Law / Lebanon

Lebanon

8 of 10 named instruments researched to a stage, across four of the six areas of law we track: 8 in force. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 5
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law5 instruments, 5 in force

Research summary (372 words)

Lebanon has one comprehensive personal-data statute in force, Part V (Articles 85 to 109, "Personal Data Protection") of Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data, which Article 136 makes effective three months after its publication in the Official Gazette and which has bound since 31 March 2019.

Part V engages five of the privacy families: an omnibus permit and licensing regime with collection, retention and security duties (Articles 85 to 98), a special-category prohibition on health, genetic-identity and sexual-life data (Articles 91 and 97), a set of notice, objection, access and correction rights (Articles 86 to 89, 92 and 99 to 105), a transfer-disclosure duty (Articles 96 and 98), and penal provisions with an individual court remedy (Articles 102 and 106 to 109).

Two families the statute does not engage get no row: Part V states no breach-notification duty of any kind, to the Ministry or to the person, and it states no biometric rule, since the special-category list at Article 91 covers only health status, genetic identity and sexual life and the words biometric, voice, facial and face appear nowhere in the act.

The operative finding is a gap between a law that binds on paper and one nobody administers: Law 81/2018 never established an independent supervisory authority, the Ministry of Economy and Trade holds the interim licensing role, and roughly six years after enactment the Ministry has not issued the implementing decrees that would make the licensing and registration regime actually work, so enforcement is concentrated in a single executive ministry with no independent oversight of it.

The cross-border provisions at Articles 96(12) and 98(8) only require a permit applicant to disclose an intended transfer and the Ministry's public registry to record it, a disclosure duty rather than a substantive transfer restriction, so Lebanon places no adequacy, consent or localization condition on moving personal data out of the country.

Article 102 gives a data owner a real, court-enforceable path to compel access and correction through the Magistrate of Summary Justice, but this is procedural, not a general private right to sue for damages; Part V's penal provisions, fines of up to thirty million Lebanese Pounds and imprisonment of up to three years, are state-prosecuted.

Comprehensive regime

Law No. 81/2018 on Electronic Transactions and Personal Data, Part V (Personal Data Protection)

Law No. 81 Official Gazette of Lebanon, promulgated 10 October 2018 (in force 31 March 2019), Arts. 85, 87, 90, 93 to 98 and 103 to 105 (Part V, Personal Data Protection), with the definitions in Article One and the provider retention duties in Arts. 72 and 74official English translation of the Official Gazette text, hosted by SMEX

In force since 31 March 2019. Binds public and private bodies.

What this law does

Article 85 applies Part V to all automatic and non-automatic processing of data of a personal nature, by public and private actors alike, exempting only processing related to the personal activities an individual carries out exclusively to fulfil their own needs, and it voids any agreement, contravening clause or unilateral undertaking that would contract out of the rights and obligations Part V sets.

Article One defines personal data as any information that helps to directly or indirectly identify a natural person, including by comparing or overlapping data collected from multiple sources, defines processing to reach collection, recording, organization, storage, adaptation, modification, extraction, reading, use, transmission, copying, dissemination, deletion and destruction alike, and puts the duties on the person who sets the processing objectives and methods, the role the act calls the personal data processor and Part V calls the personal data processing officer.

Article 87 requires personal data to be collected faithfully and for legitimate, specific and explicit purposes, to be appropriate, not to go beyond the stated objectives, to be correct, complete and as relevant as possible on a daily basis, and not to be processed later for purposes out of line with those objectives, save for statistical, historical or scientific research.

Article 90 limits retention to the period stated in the declaration of processing or in the decision authorizing it, and Article 93 requires the processing officer to take all measures, in light of the nature of the data and the risks of processing it, to keep the data intact and secure and to protect it against distortion, damage and access by unauthorized persons.

Article 94 lists the processing that needs no permit or licence at all, including book-keeping by non-profit organizations of their own members and clients, public registers kept under legal or regulatory provisions, pupil and student records held by educational institutions, the records of an institution's or company's own members, clients and customers within the needs of its lawful activity, and processing the person concerned agreed to in advance; Article 95 requires everyone else who wishes to collect and process personal data to inform the Ministry of Economy and Trade under a permit issued against a receipt, Article 96 fixes the fourteen items that permit must state, Article 97 subjects state-security, penal-offence and health, genetic-identity or sexual-life processing to a ministerial licence, and Article 98 requires the Ministry to publish the resulting permits and licences on a public list.

