Lebanon
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Lebanon — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Lebanon has a personal data law, but no privacy regulator and, as far as we can see, no enforcement. Before you use personal data you are meant to file a notice with the Ministry of Economy and Trade. The ministry's own public list of those notices has exactly one entry, filed in 2023. Nothing in the law stops data leaving Lebanon. That changes if you are a bank or a payment company.
Data governance in Lebanon
The eight things that decide how you handle data about people in Lebanon. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it can reach a company with no office in Lebanon. The data chapter covers all use of personal data, by computer or on paper. The law assumes some of the people doing it sit abroad. If you are based outside the country, the notice you file must name a representative in Lebanon. There is no size or revenue cut-off. But most ordinary business use is exempt from filing at all. Staff records, customer records and anything the person agreed to in advance are all left out.
- What you have to do here:
- Appoint a representative · Register or notify
Article 85 applies the data chapter to all use of personal data, by computer or by hand, except purely personal activity. It says the rights and duties it creates cannot be varied by agreement. Article 96(7) requires your declaration to state the identity and address of your representative where you live outside Lebanon. Article 98(4) republishes that address. Article 94 sets out the exemptions. They cover public bodies acting within their powers, non-profit membership registers, statutory public registers, schools handling pupil data, and employee and member records. They also cover the customer and counterparty records of commercial companies, unions, associations and the liberal professions. They cover anything the person agreed to in advance. And they cover work done under the 1999 interception law. There is no article saying plainly that the law applies even if you have no office in Lebanon, as there is in Europe or India. So the reach rests on the rules about representatives, not on a scope article.
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceMinistry of Economy and TradeMinistry of Economy and Trade — Personal Data page, publishing the register required by Article 98 of Law 81/2018
economy.gov.lb
“عملا" بالمادة 98 من القانون 81/2018 – المعاملات الالكترونية والبيانات ذات الطابع الشخصي، تضع وزارة الاقتصاد والتجارة في متناول الجمهور للاطلاع عليها، لائحة بمعالجات البيانات الشخصية المقدمة اليها انفاذاً لأحكام القانون المذكور.”
Link checked 18 August 2026
Where the data is allowed to live
Yes, and freely. The law never says that sending personal data to another country needs permission, a contract or a safe-country list. It only asks you to disclose it. If you have to file a notice, one of the boxes covers the personal data you plan to send abroad. Banking and payments are the exception. There, the data has to stay in Lebanon.
- What you have to do here:
- Keep the data in the country
Article 96(12) lists fourteen items your declaration must contain. One of them is 'where applicable, the transfer of personal data to another State in any form'. Article 98(8) republishes that item in the public register. Neither article makes the transfer conditional on anything. Industry by industry, checked 18 August 2026: BANKING and PAYMENTS are closed. Two rules require customer and transaction data to be stored in Lebanon. They are Article 7 of the central bank's rewritten Basic Decision 7548 and Article 27 of Basic Decision 13790. TELECOMS: we found no rule that data must stay in the country. The new Service Providers Licensing Regulation of December 2025 sets no data storage or privacy conditions. The only confidentiality article in the 2002 Telecommunications Law binds the regulator's own inspectors. HEALTH: we found no storage rule. But you cannot use health data at all without a licence from the Minister of Public Health. INSURANCE, SECURITIES, EDUCATION, GAMING, MAPPING, DEFENCE and GOVERNMENT CLOUD: we found no rule on any official site we could reach. That is a gap in our evidence, not proof that no rule exists.
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban Basic Circular 69 / Basic Decision 7548, consolidated English text — Article 7 Data Hosting
bdl.gov.lb
“Banks and financial institutions conducting electronic banking and financial operations must store in Lebanon all data and information pertaining to customers and executed operations (Local Data Hosting).”
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban Basic Decision 13790 of 9 January 2026 (Basic Circular 1) on Electronic Payment Services Providers — Article 27 Data Hosting Requirements
bdl.gov.lb
“The Institution must store in Lebanon all data and information pertaining to customers and executed operations (Local Data Hosting).”
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityTRA Decision 12/2025 of 11 December 2025 — Service Providers Licensing Regulation
tra.gov.lb
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Nothing to sign and nobody to ask. Lebanon has no approved-country list, no banned-country list, no standard contract and no transfer approval. There is one step. Name the data you intend to send abroad on the notice you file with the Ministry of Economy and Trade. For banks, finance companies and payment providers the answer is the opposite. The data has to be hosted in Lebanon. Sharing it with anyone other than the financial regulators needs the customer's explicit written consent.
