Skip to the content
Global Data RulesData governance rules, country by country

Lebanon

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Depends on your industryWork: MediumEnforcement: Dormant

Lebanon has a personal data law but no privacy regulator and, as far as we can see, no enforcement. Before you process data you are meant to file a notice with the Ministry of Economy and Trade. The ministry's own public list of those notices has exactly one entry, filed in 2023. Nothing in the law stops data leaving Lebanon - unless you are a bank or a payment company.

Data governance in Lebanon

The eight things that decide how you handle data about people in Lebanon. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it can reach a company with no office in Lebanon. The data chapter covers all handling of personal data, whether by computer or on paper, and the law assumes some of the people doing it sit abroad: the notice you file must name a representative in Lebanon if you are based outside the country. There is no size or revenue cut-off. In practice most ordinary business handling is exempt from filing at all, because staff records, customer records and anything the person agreed to in advance are carved out.

High confidenceNational rulesAppoint a local representativeRegister or notify

Where the data is allowed to live

In general yes, freely. The law never says that sending personal data to another country needs permission, a contract or a safe-country list. The only thing it asks is that you disclose it: if you have to file a notice, one of the boxes is the personal data you plan to send abroad. Banking and payments are the hard exception, and there the data has to stay in Lebanon.

High confidenceDepends on your industryNo restrictionKeep the data in the country

Sending data out of the country

Nothing to sign and nobody to ask. Lebanon has no approved-country list, no banned-country list, no standard contract and no transfer approval. The single step is disclosure: name the data you intend to send abroad on the notice you file with the Ministry of Economy and Trade. For banks, finance companies and payment providers the answer is the opposite - the data has to be hosted in Lebanon, and sharing it with anyone other than the financial regulators needs the customer's explicit written consent.

High confidenceNo restrictionNothing requiredExplicit consent

The regulator, and whether it actually acts

Nobody, in practice. Lebanon has no privacy regulator at all - no commission, no board, no office. The Ministry of Economy and Trade only collects notices and publishes a list of them, and that published list contains exactly one entry, filed in May 2023, in a file that has not been updated since. Punishment comes from criminal courts, and for two of the offences only if the affected person files a complaint. The central bank and the telecoms regulator, by contrast, are plainly working.

High confidenceDormantCriminal liability

How long you must keep it — and when to delete it

There is a ceiling and a floor, and the ceiling is unusual. You may only keep personal data for the period you yourself wrote down when you filed your notice, or the period set in your licence - so you set your own deadline and are then bound by it. The floor comes from other laws: banks, money dealers and other reporting businesses must keep transaction papers and customer identity records for at least five years. Telephone billing records would have to be kept for ten years, but only under a regulation that was never brought into force.

High confidenceDelete data after a periodKeep data for a minimum period

If something goes wrong

There is no deadline because there is no duty. Lebanon's data law does not require you to report a data breach to any authority and does not require you to tell the people whose data was exposed. We checked the full text on 18 August 2026 and found no such article. Financial firms do run one hard clock for a different problem: when they freeze an account under sanctions rules they have 48 hours to give the Special Investigation Commission the evidence.

Medium confidenceReport breaches to the regulatorTell affected peopleSecure the data

What catches people out

Four things that catch people out. First, the money is meaningless but the prison is not: the top fine is 30 million Lebanese pounds, about 335 US dollars at the central bank's own rate, while the same article allows up to three years in jail, and it bites people, not only companies. Second, health, genetic and sexual-life data are banned outright unless you fit one of four narrow exceptions, and the permission comes from the Minister of Public Health, where two months of silence counts as a refusal. Third, you cannot contract out of any of it - a clause in your terms and conditions that cuts across the data rules simply has no effect. Fourth, the central bank orders Lebanese banks to comply with Europe's privacy rulebook and to appoint a representative in Europe, which has nothing to do with Lebanese law and is easy to miss.

