Law / Syria

Syria

10 of 13 named instruments researched to a stage, across four of the six areas of law we track: 10 in force. As of 20 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law none researched
  5. Age gating law 1
  6. News aggregation law 2

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (371 words)

Syria's comprehensive personal-data statute is Law No. 12 of 2024 on Protection of Electronic Personal Data, signed by presidential decree in Damascus on 28 March 2024 and in force under its own article 46 from 1 January 2025.

It applies to a controller or processor, natural or legal, that determines or carries out the electronic collection, processing, use or transfer of personal data, reaching public and private bodies alike subject to article 40's exemptions for personal or household activity, official statistics, accurate media or scientific work, national security, public order, crime prevention, judicial records, and disaster or epidemic data exchange between states.

The law creates a Personal Data Protection Authority to license controllers and processors, receive complaints, and enforce the statute, gives a data subject rights of access, correction, deletion, objection and complaint, restricts sensitive personal data including biometric identifiers and a child's data to licensed, consented processing, conditions any cross-border transfer on the Authority's license, requires a breach to be reported to the Authority within seventy two hours of a controller or processor becoming aware of it and to the affected person within three working days of that notification, and backs its duties with administrative fines up to 15,000,000 Syrian Pounds and criminal penalties reaching imprisonment of three to seven years and a fine of up to 20,000,000 Syrian Pounds for an unlawful cross-border transfer.

On status: the Assad government that issued the law fell on 8 December 2024 and a transitional government took office on 29 March 2025; no source found confirms whether the Personal Data Protection Authority the law creates has actually been constituted and staffed, or whether the transitional administration is administering or enforcing the law today, and the law itself has not been repealed.

The transitional authorities are actively reshaping the surrounding legal and digital-governance landscape, including a July 2026 Ministry of Information public consultation on a new media law, a 7 January 2025 directive restricting government and NGO digital data collection to the Ministry of Communications and Information Technology's own platforms, and independent security research finding government data-collection portals hosted on unencrypted foreign servers, so this jurisdiction is recorded as fast-moving rather than settled even though the text of Law 12/2024 itself has not changed.

Breach notification

Law No. 12 of 2024 on Protection of Electronic Personal Data, personal data breach notification

Law No. 12 of 2024, art. 8 (personal data breach notification)Law No. 12 of 2024, full Arabic text as posted by the Syrian Ministry of Communications and Technology, read from an archived capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://moct.gov.sy/news-0171

In force since 1 January 2025. Binds public and private bodies.

What this law does

Article 8 requires a controller or processor, on becoming aware of a breach of the personal data in its possession, to notify the Authority immediately, and where the breach concerns national security matters, the Authority must immediately notify the competent authorities of the incident.

Article 8(b) requires the controller or processor to provide the Authority, within seventy two hours of becoming aware of the breach, with a description of its nature, form and causes, the approximate number of records, persons and categories affected, the data protection officer's details, the breach's likely effects, the measures taken or proposed to address it, documentation of the breach and the corrective steps taken, and any further document, information or data the Authority requests.

Article 8(c) requires the controller and processor to tell the data subject, within three working days of the date the Authority was notified, what measures have been taken.

What it requires

Comprehensive regime

Law No. 12 of 2024 on Protection of Electronic Personal Data

Law No. 12 of 2024 (Syrian Arab Republic) arts. 1-2, 4-7, 9-10, 12, 27-30, 40, 45 (definitions, lawful processing, controller and processor obligations, licensing and scope)Law No. 12 of 2024, full Arabic text as posted by the Syrian Ministry of Communications and Technology, read from an archived capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://moct.gov.sy/news-0171

In force since 1 January 2025. Binds public and private bodies.

What this law does

Law No. 12 of 2024 on Protection of Electronic Personal Data regulates the electronic collection, processing, use and transfer of personal data in Syria. Article 46 enters the law into force from 1 January 2025, and it was signed by presidential decree in Damascus on 28 March 2024.

Article 1 defines sensitive personal data as data revealing psychological, mental, physical or genetic health, biometric data, financial data, religious belief, political opinion, criminal status, or a child's or an incapacitated person's data, a controller as whoever determines how data is retained and processed, and a processor as whoever processes data on the controller's behalf.

Article 4 requires personal data to be collected for legitimate and specific purposes, processed in a manner suited to those purposes, kept no longer than the purpose requires unless the retention serves public interest archiving or scientific, historical or statistical purposes, and secured against unauthorized or unlawful processing and against loss or damage.

Article 7 makes processing lawful only where the data subject consents to a specific purpose, the processing performs a contractual or legal obligation or pursues a legal claim, a court decision requires it, it lets the controller or processor meet an obligation without conflicting with the data subject's rights, it rests on accurate and updated data, it causes the data subject no direct or indirect harm, or it preserves the data's confidentiality and integrity.

