Lebanon
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Lebanon has a personal data law but no privacy regulator and, as far as we can see, no enforcement. Before you process data you are meant to file a notice with the Ministry of Economy and Trade. The ministry's own public list of those notices has exactly one entry, filed in 2023. Nothing in the law stops data leaving Lebanon - unless you are a bank or a payment company.
Data governance in Lebanon
The eight things that decide how you handle data about people in Lebanon. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it can reach a company with no office in Lebanon. The data chapter covers all handling of personal data, whether by computer or on paper, and the law assumes some of the people doing it sit abroad: the notice you file must name a representative in Lebanon if you are based outside the country. There is no size or revenue cut-off. In practice most ordinary business handling is exempt from filing at all, because staff records, customer records and anything the person agreed to in advance are carved out.
Article 85 applies the data chapter to all automated and non-automated processing except purely personal activity, and says the rights and duties it creates cannot be varied by agreement. Article 96(7) requires the declaration to state the identity and address of the controller's representative where the controller is resident outside Lebanese territory, and Article 98(4) republishes that address. Article 94 exempts public bodies acting within their powers, non-profit membership registers, statutory public registers, schools handling pupil data, employee and member records, customer and counterparty records of commercial companies, unions, associations and the liberal professions, anything the person consented to in advance, and processing under the 1999 interception law. There is no express extraterritoriality clause of the kind found in Europe or India, so the reach rests on the representative provisions rather than on a scope article.
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceMinistry of Economy and TradeMinistry of Economy and Trade — Personal Data page, publishing the register required by Article 98 of Law 81/2018
economy.gov.lb
“عملا" بالمادة 98 من القانون 81/2018 – المعاملات الالكترونية والبيانات ذات الطابع الشخصي، تضع وزارة الاقتصاد والتجارة في متناول الجمهور للاطلاع عليها، لائحة بمعالجات البيانات الشخصية المقدمة اليها انفاذاً لأحكام القانون المذكور.”
Link checked 18 August 2026
Where the data is allowed to live
In general yes, freely. The law never says that sending personal data to another country needs permission, a contract or a safe-country list. The only thing it asks is that you disclose it: if you have to file a notice, one of the boxes is the personal data you plan to send abroad. Banking and payments are the hard exception, and there the data has to stay in Lebanon.
Article 96(12) lists, among the fourteen items a declaration must contain, 'where applicable, the transfer of personal data to another State in any form'. Article 98(8) republishes that item in the public register. Neither article makes the transfer conditional on anything. Sector by sector, checked 18 August 2026: BANKING and PAYMENTS are closed - Article 7 of the central bank's rewritten Basic Decision 7548 and Article 27 of Basic Decision 13790 both require customer and transaction data to be stored in Lebanon. TELECOMS: no localisation found; the new Service Providers Licensing Regulation of December 2025 contains no data storage or privacy conditions, and the 2002 Telecommunications Law's only confidentiality article binds the regulator's own inspectors. HEALTH: no storage rule found, but health data cannot be processed at all without a licence from the Minister of Public Health. INSURANCE, SECURITIES, EDUCATION, GAMING, MAPPING, DEFENCE and GOVERNMENT CLOUD: no rule found on any official site we could open, which is a gap in our evidence rather than proof of absence.
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban Basic Circular 69 / Basic Decision 7548, consolidated English text — Article 7 Data Hosting
bdl.gov.lb
“Banks and financial institutions conducting electronic banking and financial operations must store in Lebanon all data and information pertaining to customers and executed operations (Local Data Hosting).”
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban Basic Decision 13790 of 9 January 2026 (Basic Circular 1) on Electronic Payment Services Providers — Article 27 Data Hosting Requirements
bdl.gov.lb
“The Institution must store in Lebanon all data and information pertaining to customers and executed operations (Local Data Hosting).”
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityTRA Decision 12/2025 of 11 December 2025 — Service Providers Licensing Regulation
tra.gov.lb
Link checked 18 August 2026
Sending data out of the country
Nothing to sign and nobody to ask. Lebanon has no approved-country list, no banned-country list, no standard contract and no transfer approval. The single step is disclosure: name the data you intend to send abroad on the notice you file with the Ministry of Economy and Trade. For banks, finance companies and payment providers the answer is the opposite - the data has to be hosted in Lebanon, and sharing it with anyone other than the financial regulators needs the customer's explicit written consent.
