The Compliance Breach You Wont Find in the Contract Your Contracts May Be Compliant. Your Platform May Not Be.

By Shayma Alameeri - Attorney at Dar Al-Muhama Law Firm 8/9/2026
image

Hidden compliance risks delivery platforms must address before 1 September 2026 A delivery platform may review its contracts, confirm that the stated commission does not exceed 17%, and conclude that it complies with Ministerial Resolution No. 109 of 2026. That conclusion, however, may be incorrect. Additional charges for advertising, promotional services, premium placement, merchant-funded discounts, or operational practices embedded within the platform may exist without being reflected in the written contract. Likewise, while the contractual commission itself may be compliant, violations may arise from the platform s ranking methodology, refund procedures, complaint-handling mechanisms, or cybersecurity incident management. The Resolution s central message is clear: compliance is no longer merely contractual or financial. It requires an end-to-end assessment of the platform s business model from product display through payment settlement and final resolution of any related complaint. Risk One: Commission Is Broader Than the Percentage Stated in the Contract The Resolution adopts a broad economic concept of -commission.- Compliance is determined not by the contractual label assigned to a payment, but by the total consideration received by the platform from the merchant in exchange for its services. Accordingly, commission includes the base commission as well as fixed or variable fees, subscriptions, advertising charges, promotional fees, paid placement, priority ranking fees, and any comparable charges. The Resolution establishes two maximum commission thresholds, calculated separately for each individual order: • 17% where the platform provides the delivery service. • 10% where delivery is performed by the merchant or the merchant s own delivery personnel. The Resolution also caps the delivery fee payable by the consumer at KWD 1.000 per order. To illustrate, if an order is valued at KWD 20.000, with a base commission of 15%, an additional 1.5% promotional fee, and KWD 0.500 charged for premium placement, the platform would receive KWD 3.800 in total. This exceeds the permitted maximum of KWD 3.400, notwithstanding that the )base commission( clause, viewed in isolation, remains compliant. Merely revising the commission percentage in the standard contract is therefore insufficient. Financial systems must aggregate every charge associated with each order and verify compliance automatically before settlement. Risk Two: Existing Contracts Are Not Universally Protected Contracts concluded after the issuance of the Resolution are fully subject to its provisions. Contracts entered into prior to the Resolution that exceed the newly prescribed commission limits must be amended before 1 September 2026. By contrast, pre-existing contracts whose agreed commission does not exceed the applicable cap may continue under their existing terms until the expiry of their contractual duration. However, this should not be interpreted as granting blanket immunity to all related practices. A commission rate may comply with the Resolution while the contract or platform still contains exclusivity clauses, price-parity obligations, discriminatory treatment of merchants, or terms tying the core platform service to ancillary services. Businesses should therefore prepare a contract register identifying each agreement s term, commission rates, additional fees, delivery arrangements, exclusivity provisions, amendment and termination rights, and the action required before the compliance deadline. Risk Three: The Violation May Exist Within the Platform Itself Certain compliance risks will not be found in the written contract but rather within the platform s user interface or system configuration. Businesses should assess precisely what consumers encounter before completing an order. Are all fees clearly disclosed? Can consumers amend their orders before confirmation? Is paid placement clearly identified as advertising? Are labels such as )Best Seller( and )Highest Rated( supported by objective and verifiable data? Are refunds processed in the prescribed manner, or are consumers compelled to accept platform credit? Search ranking methodologies should also be reviewed to ensure they do not grant unjustified preference to the platforms own services or to selected merchants. Likewise, algorithms should not be used to disadvantage merchants who also operate on competing platforms or who choose to provide their own delivery services. Compliance therefore extends beyond the legal department. Product, technology, commercial, and customer service teams are all integral to the compliance framework. Risk Four: Competition Law and Cybersecurity The Resolution incorporates competition law principles into the compliance framework, requiring businesses to review exclusivity arrangements, price-parity obligations, discriminatory commissions, self-preferencing practices, predatory pricing, and unjustified refusals to deal. The Resolution further requires platforms to notify the Ministry of Commerce and Industry and all affected persons of any cybersecurity breach within three days of becoming aware of the incident. This gives rise to an important practical question: when does the three-day notification period begin? Does it commence upon the system s initial alert, upon confirmation by the cybersecurity team, or only once management receives the incident report? Unless this issue is addressed in advance, the notification deadline may expire while internal stakeholders debate who has decision-making authority. Accordingly, companies should establish a clear escalation matrix, allocate responsibilities, prepare notification templates in advance, and maintain a documented register of cybersecurity incidents together with all decisions taken in response. What Must Be Completed Before 1 September? Businesses should not wait until the final days before the deadline. Instead, they should immediately undertake the following actions: 1. Determine the scope of applicability: Review the licensed business activities, the platform s operating model, and the complete order, payment, and delivery process, and amend the licensed activity where necessary. 2. Identify and classify contracts: Distinguish contracts benefiting from transitional treatment from those requiring amendment, and prepare the necessary contractual addenda. 3. Test commissions at the order level: Aggregate commissions, fees, subscriptions, and promotional charges and implement automated controls to ensure compliance with the applicable commission cap. 4. Review the user journey: Assess disclosures relating to prices and fees, ranking mechanisms, paid placement, cancellations, refunds, complaint procedures, and customer support accessibility. 5. Examine competition practices: Review contracts, commercial policies, algorithms, and incentive structures that may create exclusivity, discrimination, or self-preferencing concerns. 6. Update the cybersecurity incident response plan: Clearly define the event triggering the notification period, designate responsibility for assessment and escalation, and prepare the required templates and records. 7. Prepare a compliance evidence file: Maintain a comprehensive record including the contract register, commission testing results, amended contracts and policies, screenshots, complaint records, incident response documentation, and evidence demonstrating that relevant personnel have received appropriate training. The Ministry of Commerce and Industry may request information and supporting documents concerning prices, services, and commissions, and may require an independent compliance audit. A simple assertion of compliance is therefore insufficient. Companies must be able to demonstrate compliance through contemporaneous documents and verifiable records. Available enforcement measures range from warnings to administrative closure and platform blocking, ultimately extending to licence revocation and permanent blocking of the platform. Merchants found in violation may likewise face closure of their commercial premises, suspension of business activities, and removal of their products from the platform. From my work as part of Dar Al-Muhama Law Firm s legal team, the most significant mistake a company can make is to reduce compliance to amending a contract or modifying its licensed commercial activity. The safer approach begins with a comprehensive legal and operational assessment, followed by clearly defined corrective measures, assigned responsibilities, and measurable timelines. The question every platform should now ask itself is: If the regulatory authority selected a single order and reviewed every stage—from its appearance on the platform until payment was settled and the related complaint was finally resolved—could the company demonstrate that every step complied with the Resolution? The answer to that question constitutes the true measure of readiness before 1 September 2026. Disclaimer: This article provides a general overview of the principal practical implications of the Resolution. It does not constitute legal advice and should not be relied upon as a substitute for a case-specific legal assessment of the applicability of the Resolution to any particular company s business model, contractual arrangements, or operational procedures.

Recent blog

Learn more related journals