Law / Lebanon

Law No. 81/2018 on Electronic Transactions and Personal Data, Part V (Personal Data Protection)

Law No. 81 Official Gazette of Lebanon, promulgated 10 October 2018 (in force 31 March 2019), Arts. 85, 87, 90, 93 to 98 and 103 to 105 (Part V, Personal Data Protection), with the definitions in Article One and the provider retention duties in Arts. 72 and 74

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 31 March 2019.

A comprehensive regime rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • File a permit with the Ministry of Economy and Trade, issued against a receipt, before collecting or processing the personal data of a person in Lebanon, unless one of the exemptions in Article 94 covers the processing.
  • State in that permit the objectives of the processing, the personal data and its source, the categories of persons concerned, the third parties who may view the data, the retention period, your identity and address and those of your representative if you live outside Lebanon, the agency carrying out the processing, who exercises the right of access and how, any subcontractor, and the measures you take to keep the data intact.
  • Obtain a ministerial licence before processing personal data on the internal or external security of the State or on penal offences and judicial proceedings, and treat no answer within two months of the application as a refusal.
  • Collect personal data faithfully and for legitimate, specific and explicit purposes, keep it appropriate to and within those purposes, correct, complete and as relevant as possible, and do not later process it for purposes out of line with the objectives you stated, except for statistical, historical or scientific research.
  • Retain personal data only for the period stated in the declaration of processing or in the decision authorizing it.
  • Take all measures, in light of the nature of the data and the risks of processing it, to keep the data intact and secure and to protect it against distortion, damage and access by unauthorized persons.
  • Do not rely on a contract clause, an agreement or a unilateral undertaking that contravenes Part V: none of them may be invoked against the rights of the persons concerned or against your own obligations.
  • As a network service provider or data host, keep the traffic data of everyone using your service, the data that identifies them and the other technical data of their communications for three years from the service delivery date, keep it under professional secrecy, and produce it to the judicial police or the court when the competent judicial authority so decides.
  • As a data host, store for ten years the identification data of a non-professional who makes information available online to the public anonymously.
  • Expect the Ministry of Economy and Trade to publish your permit or licence, its date, the name and purpose of the processing, your identity and address, the categories of personal data processed and the third parties authorized to view them on a public list on its website.

What it reaches

Obligation class

Licensing, Security, Retention, Governance, Disclosure

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 85 applies Part V to all automatic and non-automatic processing of data of a personal nature, by public and private actors alike, exempting only processing related to the personal activities an individual carries out exclusively to fulfil their own needs, and it voids any agreement, contravening clause or unilateral undertaking that would contract out of the rights and obligations Part V sets.

Article One defines personal data as any information that helps to directly or indirectly identify a natural person, including by comparing or overlapping data collected from multiple sources, defines processing to reach collection, recording, organization, storage, adaptation, modification, extraction, reading, use, transmission, copying, dissemination, deletion and destruction alike, and puts the duties on the person who sets the processing objectives and methods, the role the act calls the personal data processor and Part V calls the personal data processing officer.

Article 87 requires personal data to be collected faithfully and for legitimate, specific and explicit purposes, to be appropriate, not to go beyond the stated objectives, to be correct, complete and as relevant as possible on a daily basis, and not to be processed later for purposes out of line with those objectives, save for statistical, historical or scientific research.

Article 90 limits retention to the period stated in the declaration of processing or in the decision authorizing it, and Article 93 requires the processing officer to take all measures, in light of the nature of the data and the risks of processing it, to keep the data intact and secure and to protect it against distortion, damage and access by unauthorized persons.

Article 94 lists the processing that needs no permit or licence at all, including book-keeping by non-profit organizations of their own members and clients, public registers kept under legal or regulatory provisions, pupil and student records held by educational institutions, the records of an institution's or company's own members, clients and customers within the needs of its lawful activity, and processing the person concerned agreed to in advance; Article 95 requires everyone else who wishes to collect and process personal data to inform the Ministry of Economy and Trade under a permit issued against a receipt, Article 96 fixes the fourteen items that permit must state, Article 97 subjects state-security, penal-offence and health, genetic-identity or sexual-life processing to a ministerial licence, and Article 98 requires the Ministry to publish the resulting permits and licences on a public list.

Articles 103 to 105 carve out the limits: a person is not to be informed of processing tied to the internal or external security of the State where informing them would endanger it, access to public, official and medical files stays governed by the rules that already govern those files, and Articles 99 to 101 do not reach processing carried out solely for literary or artistic expression or for the professional exercise of journalism.

Outside Part V, Article 72 requires an IT service provider to keep the traffic data of everyone using its service, the data that identifies them and other technical communications data for three years from the service delivery date, under professional secrecy and subject to judicial production orders, and Article 74 requires a data host to store for ten years the identification data of a non-professional who publishes to the public anonymously.

Article 136 makes the law effective three months after its publication in the Official Gazette, so these provisions bind today.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • provides_telecom_services

Read the law

official English translation of the Official Gazette text, hosted by SMEX

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app