Kuwait KDPPR Articles 4 + 7 data processor + third-party vendor obligations. Controllers must conduct due diligence on Processors + cloud providers + ensure: (1) Documented contracts specifying purposes + scope + categories of Personal Data + duration + obligations of Processor including security + sub-processing + Data Subject support + audit rights + breach notification + return or deletion at end of contract; (2) Processors process only on Controller documented instructions; (3) Processors maintain confidentiality + security commensurate with KDPPR Articles 4-5; (4) Sub-processors only with prior written authorisation from Controller + flow-down contractual obligations; (5) Cloud providers categorised per Cloud First Policy + meet sovereignty for higher-classification workloads; (6) Cross-border transfers by Processor follow KDPPR Article 6 lawful bases; (7) Joint Controllership where applicable. Processor independent CITRA liability where exceeds Controller instructions or fails security obligations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.