- Ways to send data out:
- Nothing required · Explicit consent
There is no list of any kind. So there is nothing to fill in, and nothing that can be switched on by naming a country. The nearest thing to a lever is Article 94. It lets the Council of Ministers exempt more categories from the filing duty. That takes a decree proposed jointly by the Ministers of Justice and of Economy and Trade. That is a power to loosen, not to tighten. In the financial industry, Annex 3 of Basic Decision 13790 bans sharing customer personal data with any third party. The only exceptions are the central bank, the Banking Control Commission, the Special Investigation Commission and the judicial authorities. Before a supplier touches the data, the customer must be told and must give explicit written consent, limited to specific purposes.
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban Basic Decision 13790 of 9 January 2026 (Basic Circular 1) on Electronic Payment Services Providers — Article 27 Data Hosting Requirements
bdl.gov.lb
“The Institution must store in Lebanon all data and information pertaining to customers and executed operations (Local Data Hosting).”
Link checked 18 August 2026
- Official sourceMinistry of Economy and TradeMinistry of Economy and Trade — Personal Data page, publishing the register required by Article 98 of Law 81/2018
economy.gov.lb
“عملا" بالمادة 98 من القانون 81/2018 – المعاملات الالكترونية والبيانات ذات الطابع الشخصي، تضع وزارة الاقتصاد والتجارة في متناول الجمهور للاطلاع عليها، لائحة بمعالجات البيانات الشخصية المقدمة اليها انفاذاً لأحكام القانون المذكور.”
Link checked 18 August 2026
The regulator, and whether it actually acts
Nobody, as far as we can see. Lebanon has no privacy regulator at all. No commission, no board, no office. The Ministry of Economy and Trade only collects notices and publishes a list of them. That published list contains exactly one entry, filed in May 2023, in a file that has not been updated since. Punishment comes from the criminal courts. For two of the offences, that only happens if the affected person files a complaint. The central bank and the telecoms regulator, by contrast, are plainly working.
- What it costs if you get it wrong:
- Criminal liability
The law hands out jobs rather than creating an authority. The Ministry of Economy and Trade receives declarations against a receipt (Article 95) and must publish the register (Article 98). Licences for the three restricted categories come from other ministers (Article 97). Internal and external state security needs a joint decision of the Ministers of National Defence and of Interior and Municipalities. Criminal offences and judicial proceedings need the Minister of Justice. Health, genetic identity or sexual life needs the Minister of Public Health. Silence for two months counts as a refusal. Enforcement is by criminal prosecution under Articles 106 to 108. Article 109 makes prosecution for unlawful disclosure, and for ignoring an access request, depend on a complaint by the injured party. That person can withdraw the complaint. The Article 98 register we downloaded on 18 August 2026 lists a single declaration. It is number 1931/2023 of 16 May 2023, by a United States software company acting through a Beirut law firm as its Lebanese representative. The spreadsheet's own last-modified stamp is 31 May 2023. By contrast, the Banque du Liban issued new electronic banking and payments decisions in January 2026. The Telecommunications Regulatory Authority received a new five-member board by Decree 1328 in September 2025 and issued a licensing regulation in December 2025.
Sources
- Official sourceMinistry of Economy and TradeMinistry of Economy and Trade — 'List of Personal Data Processing' (the Article 98 public register), one entry, file last modified 31 May 2023
economy.gov.lb
Link checked 18 August 2026
- Official sourceMinistry of Economy and TradeMinistry of Economy and Trade — Personal Data page, publishing the register required by Article 98 of Law 81/2018
economy.gov.lb
“عملا" بالمادة 98 من القانون 81/2018 – المعاملات الالكترونية والبيانات ذات الطابع الشخصي، تضع وزارة الاقتصاد والتجارة في متناول الجمهور للاطلاع عليها، لائحة بمعالجات البيانات الشخصية المقدمة اليها انفاذاً لأحكام القانون المذكور.”
