Skip to the content
Global Data RulesData governance rules, country by country

Lebanon

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Lebanon — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Dormant

Lebanon has a personal data law, but no privacy regulator and, as far as we can see, no enforcement. Before you use personal data you are meant to file a notice with the Ministry of Economy and Trade. The ministry's own public list of those notices has exactly one entry, filed in 2023. Nothing in the law stops data leaving Lebanon. That changes if you are a bank or a payment company.

Data governance in Lebanon

The eight things that decide how you handle data about people in Lebanon. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it can reach a company with no office in Lebanon. The data chapter covers all use of personal data, by computer or on paper. The law assumes some of the people doing it sit abroad. If you are based outside the country, the notice you file must name a representative in Lebanon. There is no size or revenue cut-off. But most ordinary business use is exempt from filing at all. Staff records, customer records and anything the person agreed to in advance are all left out.

What you have to do here:
Appoint a representative · Register or notify

Where the data is allowed to live

Yes, and freely. The law never says that sending personal data to another country needs permission, a contract or a safe-country list. It only asks you to disclose it. If you have to file a notice, one of the boxes covers the personal data you plan to send abroad. Banking and payments are the exception. There, the data has to stay in Lebanon.

What you have to do here:
Keep the data in the country

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Nothing to sign and nobody to ask. Lebanon has no approved-country list, no banned-country list, no standard contract and no transfer approval. There is one step. Name the data you intend to send abroad on the notice you file with the Ministry of Economy and Trade. For banks, finance companies and payment providers the answer is the opposite. The data has to be hosted in Lebanon. Sharing it with anyone other than the financial regulators needs the customer's explicit written consent.

Ways to send data out:
Nothing required · Explicit consent

The regulator, and whether it actually acts

Nobody, as far as we can see. Lebanon has no privacy regulator at all. No commission, no board, no office. The Ministry of Economy and Trade only collects notices and publishes a list of them. That published list contains exactly one entry, filed in May 2023, in a file that has not been updated since. Punishment comes from the criminal courts. For two of the offences, that only happens if the affected person files a complaint. The central bank and the telecoms regulator, by contrast, are plainly working.

What it costs if you get it wrong:
Criminal liability

How long you must keep it — and when to delete it

There is a ceiling and a floor, and the ceiling is unusual. You may keep personal data only for the period you yourself wrote down when you filed your notice, or the period set in your licence. So you set your own deadline, and you are then bound by it. The floor comes from other laws. Banks, money dealers and other reporting businesses must keep transaction papers and customer identity records for at least five years. Telephone billing records would have to be kept for ten years. But that rule sits in a regulation that was never brought into force.

What you have to do here:
Delete data after a period · Keep data for a minimum period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There is no deadline, because there is no duty. Lebanon's data law does not require you to report a data breach to any authority. It does not require you to tell the people whose data was exposed. We checked the full text on 18 August 2026 and found no such article. Financial firms do have one firm deadline, for a different problem. When they freeze an account under sanctions rules, they have 48 hours to give the Special Investigation Commission the evidence.

What you have to do here:
Report breaches to the regulator · Tell affected people · Secure the data

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Four things that catch people out. First, the money is meaningless but the prison is not. The top fine is 30 million Lebanese pounds, about 335 US dollars at the central bank's own rate. The same article allows up to three years in jail. It applies to people, not only to companies. Second, health, genetic and sexual-life data are banned outright unless you fit one of four narrow exceptions. Permission comes from the Minister of Public Health, and two months of silence counts as a refusal. Third, you cannot contract out of any of it. A clause in your terms and conditions that cuts across the data rules simply has no effect. Fourth, the central bank orders Lebanese banks to follow Europe's privacy rulebook and to appoint a representative in Europe. That has nothing to do with Lebanese law and is easy to miss.

What you have to do here:
Appoint a representative · Appoint a data protection officer · Delete data after a period · Independent audit
What it costs if you get it wrong:
Criminal liability

What's changing next

The near-term story is banking, not privacy law. The central bank rewrote its electronic banking rules on 9 January 2026. It gave firms six months to move customer and transaction data onto servers in Lebanon. That duty became enforceable on 9 July 2026, so the first supervisory action is the thing to watch. In telecoms, the regulator got a new board in September 2025 after years without one, and is issuing rules again. That puts a 2009 consumer regulation back within reach of being published. It carries real privacy and billing-record clauses. We found no bill before Parliament to create a privacy regulator, but we could not check Parliament's own site.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries5 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Banking

Banking data needs a copy kept in the country

Official name: التعميم الأساسي رقم 69 - العمليات المالية والمصرفية بالوسائل الإلكترونية (Basic Circular 69 - Electronic Banking and Financial Operations) · Basic Decision 7548 of 30 March 2000, Articles 1 to 25 replaced by Intermediate Decision 13791 of 9 January 2026 · Regulator directive

In forceA copy must stay

This is the rule that forces data to stay in Lebanon. Banks and finance companies doing anything electronically must store all customer and transaction data in Lebanon. The whole circular was rewritten on 9 January 2026, and existing firms were given six months. So the duty has been enforceable since 9 July 2026. Customer data may not be shared with anyone except the financial regulators and the courts, unless the customer gives explicit written consent.

In force since 9 January 2026Enforced from 9 July 2026

Enforced by Banque du Liban

How this country controls where data goes: Approval each time · Accepted routes: Explicit consent, Government sign-off needed

Payments

Payments data needs a copy kept in the country

Official name: القرار الأساسي رقم 13790 - مقدّمو خدمات الدفع بالوسائل الإلكترونية (Basic Decision 13790 - Electronic Payment Services Providers, Basic Circular 1) · Basic Decision 13790 of 9 January 2026, Articles 27, 30, 31 and 44 and Annex 3 · Regulator directive

In forceA copy must stay

This is the payments twin of the banking rule, issued the same day. Any licensed electronic payment services provider must store all customer and transaction data in Lebanon. It may not share that data with anyone other than the central bank, the banking supervisor, the financial intelligence unit and the courts. It cannot outsource risk, compliance or audit at all.

