Kuwait Data Privacy Protection Regulation (KDPPR, 2021 - CMA Directive)
KDPPR - Cross-Border Transfer - Data Localisation - Cloud First Policy - Class A B C D - Articles 6-7

Kuwait Data Privacy Protection Regulation (KDPPR, 2021 - CMA Directive) KDPPR-Cross-Border-Transfer-Data-Localisation-Cloud-First-Policy-Article-6-7-CITRA-Approval: Kuwait KDPPR Cross-Border Transfer + Data Localisation + Cloud First Policy + CITRA Approval

Kuwait KDPPR Articles 6-7 cross-border transfer regime + Cloud Computing localisation. Transfer of Personal Data outside Kuwait permitted only where: (1) destination jurisdiction provides adequate level of protection (CITRA may publish list); (2) standard contractual clauses + binding corporate rules acceptable to CITRA; (3) explicit informed consent of Data Subject + Sensitive Personal Data require written informed consent; (4) necessity for contract performance + vital interests + public interest. CITRA notification + approval may be required for systematic transfers + large volumes + Sensitive Personal Data. CITRA Cloud First Policy (2017 + updated 2021) classifies cloud workloads into: Class A (publicly available data + can use foreign cloud) + Class B (internal data + Kuwait or GCC cloud preferred) + Class C (confidential + national cloud required) + Class D (highly sensitive + government data + on-premise or sovereign cloud only). Cloud service providers must register with CITRA + meet sovereignty requirements for Class C/D workloads. Coordinate with GCC + Arab League data flows.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.