Banking Law And Electronic Money Institutions Kuwait .

Banking Law and Electronic Money Institutions in Kuwait

Introduction

Electronic money institutions are increasingly important within Kuwait's financial system. They enable customers to store monetary value electronically and use that value for payments through digital wallets, mobile applications, prepaid systems, and other electronic-payment channels.

In Kuwait, electronic money services are subject to direct supervision by the Central Bank of Kuwait (CBK). The principal framework consists of Law No. 20 of 2014 concerning Electronic Transactions, Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Regulation of Banking Business, Law No. 106 of 2013 concerning Anti-Money Laundering and Combating the Financing of Terrorism, and the CBK's Instructions for Regulating the Electronic Payment of Funds, substantially updated in May 2023.

The objective is to permit financial innovation while protecting customer funds, preventing financial crime, ensuring cybersecurity, and maintaining the safety and stability of Kuwait's payment system.

Meaning of Electronic Money

Electronic money generally represents monetary value stored electronically and used for making payments.

A typical transaction involves a customer providing conventional funds to an electronic money service provider. Corresponding monetary value is then recorded electronically in a wallet or account and may be used for permitted transactions.

Electronic money should be distinguished from ordinary bank deposits. An e-money provider primarily facilitates stored-value and payment services rather than conducting unrestricted banking activities.

It should also be distinguished from speculative virtual assets. E-money is normally denominated by reference to conventional sovereign currency and exists primarily as a payment mechanism.

Central Bank of Kuwait Regulatory Authority

Law No. 20 of 2014 gives the CBK authority over electronic payment activities.

Article 28 recognizes electronic money transfers as an acceptable means of settling payments.

Article 29 requires financial institutions conducting electronic-payment business to comply with banking legislation, AML/CFT rules and relevant regulatory instructions. Institutions must also take necessary measures to provide safe services and maintain banking confidentiality.

The CBK updated its Electronic Payment of Funds Instructions in May 2023. These rules establish a formal licensing and supervisory regime covering electronic-payment services, electronic-money services and payment-system operators.

Licensing of E-Money Service Providers

Electronic money cannot be provided in Kuwait merely by establishing a technology company and launching a digital wallet.

CBK authorization is required.

The regulatory framework distinguishes, among other categories, between:

Small E-Money Service Providers, and

Large E-Money Service Providers.

The classification affects matters including capital requirements, transaction limits and permissible scale of activity.

For example, the CBK's 2023 framework establishes lower stored-value and transaction ceilings for small providers, while large providers operate under substantially higher capital and operational requirements.

A large e-money service provider must generally operate through an appropriate corporate structure and satisfy continuing minimum-capital requirements.

This proportional approach allows smaller fintech businesses to participate while subjecting larger institutions to stronger prudential controls.

Customer Money and Safeguarding

A central concern is protection of funds received from customers.

Money received in exchange for electronic value should not simply be treated as the provider's unrestricted operating capital.

Proper segregation, accounting and safeguarding are essential because customers may otherwise suffer serious losses if the provider becomes insolvent or encounters operational difficulties.

An effective safeguarding framework therefore seeks to distinguish:

customer monetary value;

corporate operating funds;

settlement balances; and

other liabilities.

The central regulatory principle is that an e-money provider should remain capable of meeting its obligations to holders of electronic monetary value.

Transaction and Stored-Value Limits

The CBK regulatory framework uses monetary ceilings as an additional risk-control measure.

For small e-money service providers, limits apply to the amount of electronic money that an individual customer may hold and the volume of transactions conducted through an account.

The 2023 framework establishes, among other limits, a maximum of KWD 1,500 in total stored electronic money for a single customer with a small provider and a corresponding monthly transaction ceiling.

For large providers, the applicable individual limits are higher, including limits reaching KWD 5,000 for stored value and monthly electronic-payment activity under the regulatory framework.

These ceilings help reduce money-laundering, fraud, operational and systemic risks.

AML and Counter-Terrorist-Financing Requirements

E-money services can be vulnerable to financial crime because money can move rapidly through digital channels.

Electronic money institutions must therefore comply with Kuwait's AML/CFT framework, particularly Law No. 106 of 2013 and CBK requirements.

Relevant controls include:

customer identification;

beneficial-owner identification;

transaction monitoring;

sanctions screening;

suspicious-transaction procedures;

recordkeeping; and

enhanced due diligence for higher-risk relationships.

Technology does not reduce these obligations. Digital onboarding systems must still enable the institution to establish who is controlling or benefiting from an account.

Cybersecurity and Operational Resilience

Cybersecurity is a core regulatory requirement.

An e-money institution may hold thousands of customer wallets and process substantial volumes of transactions through interconnected technology systems.

A significant security breach can therefore produce direct customer losses and broader confidence problems.

Providers require controls dealing with:

unauthorized system access;

credential theft;

malware;

payment fraud;

data breaches;

system outages;

disaster recovery; and

third-party technology providers.

Business-continuity arrangements must also allow important payment services to continue or recover rapidly following disruption.

Unauthorized Transactions

Article 30 of Kuwait's Electronic Transactions Law deals with unauthorized electronic account activity.

A customer may be protected where unauthorized activity occurs after the institution has been properly informed that the relevant payment mechanism or electronic signature may have been compromised.

Customer liability can nevertheless arise where the customer's negligence materially caused or contributed to unauthorized use and the institution itself had performed its preventive obligations.

Accordingly, liability requires examination of conduct on both sides rather than an automatic assumption that either the customer or institution must always bear the loss.

