Banking Law And Information Barrier Requirements In Banks Kuwait .

Banking Law and Information Barrier Requirements in Banks — Kuwait

1. Introduction

Information barriers are internal organizational, technological, and procedural controls designed to prevent confidential or price-sensitive information from moving improperly between different departments, employees, affiliates, or business functions of a financial institution.

They have traditionally been called “Chinese walls,” although “information barriers” is now the more common expression.

Information barriers are especially important for banks because a single banking group may simultaneously conduct or support:

corporate lending;

investment banking;

securities activities;

wealth management;

research;

treasury operations;

asset management;

brokerage;

mergers and acquisitions work;

customer account services; and

proprietary financial activities.

One department may therefore possess confidential information that another department could improperly exploit.

In Kuwait, information barriers do not depend on one isolated statutory provision entitled “Information Barrier Law.” Instead, they arise from several overlapping requirements involving banking secrecy, internal controls, conflicts of interest, securities regulation and insider information.

The principal authorities include:

Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Regulation of Banking;

Central Bank of Kuwait supervisory instructions;

Law No. 7 of 2010 concerning the Capital Markets Authority and Regulating Securities Activities;

the CMA Executive Bylaws; and

banks' internal governance and compliance systems.

2. Basic Purpose of an Information Barrier

Consider a bank with two departments.

The corporate banking department learns confidentially that a listed corporate customer is preparing a major acquisition.

The bank's securities or investment department trades in shares.

Without an information barrier, an employee could transfer the confidential acquisition information to a trader, portfolio manager, client, or another employee.

That could create:

insider-dealing risk;

breach of banking confidentiality;

conflicts of interest;

customer harm;

regulatory violations; and

serious reputational consequences.

An information barrier attempts to prevent this by applying the principle:

Confidential information should reach only people who have a legitimate need to know it.

3. Central Bank of Kuwait Framework

The Central Bank of Kuwait is the principal banking regulator.

Under Law No. 32 of 1968, the CBK supervises banks and can impose regulatory requirements concerning their operations and internal controls.

The CBK's published conventional-bank regulatory framework expressly includes:

instructions concerning confidentiality of customer information and data; and

instructions concerning banks' internal-control systems.

Information barriers therefore form part of a broader control environment rather than existing solely as a securities-law concept.

4. Article 85 Bis — Banking Confidentiality

Article 85 bis of Law No. 32 of 1968 is particularly important.

It provides, subject to legally permitted cases, that members of a bank's board, managers, employees and workers must not disclose information relating to:

the bank's affairs;

its customers; or

affairs of other banks

that they learned through their positions.

Importantly, this obligation continues after the individual leaves the bank.

Violation can produce statutory consequences.

Importance for Information Barriers

Article 85 bis establishes the underlying legal principle that bank information cannot be treated as freely transferable simply because an employee obtained it during employment.

Internal access must therefore be connected to legitimate professional responsibilities.

5. Customer Confidentiality

Banking confidentiality is one of the strongest reasons for maintaining information barriers.

Banks possess information concerning customers':

account balances;

transactions;

loans;

investments;

financing arrangements;

business activities;

financial condition; and

commercial plans.

Employees should not have unrestricted access merely because they work for the same institution.

For example, an employee working in an unrelated securities function should not ordinarily search the banking records of a corporate customer merely because those records could help the employee make an investment decision.

6. Article 82 and Regulatory Information

Kuwaiti banking law also addresses information supplied to the CBK.

Article 82 requires banks to provide information, data and statistics requested by the Central Bank.

The law generally treats such information as confidential, subject to specified exceptions including certain exchanges with other central banks and banking supervisory authorities for consolidated supervision.

This demonstrates a broader principle:

regulatory access to information does not mean unrestricted internal or public disclosure.

Information can legitimately move for supervisory purposes while remaining protected from improper use.