Link checked 18 August 2026
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityDecree 1328 of September 2025 appointing the Chairwoman and members of the Telecommunications Regulatory Authority
tra.gov.lb
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a ceiling and a floor, and the ceiling is unusual. You may keep personal data only for the period you yourself wrote down when you filed your notice, or the period set in your licence. So you set your own deadline, and you are then bound by it. The floor comes from other laws. Banks, money dealers and other reporting businesses must keep transaction papers and customer identity records for at least five years. Telephone billing records would have to be kept for ten years. But that rule sits in a regulation that was never brought into force.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period
Article 90 of Law 81/2018 limits how long you may keep personal data. It is the period stated in your declaration, or in the decision authorising the work. The data law itself sets no general maximum and no general minimum. Article 4(4) of Law 44/2015 sets a floor of at least five years. It covers copies of documents relating to all operations, plus customer information and identity documents. The ten-year billing record rule is Article 34 of the telecoms regulator's Consumer Affairs Regulation. The regulator's own website still lists that regulation among drafts. Where the five-year anti-money-laundering floor clashes with a shorter period you declared, the specific financial law wins. The data law has no rule for resolving the clash, which is itself a gap.
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceSpecial Investigation CommissionLaw No. 44 of 24 November 2015 on Fighting Money Laundering and Terrorism Financing — Article 4(4), five-year record keeping
sic.gov.lb
“الاحتفاظ بصور عن المستندات المتعلقة بالعمليات كافة وبالمعلومات أو بالبيانات أو بصور عن الوثائق المتعلقة بهوية المتعاملين لمدة خمس سنوات على الأقل”
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityTRA Consumer Affairs Regulation, approved by the TRA Board on 19 June 2009 — Articles 21 to 24 and 34
tra.gov.lb
“Service Providers may not disclose any Personal Information or calling patterns relating to a Consumer unless the Consumer's express and specific consent is given in advance and in writing.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There is no deadline, because there is no duty. Lebanon's data law does not require you to report a data breach to any authority. It does not require you to tell the people whose data was exposed. We checked the full text on 18 August 2026 and found no such article. Financial firms do have one firm deadline, for a different problem. When they freeze an account under sanctions rules, they have 48 hours to give the Special Investigation Commission the evidence.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Secure the data
The law punishes the leak itself, not the failure to disclose it. Article 106 makes it an offence to disclose personal data you hold to people who are not authorised, even by accident. Article 107 sets a ten working day clock. But that is for answering a person's access or correction request, not for a breach. In the financial industry, Basic Circular 144 of 2017 requires banks to pass the Special Investigation Commission technical information about suspicious transfers. That includes the customer's internet address and internet provider. No reporting deadline is attached. The 48-hour clock sits in Basic Decision 13790 and applies to evidence of a freezing action. We could not confirm that Lebanon has a working national computer emergency team with a reporting duty. So a company suffering a breach in Lebanon has, unusually, nobody it is legally obliged to call.
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban Basic Circular 144 / Basic Decision 12725 of 28 November 2017 — Cybercrime Prevention
bdl.gov.lb
“Be vigilant and cautious when selecting contractors for tasks related to IT systems, and to make sure that these contractors do not in turn outsource these tasks to less reliable parties.”
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban Basic Decision 13790 of 9 January 2026 (Basic Circular 1) on Electronic Payment Services Providers — Article 27 Data Hosting Requirements
bdl.gov.lb
“The Institution must store in Lebanon all data and information pertaining to customers and executed operations (Local Data Hosting).”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Four things that catch people out. First, the money is meaningless but the prison is not. The top fine is 30 million Lebanese pounds, about 335 US dollars at the central bank's own rate. The same article allows up to three years in jail. It applies to people, not only to companies. Second, health, genetic and sexual-life data are banned outright unless you fit one of four narrow exceptions. Permission comes from the Minister of Public Health, and two months of silence counts as a refusal. Third, you cannot contract out of any of it. A clause in your terms and conditions that cuts across the data rules simply has no effect. Fourth, the central bank orders Lebanese banks to follow Europe's privacy rulebook and to appoint a representative in Europe. That has nothing to do with Lebanese law and is easy to miss.