Articles 103 to 105 carve out the limits: a person is not to be informed of processing tied to the internal or external security of the State where informing them would endanger it, access to public, official and medical files stays governed by the rules that already govern those files, and Articles 99 to 101 do not reach processing carried out solely for literary or artistic expression or for the professional exercise of journalism.

Outside Part V, Article 72 requires an IT service provider to keep the traffic data of everyone using its service, the data that identifies them and other technical communications data for three years from the service delivery date, under professional secrecy and subject to judicial production orders, and Article 74 requires a data host to store for ten years the identification data of a non-professional who publishes to the public anonymously.

Article 136 makes the law effective three months after its publication in the Official Gazette, so these provisions bind today.

What it requires

Cross border transfer

Law No. 81/2018, Part V, transfer of personal data to another State

Law No. 81/2018, Arts. 96(12) and 98(8) (transfer of personal data to another State)official English translation of the Official Gazette text, hosted by SMEX

In force since 31 March 2019. Binds public and private bodies.

What this law does

Article 96(12) requires the permit filed with the Ministry of Economy and Trade to state, where appropriate, the transfer of personal data to another State in any form, and Article 98(8) requires the public list the Ministry publishes of authorized and licensed processing to record, for each entry, the personal data intended for transfer to a foreign State. Those two items are the whole of Lebanon's cross-border regime.

Neither conditions the transfer on the destination's level of protection, on an adequacy finding, on standard contractual clauses, on binding corporate rules, on the person's consent or on the Ministry's prior approval, and Part V nowhere requires personal data collected in Lebanon to be stored on a server or in a data centre in Lebanon, so the duty is to declare the transfer and keep the declaration accurate, not to justify it.

The declaration is still load-bearing, because processing without a permit, or outside the terms of the one filed, is an offence under Article 106 carrying a fine of one million to thirty million Lebanese Pounds and imprisonment of three months to three years. Article 136 makes the law effective three months after its publication in the Official Gazette, so these provisions bind today.

What it requires

Data subject rights

Law No. 81/2018, Part V, notice, objection, access and correction

Law No. 81/2018, Arts. 86, 88, 89, 92, 99 to 101, 103, 105 and 32 (notice, objection, access and correction)official English translation of the Official Gazette text, hosted by SMEX

In force since 31 March 2019. Binds public and private bodies.

What this law does

Article 88 requires the processing officer or their representative to tell the people the data is taken from who the officer or representative is, what the processing is for, whether answering the questions is mandatory or optional, what follows from not answering, who the data will be sent to, and that they may access and correct it, and requires the collection form itself to carry that statement explicitly and clearly.

Article 89 extends the duty to data not collected from the person concerned, who must be told personally and explicitly what the data contains, what the processing is for and that they may object to it, unless they already know or telling them is impossible or would take an effort out of proportion to the benefit.

Article 92 gives every natural person the right to object, for legitimate reasons, to the collection and processing of their personal data, including collection and processing for the purpose of commercial promotion, except where the law obliges the officer to collect it or the person has agreed to the processing.

Article 86 gives everyone the right to review and object, before the processing officer, to the information and analyses used in automated processing relied on about them, and bars any judicial or administrative decision requiring an assessment of human behavior from resting solely on automated processing aimed at identifying a person's qualities or assessing aspects of their personality.

Articles 99 to 101 carry the access and correction rights: the owner of the data or any of their heirs may ask whether their data is being processed and receive a copy of it, in an understandable form where it is encoded, compressed or encrypted, together with the purposes, categories, source, subject and nature of the processing and the identity of everyone the data is sent to or who can access it and when; the officer may charge no more than the cost of copying and may refuse only requests of an arbitrary, repetitive or systematic nature, carrying the burden of proving that character; and the officer must correct, complete, update or erase data that is incorrect, incomplete, ambiguous, expired or incompatible with the purposes of processing, free of charge and within ten days of the request, prove the work was done, notify any third party the data was sent to, and make the same correction on their own initiative once they learn of a reason for it.

Article 103 withholds that information where the processing relates to the internal or external security of the State and informing the person would endanger it, and Article 105 lifts Articles 99 to 101 from processing carried out solely for literary or artistic expression or for the professional exercise of journalism.