7. Centralized Risk Information

Article 83 permits the CBK to establish a Centralized Risks System to assist banks in evaluating applicants for credit and to support CBK monitoring of banking credit.

Information obtained through that system may be disclosed only to persons entitled to receive it under the applicable rules.

This provides another example of controlled information flow.

Information may be highly useful for a legitimate banking purpose while still being restricted from unrelated use.

8. Internal Control Systems

Article 84 requires the bank's external auditor to address the adequacy of internal-control systems in the annual report.

The CBK also maintains specific instructions concerning banks' internal-control systems.

An effective information-barrier framework should therefore form part of internal governance.

Relevant controls may include:

access restrictions;

departmental separation;

confidentiality classifications;

monitoring;

approval requirements;

employee training;

audit trails;

conflict-management procedures; and

compliance oversight.

Information barriers should exist in actual operations, not merely in a written compliance manual.

9. Capital Markets Law

Banks that conduct activities involving securities may also come within Kuwait's capital-markets framework.

Law No. 7 of 2010 established the Capital Markets Authority and regulates securities activities.

One of the CMA's statutory objectives is to impose disclosure requirements and prevent:

conflicts of interest; and

misuse of insider information.

This becomes particularly important where banking and securities functions operate within the same financial group.

10. Article 66 — Prevention of Misuse of Insider Information

Article 66 of the Capital Markets Law contains an especially relevant requirement.

A person licensed to manage securities activities must maintain written supervisory regulations and rules controlling its operations.

These must include procedures designed to prevent the misuse of insider information.

This provides a direct regulatory foundation for information-control arrangements in institutions conducting regulated securities business.

The purpose is preventive.

The institution should not wait for insider trading to occur before controlling the movement of confidential information.

11. Insider Information

Insider information generally concerns non-public information capable of having a material effect in the securities context.

For a bank, such information might arise through:

acquisition financing;

takeover discussions;

restructuring;

confidential corporate lending;

capital raising;

insolvency negotiations;

significant financing arrangements; or

advisory engagements.

The information may initially be obtained legitimately.

The regulatory problem arises when it is improperly disclosed or used.

Therefore:

lawful possession does not automatically mean lawful use.

12. Article 118 — Insider Dealing

Article 118 of Kuwait's Capital Markets Law addresses insider dealing.

It applies to an insider who, while possessing insider information concerning a security:

purchases or sells the security;

discloses insider information; or

advises another person on the basis of that information.

The provision can also reach another person who trades on insider information obtained from an insider while knowing its nature and seeking a benefit.

This creates a powerful reason for banks to prevent confidential information from moving from restricted departments to trading or investment functions.

13. Information Barriers and Conflicts of Interest

Information barriers are also a conflict-management mechanism.

Consider a bank that:

advises Company A on acquiring Company B; and

separately manages investment portfolios containing Company B shares.

The bank potentially faces competing interests.

An information barrier can prevent employees managing investment portfolios from receiving confidential acquisition information held by the advisory team.

This does not necessarily eliminate every conflict.

Some conflicts may require:

disclosure;

consent;

restrictions;

declining an engagement; or

another regulatory response.

An information barrier is therefore one conflict-management technique, not a universal solution.

14. Physical Separation

Traditional information barriers often involved physical separation.

Sensitive teams could work in:

separate offices;

restricted floors;

secure meeting rooms; or

controlled document-storage areas.

Physical separation can still be useful.

However, modern banking information is predominantly electronic.

Physical walls alone are therefore insufficient.

15. Electronic Information Barriers

Modern banks require technology-based controls.

These can include:

role-based access;

restricted electronic folders;

database permissions;

secure deal rooms;

access logging;

restrictions on downloading information;

controlled distribution lists;

document classification; and

monitoring of privileged access.

For example, an employee in securities trading should not automatically receive access to confidential files belonging to a corporate advisory team.

16. Need-to-Know Principle

The need-to-know principle is central to effective information barriers.

It means that access should be provided where the employee requires the information to perform legitimate duties.