Relevant Case Laws and Judicial Authorities

Published Kuwaiti judgments specifically addressing modern electronic-money institutions remain limited. Comparative payment-services and e-money authorities therefore provide useful guidance on concepts closely reflected in modern electronic-payment regulation.

1. Paysera LT UAB – Case C-389/17

This is one of the most directly relevant judicial authorities concerning electronic money institutions.

The Court of Justice considered the relationship between payment services and activities connected with issuing electronic money.

It held that certain payment operations can constitute activities linked to the issuance of electronic money where issuance or redemption forms part of the same payment operation.

Relevance to Kuwait: The case demonstrates why regulators must distinguish ordinary payment services from activities directly connected with e-money issuance when determining capital and licensing obligations.

2. DenizBank AG v Verein für Konsumenteninformation – Case C-287/19

The Court examined contactless NFC payment functionality and the concept of a payment instrument.

It also considered contractual changes, customer information and special rules applicable to low-value payment instruments.

Relevance: Electronic wallets and stored-value products depend upon payment instruments. Customers must be properly informed about the mechanisms and contractual conditions governing digital payments.

3. T-Mobile Austria v Verein für Konsumenteninformation – Case C-616/11

The Court considered the legal meaning of a payment instrument and payment methods including online banking instructions.

Relevance: The case demonstrates that payment regulation can apply broadly to procedures and mechanisms used by customers to initiate payment orders rather than merely to physical payment cards.

4. ING-DiBa – Case C-191/17

The Court examined whether a particular savings account constituted a payment account.

It held that an account from which transactions could only be performed through a separate current account did not fall within the relevant payment-account definition.

Relevance: Precise classification matters. An e-money account, bank account and other stored-value arrangement may attract different regulatory consequences even when customers perceive the products as similar.

5. Veracash – Case C-665/23

The Court considered unauthorized payment transactions and the customer's obligation to notify the payment provider without undue delay.

It confirmed that customer conduct can affect reimbursement rights where an unauthorized transaction is not reported promptly and the applicable conditions concerning intentional or grossly negligent delay are established.

Relevance: E-money providers require clear procedures enabling users to report unauthorized wallet or payment activity immediately.

6. Quoine Pte Ltd v B2C2 Ltd

This Singapore Court of Appeal decision concerned transactions automatically executed through an electronic trading platform.

The Court applied ordinary contractual principles to automated digital transactions.

Relevance: Electronic-money services increasingly depend upon automated systems. The legal effect of transactions does not disappear merely because software performs important stages of transaction execution.

7. Entores Ltd v Miles Far East Corporation

The court considered the rules governing contractual communications transmitted through instantaneous electronic means.

It emphasized receipt of electronic acceptance.

Relevance: Modern e-money relationships involve immediate electronic instructions, confirmations and transaction records. Determining when an instruction has been received and becomes effective can therefore be important.

Governance Requirements

An electronic money institution should maintain a governance structure proportionate to the nature and scale of its activities.

The board and senior management should exercise oversight over:

regulatory compliance;

customer-fund protection;

technology risk;

cybersecurity;

AML/CFT;

outsourcing;

financial controls;

complaints;

business continuity; and

operational resilience.

Responsibility cannot simply be transferred to a software provider.

Even where technology is outsourced, the regulated institution remains accountable for complying with CBK requirements.

Customer Protection

Customer protection forms an important part of Kuwait's e-payment framework.

Customers should receive clear information concerning:

applicable fees;

wallet and transaction limits;

payment procedures;

account suspension;

unauthorized transactions;

security responsibilities;

complaints procedures; and

termination arrangements.

Providers should also establish effective mechanisms for resolving disputes and responding to fraud reports.

Unclear digital interfaces or contractual terms can create significant consumer and regulatory risks.

Cross-Border Operations

Kuwaiti e-money institutions cannot freely expand overseas without regulatory consideration.

The CBK regulatory framework requires prior approval before regulated electronic-payment and electronic-money providers establish branches or subsidiaries outside Kuwait.

This allows the CBK to examine whether foreign expansion creates financial, legal, operational or supervisory risks.

Cross-border payment activities may additionally involve foreign AML rules, sanctions regimes, data requirements and local licensing requirements.

Difference Between E-Money Providers and Banks

An e-money licence should not be interpreted as an unrestricted banking licence.

Traditional banks perform activities such as accepting deposits, granting credit and conducting broader regulated banking business.

An e-money provider operates within the activities permitted under its CBK authorization.

This distinction protects customers and prevents institutions from conducting regulated banking activities outside the statutory licensing regime.

Conclusion

Banking Law and Electronic Money Institutions in Kuwait is governed by an increasingly detailed regulatory framework centred upon the Central Bank of Kuwait.

Law No. 20 of 2014 provides the statutory basis for electronic payments, while the CBK's 2023 Instructions for Regulating the Electronic Payment of Funds establish licensing categories and detailed requirements governing e-money and payment-service providers.

Electronic money institutions must comply with requirements relating to authorization, capital, customer-fund protection, transaction limits, AML/CFT, governance, cybersecurity, business continuity, customer protection and regulatory supervision.

The authorities in Paysera LT, DenizBank, T-Mobile Austria, ING-DiBa, Veracash, Quoine v B2C2 and Entores illustrate important principles involving e-money classification, payment instruments, electronic transaction authorization, customer rights and automated financial services.

The overall Kuwaiti regulatory approach is therefore one of controlled financial innovation: electronic-money services are permitted and encouraged, but only within a supervised framework designed to protect customers and preserve confidence in Kuwait's financial and payment systems.

LEAVE A COMMENT