Law / Yemen

Yemen

2 of 8 named instruments researched to a stage, across two of the six areas of law we track: 2 in force. As of 20 September 2026.

  1. AI law none researched
  2. Privacy law none researched
  3. Scraping law none researched
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Cybersecurity law1 instrument, 1 in force

Research summary (424 words)

Yemen's one located private-sector security duty sits inside Law No. 40 of 2006 Regarding Electronic Payment Systems and Financial and Banking Operations, a banking-sector statute rather than a dedicated cybersecurity or product-security act.

Article 27 binds every financial institution practicing electronic funds transfer under the Law to comply with the Central Bank of Yemen's Bank Law and Banks Law and, separately, to take the measures necessary to provide secure services to customers and preserve banking confidentiality; no located provision of the Law attaches a named penalty to a breach of that specific duty, and Chapter Eight's penalties (Articles 37 to 41) instead punish fraud in obtaining or issuing an authentication certificate, false information supplied to a document-authentication provider, and a licensed authentication provider's own registration or confidentiality violations, offenses this jurisdiction's scraping-topic finding already covers.

Article 44 directs the Governor of the Central Bank of Yemen to issue instructions establishing the infrastructure for payment systems, organizing authentication-certificate issuance with safeguards for the confidentiality of an electronic-signature code, and setting the technical specifications and conditions required of devices and machines used in financial and banking technology, but no implementing regulation exercising that power was located, so no checkable product-security requirement currently exists on the record.

No vulnerability or incident reporting duty running to an authority or to users was located anywhere in Yemeni law. No general, non-sector-gated reasonable-security statute reaching an ordinary data-holding business was located either; the Penal Code, Law No. 12 of 1994, contains no provision addressing a computer system, consistent with this jurisdiction's scraping-topic research.

The Central Bank of Yemen is the regulator named throughout Law No. 40 of 2006 as the issuer of binding instructions for electronic banking, but no published enforcement action against a bank or financial institution for breach of Article 27's security duty was located.

Yemen has no comprehensive data-protection statute and no breach-notification duty in the privacy-topic corpus; Articles 52 and 53 of the Constitution supply general privacy rights with no processing regime of their own, so there is no privacy-topic row to name as this jurisdiction's counterpart to Article 27's safeguards duty.

WIPO Lex carries no Yemen jurisdiction browsing page at its standard legislation/profile address, and ILO NATLEX and the ITU each return no Yemen country page at their standard address either; UNCTAD's Global Cyberlaw Tracker page sits behind a Cloudflare bot challenge that blocks every request, so its own tracked status for Yemen is not described here. Yemen's National Information Center government portal is reachable and current but surfaces no laws repository from its homepage.

Sector security regimes

Law No. 40 of 2006 on Electronic Payment Systems and Financial and Banking Operations, Secure-Services and Banking-Confidentiality Duty

Law No. 40 of 2006 Regarding Electronic Payment Systems and Financial and Banking Operations, art. 27Official Arabic-language PDF of Law No. 40 of 2006 Regarding Electronic Payment Systems and Financial and Banking Operations

In force since 28 December 2006. Binds private bodies.

What this law does

Article 27 of Law No. 40 of 2006 Regarding Electronic Payment Systems and Financial and Banking Operations binds every financial institution practicing electronic funds transfer under the Law to two duties: comply with the Bank Law, the Banks Law, and the related laws, regulations, and instructions issued under them, and take the measures necessary to provide secure services to customers and preserve banking confidentiality.

The Law defines a financial institution as any body authorized to deal in financial transfers under the laws in force, a class that reaches a payments or funds-transfer platform operating as, or through, a licensed Yemeni financial institution.

Article 30 separately empowers the Central Bank of Yemen to issue the instructions needed to organize electronic funds transfer business, including approving electronic payment methods and the disclosure of information banks and financial institutions must provide; Article 44 further directs the Bank's Governor to establish payment-system infrastructure, organize authentication-certificate issuance with confidentiality safeguards for an electronic-signature code, and set technical specifications for devices and machines used in financial and banking technology, but no implementing regulation issued under either article was located, so no specific technical standard is described here.

No provision of this Law's Chapter Eight (Articles 37 to 41) names a penalty for a breach of Article 27 itself; that chapter's penalties instead attach to authentication-certificate fraud and a licensed authentication provider's own violations, and are this jurisdiction's scraping-topic computer-misuse and fraud findings rather than a security-topic one.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (228 words)

Yemen has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining code, no recognized hot-news misappropriation doctrine distinct from ordinary copyright law, and no located statute or case law addressing hyperlinking or framing liability.

The operative instrument is Law No. 15 of 2012 on the Protection of Copyright and Related Rights: article 5(3) excludes the news of incidents or events that is merely media descriptive material from copyright protection outright, so a bare news item or fact is never a protected work regardless of who first reported it.

Article 40(3) lets any person quote items or excerpts from another work for clarification, explanation, or critique with attribution, and states expressly that the exception reaches items taken from articles and journalist periodicals, and article 41(A) separately lets any person copy or republish a newspaper article, or an article in an economic, political, or religious periodical, with attribution, unless the right to copy or transfer it to the public has been explicitly reserved by the author or right holder, an opt-out condition rather than a blanket permission.

Neither provision is capped at headline length or a short extract, and whether either reaches a systematic news aggregator, as opposed to a traditional press review, has not been tested in a reported Yemeni decision. The Law predates the concept of a machine-readable text-and-data-mining reservation entirely, so no opt-out mechanism of that kind exists.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.