Wallet → Token → Card Network → Issuer
The customer may never physically present the card.
Nevertheless, the underlying transaction can remain a card-network transaction.
Regulation therefore increasingly focuses on function rather than physical form.
20. Payment Network Operational Resilience
Payment networks are critical infrastructure because an outage can affect thousands or potentially millions of transactions.
Banks and payment providers therefore require systems addressing:
- redundancy;
- backup facilities;
- cyber incidents;
- disaster recovery;
- transaction reconciliation;
- service continuity; and
- recovery procedures.
A card network failure is not merely an IT inconvenience. A sufficiently serious outage can become a banking and financial-stability concern.
21. Case Law
An important limitation applies here: publicly accessible Kuwaiti appellate decisions specifically concerning payment-card network regulation are relatively limited, and many banking disputes are reported without the detailed factual material available in some common-law jurisdictions.
It would therefore be misleading to invent six Kuwaiti "Visa/Mastercard network" cases.
The following comparative cases provide useful legal principles while remaining distinct from binding Kuwaiti precedent.
Case 1 — Mastercard Inc. v European Commission, Case C-382/12 P
The Court of Justice of the European Union considered Mastercard's multilateral interchange fees and competition law.
The case demonstrates that card-network pricing arrangements can be subject to competition-law scrutiny rather than being treated merely as internal network rules.
Kuwaiti relevance: card-network arrangements must be considered alongside applicable competition rules and financial regulation.
Case 2 — Sainsbury's Supermarkets Ltd v Visa Europe Services LLC
The UK litigation concerned interchange fees and competition law.
The litigation examined the economic structure connecting issuing banks, acquiring banks, merchants and card networks.
Kuwaiti relevance: interchange arrangements can have significant effects on merchants and market competition, making the economic substance of network rules important.
Case 3 — Sainsbury's Supermarkets Ltd v Mastercard Inc. [2020] UKSC 24
The UK Supreme Court considered major competition-law claims relating to multilateral interchange fees.
The judgment illustrates how card-network arrangements can be analysed under competition principles even where the relevant charges arise from a sophisticated multi-sided payment system.
Kuwaiti relevance: private network arrangements are not automatically insulated from competition-law analysis.
Case 4 — Lloyds TSB Bank plc v Markandan & Uddin [2012] EWCA Civ 65
Although not a card-network case, the decision concerned banking/payment-related responsibility where funds were transferred in circumstances involving fraud.
Its broader significance is the importance of clearly identifying the obligations assumed by financial intermediaries.
Kuwaiti relevance: card disputes similarly require examination of the separate obligations of issuer, acquirer, processor, merchant and customer rather than treating the payment chain as a single contractual relationship.
Case 5 — Philipp v Barclays Bank UK PLC [2023] UKSC 25
The UK Supreme Court examined a bank's obligations where a customer personally instructed payments that turned out to be connected with fraud.
This was an authorized push-payment case rather than a card case.
Its comparative significance lies in the distinction between authorized instructions and fraudulent circumstances surrounding those instructions.
Kuwaiti relevance: the legal characterization of authorization can be critical when allocating responsibility for disputed electronic transactions.
Case 6 — Office of Fair Trading v Abbey National plc [2009] UKSC 6
This litigation concerned bank charges and consumer-contract regulation rather than payment-card networks specifically.
The case illustrates the interaction between:
- banking contracts;
- standardized consumer terms;
- fees; and
- consumer-protection legislation.
Kuwaiti relevance: card fees and contractual provisions should be assessed not only under the card agreement but also under applicable mandatory regulatory and consumer-protection requirements.
22. Status of Comparative Case Law in Kuwait
These decisions are not binding Kuwaiti precedents.
Their value is analytical.
They illustrate recurring issues that can also arise in Kuwait:
| Issue | Banking-law significance |
|---|---|
| Interchange fees | Competition and merchant costs |
| Network rules | Cannot automatically displace mandatory law |
| Fraud | Allocation of payment responsibility |
| Authorization | Determines important liability questions |
| Standard contracts | Consumer protection becomes relevant |
| Multiple intermediaries | Responsibilities must be separately identified |
| Network dominance | May trigger competition scrutiny |
| Cybersecurity | Creates operational and regulatory risk |
A Kuwaiti court would ultimately apply Kuwaiti legislation, applicable CBK requirements and the governing contractual arrangements.
23. Practical Example
Assume a Kuwaiti customer has a credit card issued by Bank A.
The customer makes a:
KD 1,200 online purchase.
The transaction passes through:
Customer → Merchant → Payment Gateway → Acquirer → International Card Network → Bank A
Later the customer claims:
"I never authorized this payment."
A proper investigation should not focus exclusively on whether the merchant received money.
It should examine:
- authentication records;
- transaction timestamp;
- card credentials;
- OTP records;
- device information;
- merchant records;
- network authorization;
- issuing-bank records;
- fraud alerts;
- customer notification;
- chargeback rules; and
- applicable contractual and regulatory obligations.
The outcome therefore depends upon the complete payment chain.
24. Regulatory Compliance Framework
A payment-card business operating in Kuwait should generally examine five layers:
Layer 1 — CBK regulation
Licensing, banking supervision, payment activities and prudential requirements.
Layer 2 — Payment infrastructure
Authorization, processing, clearing, settlement and operational resilience.
Layer 3 — Financial-crime compliance
AML/CFT, fraud monitoring and customer identification.
Layer 4 — Customer protection
Disclosure, fees, unauthorized transactions and complaints.
Layer 5 — Technology governance
Cybersecurity, outsourcing, data management and business continuity.
Failure in one layer can create consequences across the others.
25. Conclusion
Payment card network regulation in Kuwait is a multi-layered area of banking law rather than a single statutory regime. Its foundation includes Law No. 32 of 1968, CBK regulation and supervision, the electronic-payment regulatory framework, Law No. 20 of 2014 on Electronic Transactions, Law No. 106 of 2013 on AML/CFT, consumer rules, competition law and private card-network agreements.
The most important legal issues concern authorization, fraud, card issuance, acquiring, clearing and settlement, chargebacks, merchant fees, cybersecurity, outsourcing, AML/CFT compliance, customer protection and operational resilience.
There is limited readily accessible Kuwaiti reported case law dealing specifically with card-network regulation. Comparative decisions such as Mastercard v Commission, Sainsbury's v Mastercard, and Philipp v Barclays can help explain particular competition or payment-law principles, but they should not be represented as Kuwaiti precedent. In an actual Kuwaiti dispute, priority must be given to Kuwaiti legislation, current CBK requirements, the relevant card agreement and the applicable network rules.

comments