Compare countries
Two or three countries, side by side, one row per question. Pick up to 3.
LebanonChecked 18 August 2026
Depends on your industryWork: MediumEnforcement: Dormant
- In one paragraph
- Lebanon has a personal data law but no privacy regulator and, as far as we can see, no enforcement. Before you process data you are meant to file a notice with the Ministry of Economy and Trade. The ministry's own public list of those notices has exactly one entry, filed in 2023. Nothing in the law stops data leaving Lebanon - unless you are a bank or a payment company.
- The catch
- The relaxed headline stops at the door of the financial sector. Since 9 January 2026 every bank, finance company and electronic payment provider must keep all customer and transaction data on servers inside Lebanon, and firms already licensed had until 9 July 2026 to move it. Banks are separately ordered by the central bank to follow Europe's privacy rulebook and to appoint a representative in Europe.
- Does this apply to me?
- Yes, it can reach a company with no office in Lebanon. The data chapter covers all handling of personal data, whether by computer or on paper, and the law assumes some of the people doing it sit abroad: the notice you file must name a representative in Lebanon if you are based outside the country. There is no size or revenue cut-off. In practice most ordinary business handling is exempt from filing at all, because staff records, customer records and anything the person agreed to in advance are carved out.High confidence
- Can the data leave the country?
- In general yes, freely. The law never says that sending personal data to another country needs permission, a contract or a safe-country list. The only thing it asks is that you disclose it: if you have to file a notice, one of the boxes is the personal data you plan to send abroad. Banking and payments are the hard exception, and there the data has to stay in Lebanon.High confidence
- What do I have to do to send it abroad?
- Nothing to sign and nobody to ask. Lebanon has no approved-country list, no banned-country list, no standard contract and no transfer approval. The single step is disclosure: name the data you intend to send abroad on the notice you file with the Ministry of Economy and Trade. For banks, finance companies and payment providers the answer is the opposite - the data has to be hosted in Lebanon, and sharing it with anyone other than the financial regulators needs the customer's explicit written consent.High confidence
- Who enforces this — and are they actually working?
- Nobody, in practice. Lebanon has no privacy regulator at all - no commission, no board, no office. The Ministry of Economy and Trade only collects notices and publishes a list of them, and that published list contains exactly one entry, filed in May 2023, in a file that has not been updated since. Punishment comes from criminal courts, and for two of the offences only if the affected person files a complaint. The central bank and the telecoms regulator, by contrast, are plainly working.High confidence
- How long must I keep it, and when must I delete it?
- There is a ceiling and a floor, and the ceiling is unusual. You may only keep personal data for the period you yourself wrote down when you filed your notice, or the period set in your licence - so you set your own deadline and are then bound by it. The floor comes from other laws: banks, money dealers and other reporting businesses must keep transaction papers and customer identity records for at least five years. Telephone billing records would have to be kept for ten years, but only under a regulation that was never brought into force.High confidence
- What happens when something goes wrong?
- There is no deadline because there is no duty. Lebanon's data law does not require you to report a data breach to any authority and does not require you to tell the people whose data was exposed. We checked the full text on 18 August 2026 and found no such article. Financial firms do run one hard clock for a different problem: when they freeze an account under sanctions rules they have 48 hours to give the Special Investigation Commission the evidence.Medium confidence
- What's the trap?
- Four things that catch people out. First, the money is meaningless but the prison is not: the top fine is 30 million Lebanese pounds, about 335 US dollars at the central bank's own rate, while the same article allows up to three years in jail, and it bites people, not only companies. Second, health, genetic and sexual-life data are banned outright unless you fit one of four narrow exceptions, and the permission comes from the Minister of Public Health, where two months of silence counts as a refusal. Third, you cannot contract out of any of it - a clause in your terms and conditions that cuts across the data rules simply has no effect. Fourth, the central bank orders Lebanese banks to comply with Europe's privacy rulebook and to appoint a representative in Europe, which has nothing to do with Lebanese law and is easy to miss.High confidence
- What's about to change?
- The near-term story is banking, not privacy law. The central bank rewrote its electronic banking rules on 9 January 2026 and gave firms six months to move customer and transaction data onto servers in Lebanon, so that duty became enforceable on 9 July 2026 and the first supervisory action is the thing to watch. In telecoms, the regulator got a new board in September 2025 after years without one and is issuing rules again, which puts a 2009 consumer regulation with real privacy and billing-record clauses back within reach of being published. We found no bill before Parliament to create a privacy regulator, but we could not open the Parliament's own site to be sure.Medium confidence
- Hardest industry wall
- Banking — التعميم الأساسي رقم 69 - العمليات المالية والمصرفية بالوسائل الإلكترونية (Basic Circular 69 - Electronic Banking and Financial Operations)
- Payments — القرار الأساسي رقم 13790 - مقدّمو خدمات الدفع بالوسائل الإلكترونية (Basic Decision 13790 - Electronic Payment Services Providers, Basic Circular 1)
AlgeriaChecked 18 August 2026
Yes, with paperworkWork: HighEnforcement: Waking up
- In one paragraph
- Data can leave Algeria, but not freely. Every transfer abroad needs the national data protection authority's permission unless a listed exception applies, and breaking that rule is a crime carrying prison. Since July 2025 every organisation must have a data protection officer, a processing register and an automatic log of every operation. The regulator is staffed but has issued no known decisions.
