Law No. 12 of 2024 on Protection of Electronic Personal Data
Law No. 12 of 2024 (Syrian Arab Republic) arts. 1-2, 4-7, 9-10, 12, 27-30, 40, 45 (definitions, lawful processing, controller and processor obligations, licensing and scope)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 January 2025.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Determine a lawful basis under one of the grounds article 7 lists before processing personal data, such as the data subject's consent to a specific purpose, a contractual or legal obligation, or a court order.
- Obtain a license or permit from the Personal Data Protection Authority before collecting, storing, transferring or processing personal data, and appoint a local representative if you are established outside Syria.
- Collect personal data only for legitimate and specific purposes, process it in a manner appropriate to those purposes, and do not retain it longer than the purpose requires unless the retention is for archiving in the public interest or for scientific, historical or statistical purposes.
- Take the technical and organizational security measures the Authority approves to protect personal data against unauthorized or unlawful processing and against loss or damage, and appoint a data protection officer, registered with the Authority, if you are a legal person.
- Keep a register describing the categories of personal data you hold, who you disclose it to, the retention periods, and any cross border transfer, and make it available for the Authority's inspection.
- Erase personal data once the purpose for holding it lapses, unless a lawful reason permits retention, in which case keep it in a form that no longer identifies the data subject.
What it reaches
Obligation class
Consent, Governance, Security, Retention, Licensing
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Law No. 12 of 2024 on Protection of Electronic Personal Data regulates the electronic collection, processing, use and transfer of personal data in Syria. Article 46 enters the law into force from 1 January 2025, and it was signed by presidential decree in Damascus on 28 March 2024.
Article 1 defines sensitive personal data as data revealing psychological, mental, physical or genetic health, biometric data, financial data, religious belief, political opinion, criminal status, or a child's or an incapacitated person's data, a controller as whoever determines how data is retained and processed, and a processor as whoever processes data on the controller's behalf.
Article 4 requires personal data to be collected for legitimate and specific purposes, processed in a manner suited to those purposes, kept no longer than the purpose requires unless the retention serves public interest archiving or scientific, historical or statistical purposes, and secured against unauthorized or unlawful processing and against loss or damage.
Article 7 makes processing lawful only where the data subject consents to a specific purpose, the processing performs a contractual or legal obligation or pursues a legal claim, a court decision requires it, it lets the controller or processor meet an obligation without conflicting with the data subject's rights, it rests on accurate and updated data, it causes the data subject no direct or indirect harm, or it preserves the data's confidentiality and integrity.
Article 5 requires a controller to obtain the data subject's consent before collecting personal data, obtain a license or permit from the Authority to deal with it, take the Authority's approved technical and organizational security measures, appoint a local representative if established outside Syria, erase personal data once its purpose lapses, and keep a register of the categories held, the recipients, the retention periods and any cross border transfer.
Article 6 places the equivalent obligations on a processor, including a bar on engaging a sub-processor without the controller's prior consent. Articles 9 and 10 require a controller or processor that is a legal person to appoint a data protection officer, registered with the Authority and announced on its website, responsible for periodic assessment of the protection systems, coordinating with the Authority, enabling the data subject's rights, and reporting any breach to the Authority.
Articles 27 to 30 make a license, permit or accreditation from the Authority a precondition for collecting, storing, transferring or processing electronic personal data, and let the Authority amend or revoke one for breach of its conditions, non-payment of fees, an unauthorized transfer to another party, or the holder's bankruptcy.
Article 40 exempts processing by a natural person for purely personal activity not disclosed to others, official statistics, accurate media or scientific work that does not target a decision, an action or a rights violation, national security, public order or crime prevention, judicial records and proceedings, and disaster or epidemic data exchange between states or ministries, and bars retaining data once its processing purpose has lapsed unless another law states otherwise.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachprocesses_voiceprocesses_biometricshigh_risk_decisions
Read the law
archived copy
Read from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://moct.gov.sy/news-0171Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.