High confidenceCriminal liabilityAppoint a local representativeAppoint a data protection officerDelete data after a periodIndependent audit

What's changing next

The near-term story is banking, not privacy law. The central bank rewrote its electronic banking rules on 9 January 2026 and gave firms six months to move customer and transaction data onto servers in Lebanon, so that duty became enforceable on 9 July 2026 and the first supervisory action is the thing to watch. In telecoms, the regulator got a new board in September 2025 after years without one and is issuing rules again, which puts a 2009 consumer regulation with real privacy and billing-record clauses back within reach of being published. We found no bill before Parliament to create a privacy regulator, but we could not open the Parliament's own site to be sure.

Medium confidenceProposedKeep the data in the country

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

التعميم الأساسي رقم 69 - العمليات المالية والمصرفية بالوسائل الإلكترونية (Basic Circular 69 - Electronic Banking and Financial Operations)

Regulator directive · Basic Decision 7548 of 30 March 2000, Articles 1 to 25 replaced by Intermediate Decision 13791 of 9 January 2026

In forceA copy must stay

The hard localisation rule in Lebanon. Banks and finance companies doing anything electronically must store all customer and transaction data in Lebanon. The whole circular was rewritten on 9 January 2026 and existing firms were given six months, so the duty has been enforceable since 9 July 2026. Customer data may not be shared with anyone except the financial regulators and the courts without the customer's explicit written consent.

In force since 9 January 2026But only enforceable from 9 July 2026

Enforced by Banque du Liban

Transfer model: Approval each time · Accepted routes: Explicit consent, Government sign-off needed

High confidence
Payments

القرار الأساسي رقم 13790 - مقدّمو خدمات الدفع بالوسائل الإلكترونية (Basic Decision 13790 - Electronic Payment Services Providers, Basic Circular 1)

Regulator directive · Basic Decision 13790 of 9 January 2026, Articles 27, 30, 31 and 44 and Annex 3

In forceA copy must stay

The payments twin of the banking rule, issued the same day. Any licensed electronic payment services provider must store all customer and transaction data in Lebanon, may not share it with anyone other than the central bank, the banking supervisor, the financial intelligence unit and the courts, and cannot outsource risk, compliance or audit at all.

In force since 9 January 2026But only enforceable from 9 July 2026

Enforced by Banque du Liban

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Explicit consent

High confidence
Finance

التعميم الأساسي رقم 146 - النظام الأوروبي العام لحماية البيانات (Basic Circular 146 - General Data Protection Regulation)

Regulator directive · Basic Decision 12872 of 13 September 2018

In forceYes, with paperwork

An oddity worth knowing about. Lebanon's central bank ordered every bank, finance company and other supervised institution to take measures in line with the European Union's General Data Protection Regulation, to appoint a data protection officer from their compliance unit, to designate a representative in Europe, and to report their procedures by the end of 2018. External auditors check it every year.

In force since 13 September 2018But only enforceable from 31 December 2018

Enforced by Banque du Liban

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

قانون رقم 81 تاريخ 2018/10/10 - المعاملات الإلكترونية والبيانات ذات الطابع الشخصي (Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data)

Act of parliament · Law No. 81 of 10 October 2018, Part Five (Articles 85 to 109)

In forceYes — store it anywhere

Lebanon's only general personal data law. It is a filing regime, not a supervision regime: tell the Ministry of Economy and Trade what you are doing, keep the data only for the period you declared, and answer access requests in ten working days. It says nothing at all about sending data abroad beyond asking you to disclose it. Health, genetic and sexual-life data are banned without a ministerial licence. Penalties are criminal but the cash ceilings have been destroyed by the currency collapse.

In force since 18 January 2019

Enforced by Ministry of Economy and Trade — not yet operational

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Who you would hear from

  • وزارة الاقتصاد والتجارة

    Receives personal data declarations and publishes the statutory register under Law 81/2018

    The ministry exists and functions, but its data protection function does not. It has no supervisory, investigative or fining power under the law, and the register it is required to publish held exactly one entry when we downloaded it on 18 August 2026, in a file last modified on 31 May 2023.