Because there is no list of any kind, there is nothing to be populated and nothing that can be switched on by naming a country. The nearest thing to a lever is Article 94, which lets the Council of Ministers, by decree proposed jointly by the Ministers of Justice and of Economy and Trade, exempt further categories of processing from the filing regime - a loosening power, not a tightening one. In the financial sector, Annex 3 of Basic Decision 13790 forbids sharing customer personal data with any third party except the central bank, the Banking Control Commission, the Special Investigation Commission and the judicial authorities, and requires the customer to be told and to give explicit written consent, limited to specific purposes, before a processor touches the data.
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban Basic Decision 13790 of 9 January 2026 (Basic Circular 1) on Electronic Payment Services Providers — Article 27 Data Hosting Requirements
bdl.gov.lb
“The Institution must store in Lebanon all data and information pertaining to customers and executed operations (Local Data Hosting).”
Link checked 18 August 2026
- Official sourceMinistry of Economy and TradeMinistry of Economy and Trade — Personal Data page, publishing the register required by Article 98 of Law 81/2018
economy.gov.lb
“عملا" بالمادة 98 من القانون 81/2018 – المعاملات الالكترونية والبيانات ذات الطابع الشخصي، تضع وزارة الاقتصاد والتجارة في متناول الجمهور للاطلاع عليها، لائحة بمعالجات البيانات الشخصية المقدمة اليها انفاذاً لأحكام القانون المذكور.”
Link checked 18 August 2026
The regulator, and whether it actually acts
Nobody, in practice. Lebanon has no privacy regulator at all - no commission, no board, no office. The Ministry of Economy and Trade only collects notices and publishes a list of them, and that published list contains exactly one entry, filed in May 2023, in a file that has not been updated since. Punishment comes from criminal courts, and for two of the offences only if the affected person files a complaint. The central bank and the telecoms regulator, by contrast, are plainly working.
The law hands out functions rather than creating an authority. The Ministry of Economy and Trade receives declarations against a receipt (Article 95) and must publish the register (Article 98). Licences for the three restricted categories come from other ministers: internal and external state security from a joint decision of the Ministers of National Defence and of Interior and Municipalities, criminal offences and judicial proceedings from the Minister of Justice, and health, genetic identity or sexual life from the Minister of Public Health (Article 97). Silence for two months is a refusal. Enforcement is by criminal prosecution under Articles 106 to 108, and Article 109 makes prosecution for unlawful disclosure and for ignoring an access request depend on a complaint by the injured party, which the complainant can withdraw. The Article 98 register we downloaded on 18 August 2026 lists a single declaration, number 1931/2023 of 16 May 2023, by a United States software company acting through a Beirut law firm as its Lebanese representative; the spreadsheet's own last-modified stamp is 31 May 2023. By contrast the Banque du Liban issued new electronic banking and payments decisions in January 2026, and the Telecommunications Regulatory Authority received a new five-member board by Decree 1328 in September 2025 and issued a licensing regulation in December 2025.
Sources
- Official sourceMinistry of Economy and TradeMinistry of Economy and Trade — 'List of Personal Data Processing' (the Article 98 public register), one entry, file last modified 31 May 2023
economy.gov.lb
Link checked 18 August 2026
- Official sourceMinistry of Economy and TradeMinistry of Economy and Trade — Personal Data page, publishing the register required by Article 98 of Law 81/2018
economy.gov.lb
“عملا" بالمادة 98 من القانون 81/2018 – المعاملات الالكترونية والبيانات ذات الطابع الشخصي، تضع وزارة الاقتصاد والتجارة في متناول الجمهور للاطلاع عليها، لائحة بمعالجات البيانات الشخصية المقدمة اليها انفاذاً لأحكام القانون المذكور.”
Link checked 18 August 2026
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityDecree 1328 of September 2025 appointing the Chairwoman and members of the Telecommunications Regulatory Authority
tra.gov.lb
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a ceiling and a floor, and the ceiling is unusual. You may only keep personal data for the period you yourself wrote down when you filed your notice, or the period set in your licence - so you set your own deadline and are then bound by it. The floor comes from other laws: banks, money dealers and other reporting businesses must keep transaction papers and customer identity records for at least five years. Telephone billing records would have to be kept for ten years, but only under a regulation that was never brought into force.