- What you have to do here:
- Appoint a representative · Appoint a data protection officer · Delete data after a period · Independent audit
- What it costs if you get it wrong:
- Criminal liability
Article 106 sets a fine of 1 to 30 million Lebanese pounds and imprisonment of three months to three years, or either. It applies to working with data without a declaration or a prior licence. It applies to breaking the rules on collecting and using data. And it applies to disclosing personal data to unauthorised people, even by accident. Article 107 adds a fine of 1 to 15 million pounds. That one applies if you refuse an access or correction request, or answer it wrongly or incompletely within ten working days. Article 108 raises repeat penalties by between a third and a half. The Banque du Liban published a rate of 89,500 pounds to the dollar on 14 August 2026. At that rate, those ceilings are roughly 335 and 168 US dollars. Article 91 bans collecting or using data that reveals health status, genetic identity or sexual life. There are four exceptions. The person made it public or expressly agreed. It is needed for medical diagnosis or treatment by a health professional. It is needed to establish or defend a right in court. Or you hold a licence under Article 97. Article 85 says the chapter cannot be set aside. No agreement, contrary clause or one-sided undertaking can be used against it. Basic Circular 146 of 13 September 2018 covers banks, finance companies and other supervised institutions. It required them to take measures in line with the European General Data Protection Regulation. They had to appoint a data protection officer from the compliance unit, name a European representative, and notify their procedures by 31 December 2018. External auditors verify this every year. Two further snags. A foreign company must name a Lebanese representative on the declaration. And the retention period you write on that declaration becomes the legal maximum you may keep the data.
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban daily exchange rates — US dollar at 89,500 Lebanese pounds, 14 August 2026
bdl.gov.lb
Link checked 18 August 2026
- Official sourceBanque du LibanBanque du Liban Basic Circular 146 / Basic Decision 12872 of 13 September 2018 — General Data Protection Regulation (GDPR)
bdl.gov.lb
Link checked 18 August 2026
What's changing next
The near-term story is banking, not privacy law. The central bank rewrote its electronic banking rules on 9 January 2026. It gave firms six months to move customer and transaction data onto servers in Lebanon. That duty became enforceable on 9 July 2026, so the first supervisory action is the thing to watch. In telecoms, the regulator got a new board in September 2025 after years without one, and is issuing rules again. That puts a 2009 consumer regulation back within reach of being published. It carries real privacy and billing-record clauses. We found no bill before Parliament to create a privacy regulator, but we could not check Parliament's own site.
Unused powers worth watching. One: Article 94 lets the Council of Ministers exempt more categories from the filing duty. That takes a decree on the joint proposal of the Ministers of Justice and of Economy and Trade. That is a power to loosen, with no consultation. Two: Article 97 licensing sits with three sets of ministers. Each can set conditions on state security, criminal and health data by its own decision. Three: the central bank amended Basic Circular 69 twenty-seven times between 2003 and 2026, and rewrote Articles 1 to 25 wholesale in January 2026. So the financial data rules can change by a single decision of the Governor. Four: the telecoms regulator's board approved its Consumer Affairs Regulation on 19 June 2009. The regulator's own site still lists it among draft regulations. Under its own Article 83 it would take effect on publication in the Official Gazette. It gives subscribers privacy rights, bans disclosing calling patterns without advance written consent, and imposes a ten-year billing record duty. It could be published without further consultation.
Sources
- Official sourceBanque du LibanIntermediate Decision 13791 of 9 January 2026 — repeals and replaces Articles 1 to 25 of Basic Decision 7548, and gives six months to comply with Article 7
bdl.gov.lb
“تُمنَح المصارف والمؤسسات المالية مهلة /6/ أشهر للتقيّد بأحكام المادة /7/ من هذا القرار.”
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityDecree 1328 of September 2025 appointing the Chairwoman and members of the Telecommunications Regulatory Authority
tra.gov.lb
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityTRA Regulations page — the Consumer Affairs Regulation is listed under draft regulations
tra.gov.lb
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityTRA Consumer Affairs Regulation, approved by the TRA Board on 19 June 2009 — Articles 21 to 24 and 34
tra.gov.lb
“Service Providers may not disclose any Personal Information or calling patterns relating to a Consumer unless the Consumer's express and specific consent is given in advance and in writing.”
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries5 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Banking data needs a copy kept in the country
Official name: التعميم الأساسي رقم 69 - العمليات المالية والمصرفية بالوسائل الإلكترونية (Basic Circular 69 - Electronic Banking and Financial Operations) · Basic Decision 7548 of 30 March 2000, Articles 1 to 25 replaced by Intermediate Decision 13791 of 9 January 2026 · Regulator directive
This is the rule that forces data to stay in Lebanon. Banks and finance companies doing anything electronically must store all customer and transaction data in Lebanon. The whole circular was rewritten on 9 January 2026, and existing firms were given six months. So the duty has been enforceable since 9 July 2026. Customer data may not be shared with anyone except the financial regulators and the courts, unless the customer gives explicit written consent.