The question should therefore not be:

“Does this person work for the bank?”

Instead, it should be:

“Does this person require this particular information for an authorized business purpose?”

This significantly reduces unnecessary circulation of confidential information.

17. Restricted Lists

Financial institutions can use restricted lists as part of their information-barrier framework.

If a bank possesses confidential price-sensitive information concerning a company, relevant securities can be placed under appropriate dealing restrictions.

This can prevent or control activities such as:

proprietary trading;

employee personal trading;

recommendations;

research publication; or

particular client transactions,

depending on applicable rules and circumstances.

The restricted list itself should also be carefully controlled because its contents may reveal that the institution possesses sensitive information.

18. Watch Lists

A watch list is conceptually different from a restricted list.

It can identify issuers about which the institution possesses confidential information while allowing compliance personnel to monitor relevant transactions.

Access to a watch list is usually tightly controlled.

If ordinary traders could see that a particular company had suddenly appeared on a confidential monitoring list, the list itself could indirectly reveal sensitive information.

19. Wall Crossing

Sometimes information legitimately needs to cross an information barrier.

For example, a specialist from another department may be required to assist with a confidential transaction.

A controlled process can be used.

Conceptually:

business justification → compliance approval → confidentiality warning → limited disclosure → temporary restrictions → monitoring → eventual removal of restrictions when appropriate.

The purpose is not to create an absolute prohibition on internal communication.

It is to make sensitive information transfers controlled and accountable.

20. Personal Account Dealing

Employees of banks and securities businesses can create conflicts by trading for their own accounts.

An employee who receives confidential information through employment should not use it to obtain a personal trading advantage.

Institutions may therefore maintain controls concerning:

pre-clearance;

prohibited securities;

restricted periods;

disclosure of employee holdings; and

compliance monitoring.

Information barriers and personal-account dealing controls consequently operate together.

21. Research Departments

Research analysts can create particular information-barrier issues.

Suppose a bank's corporate-finance department possesses confidential information that Company X will soon announce a major transaction.

A research analyst covering Company X should not improperly receive that information and then alter a public recommendation.

Accordingly, banks involved in both research and investment banking need controls over communication between those functions.

The objective is to preserve the integrity and independence of research.

22. Lending and Investment Banking

Commercial lending can itself generate market-sensitive information.

A corporate borrower may privately tell its bank about:

declining financial performance;

acquisition plans;

asset disposals;

restructuring;

financing problems; or

major new contracts.

Employees receiving such information through lending relationships must not automatically transfer it to securities-trading or investment-management teams.

This is one reason information barriers are relevant even to traditional commercial banks.

23. Mergers and Acquisitions

M&A information is particularly sensitive.

Before public announcement, knowledge of a takeover can substantially affect the market price of securities.

A bank advising or financing an acquisition should therefore restrict information concerning:

target identity;

proposed price;

financing;

negotiation status;

timetable; and

transaction structure.

Access should generally be limited to employees legitimately working on the transaction and necessary control functions.

24. Treasury Functions

Bank treasury departments trade and manage substantial financial positions.

If treasury personnel improperly receive confidential information from corporate-banking or advisory departments, serious conflicts can arise.

Therefore, access controls should separate sensitive customer information from trading decisions where required.

Treasury employees should make decisions using information they are legally permitted to use.

25. Asset and Wealth Management

Banks may manage investments for customers.

Portfolio managers should not receive confidential information from another department merely because it could improve investment performance.

Using inside information to benefit one client can harm:

market integrity;

other investors;

the issuer;

the bank; and

the financial system's reputation.

Information barriers therefore support fair investment management.

26. Compliance Function

Compliance commonly plays a central role in administering information barriers.

Its responsibilities can include:

maintaining restricted lists;

monitoring wall-crossing;

reviewing conflicts;

approving sensitive access;

monitoring employee trading;

investigating suspicious information flows;

maintaining records; and

providing training.