Article 32, in the electronic-commerce part of the same law, requires an online promotional advertisement to say that it is one and to name the person it was placed for, forbids unsolicited marketing email to a real person's name and address without that person's consent unless the address was lawfully obtained through a previous engagement with them, and requires every marketing email to carry a reply address through which the recipient can stop receiving them permanently and free of charge.

Article 136 makes the law effective three months after its publication in the Official Gazette, so these provisions bind today.

What it requires

Enforcement supervision

Law No. 81/2018, Part V, penal provisions and supervision

Law No. 81/2018 Arts. 102 and 106 to 109 (penal provisions and the court remedy), with the Ministry of Economy and Trade's role under Arts. 95 to 98official English translation of the Official Gazette text, hosted by SMEX

In force since 31 March 2019. Binds public and private bodies.

What this law does

Article 106 punishes three things with a fine of one million to thirty million Lebanese Pounds and imprisonment of three months to three years, or with one of those two penalties: processing personal data without filing a permit or obtaining a prior licence before starting work, collecting or processing personal data outside the rules of Section II, and disclosing personal data under processing to unauthorized persons, even negligently.

Article 107 punishes a processing officer who refuses to answer a person's access or correction request within ten working days, or answers it incorrectly or imperfectly, with a fine of one million to fifteen million Lebanese Pounds.

Article 108 raises the penalties and fines by one third to one half where the act recurs, and Article 109 makes prosecution for the disclosure offence and for the refusal offence turn on a complaint by the injured party, the general right lapsing with the personal right where the waiver comes before the judgment becomes final.

Article 102 gives the owner of the personal data, or any of their heirs, access to the competent courts and in particular to the Magistrate of Summary Justice to enforce the right of access and correction, which is a procedural remedy rather than a general claim for damages.

Supervision itself is administrative and not independent: Law 81/2018 creates no data protection authority, and the permit function sits with the Ministry of Economy and Trade under Article 95, the licence function with the Minister of National Defence and the Minister of Interior and Municipalities, the Minister of Justice and the Minister of Public Health under Article 97, and the public register of permits and licences with the Ministry under Article 98.

Article 136 makes the law effective three months after its publication in the Official Gazette, so these provisions bind today.

What it requires

Sensitive categories

Law No. 81/2018, Part V, health, genetic identity and sexual-life data

Law No. 81/2018, Arts. 91 and 97(3) (health, genetic identity and sexual-life data)official English translation of the Official Gazette text, hosted by SMEX

In force since 31 March 2019. Binds public and private bodies.

What this law does

Article 91 prohibits collecting or processing any data that reveals, directly or indirectly, the health status, genetic identity or sexual life of the person concerned, and admits four exceptions and no others: the person made the data public or explicitly agreed to its processing and no legal impediment stands in the way; the collection or processing is necessary to establish a medical diagnosis or to provide medical treatment by a healthcare professional; a right is being proved or defended before a court; or a licence has been obtained under Article 97.

Article 97(3) is that licence, issued for cases of health, genetic identity or sexual life of persons by a decision of the Minister of Public Health, and Article 97 gives the Minister two months from the application, after which the licence is deemed implicitly denied.

That list is the whole of Lebanon's special-category law: it names no biometric data, no racial or ethnic origin, no political opinion, no religious belief and no trade union membership, and the act contains no rule at all about a child's personal data, so a voiceprint, a faceprint or a minor's data is governed by the ordinary permit regime of Articles 94 to 96 rather than by a heightened standard.

Article 136 makes the law effective three months after its publication in the Official Gazette, so these provisions bind today.

What it requires

Scraping law1 instrument, 1 in force

Research summary (315 words)

Lebanon has no scraping-specific statute, so general law governs each dimension separately.

Law No. 81/2018 on Electronic Transactions and Personal Data criminalizes fraudulently accessing, entering, or remaining in an information system without authorization, alongside compromising system or data integrity and hindering access to a service through the information network; because each offense turns on fraudulent, unauthorized interference with a system, a person who reads a public, unauthenticated page without defeating any access control falls outside a plain reading of these provisions, and no reported Lebanese case has tested the point.