Enforced by Banque du Liban
How this country controls where data goes: Approval each time · Accepted routes: Explicit consent, Government sign-off needed
What you have to do
- Keep the data in the country — from 9 July 2026Article 7. The rule is written as a duty to store the data in Lebanon. It does not say in words that you cannot keep a further copy abroad. But Article 8 only lets you share the data with a non-regulator if the customer gives explicit written consent.
- Secure the dataArticle 8 requires the highest degree of security for customers' personal data.
- Written vendor contractContracts with suppliers must limit them to the original declared purpose. They must impose the same security standard. The institution stays answerable to the customer for misuse.
- Get consentThe customer must be told that a third party will handle their data, and must give explicit written consent.
- Register or notify — within 2160 hoursNinety days' prior written notice to the central bank before starting, promoting or changing any electronic operation; prior approval for electronic know-your-customer and electronic money.
What it costs if you get it wrong
- Loss of your licenceNon-compliance with the conditions of the decision, supervised by the Banking Control Commission of Lebanon
Sources
- Official sourceBanque du LibanBanque du Liban Basic Circular 69 / Basic Decision 7548, consolidated English text — Article 7 Data Hosting
bdl.gov.lb
“Banks and financial institutions conducting electronic banking and financial operations must store in Lebanon all data and information pertaining to customers and executed operations (Local Data Hosting).”
Link checked 18 August 2026
- Official sourceBanque du LibanIntermediate Decision 13791 of 9 January 2026 — repeals and replaces Articles 1 to 25 of Basic Decision 7548, and gives six months to comply with Article 7
bdl.gov.lb
“تُمنَح المصارف والمؤسسات المالية مهلة /6/ أشهر للتقيّد بأحكام المادة /7/ من هذا القرار.”
Link checked 18 August 2026
Payments data needs a copy kept in the country
Official name: القرار الأساسي رقم 13790 - مقدّمو خدمات الدفع بالوسائل الإلكترونية (Basic Decision 13790 - Electronic Payment Services Providers, Basic Circular 1) · Basic Decision 13790 of 9 January 2026, Articles 27, 30, 31 and 44 and Annex 3 · Regulator directive
This is the payments twin of the banking rule, issued the same day. Any licensed electronic payment services provider must store all customer and transaction data in Lebanon. It may not share that data with anyone other than the central bank, the banking supervisor, the financial intelligence unit and the courts. It cannot outsource risk, compliance or audit at all.
Enforced by Banque du Liban
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Explicit consent
What you have to do
- Keep the data in the country — from 9 July 2026Article 27. Firms already licensed under the old electronic banking decision were given six months from 9 January 2026.
- Register or notifyPrior approval from the Banque du Liban is required to be licensed as an electronic payment services provider.
- Secure the dataAnnex 3 requires utmost security and access on a need-to-know basis.
- Written vendor contractArticle 31 bans outsourcing risk management, compliance and internal audit. You may outsource information security and cyber risk work only with prior central bank approval. The Banking Control Commission must supervise it.
- Get consentExplicit written consent, limited to specific purposes, before any supplier handles customer personal data.
- Independent auditInternal audit unit or named internal auditor, plus periodic statements to the central bank.
What it costs if you get it wrong
- Loss of your licenceBreach of the licensing conditions; the decision also allows referral of an infringing institution to the competent judicial authority
Sources
- Official sourceBanque du LibanBanque du Liban Basic Decision 13790 of 9 January 2026 (Basic Circular 1) on Electronic Payment Services Providers — Article 27 Data Hosting Requirements
bdl.gov.lb
“The Institution must store in Lebanon all data and information pertaining to customers and executed operations (Local Data Hosting).”
Link checked 18 August 2026
- Official sourceBanque du LibanIntermediate Decision 13791 of 9 January 2026 — repeals and replaces Articles 1 to 25 of Basic Decision 7548, and gives six months to comply with Article 7
bdl.gov.lb
“تُمنَح المصارف والمؤسسات المالية مهلة /6/ أشهر للتقيّد بأحكام المادة /7/ من هذا القرار.”
Link checked 18 August 2026
Europe's main privacy law
Official name: التعميم الأساسي رقم 146 - النظام الأوروبي العام لحماية البيانات (Basic Circular 146 - General Data Protection Regulation) · Basic Decision 12872 of 13 September 2018 · Regulator directive
An oddity worth knowing about. Lebanon's central bank ordered every bank, finance company and other supervised institution to take measures in line with the European Union's General Data Protection Regulation. They must appoint a data protection officer from their compliance unit. They must name a representative in Europe. They had to report their procedures by the end of 2018. External auditors check it every year.