Article 5 requires a controller to obtain the data subject's consent before collecting personal data, obtain a license or permit from the Authority to deal with it, take the Authority's approved technical and organizational security measures, appoint a local representative if established outside Syria, erase personal data once its purpose lapses, and keep a register of the categories held, the recipients, the retention periods and any cross border transfer.

Article 6 places the equivalent obligations on a processor, including a bar on engaging a sub-processor without the controller's prior consent. Articles 9 and 10 require a controller or processor that is a legal person to appoint a data protection officer, registered with the Authority and announced on its website, responsible for periodic assessment of the protection systems, coordinating with the Authority, enabling the data subject's rights, and reporting any breach to the Authority.

Articles 27 to 30 make a license, permit or accreditation from the Authority a precondition for collecting, storing, transferring or processing electronic personal data, and let the Authority amend or revoke one for breach of its conditions, non-payment of fees, an unauthorized transfer to another party, or the holder's bankruptcy.

Article 40 exempts processing by a natural person for purely personal activity not disclosed to others, official statistics, accurate media or scientific work that does not target a decision, an action or a rights violation, national security, public order or crime prevention, judicial records and proceedings, and disaster or epidemic data exchange between states or ministries, and bars retaining data once its processing purpose has lapsed unless another law states otherwise.

What it requires

Cross border transfer

Law No. 12 of 2024 on Protection of Electronic Personal Data, cross border transfer

Law No. 12 of 2024, arts. 15-16 (cross-border transfer of personal data)Law No. 12 of 2024, full Arabic text as posted by the Syrian Ministry of Communications and Technology, read from an archived capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://moct.gov.sy/news-0171

In force since 1 January 2025. Binds public and private bodies.

What this law does

Article 15(a) prohibits transferring, preparing to process, storing or sharing personal data with an Arab or foreign state unless the Authority has verified an acceptable level of protection there and licensed the transfer.

Article 15(b) lets a transfer proceed with the data subject's or their representative's explicit consent, even to a state lacking that verified protection level, only to preserve the data subject's life or provide medical care, to establish or defend a legal right before a competent judicial body, to conclude or perform a contract for the data subject's benefit, to carry out a judicial cooperation procedure, to meet a legal obligation protecting the public interest, or to perform a bilateral or multilateral international agreement Syria has joined.

Article 16 lets a controller or processor make personal data available to another controller or processor outside Syria, with the Authority's license, only where the nature of their work or the purpose for which they hold the data agree, both sides have a legitimate interest in the data, and the foreign controller's or processor's legal and technical protection is not below the level the law's executive instructions set.

What it requires

Data subject rights

Law No. 12 of 2024 on Protection of Electronic Personal Data, rights of data subjects and electronic marketing

Law No. 12 of 2024, arts. 3, 11, 17-18, 33 (rights, requests and electronic marketing)Law No. 12 of 2024, full Arabic text as posted by the Syrian Ministry of Communications and Technology, read from an archived capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://moct.gov.sy/news-0171

In force since 1 January 2025. Binds public and private bodies.

What this law does

Article 3(a) bars processing, disclosing or divulging personal data without the data subject's explicit consent or a case the law authorizes.

Article 3(b) gives the data subject the right to know the nature, purpose and method of any processing of their personal data, to access or obtain their personal data held by a controller or processor, to learn the retention period or the criteria used to set it, to withdraw a prior consent without retroactive effect, to correct, amend, delete, add to or update their personal data, to confine processing to a defined purpose or scope, to be told of any breach of their personal data, to object to processing or its results where it violates their constitutional rights and freedoms, and to file a complaint with the Authority.

Article 11 requires a controller or processor to decide a request to make personal data available within five working days of registering it, verifying the legal justification the requester attaches, and to give reasons for any refusal. Article 33 requires whoever receives a request from a data subject to exercise a right under the law to respond within seven working days of its submission.

Article 17 bars a sender from making electronic contact with a data subject for marketing without the data subject's consent, an identified originator and sender, a correct and sufficient return address, a statement that the contact is for direct marketing, and a clear and easy mechanism for the data subject to refuse the contact or withdraw consent to it.

Article 18 requires a marketing sender to keep to the stated marketing purpose, not disclose the data subject's contact data, and retain electronic records of the data subject's consent, its amendments, or their non-objection to continued marketing contact for three years from the last message sent.

What it requires

Enforcement supervision

Law No. 12 of 2024 on Protection of Electronic Personal Data, Authority, complaints and penalties

Law No. 12 of 2024, arts. 19-26, 31, 34-39, 43 (Authority, complaints, fines and offences)Law No. 12 of 2024, full Arabic text as posted by the Syrian Ministry of Communications and Technology, read from an archived capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://moct.gov.sy/news-0171

In force since 1 January 2025. Binds public and private bodies.

