Most of our clients are restaurants, clinics, chalets and shops — not ministries. But the questions a regulator would ask are the same questions a careful owner should ask. This page answers them plainly: who regulates what in Kuwait, what we do about it, and exactly where data is stored.
Communication & Information Technology Regulatory Authority. Kuwait's ICT and telecom regulator. It licenses telecom and cloud providers, runs the .kw domain registry, publishes the cloud computing and data-classification framework, and reports on electronic fraud. It supports the technical and data side of digital commerce.
Ministry of Commerce and Industry. Issues commercial licences (including ours) and administers the registration regime created by Decree-Law No. 10 of 2026 on digital commerce — the law that sets what an online shop must show and do for consumers.
Central Bank of Kuwait. Licenses payment service providers. We never process cards ourselves: KNET and card payments on the sites we build run through CBK-licensed gateways, so card data never touches our systems or the client's.
CITRA's framework (issued September 2021) classifies data by sensitivity. The rule that matters in practice: government data and higher-classification personal data must be stored inside Kuwait, encrypted, with cloud providers registered with CITRA. Ordinary business data — a restaurant's menu, a chalet's booking calendar, a shop's product list — is not in that category.
Published 1 March 2026, this law introduced mandatory registration for e-commerce operators with MOCI, and consumer-protection duties for anyone selling online — including social-media sellers. Every store and ordering site we build ships with the fields the law expects visible on the site:
Our site builder has a dedicated "Official information" section for exactly these fields, and it refuses to invent a trade name or licence number — the owner enters them. A plain-language explainer of the law is at /ar/ecommerce-law/ (Arabic).
| Data | Where | Kept for |
|---|---|---|
| Websites we build (code, pages, images) | Cloudflare Pages, served from the nearest edge location; source code in a private GitHub repository | Life of the contract |
| Contact-form and lead submissions on techlabskw.com | Cloudflare KV (encrypted at rest), accessible only to the owner of Tech Labs via Google sign-in | Until resolved, then archived |
| Site-builder drafts and uploaded photos | Cloudflare KV, unguessable private links, never indexed | 90 days if never sent to us; permanently once the owner claims or publishes the site |
| Bookings, orders and messages on client sites | Cloudflare KV, visible only to the site owner in their panel and to Tech Labs for support | As long as the site is live |
| Card and KNET payment data | Never stored by us. Handled entirely by the CBK-licensed gateway | — |
| techlabskw.com mail is authenticated with SPF, DKIM (2048-bit) and DMARC (quarantine), so nobody can send mail pretending to be us | — |
Five questions, answered in writing, before any quote for a bank, insurer, clinic chain, government entity or telecom partner:
If you're a business that needs this answered properly, or a partner evaluating us, we'd rather have that conversation early.
Ask on WhatsApp [email protected]This page describes our practices; it is not legal advice. Regulations change — the date at the top is when we last checked.