  • مصرف لبنان

    Banks, finance companies, electronic payment services providers; data hosting, data protection and cyber rules for the financial sector

    Plainly active. It rewrote its electronic banking decision and issued a new electronic payments decision on 9 January 2026, and has issued intermediate circulars as recently as July 2026.

  • الهيئة المنظمة للاتصالات

    Telecommunications licensing, spectrum, quality of service, consumer affairs

    Back in business. A five-member board including a full-time chairwoman was appointed by Decree 1328 in September 2025, after a long period without one, and the authority issued a Service Providers Licensing Regulation in December 2025 and further decisions in 2026.

  • هيئة التحقيق الخاصة

    Financial intelligence, banking secrecy lifting, record keeping duties under the anti-money-laundering law

  • وزارة الصحة العامة

    Licensing of processing that relates to health, genetic identity or sexual life, under Article 97 of Law 81/2018

    We found no evidence that any licence has ever been issued under this power, and could not reach the ministry's site from our tooling on 18 August 2026. Note that silence for two months is a refusal, so an unstaffed process is a de facto prohibition.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact date Law 81/2018 came into force

    Article 136 says the law applies three months after publication in the Official Gazette. We could not open the Lebanese Official Gazette (its site failed certificate validation on 18 August 2026), so the publication date, and therefore the 18 January 2019 commencement we record, is inferred rather than verified.

  • That the Ministry of Economy and Trade has received only one declaration since 2019

    We can prove only that the register it publishes contains one entry and was last modified on 31 May 2023. The ministry may hold filings it has not published. That is itself a failure of the Article 98 duty, but it is not the same as an empty register.

  • That nobody has ever been prosecuted under Articles 106 to 108

    Lebanon has no accessible official case-law database. We could not open the judiciary's or Parliament's sites, so we can neither confirm nor exclude prosecutions.

  • Whether the Telecommunications Regulatory Authority's Consumer Affairs Regulation was ever published in the Official Gazette

    The authority's own regulations page lists it among draft regulations, which points to not in force, but we could not check the Gazette directly. We have therefore marked it proposed and flagged it as revivable.

  • Health sector storage and confidentiality rules

    The Ministry of Public Health's website returned an access error to our tooling on 18 August 2026. We can evidence the Article 97 licensing requirement from the statute, but not any ministerial decision, circular or electronic health record policy.

  • Insurance, securities, education, gaming, mapping, defence and government cloud rules

    We found no data storage or transfer rule for any of these, but this is weak evidence. The Insurance Control Commission has no reachable website of its own, the Capital Markets Authority's regulations section did not surface any data instrument, and the administrative reform office publishes no cloud or hosting policy. Record this as not found, not as absent.

  • Whether a comprehensive data protection bill or a bill creating a privacy regulator is before Parliament in 2026

    The Parliament's website timed out repeatedly on 18 August 2026 and we could not verify the legislative pipeline from an official source.

  • Which amendment first introduced the local data hosting duty for banks

    We can prove that Intermediate Decision 13791 of 9 January 2026 repealed and replaced Articles 1 to 25 of the basic decision and gave six months to comply with Article 7, so the current duty dates from then. We did not check all twenty-seven earlier amendments for an earlier version of the same duty.

  • Completeness of the sectoral sweep

    General web search was unavailable throughout this run, so every finding comes from directly navigating official Lebanese sites. A rule published on an official site we did not think to visit would have been missed. Treat the sectoral list as a floor, not a ceiling.

60-day cadence. The banking localisation duty only became enforceable on 9 July 2026, so the first supervisory action under it is likely inside this window, and the newly reconstituted telecoms regulator is issuing decisions at pace after fourteen years without a board.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Lebanon versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.