Article 90 of Law 81/2018 provides that keeping personal data is lawful only during the period stated in the declaration of the processing, or in the decision authorising it. There is no general statutory maximum and no general minimum in the data law itself. Article 4(4) of Law 44/2015 requires copies of documents relating to all operations, and information and identity documents of customers, to be kept for at least five years. The ten-year billing record rule is Article 34 of the telecoms regulator's Consumer Affairs Regulation, which its own website still lists among draft regulations. Where the five-year anti-money-laundering floor and a shorter self-declared retention period collide, the specific financial statute prevails in practice; the data law contains no conflict rule, which is itself a gap.
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceSpecial Investigation CommissionLaw No. 44 of 24 November 2015 on Fighting Money Laundering and Terrorism Financing — Article 4(4), five-year record keeping
sic.gov.lb
“الاحتفاظ بصور عن المستندات المتعلقة بالعمليات كافة وبالمعلومات أو بالبيانات أو بصور عن الوثائق المتعلقة بهوية المتعاملين لمدة خمس سنوات على الأقل”
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityTRA Consumer Affairs Regulation, approved by the TRA Board on 19 June 2009 — Articles 21 to 24 and 34
tra.gov.lb
“Service Providers may not disclose any Personal Information or calling patterns relating to a Consumer unless the Consumer's express and specific consent is given in advance and in writing.”
Link checked 18 August 2026
If something goes wrong
There is no deadline because there is no duty. Lebanon's data law does not require you to report a data breach to any authority and does not require you to tell the people whose data was exposed. We checked the full text on 18 August 2026 and found no such article. Financial firms do run one hard clock for a different problem: when they freeze an account under sanctions rules they have 48 hours to give the Special Investigation Commission the evidence.
What the law punishes is the leak itself rather than the failure to disclose it: Article 106 makes it an offence to disclose personal data under processing to unauthorised persons, even negligently. Article 107 sets a ten working day clock, but for answering a person's access or correction request, not for a breach. In the financial sector, Basic Circular 144 of 2017 requires banks to pass the Special Investigation Commission technical information about suspicious transfers, including the customer's internet address and internet provider, but attaches no reporting deadline. The 48-hour clock is in Basic Decision 13790 and applies to evidence of a freezing action. Because Lebanon has no operating national computer emergency team with a reporting duty that we could verify, a company suffering a breach in Lebanon has, unusually, nobody it is legally obliged to call.
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban Basic Circular 144 / Basic Decision 12725 of 28 November 2017 — Cybercrime Prevention
bdl.gov.lb
“Be vigilant and cautious when selecting contractors for tasks related to IT systems, and to make sure that these contractors do not in turn outsource these tasks to less reliable parties.”
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban Basic Decision 13790 of 9 January 2026 (Basic Circular 1) on Electronic Payment Services Providers — Article 27 Data Hosting Requirements
bdl.gov.lb
“The Institution must store in Lebanon all data and information pertaining to customers and executed operations (Local Data Hosting).”
Link checked 18 August 2026
What catches people out
Four things that catch people out. First, the money is meaningless but the prison is not: the top fine is 30 million Lebanese pounds, about 335 US dollars at the central bank's own rate, while the same article allows up to three years in jail, and it bites people, not only companies. Second, health, genetic and sexual-life data are banned outright unless you fit one of four narrow exceptions, and the permission comes from the Minister of Public Health, where two months of silence counts as a refusal. Third, you cannot contract out of any of it - a clause in your terms and conditions that cuts across the data rules simply has no effect. Fourth, the central bank orders Lebanese banks to comply with Europe's privacy rulebook and to appoint a representative in Europe, which has nothing to do with Lebanese law and is easy to miss.
