Kuwait KDPPR Article 5 + supplementary CITRA Incident Reporting Guidelines mandate breach notification regime. Personal Data breach defined as breach of security leading to accidental or unlawful destruction + loss + alteration + unauthorised disclosure of + access to Personal Data. Notification to CITRA Data Privacy Office within 72 hours of becoming aware (similar to GDPR Article 33) + earlier where high-risk. Notification to affected Data Subjects without undue delay where likely to result in high risk to rights and freedoms (compromise of credentials + financial data + Sensitive Personal Data + risk of identity theft + fraud + reputational harm). Notifications include: nature + categories + approximate number of affected Subjects + likely consequences + measures taken or proposed + contact for queries. Records of all breaches whether notified or not. Incident response playbook + tabletop exercises + coordination with CITRA + Kuwait National Cybersecurity Centre + Ministry of Interior for criminal aspects.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.