What this law does

Article 19 establishes the Personal Data Protection Authority as a public body with legal personality and financial and administrative independence, seated in Damascus and linked to the Minister of Communications and Technology, with the power to set data protection policy, license and inspect controllers and processors, receive complaints and notifications, verify cross-border data movement, and issue an annual report on personal data protection in Syria.

Articles 20 to 26 place the Authority under a Board of Directors chaired by the Minister and a Director General, both appointed by decree, bar Board members and staff from disclosing any document or data from a case under the Authority's review, and let the Authority cooperate with foreign counterparts to verify a controller's or processor's compliance abroad.

Article 31 lets the Director General, on any violation of the law other than a licensing violation under article 30, order the violator to stop and remove its cause, and lets the Board, if that order is not obeyed, warn of, partially or wholly suspend, or partially or wholly revoke the violator's license, permit or accreditation, publish the violation in the media at the violator's expense, or place the violator under the Authority's technical supervision.

Article 34 gives a data subject the right to complain to the Authority over an infringement of their personal data rights, a refusal to let them exercise those rights, or a decision their controller's or processor's data protection officer made on their request, and requires the Authority to decide the complaint within thirty days and the party complained against to comply within seven working days of being notified.

Article 35 lets the Minister assign Authority staff judicial police powers to enter a licensee's premises, record violations, and seize any material or means used to commit one.

Article 36 sets administrative fines from 1,000,000 to 15,000,000 Syrian Pounds for a controller's or processor's specific failures under articles 3, 5, 6, 9, 10 and 11, for a marketing violation of articles 17 and 18, for an Authority board member's or staff member's breach of article 23, and for violating the terms of a license, permit or accreditation.

Article 37 punishes unlawfully collecting, processing, disclosing, storing, transferring or deleting personal data with imprisonment from one month to two years and a fine from 1,000,000 to 10,000,000 Syrian Pounds, rising to imprisonment from three to seven years and a fine from 10,000,000 to 20,000,000 Syrian Pounds for violating the cross-border transfer rules in articles 15 and 16, and punishes practicing an activity that needs the Authority's license before obtaining it, and obstructing an Authority officer with judicial police powers.

Article 43 requires every public and private entity to provide the Authority with any reports, statistics or information it requests about the Authority's personal data protection activities.

What it requires

Sensitive categories

Law No. 12 of 2024 on Protection of Electronic Personal Data, sensitive personal data

Law No. 12 of 2024, arts. 13-14 (sensitive personal data)Law No. 12 of 2024, full Arabic text as posted by the Syrian Ministry of Communications and Technology, read from an archived capture

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://moct.gov.sy/news-0171

In force since 1 January 2025. Binds public and private bodies.

What this law does

Article 13(a) prohibits a controller or processor, whether a natural or legal person, from processing sensitive personal data except with a license or permit from the Authority. Article 1 defines sensitive personal data as data revealing psychological, mental, physical or genetic health, biometric data, financial data, religious belief, political opinion, or criminal status, and data belonging to a child or to a person lacking legal capacity.

Article 13(b) requires written and explicit consent from the data subject before processing sensitive personal data, except in cases the law permits. Article 13(c) requires the consent of a child's legal guardian for any operation involving a child's data, and where a child takes part in a game, competition or other activity that requires personal data, that data must not exceed what participation needs.

Article 14 requires the data protection officer and the staff under their supervision to follow the information security plans, policies and procedures the Authority sets.

What it requires

Scraping law1 instrument, 1 in force

Research summary (269 words)

Syria has no scraping-specific statute, so general law governs each dimension separately.

The Cybercrime Law No. 20 of 2022, which reorganized the criminal and legal rules for cybercrime previously set out in Legislative Decree No. 17 of 2012, is Syria's core computer-misuse statute on a plain reading of its subject matter; its article text is not described here, so whether its offences reach a crawler that reads only a public, unauthenticated page, and how the Law defines unauthorized access, are not established here.

No Syrian statute or reported decision addresses whether a browsewrap or clickwrap terms-of-service restriction against scraping is enforceable as a matter of contract law.

The Law on the Protection of Copyright and Related Rights (Law No. 62 of 2013) lets the legitimate holder of a database copy it for private purposes only where the database is non-electronic, and lets a licensee access a database's content only for the licensee's own use; the Law creates no text-and-data-mining-specific exception and no machine-readable opt-out mechanism, so training a model on scraped copyrighted text is not clearly authorized outside the Law's narrow, purpose-bound exceptions.