Article 106 sets a fine of 1 to 30 million Lebanese pounds and imprisonment of three months to three years, or either, for processing without a declaration or without a prior licence, for breaking the collection and processing rules, and for disclosing personal data to unauthorised persons even by negligence. Article 107 adds a fine of 1 to 15 million pounds for refusing, or answering wrongly or incompletely within ten working days, an access or correction request. Article 108 raises repeat penalties by between a third and a half. At the Banque du Liban's own published rate of 89,500 pounds to the dollar on 14 August 2026, those ceilings are roughly 335 and 168 US dollars. Article 91 bans collecting or processing data revealing health status, genetic identity or sexual life, with exceptions only where the person made it public or expressly agreed, where it is needed for medical diagnosis or treatment by a health professional, where it is to establish or defend a right in court, or under an Article 97 licence. Article 85 makes the chapter non-derogable and says no agreement, contrary clause or unilateral undertaking can be relied on against it. Basic Circular 146 of 13 September 2018 required banks, finance companies and other supervised institutions to take measures in line with the European General Data Protection Regulation, to appoint a data protection officer from the compliance unit, to designate a European representative and to notify their procedures by 31 December 2018, with annual external audit verification. Two further snags: a foreign controller must name a Lebanese representative on the declaration, and the retention period you write on that declaration becomes the legal maximum you may keep the data.
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban daily exchange rates — US dollar at 89,500 Lebanese pounds, 14 August 2026
bdl.gov.lb
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban Basic Circular 146 / Basic Decision 12872 of 13 September 2018 — General Data Protection Regulation (GDPR)
bdl.gov.lb
Link checked 18 August 2026
What's changing next
The near-term story is banking, not privacy law. The central bank rewrote its electronic banking rules on 9 January 2026 and gave firms six months to move customer and transaction data onto servers in Lebanon, so that duty became enforceable on 9 July 2026 and the first supervisory action is the thing to watch. In telecoms, the regulator got a new board in September 2025 after years without one and is issuing rules again, which puts a 2009 consumer regulation with real privacy and billing-record clauses back within reach of being published. We found no bill before Parliament to create a privacy regulator, but we could not open the Parliament's own site to be sure.
Dormant switches worth watching. One: Article 94 lets the Council of Ministers, by decree on the joint proposal of the Ministers of Justice and of Economy and Trade, exempt further categories of processing from the filing regime - a power to loosen with no consultation. Two: Article 97 licensing sits with three sets of ministers who can each set conditions on state security, criminal and health data processing by their own decision. Three: the central bank amended Basic Circular 69 twenty-seven times between 2003 and 2026 and rewrote Articles 1 to 25 wholesale in January 2026, so the financial data rules can change by a single decision of the Governor. Four: the telecoms regulator's Consumer Affairs Regulation, approved by its board on 19 June 2009 and still listed on its own site among draft regulations, would take effect on publication in the Official Gazette under its own Article 83; it grants subscribers privacy rights, bans disclosing calling patterns without advance written consent and imposes a ten-year billing record duty, and it could be published without further consultation.
Sources
- Official sourceBanque du LibanIntermediate Decision 13791 of 9 January 2026 — repeals and replaces Articles 1 to 25 of Basic Decision 7548, and gives six months to comply with Article 7
bdl.gov.lb
“تُمنَح المصارف والمؤسسات المالية مهلة /6/ أشهر للتقيّد بأحكام المادة /7/ من هذا القرار.”
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityDecree 1328 of September 2025 appointing the Chairwoman and members of the Telecommunications Regulatory Authority
tra.gov.lb
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityTRA Regulations page — the Consumer Affairs Regulation is listed under draft regulations
tra.gov.lb
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityTRA Consumer Affairs Regulation, approved by the TRA Board on 19 June 2009 — Articles 21 to 24 and 34
tra.gov.lb
“Service Providers may not disclose any Personal Information or calling patterns relating to a Consumer unless the Consumer's express and specific consent is given in advance and in writing.”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
التعميم الأساسي رقم 69 - العمليات المالية والمصرفية بالوسائل الإلكترونية (Basic Circular 69 - Electronic Banking and Financial Operations)
Regulator directive · Basic Decision 7548 of 30 March 2000, Articles 1 to 25 replaced by Intermediate Decision 13791 of 9 January 2026
The hard localisation rule in Lebanon. Banks and finance companies doing anything electronically must store all customer and transaction data in Lebanon. The whole circular was rewritten on 9 January 2026 and existing firms were given six months, so the duty has been enforceable since 9 July 2026. Customer data may not be shared with anyone except the financial regulators and the courts without the customer's explicit written consent.