No Lebanese court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

Law No. 75/1999 on the Protection of Literary and Artistic Property permits the media, without the author's authorization or compensation, to use short excerpts of a work displayed or heard during current events in the course of reporting those events, and separately permits reproducing newspaper and magazine articles, or short excerpts of a work, for educational purposes within necessary limits, but Lebanon has not enacted a text-and-data-mining exception, and the same statute excludes recording or transmitting compilations of data from its general personal-use exemption.

Lebanon's copyright statute protects a compilation of data as a derivative work only where its selection or arrangement is an intellectual creation authorized by the rights holder, which is a compilation-copyright standard rather than a sui generis database right of the kind the European Union's Database Directive creates.

Law No. 81/2018's own personal-data provisions apply to any automatic or non-automatic processing of personal data with no exemption for data that is publicly available, so scraping personal data from a public Lebanese website remains subject to the same permit, notice, and purpose-limitation duties as any other collection.

No Lebanese statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Law No. 81/2018 on Electronic Transactions and Personal Data, Illegal Access to an Information System and Related IT-System Offences

Law No. 81 Official Gazette of Lebanon, Part VI Chapter I (Crimes Related to IT Systems and Data, Arts. 110-115), promulgated 10 October 2018official English translation of the Official Gazette text, hosted by SMEX

In force. Binds public and private bodies.

What this law does

Article 110 penalizes fraudulently accessing, entering, or staying in an information system, or a part of it, with imprisonment from three months to two years and a fine of one to twenty million Lebanese pounds, rising to six months to three years and two to forty million pounds where the access cancels, reproduces, or amends digital data or software, or jeopardizes the system's operation.

Article 111 penalizes fraudulently damaging or hindering an information system's operation; Article 112 penalizes fraudulently entering, deleting, or modifying digital data hosted by a system; Article 113 penalizes intentionally hindering, disturbing, or disrupting access to a service, hardware, software, or data source through the information network; Article 114 penalizes importing, producing, or distributing hardware, software, or data intended to commit any of these offenses; and Article 115 extends the same penalties to an attempt.

Because each offense turns on fraudulent, unauthorized interference with a system, a person who reads a public, unauthenticated page without defeating any access control falls outside a plain reading of the chapter. The whole statute took effect three months after its publication in the Official Gazette, but no commencement date distinct from its 2018 enactment year has been located.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (280 words)

Lebanon's private-sector cybersecurity duties sit almost entirely inside one banking-sector regulation, Banque du Liban's Basic Circular No. 144 (Basic Decision No. 12725 of 28 November 2017), which requires every bank and financial institution to adopt a defined slate of cybersecurity policies and technical safeguards and to notify Lebanon's Special Investigation Commission when a customer falls victim to financially-natured electronic crime.

Lebanon's Telecommunications Regulatory Authority (TRA) has adopted no comparable regime for licensed telecom operators: the regulator's own published page on cybersecurity states plainly that Lebanon has not yet established legislation related to cybersecurity, that no government entity exists to handle cybersecurity issues, and that industry should merely give a higher priority to security measures, a call for voluntary action rather than a legal duty, and the same wording still stood in the most recent reachable capture of that page.

Law No. 81/2018 on Electronic Transactions and Personal Data requires a personal-data processing officer to take measures ensuring the integrity and security of the data it processes, but that duty runs specifically to personal data and is recorded under Lebanon's privacy topic rather than here, consistent with this corpus's seam rule.

The same statute lets an electronic authentication service provider apply for a voluntary accreditation from the Lebanese Accreditation Council covering the security of its protection measures, but the statute expressly exempts the provision of authentication services from any pre-licensing requirement, so accreditation carries no legal force beyond the accredited certificate itself and no Lebanese statute conditions market entry or continued operation of a connected device or software product on meeting a security standard.

No Lebanese statute establishes a general, sector-neutral information-security baseline duty binding every information-system operator regardless of sector.

Sector security regimes

Banque du Liban Basic Circular No. 144 (Prevention of Electronic Criminal Acts)

Banque du Liban Basic Decision No. 12725 of 28 November 2017 (Basic Circular No. 144 to Banks, also addressed to Financial Institutions) Prevention of Electronic Criminal Acts, Arts. 1-6Official Arabic-language PDF of Banque du Liban Basic Decision No. 12725, served from BDL's own circular-download endpoint

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived August 15, 2022. Publisher's page: http://www.bdl.gov.lb/circulars/download/651/ar

In force since 28 November 2017. Binds private bodies.