- The catch
- The national rule is already strict, and three areas are stricter still. Online shops must run their site on servers inside Algeria under a .com.dz address. Electronic trust services, such as digital signatures and electronic identity, must host all the data they collect inside Algeria. Public bodies must exchange data only over a state-run network that is deliberately kept separate from the internet. Banking, insurance and securities have no storage rule that we could find, but the central bank's own website could not be reached, so treat that as unchecked rather than settled.
- Does this apply to me?
- Yes, it can reach a company with no office in Algeria, but the trigger is equipment, not customers. You are covered if you are set up in Algeria, or if you use any means of processing located in Algeria, such as servers or devices. In that second case you must tell the regulator the name of a representative based in Algeria, and that person takes on your rights and duties. There is no size or revenue threshold to fall below.High confidence
- Can the data leave the country?
- Yes, with permission or a listed excuse. The starting rule is that you may only send personal data to another country if the national data protection authority allows it and that country protects privacy well enough. There is a short list of exceptions that most businesses will rely on instead, such as the person's express consent or a transfer that is needed to carry out their contract. Two things are banned outright: transfers that could harm public safety or the state's vital interests, and any processing of sensitive data such as health, religion, politics or trade union membership unless a narrow exception applies.High confidence
- What do I have to do to send it abroad?
- The model is case by case. Before data goes abroad you need the national data protection authority to authorise it, and the destination country must protect privacy well enough in the authority's judgement. There is no published list of approved countries and no official standard contract you can sign instead. In practice most companies rely on the written exceptions: the person's express consent, a transfer needed for their contract, a court claim, saving someone's life, an important public interest, an international mutual legal assistance request, medical care, or a treaty Algeria has signed.High confidence
- Who enforces this — and are they actually working?
- The national data protection authority, and it does exist in real life. Fifteen members, including a president, were appointed by presidential decree on 18 May 2022 for five years, a new president was appointed in October 2023, and the authority has its own staff, pay scales, an executive secretariat, an official bulletin and internal committees. Its president was still signing published decisions in August 2025. What is missing is enforcement: in four years the official gazette shows only housekeeping texts from the authority, and no fine, order or filing procedure. Treat it as awake but not yet biting.High confidence
- How long must I keep it, and when must I delete it?
- There is a floor and a ceiling, and the floor is the one people miss. Accounting books and the paperwork behind them must be kept for ten years after the end of each financial year. Telephone and internet providers must keep the data that identifies users and their connections for one year. Online sellers must keep records of every transaction and send them to the national trade register centre. The ceiling is that personal data must not be kept in a form that identifies people for longer than the purpose needs, and keeping it too long is a crime.High confidence
- What happens when something goes wrong?
- There is no seventy-two hour clock here, and the five-day deadline people quote is not for ordinary businesses. If you provide a service over a public electronic communications network and data is destroyed, lost, altered, disclosed or accessed without permission, you must warn the authority and the affected person straight away, with no fixed number of hours. Failing to do that is a crime punishable by one to three years in prison. The five-day deadline added in July 2025 applies to police, prosecutors, courts and prison services, not to a normal company.High confidence
- What's the trap?
- Five things that cost people their weekend. One: this is a criminal regime. Sending data abroad in breach of the rule is punished by one to five years in prison and a fine of up to one million dinars, roughly seven thousand seven hundred US dollars, and prison can attach to individuals. Two: since 24 July 2025 every organisation must appoint a data protection officer, keep a written register of processing and keep an automatic log recording every collection, consultation, disclosure and deletion, with no exemption for small companies. Three: sensitive data is banned by default, and consent must be express, so silence or a pre-ticked box is worth nothing. Four: anything to do with national defence and security now sits completely outside the law, so there is no privacy protection to point to there. Five: a 2021 ordinance makes it a crime to disclose classified administrative documents, it reaches acts committed outside Algeria against the Algerian state, and it can force any person to hand over stored data.High confidence
- What's about to change?
- Three things to watch in the next twelve months. The five-year terms of the data protection authority's members, appointed on 18 May 2022, run out in May 2027, so appointments are due. The regional inspection and audit units created for the authority in July 2025 still need an implementing regulation before inspectors can appear at your door. And the rules that switch on the new government data framework, two reference documents on classifying data and cataloguing data sources, can be published by a single decision of the High Commission for Digitalisation, at which point every public body and every company running a public service must classify and catalogue its data.High confidence
- Hardest industry wall
- Telecoms — Loi n° 26-02 fixant les regles generales relatives aux services de confiance pour les transactions electroniques et a l'identification electronique
- E-commerce — Loi n° 18-05 relative au commerce electronique
- Government — Decret presidentiel n° 25-320 portant mise en place d'un dispositif national de gouvernance des donnees