Compliance itself may need broad access because it acts as a control function.

That access should nevertheless be used only for legitimate compliance purposes.

27. Internal Audit

Internal audit should periodically determine whether information barriers actually work.

It can examine:

access permissions;

exceptions;

compliance approvals;

restricted lists;

employee trading;

information-sharing records; and

management oversight.

A policy that looks strong on paper but is routinely bypassed represents a weak control environment.

28. Employee Training

Information barriers depend heavily on employees.

Training should explain:

what constitutes confidential information;

what may constitute insider information;

who may receive information;

when compliance should be consulted;

personal-trading restrictions;

handling of electronic documents; and

consequences of unauthorized disclosure.

Employees should understand that casual conversations can create serious risks.

Information does not have to be transferred through a formal document to constitute improper disclosure.

29. Confidentiality After Employment

Article 85 bis is particularly significant because confidentiality obligations do not simply disappear when an employee leaves a Kuwaiti bank.

A former employee cannot ordinarily treat confidential customer or bank information learned through employment as personal information available for unrestricted disclosure.

This protects banking confidentiality beyond the employment relationship.

30. Regulatory Consequences

Article 85 of the CBK Law gives the Central Bank powers where a bank violates banking legislation, decisions or regulatory instructions.

Potential measures include:

warnings;

financial penalties;

restrictions on operations;

suspension of certain dealings with the CBK; and

action concerning responsible personnel.

Therefore, defective information controls can create institutional regulatory exposure in addition to individual liability.

31. Case-Law Position

Publicly accessible Kuwaiti judgments specifically using the modern expression “information barrier” or “Chinese wall” in banking are limited.

It would therefore be inaccurate to invent six Kuwaiti case citations.

The following cases are established comparative authorities illustrating confidentiality, conflicts of interest, insider information and information barriers.

They are not automatically binding precedents in Kuwait.

32. Case 1 — Prince Jefri Bolkiah v KPMG [1999] 2 AC 222

This House of Lords case is one of the leading authorities concerning information barriers.

KPMG had previously performed work for Prince Jefri and subsequently accepted work connected with an investigation in circumstances potentially involving confidential information obtained during the earlier engagement.

The central question concerned whether internal arrangements could adequately protect confidential information.

The House of Lords emphasized the need for effective safeguards where confidential information is held within an organization.

Importance for Kuwait

The case demonstrates that merely saying that a “Chinese wall” exists is insufficient.

An institution should be capable of showing that its information barrier is genuinely effective.

33. Case 2 — Rakusen v Ellis, Munday & Clarke [1912] 1 Ch 831

This older English authority concerned confidential information and professional conflicts.

The case became important in the development of principles dealing with whether different parts of an organization can operate independently despite confidential information being held elsewhere within it.

Importance

The case illustrates the historical foundation of organizational separation.

Modern banking information barriers build on the same underlying concern:

Can confidential information realistically be prevented from reaching the wrong person?

34. Case 3 — Re a Firm of Solicitors [1992] QB 959

This English case concerned the protection of confidential information where a professional firm faced potential conflicts arising from information acquired through earlier work.

The court examined the risk of confidential information being transferred within the organization.

Importance

The principle applies conceptually to banks with multiple departments.

A financial institution should assess the practical risk of information leakage rather than relying solely on organizational charts.

35. Case 4 — Young v Robson Rhodes [1999] 3 All ER 524

This case concerned confidential information and the effectiveness of internal arrangements intended to prevent disclosure.

The decision forms part of the wider body of authority examining whether organizational safeguards can adequately protect confidential material.

Importance

Information barriers must reflect the actual organization, employees and information systems involved.

A theoretical barrier is less valuable if employees regularly communicate across it without control.

36. Case 5 — ASIC v Citigroup Global Markets Australia Pty Ltd (No 4) [2007] FCA 963

This Australian Federal Court case is especially important for financial institutions.