What this law does

Banque du Liban (BDL), Lebanon's central bank, issued Basic Decision No. 12725 dated 28 November 2017 on the prevention of electronic criminal acts. BDL published the Decision as Basic Circular No. 144 to banks, also addressed to financial institutions. The Decision took effect immediately upon its issuance.

Article One requires every bank and financial institution to prepare policies and take preventive measures and procedures against crimes committed by electronic means, covering at minimum a defined list of general policies and technical measures.

Those general policies include analyzing potential cybercrime risk and continuously following developments in information-security technology, budgeting for an information-technology security policy, arranging insurance against electronic-crime risk, maintaining a continuously updated incident-response and business-continuity plan, forming a dedicated prevention team, sharing threat information with relevant parties inside and outside the institution, training employees and customers, monitoring employees with privileged system access, and vetting any external party entrusted with tasks touching the institution's electronic systems.

The required technical measures include adopting a technology that relies on at least two factors to verify the identity of a user accessing the system from outside the bank or financial institution, fully encrypting highly sensitive data, strictly filtering inbound email, verifying the security of any device an employee uses outside the institution, monitoring network traffic for unusual behavior, and verifying data integrity to detect and trace unlawful tampering.

They also include penetration testing to detect any potential vulnerability in the network. Upon learning that a customer has fallen victim to a financially-natured electronic crime, the bank or financial institution must notify Lebanon's Special Investigation Commission of technical information related to the incident. A dedicated Compliance Department established at each bank and financial institution implements the Decision.

The Decision sets no fixed fine or criminal penalty of its own, and Banque du Liban's own circular index shows no later Basic or Intermediate Circular amending or superseding it through the most recent reachable listing.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (307 words)

Lebanon has no mandatory platform-to-publisher bargaining code; the general copyright framework of Law No. 75/1999 on the Protection of Literary and Artistic Property is the primary law reaching an aggregator's reproduction of news content.

Its current-events exception permits the media, without the author's authorization or compensation, to use short excerpts of a work displayed or heard during current events in the course of reporting those events, provided the author and the source are named, and a narrower exception separately permits reproducing newspaper and magazine articles, or short excerpts of a work, for educational purposes within necessary limits.

Neither provision carries a headline-length or short-extract cap distinct from these purpose-bound tests, and no reported Lebanese decision applies either to a systematic news aggregator rather than a broadcaster or educator excerpting a published work.

Chapter VII of the statute names publishing houses, alongside performers, sound-recording producers, and broadcasting organizations, as related-rights holders with a fifty-year term running from first publication, but the statute's own text does not set out a specific exclusive right for a publishing house distinct from the rights it spells out for performers, producers, and broadcasters, so whether this reaches an aggregator's use of a publisher's content the way the European Union's Digital Single Market Directive Article 15 does is not established here.

No statute or case law addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law exists.

Law No. 75/1999 predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists; the statute instead protects a compilation of data as a derivative work only where its selection or arrangement is an intellectual creation authorized by the rights holder, a compilation-copyright standard rather than a sui generis database right.

Snippet reproduction

Law No. 75/1999 on the Protection of Literary and Artistic Property, Current-Events Reporting Exception

Law No. 75 of 3 April 1999 on the Protection of Literary and Artistic Property, art. 30 (Current-Events Reporting Exception)Law No. 75/1999 on the Protection of Literary and Artistic Property, official text hosted by the Lebanese Ministry of Economy and Trade

In force. Binds private bodies.

What this law does

Article 30 permits the media, without the author's authorization and without obligation to pay compensation, to use short excerpts of works that are displayed or heard during current events in the course of reporting those events, provided the name of the author and the source are mentioned.

A separate exception at article 26 permits copying or reproducing articles published in newspapers and magazines, or short excerpts of a work, without authorization or compensation, solely for educational purposes and within the necessary limits of that purpose, with the author's and publisher's names credited on each use.

Neither exception carries a headline-length or short-extract cap distinct from its own purpose-bound test, and no reported Lebanese decision applies either to a systematic news aggregator rather than a broadcaster reporting an event or an educator excerpting a published work. The statute took effect two months after its publication in the Official Gazette, but no commencement date distinct from its 1999 enactment date has been located.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.