Enforced by Banque du Liban
Transfer model: Approval each time · Accepted routes: Explicit consent, Government sign-off needed
What it makes you do
- Keep the data in the country — from 9 July 2026Article 7. The rule is expressed as a duty to store the data in Lebanon; it does not in terms forbid a further copy abroad, but Article 8 makes sharing it with any non-regulator conditional on the customer's explicit written consent.
- Secure the dataArticle 8 requires the highest degree of security for customers' personal data.
- Written vendor contractContracts with processors must limit them to the original declared purpose, impose the same security standard, and leave the institution answerable to the customer for misuse.
- Get consentThe customer must be told a third party will process their data and must give explicit written consent.
- Register or notify — within 2160 hoursNinety days' prior written notice to the central bank before starting, promoting or changing any electronic operation; prior approval for electronic know-your-customer and electronic money.
What it costs if you get it wrong
- Loss of your licenceNon-compliance with the conditions of the decision, supervised by the Banking Control Commission of Lebanon
Sources
- Official sourceBanque du LibanBanque du Liban Basic Circular 69 / Basic Decision 7548, consolidated English text — Article 7 Data Hosting
bdl.gov.lb
“Banks and financial institutions conducting electronic banking and financial operations must store in Lebanon all data and information pertaining to customers and executed operations (Local Data Hosting).”
Link checked 18 August 2026
- Official sourceBanque du LibanIntermediate Decision 13791 of 9 January 2026 — repeals and replaces Articles 1 to 25 of Basic Decision 7548, and gives six months to comply with Article 7
bdl.gov.lb
“تُمنَح المصارف والمؤسسات المالية مهلة /6/ أشهر للتقيّد بأحكام المادة /7/ من هذا القرار.”
Link checked 18 August 2026
القرار الأساسي رقم 13790 - مقدّمو خدمات الدفع بالوسائل الإلكترونية (Basic Decision 13790 - Electronic Payment Services Providers, Basic Circular 1)
Regulator directive · Basic Decision 13790 of 9 January 2026, Articles 27, 30, 31 and 44 and Annex 3
The payments twin of the banking rule, issued the same day. Any licensed electronic payment services provider must store all customer and transaction data in Lebanon, may not share it with anyone other than the central bank, the banking supervisor, the financial intelligence unit and the courts, and cannot outsource risk, compliance or audit at all.
Enforced by Banque du Liban
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Explicit consent
What it makes you do
- Keep the data in the country — from 9 July 2026Article 27. Firms already licensed under the old electronic banking decision were given six months from 9 January 2026.
- Register or notifyPrior approval from the Banque du Liban is required to be licensed as an electronic payment services provider.
- Secure the dataAnnex 3 requires utmost security and access on a need-to-know basis.
- Written vendor contractArticle 31 bans outsourcing risk management, compliance and internal audit; information security and cyber risk work may be outsourced only with prior central bank approval and under Banking Control Commission supervision.
- Get consentExplicit written consent, limited to specific purposes, before any processor handles customer personal data.
- Independent auditInternal audit unit or named internal auditor, plus periodic statements to the central bank.
What it costs if you get it wrong
- Loss of your licenceBreach of the licensing conditions; the decision also allows referral of an infringing institution to the competent judicial authority
Sources
- Official sourceBanque du LibanBanque du Liban Basic Decision 13790 of 9 January 2026 (Basic Circular 1) on Electronic Payment Services Providers — Article 27 Data Hosting Requirements
bdl.gov.lb
“The Institution must store in Lebanon all data and information pertaining to customers and executed operations (Local Data Hosting).”
Link checked 18 August 2026
- Official sourceBanque du LibanIntermediate Decision 13791 of 9 January 2026 — repeals and replaces Articles 1 to 25 of Basic Decision 7548, and gives six months to comply with Article 7
bdl.gov.lb
“تُمنَح المصارف والمؤسسات المالية مهلة /6/ أشهر للتقيّد بأحكام المادة /7/ من هذا القرار.”
Link checked 18 August 2026
التعميم الأساسي رقم 146 - النظام الأوروبي العام لحماية البيانات (Basic Circular 146 - General Data Protection Regulation)
Regulator directive · Basic Decision 12872 of 13 September 2018
An oddity worth knowing about. Lebanon's central bank ordered every bank, finance company and other supervised institution to take measures in line with the European Union's General Data Protection Regulation, to appoint a data protection officer from their compliance unit, to designate a representative in Europe, and to report their procedures by the end of 2018. External auditors check it every year.