Enforced by Banque du Liban
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Appoint a data protection officer — from 31 December 2018Drawn from the institution's own compliance unit.
- Appoint a representative — from 31 December 2018A representative in the European Union, not in Lebanon.
- Put a transfer safeguard in placeBy importing the European rulebook, the European transfer conditions come with it.
- Independent auditExternal auditors must verify compliance and report annually.
Sources
- Official sourceBanque du LibanBanque du Liban Basic Circular 146 / Basic Decision 12872 of 13 September 2018 — General Data Protection Regulation (GDPR)
bdl.gov.lb
Link checked 18 August 2026
Banking rules
Official name: التعميم الأساسي رقم 144 - الوقاية من الجرائم الإلكترونية (Basic Circular 144 - Cybercrime Prevention) · Basic Decision 12725 of 28 November 2017 · Regulator directive
This is Lebanon's only cyber rulebook with real force, and it covers banks and finance companies only. It is about controls and checking your contractors, not about reporting incidents. There is no clock. The only reporting duty is to hand technical details of suspicious transfers to the financial intelligence unit. The compliance department runs it.
Enforced by Banque du Liban
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the data
- Written vendor contractInstitutions must be cautious in choosing information technology contractors and must ensure those contractors do not themselves sub-contract to less reliable parties.
- Report cyber incidentsNo hour or day deadline. The duty is to pass the financial intelligence unit technical information about suspicious transfer orders, including the customer's internet address and internet service provider.
Sources
- Official sourceBanque du LibanBanque du Liban Basic Circular 144 / Basic Decision 12725 of 28 November 2017 — Cybercrime Prevention
bdl.gov.lb
“Be vigilant and cautious when selecting contractors for tasks related to IT systems, and to make sure that these contractors do not in turn outsource these tasks to less reliable parties.”
Link checked 18 August 2026
Telecoms rules
Official name: Consumer Affairs Regulation · Approved by the TRA Board on 19 June 2009; Article 83 makes it effective on publication in the Official Gazette · Directly binding regulation
This is a trap for anyone reading the telecoms regulator's website. The regulation holds the only real telecoms privacy rules in Lebanon. No disclosure of calling patterns without advance written consent. Confidentiality of customer records. Ten-year billing records. But the regulator's own site still files it under draft regulations, seventeen years after its board approved it. Treat it as not binding, and as something publication in the Official Gazette could revive.
Enforced by Telecommunications Regulatory Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Let people see their dataNot in force. Consumers would have a right to privacy and to protection from unauthorised use of their records.
- Extra vendor secrecy termsNot in force. Service providers would have to keep customer information, usage information and network information confidential.
- Keep data for a minimum period — 10 yearsNot in force. Billing records would have to be kept for at least ten years.
Sources
- Official sourceTelecommunications Regulatory AuthorityTRA Consumer Affairs Regulation, approved by the TRA Board on 19 June 2009 — Articles 21 to 24 and 34
tra.gov.lb
“Service Providers may not disclose any Personal Information or calling patterns relating to a Consumer unless the Consumer's express and specific consent is given in advance and in writing.”
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory AuthorityTRA Regulations page — the Consumer Affairs Regulation is listed under draft regulations
tra.gov.lb
Link checked 18 August 2026
Applies to every company1 rule
These bind you whatever business you are in, once the country's rules reach you.
Health data rules
Official name: قانون رقم 81 تاريخ 2018/10/10 - المعاملات الإلكترونية والبيانات ذات الطابع الشخصي (Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data) · Law No. 81 of 10 October 2018, Part Five (Articles 85 to 109) · Act of parliament
This is Lebanon's only general personal data law. It asks you to file, not to be supervised. Tell the Ministry of Economy and Trade what you are doing. Keep the data only for the period you declared. Answer access requests in ten working days. It says nothing about sending data abroad, beyond asking you to disclose it. Health, genetic and sexual-life data are banned without a ministerial licence. Penalties are criminal, but the currency collapse has destroyed the cash ceilings.
Enforced by Ministry of Economy and Trade — not yet operational
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notifyA declaration must be filed with the Ministry of Economy and Trade against a receipt, unless one of the eight exemptions applies. Fourteen items are required, including retention period and any data to be sent abroad.