In force since 9 January 2026Enforced from 9 July 2026

Enforced by Banque du Liban

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Explicit consent

Finance

Europe's main privacy law

Official name: التعميم الأساسي رقم 146 - النظام الأوروبي العام لحماية البيانات (Basic Circular 146 - General Data Protection Regulation) · Basic Decision 12872 of 13 September 2018 · Regulator directive

In forceYes, with paperwork

An oddity worth knowing about. Lebanon's central bank ordered every bank, finance company and other supervised institution to take measures in line with the European Union's General Data Protection Regulation. They must appoint a data protection officer from their compliance unit. They must name a representative in Europe. They had to report their procedures by the end of 2018. External auditors check it every year.

In force since 13 September 2018Enforced from 31 December 2018

Enforced by Banque du Liban

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Applies to every company1 rule

These bind you whatever business you are in, once the country's rules reach you.

Health data rules

Official name: قانون رقم 81 تاريخ 2018/10/10 - المعاملات الإلكترونية والبيانات ذات الطابع الشخصي (Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data) · Law No. 81 of 10 October 2018, Part Five (Articles 85 to 109) · Act of parliament

In forceYes — store it anywhere

This is Lebanon's only general personal data law. It asks you to file, not to be supervised. Tell the Ministry of Economy and Trade what you are doing. Keep the data only for the period you declared. Answer access requests in ten working days. It says nothing about sending data abroad, beyond asking you to disclose it. Health, genetic and sexual-life data are banned without a ministerial licence. Penalties are criminal, but the currency collapse has destroyed the cash ceilings.

In force since 18 January 2019

Enforced by Ministry of Economy and Trade — not yet operational

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • وزارة الاقتصاد والتجارة

    Receives personal data declarations and publishes the statutory register under Law 81/2018

    The ministry exists and works, but its data protection job does not. It has no power to supervise, investigate or fine under the law. The register it is required to publish held exactly one entry when we downloaded it on 18 August 2026. That file was last modified on 31 May 2023.

  • مصرف لبنان

    Banks, finance companies, electronic payment services providers; data hosting, data protection and cyber rules for the financial sector

    Plainly active. It rewrote its electronic banking decision and issued a new electronic payments decision on 9 January 2026. It has issued intermediate circulars as recently as July 2026.

  • الهيئة المنظمة للاتصالات

    Telecommunications licensing, spectrum, quality of service, consumer affairs

    Back in business. A five-member board, including a full-time chairwoman, was appointed by Decree 1328 in September 2025. That followed a long period with no board. The authority issued a Service Providers Licensing Regulation in December 2025, and further decisions in 2026.

  • هيئة التحقيق الخاصة

    Financial intelligence, banking secrecy lifting, record keeping duties under the anti-money-laundering law

  • وزارة الصحة العامة

    Licensing of processing that relates to health, genetic identity or sexual life, under Article 97 of Law 81/2018

    We found no evidence that any licence has ever been issued under this power. We could not reach the ministry's website on 18 August 2026. Silence for two months counts as a refusal, so a process nobody staffs works as a ban.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact date Law 81/2018 came into force

    Article 136 says the law applies three months after publication in the Official Gazette. We could not confirm the publication date in the Lebanese Official Gazette. So the 18 January 2019 start date recorded here is worked out, not confirmed.

  • That the Ministry of Economy and Trade has received only one declaration since 2019

    We can show only that the published register holds one entry and was last modified on 31 May 2023. The ministry may hold filings it has never published. That would break its own duty to publish, but it is not the same as an empty register.

  • That nobody has ever been prosecuted under Articles 106 to 108

    Lebanon has no public database of court decisions that we could reach. We can neither confirm nor rule out prosecutions. Assume a case is possible, even though we found none.

  • Whether the Telecommunications Regulatory Authority's Consumer Affairs Regulation was ever published in the Official Gazette

    The authority's own regulations page lists it among draft regulations, which suggests it is not in force. We could not confirm this in the Official Gazette. We have marked it as proposed and flagged that it could be revived.

  • Health sector storage and confidentiality rules

    We could not reach the Ministry of Public Health's website on 18 August 2026. We can show the Article 97 licensing requirement from the law itself. We cannot show any ministerial decision, circular or electronic health record policy. If you work in health, ask the ministry before you rely on this.

  • Insurance, securities, education, gaming, mapping, defence and government cloud rules

    We found no rule on storing or sending data for any of these industries, but the evidence is weak. The Insurance Control Commission has no website of its own that we could reach. The Capital Markets Authority's regulations section showed nothing about data. The administrative reform office publishes no cloud or hosting policy. Treat this as no rule found, not as no rule.

  • Whether a comprehensive data protection bill or a bill creating a privacy regulator is before Parliament in 2026

    We could not reach Parliament's website on 18 August 2026, so we could not confirm the pipeline from an official source. Check with Lebanese counsel if a new law would change your plans.

  • Which amendment first introduced the local data hosting duty for banks

    Intermediate Decision 13791 of 9 January 2026 repealed and replaced Articles 1 to 25 of the basic decision. It also gave six months to comply with Article 7. So the current duty dates from then. We did not check all twenty-seven earlier amendments for an earlier version of the same duty.

  • Completeness of the sectoral sweep

    Every finding here comes from official Lebanese websites we visited directly. A rule published on an official site we did not visit would have been missed. Treat the industry list as a floor, not a ceiling.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.