Citigroup was involved in both proprietary trading and investment-banking activities surrounding a corporate transaction.

The case examined conflicts of interest, inside information and the operation of information barriers within a major financial institution.

The court considered the firm's Chinese-wall arrangements and the movement of information between business divisions.

Importance for Kuwait

This is one of the most useful comparative banking authorities.

It demonstrates why institutions combining:

advisory services + securities trading

need carefully structured information barriers and conflict-management procedures.

37. Case 6 — SEC v Texas Gulf Sulphur Co., 401 F.2d 833 (2d Cir. 1968)

This major United States securities case concerned trading while possessing material non-public information.

Company insiders possessed important information concerning a mineral discovery before it became public.

The case became highly influential in the development of insider-trading principles.

Importance

The fundamental lesson is that persons possessing material confidential information cannot simply treat their informational advantage as freely exploitable.

For banks, information barriers reduce the risk that confidential customer information reaches employees capable of trading on it.

38. Case 7 — Dirks v SEC, 463 U.S. 646 (1983)

This US Supreme Court case concerned disclosure of non-public corporate information and liability involving recipients of information.

The decision developed important principles relating to insiders, tipping and persons receiving inside information.

Importance

Information can create legal risk after it passes from the original insider to another person.

Therefore, banks must control not only trading by the person who originally obtained confidential information but also unauthorized internal disclosure.

39. Case 8 — Salman v United States, 580 U.S. 39 (2016)

The US Supreme Court considered insider information passed through personal relationships.

The case demonstrates how confidential information can travel from an insider to another person and eventually be used for securities trading.

Importance

Information-barrier policies must address informal disclosure as well as formal document transfers.

A sensitive fact disclosed verbally can create the same basic confidentiality concern as an emailed document.

40. Lessons from the Case Law

The comparative authorities produce several important principles.

A written wall alone is insufficient

Bolkiah v KPMG demonstrates the importance of effective practical safeguards.

Organizational structure matters

Cases involving professional conflicts demonstrate that actual employee interaction and information flows must be examined.

Trading creates heightened risk

ASIC v Citigroup shows why financial groups combining advisory and trading functions require particularly careful controls.

Non-public information can create market-abuse risk

Texas Gulf Sulphur demonstrates the significance of material confidential information.

Improper disclosure can extend liability

Dirks and Salman illustrate why passing information to another person can itself create serious consequences.

41. Example of an Effective Banking Information Barrier

Consider a Kuwaiti bank advising a listed company on a confidential acquisition.

An appropriate control structure could conceptually operate as follows:

Confidential mandate received

Deal team identified

Access restricted

Compliance notified

Issuer placed under appropriate monitoring/restrictions

Electronic deal room established

Employee trading monitored

No disclosure to trading/research teams without authorization

Any necessary wall-crossing documented

Public announcement occurs

Compliance reviews whether restrictions may be changed

This creates a traceable control system.

42. Information Barrier Versus Absolute Secrecy

Information barriers should not be misunderstood as requiring complete isolation.

Banks legitimately need to share information with:

compliance;

internal audit;

risk management;

legal departments;

senior management;

external auditors; and

regulators,

where legally appropriate.

The objective is therefore:

controlled disclosure rather than zero disclosure.

The correct question is whether the recipient has a legitimate purpose and appropriate authorization.

43. Information Barriers in Banking Groups

Large banking groups may contain:

banks;

investment companies;

asset managers;

brokerage businesses;

finance companies; and

overseas subsidiaries.

Information-barrier design should therefore consider both departmental and corporate boundaries.

A subsidiary should not automatically receive confidential customer information simply because it belongs to the same corporate group.

Group membership does not eliminate confidentiality and conflict requirements.

44. Digital Banking and Information Barriers

Digital transformation makes information barriers more complex.

Large quantities of customer information may be stored centrally and accessed remotely.