- Tell people what you doThe person must be told who is running the data and why it is collected. They must be told whether answering is compulsory, and what happens if they do not answer. They must also be told who will receive the data, and how to access and correct it.
- Get consentPrior consent is one of the routes out of the filing duty. It is also the only general route for health, genetic and sexual-life data outside medical care.
- Let people see their data — within 240 hoursTen working days to answer. Heirs may also exercise the right. A charge no higher than the cost of copying may be made.
- Let people correct their data — within 240 hours
- Let people objectIncludes objecting to use for commercial promotion, unless collection is required by law or the person consented.
- Limit automated decisionsNo court or government decision assessing a person's conduct may rest on an automated system alone.
- Secure the data
- Delete data after a periodOnly for the period stated in the declaration or in the licence decision.
- Appoint a representativeIf you live outside Lebanon you must name a representative and an address in the declaration and in the public register.
What it costs if you get it wrong
- Criminal liability: LBP 30,000,000 and 3 years' imprisonment — about $335Processing without a declaration or prior licence, breaking the collection and processing rules, or disclosing personal data to unauthorised persons even negligently
- Fixed maximum fine: LBP 15,000,000 — about $168Refusing, or answering wrongly or incompletely within ten working days, an access or correction request
Sources
- Official sourceBanque du Liban (official law library)Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data — official Arabic text
bdl.gov.lb
Link checked 18 August 2026
- Official sourceMinistry of Economy and TradeMinistry of Economy and Trade — Personal Data page, publishing the register required by Article 98 of Law 81/2018
economy.gov.lb
“عملا" بالمادة 98 من القانون 81/2018 – المعاملات الالكترونية والبيانات ذات الطابع الشخصي، تضع وزارة الاقتصاد والتجارة في متناول الجمهور للاطلاع عليها، لائحة بمعالجات البيانات الشخصية المقدمة اليها انفاذاً لأحكام القانون المذكور.”
Link checked 18 August 2026
- Official sourceMinistry of Economy and TradeMinistry of Economy and Trade — 'List of Personal Data Processing' (the Article 98 public register), one entry, file last modified 31 May 2023
economy.gov.lb
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact date Law 81/2018 came into force
Article 136 says the law applies three months after publication in the Official Gazette. We could not confirm the publication date in the Lebanese Official Gazette. So the 18 January 2019 start date recorded here is worked out, not confirmed.
That the Ministry of Economy and Trade has received only one declaration since 2019
We can show only that the published register holds one entry and was last modified on 31 May 2023. The ministry may hold filings it has never published. That would break its own duty to publish, but it is not the same as an empty register.
That nobody has ever been prosecuted under Articles 106 to 108
Lebanon has no public database of court decisions that we could reach. We can neither confirm nor rule out prosecutions. Assume a case is possible, even though we found none.
Whether the Telecommunications Regulatory Authority's Consumer Affairs Regulation was ever published in the Official Gazette
The authority's own regulations page lists it among draft regulations, which suggests it is not in force. We could not confirm this in the Official Gazette. We have marked it as proposed and flagged that it could be revived.
Health sector storage and confidentiality rules
We could not reach the Ministry of Public Health's website on 18 August 2026. We can show the Article 97 licensing requirement from the law itself. We cannot show any ministerial decision, circular or electronic health record policy. If you work in health, ask the ministry before you rely on this.
Insurance, securities, education, gaming, mapping, defence and government cloud rules
We found no rule on storing or sending data for any of these industries, but the evidence is weak. The Insurance Control Commission has no website of its own that we could reach. The Capital Markets Authority's regulations section showed nothing about data. The administrative reform office publishes no cloud or hosting policy. Treat this as no rule found, not as no rule.
Whether a comprehensive data protection bill or a bill creating a privacy regulator is before Parliament in 2026
We could not reach Parliament's website on 18 August 2026, so we could not confirm the pipeline from an official source. Check with Lebanese counsel if a new law would change your plans.
Which amendment first introduced the local data hosting duty for banks
Intermediate Decision 13791 of 9 January 2026 repealed and replaced Articles 1 to 25 of the basic decision. It also gave six months to comply with Article 7. So the current duty dates from then. We did not check all twenty-seven earlier amendments for an earlier version of the same duty.
Completeness of the sectoral sweep
Every finding here comes from official Lebanese websites we visited directly. A rule published on an official site we did not visit would have been missed. Treat the industry list as a floor, not a ceiling.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.