Enforced by Banque du Liban
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Appoint a data protection officer — from 31 December 2018Drawn from the institution's own compliance unit.
- Appoint a local representative — from 31 December 2018A representative in the European Union, not in Lebanon.
- Put a transfer safeguard in placeBy importing the European rulebook, the European transfer conditions come with it.
- Independent auditExternal auditors must verify compliance and report annually.
Sources
- Official sourceBanque du LibanBanque du Liban Basic Circular 146 / Basic Decision 12872 of 13 September 2018 — General Data Protection Regulation (GDPR)
bdl.gov.lb
Link checked 18 August 2026
التعميم الأساسي رقم 144 - الوقاية من الجرائم الإلكترونية (Basic Circular 144 - Cybercrime Prevention)
Regulator directive · Basic Decision 12725 of 28 November 2017
Lebanon's only cyber rulebook with real force, and it covers banks and finance companies only. It is about controls and contractor diligence rather than incident reporting: there is no clock, and the only reporting duty is to hand technical details of suspicious transfers to the financial intelligence unit. Implementation sits with the compliance department.
Enforced by Banque du Liban
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the data
- Written vendor contractInstitutions must be cautious in choosing information technology contractors and must ensure those contractors do not themselves sub-contract to less reliable parties.
- Report cyber incidentsNo hour or day deadline. The duty is to pass the financial intelligence unit technical information about suspicious transfer orders, including the customer's internet address and internet service provider.
Sources
- Official sourceBanque du LibanBanque du Liban Basic Circular 144 / Basic Decision 12725 of 28 November 2017 — Cybercrime Prevention
bdl.gov.lb
“Be vigilant and cautious when selecting contractors for tasks related to IT systems, and to make sure that these contractors do not in turn outsource these tasks to less reliable parties.”
Link checked 18 August 2026
Consumer Affairs Regulation
Directly binding regulation · Approved by the TRA Board on 19 June 2009; Article 83 makes it effective on publication in the Official Gazette
A trap for anyone reading the telecoms regulator's website. This regulation contains the only real telecoms privacy rules in Lebanon - no disclosure of calling patterns without advance written consent, confidentiality of customer records, ten-year billing records - but the regulator's own site still files it under draft regulations, seventeen years after its board approved it. Treat it as not binding, and as revivable by publication in the Official Gazette.
Enforced by Telecommunications Regulatory Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Let people see their dataNot in force. Consumers would have a right to privacy and to protection from unauthorised use of their records.
- Extra vendor secrecy termsNot in force. Service providers would have to keep customer information, usage information and network information confidential.
- Keep data for a minimum period — 10 yearsNot in force. Billing records would have to be kept for at least ten years.
Sources
- Official sourceTelecommunications Regulatory AuthorityTRA Consumer Affairs Regulation, approved by the TRA Board on 19 June 2009 — Articles 21 to 24 and 34
tra.gov.lb
“Service Providers may not disclose any Personal Information or calling patterns relating to a Consumer unless the Consumer's express and specific consent is given in advance and in writing.”
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityTRA Regulations page — the Consumer Affairs Regulation is listed under draft regulations
tra.gov.lb
Link checked 18 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
قانون رقم 81 تاريخ 2018/10/10 - المعاملات الإلكترونية والبيانات ذات الطابع الشخصي (Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data)
Act of parliament · Law No. 81 of 10 October 2018, Part Five (Articles 85 to 109)
Lebanon's only general personal data law. It is a filing regime, not a supervision regime: tell the Ministry of Economy and Trade what you are doing, keep the data only for the period you declared, and answer access requests in ten working days. It says nothing at all about sending data abroad beyond asking you to disclose it. Health, genetic and sexual-life data are banned without a ministerial licence. Penalties are criminal but the cash ceilings have been destroyed by the currency collapse.
Enforced by Ministry of Economy and Trade — not yet operational
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notifyA declaration must be filed with the Ministry of Economy and Trade against a receipt, unless one of the eight exemptions applies. Fourteen items are required, including retention period and any data to be sent abroad.
- Tell people what you doThe person must be told who the controller is, why the data is collected, whether answering is compulsory, what happens if they do not answer, who will receive the data, and how to access and correct it.
- Get consentPrior consent is one of the routes out of the filing duty, and the only general route for health, genetic and sexual-life data outside medical care.
