What this law does
Law No. 12 of 2024 on Protection of Electronic Personal Data regulates the electronic collection, processing, use and transfer of personal data in Syria. Article 46 enters the law into force from 1 January 2025, and it was signed by presidential decree in Damascus on 28 March 2024.
Article 1 defines sensitive personal data as data revealing psychological, mental, physical or genetic health, biometric data, financial data, religious belief, political opinion, criminal status, or a child's or an incapacitated person's data, a controller as whoever determines how data is retained and processed, and a processor as whoever processes data on the controller's behalf.
Article 4 requires personal data to be collected for legitimate and specific purposes, processed in a manner suited to those purposes, kept no longer than the purpose requires unless the retention serves public interest archiving or scientific, historical or statistical purposes, and secured against unauthorized or unlawful processing and against loss or damage.
Article 7 makes processing lawful only where the data subject consents to a specific purpose, the processing performs a contractual or legal obligation or pursues a legal claim, a court decision requires it, it lets the controller or processor meet an obligation without conflicting with the data subject's rights, it rests on accurate and updated data, it causes the data subject no direct or indirect harm, or it preserves the data's confidentiality and integrity.
Article 5 requires a controller to obtain the data subject's consent before collecting personal data, obtain a license or permit from the Authority to deal with it, take the Authority's approved technical and organizational security measures, appoint a local representative if established outside Syria, erase personal data once its purpose lapses, and keep a register of the categories held, the recipients, the retention periods and any cross border transfer.
Article 6 places the equivalent obligations on a processor, including a bar on engaging a sub-processor without the controller's prior consent. Articles 9 and 10 require a controller or processor that is a legal person to appoint a data protection officer, registered with the Authority and announced on its website, responsible for periodic assessment of the protection systems, coordinating with the Authority, enabling the data subject's rights, and reporting any breach to the Authority.
Articles 27 to 30 make a license, permit or accreditation from the Authority a precondition for collecting, storing, transferring or processing electronic personal data, and let the Authority amend or revoke one for breach of its conditions, non-payment of fees, an unauthorized transfer to another party, or the holder's bankruptcy.
Article 40 exempts processing by a natural person for purely personal activity not disclosed to others, official statistics, accurate media or scientific work that does not target a decision, an action or a rights violation, national security, public order or crime prevention, judicial records and proceedings, and disaster or epidemic data exchange between states or ministries, and bars retaining data once its processing purpose has lapsed unless another law states otherwise.
What it requires