Banking Law And Financial Sector Information Sharing Networks Kuwait .

Banking Law and Financial Sector Information Sharing Networks in Kuwait

Introduction

Information sharing is an important part of Kuwait’s banking and financial-sector framework. Banks and financial institutions need access to reliable information about customers, credit obligations, payment behaviour, risks, fraud and regulatory compliance. At the same time, Kuwait places strong legal importance on banking confidentiality. The central legal challenge is therefore to permit lawful and controlled information sharing without allowing unauthorized disclosure of customer information.

The principal framework includes the Central Bank of Kuwait Law No. 32 of 1968, CBK supervisory instructions, the Law No. 9 of 2019 Regulating the Exchange of Credit Information, its executive regulations, and AML/CFT requirements. The CBK expressly permits certain information exchanges for supervisory purposes, while confidentiality remains the general rule.

Legal and Regulatory Framework

1. Central Bank information-sharing powers

Articles 78–83 of the CBK Law provide an important foundation for information networks. Banks must provide the CBK with information, data and statistics requested for supervisory purposes. Article 82 also recognises the possibility of exchanging information between the CBK and other central banks and banking supervisory authorities for consolidated supervision, subject to agreed arrangements.

This creates a distinction between:

  • information supplied to the regulator;
  • information exchanged between supervisory authorities;
  • information shared through credit-information systems; and
  • information disclosed to private third parties.

The legal basis and permitted purpose are different in each situation.

2. Banking secrecy

Banking confidentiality remains a fundamental principle. Article 28 of the CBK Law restricts CBK directors, officers and employees from disclosing information concerning the CBK, its customers or supervised banks unless disclosure is legally permitted.

Similarly, Article 80 requires CBK inspection officials to maintain secrecy concerning accounts, books and customer affairs, subject to lawful exceptions. Article 82 provides that information supplied by banks remains confidential except for specified forms of aggregate data and permitted supervisory exchange.

Therefore, an information-sharing network is not a general waiver of banking secrecy. It operates within statutory exceptions and regulatory controls.

3. Credit-information networks

Law No. 9 of 2019 provides a specific statutory framework for credit-information exchange. It covers the credit-information company, information providers, licensed users and customers connected with credit-reporting systems. Credit information may include positive and negative payment information, credit records, credit reports and credit ratings.

Kuwait Credit Information Network Company (CINET) operates under this framework. Its system can receive information from banks, investment companies, finance companies and other entities providing credit facilities.

The framework is designed to improve lenders' ability to evaluate credit risk while imposing requirements concerning security and confidentiality.

4. Customer consent and controlled access

Information sharing does not mean that every participating institution can freely inspect every customer's financial information. CINET states that subscribed entities generally require customer authorization before accessing a customer's credit report, and customers can obtain information about entities that have accessed their reports.

This supports an important principle of financial information governance:

access should be connected to a legitimate purpose, authorized user and appropriate legal basis.

5. Data security

The executive framework for credit-information companies requires measures to protect information security and confidentiality. These include physical security controls and an alternative emergency centre designed to protect the system against risks and disasters.

Consequently, information-sharing networks have both a legal-compliance dimension and a cybersecurity dimension.

6. AML/CFT and regulatory information sharing

Financial institutions also operate within Kuwait's AML/CFT framework. Information may need to move between regulated institutions and competent authorities for customer due diligence, suspicious-transaction monitoring, sanctions compliance and financial-crime prevention. CBK instructions contain specific AML/CFT requirements for banks, financing companies and exchange companies.

The existence of banking secrecy does not prevent lawful regulatory access. The IMF has noted that CBK supervisory powers under Articles 78 and 82 allow the CBK to obtain information from supervised institutions, including information relevant to AML/CFT.

Key Legal Issues and Principles

Purpose limitation

Information should be exchanged for a legally recognised purpose rather than for unrestricted commercial use. Credit assessment, regulatory supervision, AML/CFT and lawful investigations are examples of purposes supported by the regulatory framework.

Accuracy of information

Incorrect credit information can affect a customer's ability to obtain financing. Law No. 9 of 2019 therefore makes accuracy and updating important features of the credit-information system. CINET provides mechanisms through which customers can dispute information appearing in their reports.

Confidentiality

Banks and information networks must maintain controls preventing unauthorized access. Confidentiality duties apply even though certain forms of information exchange are legally authorised.