- Let people see their data — within 240 hoursTen working days to answer. Heirs may also exercise the right. A charge no higher than the cost of copying may be made.
- Let people correct their data — within 240 hours
- Let people objectIncludes objecting to use for commercial promotion, unless collection is required by law or the person consented.
- Limit automated decisionsNo judicial or administrative decision assessing a person's conduct may rest on automated processing alone.
- Secure the data
- Delete data after a periodOnly for the period stated in the declaration or in the licence decision.
- Appoint a local representativeControllers resident outside Lebanon must name a representative and address in the declaration and in the public register.
What it costs if you get it wrong
- Criminal liability: LBP 30,000,000 and 3 years' imprisonment — about $335Processing without a declaration or prior licence, breaking the collection and processing rules, or disclosing personal data to unauthorised persons even negligently
- Fixed maximum fine: LBP 15,000,000 — about $168Refusing, or answering wrongly or incompletely within ten working days, an access or correction request
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceMinistry of Economy and TradeMinistry of Economy and Trade — Personal Data page, publishing the register required by Article 98 of Law 81/2018
economy.gov.lb
“عملا" بالمادة 98 من القانون 81/2018 – المعاملات الالكترونية والبيانات ذات الطابع الشخصي، تضع وزارة الاقتصاد والتجارة في متناول الجمهور للاطلاع عليها، لائحة بمعالجات البيانات الشخصية المقدمة اليها انفاذاً لأحكام القانون المذكور.”
Link checked 18 August 2026
- Official sourceMinistry of Economy and TradeMinistry of Economy and Trade — 'List of Personal Data Processing' (the Article 98 public register), one entry, file last modified 31 May 2023
economy.gov.lb
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact date Law 81/2018 came into force
Article 136 says the law applies three months after publication in the Official Gazette. We could not open the Lebanese Official Gazette (its site failed certificate validation on 18 August 2026), so the publication date, and therefore the 18 January 2019 commencement we record, is inferred rather than verified.
That the Ministry of Economy and Trade has received only one declaration since 2019
We can prove only that the register it publishes contains one entry and was last modified on 31 May 2023. The ministry may hold filings it has not published. That is itself a failure of the Article 98 duty, but it is not the same as an empty register.
That nobody has ever been prosecuted under Articles 106 to 108
Lebanon has no accessible official case-law database. We could not open the judiciary's or Parliament's sites, so we can neither confirm nor exclude prosecutions.
Whether the Telecommunications Regulatory Authority's Consumer Affairs Regulation was ever published in the Official Gazette
The authority's own regulations page lists it among draft regulations, which points to not in force, but we could not check the Gazette directly. We have therefore marked it proposed and flagged it as revivable.
Health sector storage and confidentiality rules
The Ministry of Public Health's website returned an access error to our tooling on 18 August 2026. We can evidence the Article 97 licensing requirement from the statute, but not any ministerial decision, circular or electronic health record policy.
Insurance, securities, education, gaming, mapping, defence and government cloud rules
We found no data storage or transfer rule for any of these, but this is weak evidence. The Insurance Control Commission has no reachable website of its own, the Capital Markets Authority's regulations section did not surface any data instrument, and the administrative reform office publishes no cloud or hosting policy. Record this as not found, not as absent.
Whether a comprehensive data protection bill or a bill creating a privacy regulator is before Parliament in 2026
The Parliament's website timed out repeatedly on 18 August 2026 and we could not verify the legislative pipeline from an official source.
Which amendment first introduced the local data hosting duty for banks
We can prove that Intermediate Decision 13791 of 9 January 2026 repealed and replaced Articles 1 to 25 of the basic decision and gave six months to comply with Article 7, so the current duty dates from then. We did not check all twenty-seven earlier amendments for an earlier version of the same duty.
Completeness of the sectoral sweep
General web search was unavailable throughout this run, so every finding comes from directly navigating official Lebanese sites. A rule published on an official site we did not think to visit would have been missed. Treat the sectoral list as a floor, not a ceiling.
60-day cadence. The banking localisation duty only became enforceable on 9 July 2026, so the first supervisory action under it is likely inside this window, and the newly reconstituted telecoms regulator is issuing decisions at pace after fourteen years without a board.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Lebanon versus
Compare