Evidence: historical governance case. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.
Case at a glance
- Case number
- 029
- Date / range
- 2015–2017
- Sector
- Law enforcement and forensic genetics
- Genetic asset
- Proposed population DNA collection and database
- Security principle
- Population-Scale Collection Limits
Event summary
Kuwait adopted a law requiring DNA collection on an extraordinary population-wide scale after a 2015 terrorist attack, but its Constitutional Court struck the law down in 2017, making it a landmark boundary case for universal forensic databases.
The case in context
Kuwait's law proposed DNA collection on a scale much broader than an ordinary suspect database. The security rationale, the population covered by the mandate, and the constitutional response are separate elements of the case.
A collection plan also needs to be distinguished from its implementation. A broad statutory mandate does not prove that every intended sample was collected or that every proposed use occurred. The case illustrates the importance of examining proportionality and limits before a population-scale system creates durable biological records.
Acquisition and processing
national-security shock → universal collection mandate → centralized DNA database → constitutional challenge → invalidation
The sequence of events
- national-security shock
- universal collection mandate
- centralized DNA database
- constitutional challenge
- invalidation
What became inferable or exposed
Proposed population DNA collection and database
Kuwait adopted a law requiring DNA collection on an extraordinary population-wide scale after a 2015 terrorist attack, but its Constitutional Court struck the law down in 2017, making it a landmark boundary case for universal forensic databases.
Affected parties and consent
- Direct parties
- People within the collection mandate
- Indirect parties
- Relatives and connected participants may be relevant where the asset contains relationship information.
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.
Security dimensions
Confidentiality
The confidentiality question concerns proposed population dna collection and database. Exposure and further inference must be distinguished from the fact of collection or availability.
Integrity
The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Population-Scale Collection Limits identifies the particular boundary examined here.
Availability
Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.
Provenance
The relevant chain follows proposed population dna collection and database through the stages shown below. Missing public detail is not proof that internal records did not exist.
Consent, persistence, and relational exposure
Consent
The authority for collection and comparison must be assessed in the specific investigative or legal context; affected relatives may not have participated themselves.
Persistence
Later reuse depends on the actual asset and links to other records; no future misuse is asserted.
Relational exposure
Relatives and connected participants may be relevant where the asset contains relationship information.
Case-specific assessment
confidentiality critical; integrity/provenance critical; availability high for state searches; consent absent; persistence critical; relational exposure population-scale.
GeneticSecurity.org analysis
Genetic Exposure Radius
No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Proposed classification and its limits
Suggested GER: GER-4/5. Suggested GPR: GPR-5. Suggested GPI: unknown unless implementation records support scoring.
These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.
What this case does not prove
It does not establish one global constitutional rule. It illustrates how proportionality and scope can defeat an asserted security objective.
Mitigations and lessons
- Narrow predicates
- Judicial authorization
- Strict purpose limitation
- Deletion
- Independent oversight
- Transparency
- Limits on familial searching
- Constitutional review before collection
Primary sources
- PRIMARY SOURCE hrw.org — Kuwait's Universal DNA Law source 1
Secondary sources
No additional source listed. See the evidence notes for limitations.
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-029. Kuwait's DNA Law: The Universal Database That the Court Rejected. GeneticSecurity.org. https://geneticsecurity.org/cases/029-kuwait-universal-dna-law/