Banks therefore increasingly require:

identity-based permissions;

privileged-access management;

logging;

data-loss prevention;

encryption;

automated alerts; and

periodic access reviews.

Modern information barriers are consequently as much a technology-control issue as a physical organizational issue.

45. Artificial Intelligence

AI creates additional information-barrier concerns.

A bank should consider whether confidential customer information entered into an AI system could become accessible to:

unauthorized employees;

external service providers;

unrelated business units; or

other users.

The traditional principle remains applicable:

technology should not defeat confidentiality restrictions.

AI governance should therefore operate consistently with existing banking confidentiality and access-control requirements.

46. Record Keeping

A strong information-barrier framework should generate reliable records.

These can include:

access approvals;

restricted-list changes;

wall-crossing decisions;

employee acknowledgments;

conflict assessments;

personal-trading approvals;

compliance reviews; and

investigation records.

Documentation enables the bank to demonstrate that information controls actually operated.

47. Enforcement and Investigation

If suspicious information movement is detected, the bank should determine:

what information was involved;

whether it was confidential or inside information;

who originally possessed it;

who subsequently received it;

whether disclosure was authorized;

whether securities were traded;

whether customers were affected; and

whether regulatory reporting or further action is required.

Electronic access logs can be particularly important in reconstructing events.

48. Practical Compliance Framework

A Kuwaiti bank can conceptually structure information-barrier compliance as:

Identify confidential information

Classify sensitivity

Identify authorized employees

Restrict physical and electronic access

Maintain conflict/watch/restricted-list controls

Monitor personal and institutional trading

Control wall-crossing

Record exceptions

Conduct compliance monitoring

Perform internal audit

Investigate suspected leakage

Remediate weaknesses

This creates a continuous information-governance process rather than a one-time policy.

49. Relationship Between CBK and CMA Requirements

For banks involved solely in traditional banking activities, CBK confidentiality and internal-control requirements are central.

Where a bank or group entity conducts regulated securities activities, the CMA framework can add another layer.

The two regimes address overlapping but different concerns.

CBK framework:
customer confidentiality, banking secrecy, sound internal controls and banking supervision.

CMA framework:
market integrity, conflicts of interest, insider information and regulated securities activities.

A diversified financial group may therefore need controls capable of satisfying both regimes.

50. Conclusion

Information-barrier requirements in Kuwaiti banks arise from the combined operation of banking confidentiality, internal controls, conflict-of-interest management and capital-markets regulation.

Article 85 bis of Law No. 32 of 1968 establishes an important confidentiality obligation for bank directors, managers and employees concerning information obtained through their positions. Articles 82 and 83 provide further examples of legally controlled information flows, while Article 84 emphasizes the importance of adequate internal-control systems.

Where securities activities are involved, Law No. 7 of 2010 becomes particularly important. Article 66 requires relevant licensed persons to maintain written supervisory procedures, including procedures preventing misuse of insider information. Article 118 establishes serious consequences for insider dealing, improper disclosure and advice based upon inside information.

The comparative cases—Prince Jefri Bolkiah v KPMG, Rakusen v Ellis Munday & Clarke, Re a Firm of Solicitors, Young v Robson Rhodes, ASIC v Citigroup Global Markets Australia, SEC v Texas Gulf Sulphur, Dirks v SEC, and Salman v United States—illustrate why information barriers must be practical and effective rather than merely written policies.

For Kuwaiti banks, the central principle can therefore be expressed simply:

Confidential information should be available only to people who have a legitimate need to know it, and sensitive information must not move between banking, advisory, trading, research or investment functions in a way that compromises customer confidentiality, creates unmanaged conflicts or permits misuse of insider information.

A strong information-barrier system combines organizational separation, electronic access controls, restricted and watch lists, compliance oversight, controlled wall-crossing, employee-trading controls, monitoring, training, internal audit and documented enforcement. This protects customers, the bank and the integrity of Kuwait's financial markets.

LEAVE A COMMENT