The Law creates no sui generis database right; it protects a database as a derivative work only where its selection or arrangement is an original intellectual creation. Syria's Electronic Personal Data Protection Law No. 12 of 2024 is researched under the privacy topic for this jurisdiction, including its reach over scraped personal data, and is not repeated here.

No Syrian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Age gating law1 instrument, 1 in force

Research summary (182 words)

Syria's Child Rights Law (Law No. 21 of 2021) prohibits an operator of an establishment providing internet access service from allowing a child to access pornographic or indecent websites, backed by imprisonment and a fine, and separately directs the State to take measures preventing children's access to violence-inciting, hateful, or pornographic websites generally, a duty that runs to the State rather than to a service provider.

The same Law requires every producer or broadcaster of media material to state the age category the material is directed at, a general media-labeling duty that is not scoped to an online, app, or platform service and is not recorded as an instrument here. No social-media minor-access restriction, app-store age-verification requirement, or age-appropriate design code was found.

Syria's Cybercrime Law (Law No. 20 of 2022), read through a Syrian human-rights organization's article-by-article legal analysis quoting the Law's definitions and principal offences, and the Media Law (Legislative Decree No. 108 of 2011, read in full for this jurisdiction's other law topics), both contain no provision addressing minors, age verification, or a service's duty toward a child user.

Adult content age verification (AV)

Child Rights Law, Internet-Access Establishment Duty to Block Minors from Pornographic Websites

Law No. 21 of 2021 (Child Rights Law), arts. 1, 34, 60Full text of Law No. 21 of 2021

In force. Binds private bodies.

What this law does

Article 1 defines a child as anyone who has not completed eighteen years of age. Article 34 prohibits an operator of an establishment providing internet access service from allowing a child to access pornographic or indecent websites. Article 35 separately directs the State, not the establishment operator, to take measures preventing children's access to websites that incite violence, racial discrimination, hatred, religious contempt, intolerance, or pornography generally.

Article 60 penalizes a violation of Article 34 with imprisonment of one to three months and a fine of 100,000 to 300,000 Syrian pounds.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (314 words)

Syria has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code.

The Law on the Protection of Copyright and Related Rights (Law No. 62 of 2013) permits, without the author's authorization and without compensation, reproducing in a newspaper or periodical an economic, political, or religious article already published in a newspaper, or similar broadcast material, or transmitting that article or material to the public, in cases where the right to authorize the reproduction or transmission has not been expressly reserved by the author or rights holder, and separately permits reproducing short excerpts of works seen or heard in the course of covering current events, and quoting a short part of a published work for illustration, criticism, or educational purposes, each conditioned on citing the source and author.

These exceptions carry no headline-length or short-extract cap distinct from their own purpose-bound tests, the Law's exceptions are a closed, enumerated list rather than an open-ended fair-use standard, and the Law predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

No sui generis database right was found in the text read; a compilation is protected as a derivative work only where its selection or arrangement is an original intellectual creation.

The Law on Media (Legislative Decree No. 108 of 2011) separately punishes, with a fine of twenty thousand to one hundred thousand Syrian pounds, transmitting or publishing any media content without citing the source it was taken from, without prejudice to the injured party's right to claim compensation; this is a general attribution mandate reaching any republication of media content rather than a neighbouring right conditioned on copyright ownership.

No provision read in either statute addresses hyperlinking, framing, or inline display, and no reported Syrian decision applies any of these provisions to a systematic news aggregator. No hot-news or misappropriation doctrine distinct from ordinary copyright law has been located.

Law on Media, Duty to Cite Source on Republication

Law on Media (Legislative Decree No. 108 of 2011), Art. 96Arabic-language text of the Law on Media, Legislative Decree No. 108 of 2011, hosted by WIPO Lex

In force. Binds public and private bodies.

What this law does

Article 96 punishes, with a fine of twenty thousand to one hundred thousand Syrian pounds, whoever transmits or publishes any media content without citing the source it was taken from, without prejudice to the injured party's right to seek compensation.

The Law defines media content broadly, as the body of information of interest to a recipient in the form of articles, news, investigations, programs, notes, comments, or similar material, and defines a media outlet to include an electronic media outlet and, specifically, a network communication outlet whose published media content is accessible to any individual over the network.

Article 96 is not conditioned on the reproduced content being protected by copyright and applies regardless of whether the source has reserved its rights, so it functions as a general attribution mandate on republication rather than a press-publisher neighbouring right of the kind the European Union's Digital Single Market Directive Article 15 creates, and it carries no separate exclusive right, term, or licensing mechanism.

No provision read in this Law addresses hyperlinking, framing, or inline display, and no reported Syrian decision applies Article 96 to a systematic news aggregator.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.