Law / Iran

Electronic Commerce Law (2003), Personal Data Chapter

Electronic Commerce Law, approved by the Islamic Consultative Assembly, 2003, Arts. 58-61 (personal-data chapter)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 January 2004.

A sensitive categories rule binding private bodies.

As of 29 August 2026.

What it requires

  • An app that stores, processes, or distributes data revealing a Iranian resident's tribal or ethnic origin, religious or moral belief, ethical characteristics, or physical, psychological, or sexual condition needs their explicit consent first. Any other collection or processing of personal data needs consent for a specified, described purpose, must be limited to that purpose, must stay accurate, and must let the person access their own data with a right to have it corrected or completely removed. The law names no biometric category, so a voiceprint or faceprint is not subject to a heightened consent, retention, or destruction standard beyond the general consent-based rule, and nothing in this chapter conditions moving personal data out of Iran or requires notifying anyone after a security incident. Violating Article 58's sensitive-data consent rule is a criminal offense (one to three years' imprisonment), state-prosecuted rather than privately actionable.

If you get it wrong

Private right of actionNo

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 58 requires explicit consent before storing, processing, or distributing data revealing tribal or ethnic origin, religious or moral belief, ethical characteristics, or physical, psychological, or sexual condition; this is Iran's complete sensitive-category list and it names no biometric category.

Article 59 sets a general consent-based processing standard (specified purpose, data minimization, accuracy) and gives the data subject access to their own files with a right to correct or completely remove them. Article 60 defers medical and health-record data to separate, unlocated regulations, and Article 61 defers exceptions and "supervision and control" to other chapters without spelling out a dedicated regulator.

Enforcement is criminal only, one to three years' imprisonment under Article 71 (enhanced for institutional offenders under Article 72), with no described administrative penalty scheme and no private right of action found. No cross-border-transfer provision and no breach-notification duty were found anywhere in the chapter.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web
  • trains_models

Read the law

Electronic Commerce Law official text hosted by WIPO Lex, a UN-agency legal database republishing verbatim government-supplied texts

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app