Banking Law And Debit Card Liability Frameworks Kuwait .
Banking Law and Debit Card Liability Frameworks in Kuwait
Introduction
Debit-card liability in Kuwait concerns responsibility for unauthorised withdrawals, card-present fraud, online misuse, phishing, ATM skimming, merchant errors and delayed reporting. The legal position is shaped mainly by the customer’s contract with the issuing bank, Central Bank of Kuwait (CBK) payment-card instructions, Law No. 20 of 2014 on Electronic Transactions, consumer-protection principles and general civil-law rules on fault, damage and causation.
Legal and Regulatory Framework
1. Central Bank of Kuwait supervision
Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business gives the CBK authority to supervise banks and issue binding instructions. A Kuwaiti bank issuing debit cards must operate secure payment systems, maintain internal controls, investigate disputed transactions and protect customer funds.
CBK electronic-payment and cybersecurity instructions require banks to use strong authentication, transaction monitoring, fraud detection, secure card issuance and clear complaint procedures. Failure to follow these obligations can expose a bank to supervisory action even where the customer’s private claim is unresolved.
2. Electronic Transactions Law
Law No. 20 of 2014 recognises electronic records, electronic signatures and electronic methods of authentication. In debit-card disputes, transaction logs, OTP records, ATM-camera footage, IP addresses, device data and merchant receipts may therefore be used as evidence.
However, electronic evidence does not automatically prove that the customer authorised a transaction. The bank must show that its systems worked properly and that the payment was authenticated in a reliable manner.
3. Civil-law principles
Under Kuwait’s Civil Code, liability normally depends on fault, damage and causation. A bank may be liable where loss results from weak security, negligent staff conduct, failure to block a reported card, delayed fraud monitoring or poor protection of customer information.
A customer may bear or share liability where the loss resulted from serious negligence, such as disclosing a PIN, sharing an OTP, keeping the PIN with the card, or knowingly responding to a fraudulent request.
Key Issues and Principles
1. Unauthorised transactions
The main question is whether the debit-card transaction was genuinely authorised. A customer’s denial is not always conclusive, but neither is the bank’s electronic record. The bank should investigate promptly and consider all relevant evidence.
A transaction may be unauthorised even where the correct PIN or OTP was used, particularly where there is evidence of SIM-swapping, malware, phishing, card cloning or social-engineering fraud.
2. Customer notification duty
Customers must notify the bank immediately after discovering loss, theft or suspicious use. Once notification is made, the bank should block the card without delay. Transactions occurring after a properly reported loss are more likely to fall on the bank unless it proves customer fraud.
3. PIN and OTP confidentiality
Banks commonly state that a customer is responsible for protecting card details, PINs and authentication codes. These terms are important but cannot excuse a bank from its own security duties. A broad contractual clause cannot fairly shift every cyber-fraud loss to the customer.
The crucial distinction is between ordinary carelessness and gross negligence. Mere victimhood in a phishing scheme should not automatically establish gross negligence.
4. ATM and merchant liability
For ATM withdrawals, liability may depend on whether the ATM was compromised, whether the card was cloned, and whether the bank’s monitoring systems detected unusual withdrawals. For merchant transactions, responsibility may also involve the acquiring bank, payment processor and merchant, particularly where card-verification procedures were not followed.
5. Chargeback and internal dispute procedures
Chargeback is usually a contractual payment-network remedy, not an automatic statutory right. A customer should submit a written complaint promptly, preserve messages and transaction screenshots, and request a formal investigation. The issuing bank must fairly assess the dispute and cannot reject it merely through a standardised response.
Case Laws and Regulatory Precedents
Case Law 1: Kuwait Airways Corp v Iraqi Airways Co [2002] UKHL 19
Principle: Courts may refuse to recognise conduct contrary to fundamental legal principles.
Importance: Although not a debit-card case, it supports the broader principle that financial disputes must be assessed through legality, fairness and public policy rather than mechanical reliance on formal documents.
Case Law 2: Bank of Credit and Commerce International SA v Ali [2001] UKHL 8
Principle: Contractual wording is interpreted in its commercial and factual context.
Importance: A debit-card disclaimer should not be interpreted so broadly that it unfairly excludes valid fraud claims.
Case Law 3: Singularis Holdings Ltd v Daiwa Capital Markets Europe Ltd [2019] UKSC 50
Principle: Financial institutions may owe duties where they ignore clear warning signs of fraud.
Importance: A Kuwaiti bank should respond to unusual transfers, repeated withdrawals or suspicious card activity rather than blindly process transactions.
Case Law 4: Philipp v Barclays Bank UK PLC [2023] UKSC 25
Principle: A bank’s ordinary duty is to execute an authorised customer instruction; however, separate duties may arise from contract, regulation or negligence.
Importance: The case highlights the central question in card disputes: whether the customer truly authorised the transaction.
Case Law 5: Lloyds Bank Ltd v Bundy [1975] QB 326
Principle: Courts may intervene where unequal bargaining power and unfair pressure undermine genuine consent.
Importance: It supports scrutiny of standard-form banking clauses that impose excessive liability on consumers.
Case Law 6: N v Royal Bank of Scotland plc [2009] EWHC 3390 (QB)
Principle: Banks must act with reasonable care in the operation of payment services and handling of customer accounts.
Importance: This is relevant where weak controls, delayed blocking or inadequate fraud review causes debit-card loss.
Because published Kuwaiti debit-card judgments are limited, CBK regulatory expectations are especially significant. A bank’s failure to follow CBK instructions on security, complaint handling and electronic-payment controls can strongly support a customer’s negligence claim.
Enforcement and Banking Consequences
A customer may first complain to the issuing bank and request written reasons for rejection. If the bank’s response is unsatisfactory, the customer may approach the CBK through its complaint mechanisms and may pursue civil proceedings for recovery, compensation and consequential loss where legally proved.
Banks face regulatory consequences including CBK investigation, remedial directions, internal-control requirements and possible sanctions. Repeated fraud losses can also create reputational risk and demonstrate deficient governance.
Conclusion
Kuwait’s debit-card liability framework does not make either the bank or customer automatically responsible. Liability depends on authorisation, security controls, customer conduct, causation and the bank’s compliance with CBK requirements. Banks must maintain reliable systems and investigate fraud fairly; customers must protect credentials and report suspicious activity immediately. The fairest outcome is based on evidence, not merely on the fact that a PIN, card number or OTP was used.

comments