Cross-border sharing

Cross-border supervisory information exchange requires particular care because Kuwait's banking-secrecy rules interact with foreign regulatory requirements. The CBK has historically used arrangements with foreign supervisory authorities for permitted information exchange.

Customer remedies

Kuwait's banking consumer-protection system provides complaint mechanisms. Where a complaint concerns a credit-information company, the company is expected to respond within the prescribed period, after which the customer can escalate the matter to the CBK.

Case Laws

A significant qualification is necessary: published Kuwaiti jurisprudence specifically devoted to modern financial-sector information-sharing networks is relatively limited in accessible English sources. Accordingly, the following authorities should not all be described as Kuwaiti precedents. They are useful comparative authorities for the legal principles that arise in Kuwait.

1. Tournier v National Provincial and Union Bank of England [1924]

This is the classic banking-confidentiality authority. The court recognised that a banker's duty of confidentiality is subject to exceptions, including disclosure required by law, public duty and circumstances in which disclosure is justified by the customer's interests.

Its importance for Kuwait is conceptual: banking secrecy is strong but not absolute. Kuwait's statutory exceptions similarly permit defined forms of regulatory and legally authorised disclosure.

2. Campbell v MGN Ltd [2004] UKHL 22

The House of Lords considered privacy and misuse of private information. The case illustrates the importance of controlling disclosure of information where individuals have a reasonable expectation of privacy.

For financial institutions, the principle supports careful treatment of personal financial information even where information has been lawfully obtained.

3. Durant v Financial Services Authority [2003] EWCA Civ 1746

The English Court of Appeal considered the scope of personal information in the context of financial regulation and access rights.

The case is relevant comparatively because financial-sector information frequently exists within regulatory databases, and determining whether information is personal and how it may be accessed requires attention to statutory purpose.

4. Vidal-Hall v Google Inc [2015] EWCA Civ 311

The court addressed privacy and misuse of private information in connection with digital data. Although not a banking case, it demonstrates the increasing legal significance of electronic personal information.

For Kuwaiti information-sharing networks, the case illustrates why traditional confidentiality principles must be supplemented by cybersecurity and digital-data controls.

5. Lloyd v Google LLC [2021] UKSC 50

The UK Supreme Court examined claims arising from the alleged collection and processing of personal data.

Its relevance is comparative: large-scale databases can create legal issues concerning the collection, processing and governance of information affecting large groups of individuals. This is particularly relevant to credit-information databases.

6. Schrems II, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems, Case C-311/18

The Court of Justice of the European Union examined international transfers of personal data and the protection available when information moves between jurisdictions.

The decision is particularly useful for analysing cross-border financial-information networks, although it is not binding Kuwaiti law. It demonstrates why international information exchange requires attention to confidentiality, legal authority and safeguards in the receiving jurisdiction.

Enforcement and Institutional Responsibilities

The CBK is central to the supervision of Kuwait's banking information environment. It can require information from supervised institutions and establish systems for collecting banking-credit information.

Credit-information companies operate under the statutory framework established by Law No. 9 of 2019 and CBK supervision. CINET's ownership structure includes the CBK, commercial banks and financial companies, reflecting its role in the national credit-information infrastructure.

Banks must consequently establish internal controls addressing:

  1. authorized access;
  2. customer authentication and consent;
  3. data accuracy;
  4. confidentiality;
  5. cybersecurity;
  6. audit trails;
  7. third-party access;
  8. regulatory reporting;
  9. cross-border disclosures; and
  10. customer complaints and correction requests.

Unauthorized disclosure can also create statutory consequences. The CBK Law contains penalties for breaches of confidentiality by relevant officials.

Conclusion

Kuwait's financial-sector information-sharing system attempts to balance banking secrecy with the practical need for regulated information exchange. The CBK Law provides supervisory information powers, while Law No. 9 of 2019 creates a dedicated framework for credit-information exchange. CINET provides an important operational infrastructure for sharing credit information among authorised participants.

The central legal principle is therefore not unrestricted information sharing but lawful, necessary, purpose-specific and secure information sharing. Banks and financial institutions must distinguish regulatory disclosure from commercial disclosure and maintain confidentiality controls throughout the information lifecycle.

For modern Kuwait banking practice, the major legal issues are increasingly connected: credit reporting, customer consent, data accuracy, cybersecurity, AML/CFT, regulatory cooperation and cross-border information exchange. Effective information-sharing networks must accommodate all of these requirements while preserving the confidentiality that remains a fundamental feature of Kuwait's banking system.

LEAVE A COMMENT