Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cross-Border + Vendor + Marketing + Retention
Lebanon Law 81/2018 Articles 116-122 + LB81-12 + LB81-13 + LB81-15 + LB81-16 Cross-Border + Vendor + Marketing + Retention. Article 116 Cross-Border Data Transfer (LB81-12) - transfer of personal data outside Lebanon permitted only where: (a) destination jurisdiction provides adequate level of protection (MoET assessment + Article 116 White List) + recognised jurisdictions: EU + EEA + UK + Switzerland + Canada + Japan + Convention 108 parties + GCC convergence; (b) explicit informed consent of data subject; (c) Performance of contract; (d) Vital interests; (e) Compelling public interest authorised by law; (f) MoET-approved Standard Contractual Clauses + Binding Corporate Rules equivalent for intra-group transfers; (g) MoET-approved Codes of Conduct + Certification. Sensitive personal data cross-border requires additional MoET Minister authorisation. Article 117 Data Retention (LB81-13) -
- Cross-border transfer inventory
- Article 116 lawful-basis documentation
- MoET-approved SCC executed copies
- Sensitive data Minister authorisation
- Vendor contracts (Article 118 compliant)
- Retention schedule by sector
- Marketing opt-in evidence + spam prohibition compliance
- Transfer without lawful basis
- Sensitive cross-border without Minister authorisation
- No vendor contracts
- Marketing without opt-in
- No retention schedule
E-Commerce + Electronic Contracts + Consumer Protection
Lebanon Law 81/2018 Articles 26-44 + LB81-4 + LB81-5 + LEB-3 + LEB-4 E-Commerce and Electronic Contracts. Article 26-31 E-Commerce Disclosures (LB81-4) - pre-contractual information requirements including identity + geographic address + email + telephone + commercial register number + Ministry of Economy and Trade licence + clear price + delivery terms + payment methods + cancellation rights + dispute resolution + Lebanese applicable law + Arabic + French + English language requirements. Articles 32-37 Electronic Contracts (LB81-5) - validity + formation + offer and acceptance + electronic signature integration + click-wrap + browse-wrap recognition + record retention + Article 35 distance contracts + Article 36 right of withdrawal (cooling-off period typically 14 days) + Article 37 returns + refunds. Articles 38-44 Consumer Protection in E-Commerce (LEB-4) - integration with Consumer Pr
- Pre-contractual disclosure compliance evidence
- Contract formation audit (click-wrap/browse-wrap)
- Cooling-off period evidence
- Consumer Protection Law 659/2005 alignment
- Privacy policy + terms of service + cookies banner
- Cross-border consumer protection records
- No pre-contractual disclosures
- No cooling-off period
- No cookies banner
- Not Arabic-language compliant
- No consumer complaint procedure
E-Signature + Certified Providers + Articles 15-25
Lebanon Law 81/2018 Articles 15-25 + LB81-2 + LB81-3 Electronic Signature and Trust Services. Article 15-19 Electronic Signature Validity - electronic signatures recognised with same legal effect as handwritten signatures provided meeting requirements: (a) uniquely identifies signatory + (b) created by means under sole control of signatory + (c) linked to signed data in such manner that any subsequent change is detectable + (d) supported by qualified electronic certificate where required. Article 17 Advanced Electronic Signature with PKI infrastructure. Article 18 Qualified Electronic Signature requires Certified Electronic Signature Provider (CESP) authorisation. Articles 20-25 Certified Electronic Signature Providers (Muqaddimi Khadamat al Tasdiq) - Ministry of Economy and Trade licensing + accreditation + supervision + Article 21 minimum capital + insurance + technical capacity + ISO
- E-signature deployment evidence
- CESP licence/accreditation
- CRL maintenance evidence
- Qualified electronic certificate documentation
- ISO 27001 + Common Criteria certificates
- eIDAS equivalence assessment
- E-signatures without qualified certificates
- CESP not MoET-licensed
- No CRL maintenance
- No ISO 27001/Common Criteria certification
Incident + Supervisory + Penalties + Electronic Payment
Lebanon Law 81/2018 Articles 123-125 + LB81-17 + LB81-18 + LB81-19 + LB81-20 + LEB-12 + LEB-13 Incident Response + Supervisory + Sanctions + Electronic Payment. Article 123 Incident Detection and Handling (LB81-17) - documented incident response plan + 72-hour notification to Ministry of Economy and Trade + Higher Privacy Committee + notification to affected data subjects without undue delay where high-risk + Lebanese Cybersecurity Coordination Committee notification + Internal Security Forces Cyber Crime Bureau coordination + tabletop exercises + sectoral CSIRT participation. Article 124 Supervisory Authority Cooperation (LB81-18) - MoET inspections + investigations + production orders + on-site access + cooperation with international DPAs + Arab League Data Protection Cooperation + Convention 108+ Committee observer status + reciprocal arrangements with Arab states. Article 125 Penalti
- Incident response plan + 72-hour notification evidence
- MoET investigation response plan
- Sanctions exposure register (LBP 5M-500M + criminal Article 109-115)
- BdL/Banking Control Commission coordination for electronic payment
- EPSP licensing evidence
- Annual training records
- Higher Privacy Committee engagement
- No 72-hour notification
- No MoET response plan
- No sanctions exposure analysis
- Electronic payment without BdL coordination
- No annual training
Lawful Processing + Consent + Notice + Articles 87-92
Lebanon Law 81/2018 Articles 87-92 + LB81-6 + LB81-8 + LEB-5 + LEB-6 + LEB-7 Personal Data Lawful Processing. Article 87 Lawful Basis - personal data must be processed lawfully + consent of data subject + performance of contract + legal obligation + vital interests + public interest task + legitimate interests not overridden by data subject fundamental rights. Article 88 Consent (Muafaqa) - explicit + specific + informed + free + unambiguous + withdrawable + verifiable + special form for minors via legal guardian (children under 18 Lebanese age of majority). Article 89 Information Duty - notice to data subject must cover: identity of controller + Lebanese establishment + purposes + categories + recipients + retention + Cross-Border transfer destinations + safeguards + data subject rights + MoET complaint avenue + free Arabic + French + English notice. Article 90 Purpose Limitation - pers
- Lawful basis register
- Consent records (explicit + verifiable + withdrawable)
- Arabic + French + English privacy notices
- Purpose specification documentation
- Data accuracy procedures
- Withdrawal mechanism evidence
- Bundled consent
- Notices not in Arabic
- No purpose limitation policy
- Data not regularly updated
- Withdrawal harder than giving
Scope + Law 81/2018 + Lebanese Parliament + MoET
Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018) (Qanun al Mu amalat al Iliktruniyya wa Hamayat al Bayanat al Shakhsiyya) enacted by Lebanese Parliament on 10 October 2018 + published Official Gazette of the Republic of Lebanon (Al Jarida al Rasmiyya). First comprehensive Lebanese e-commerce + e-signature + personal data protection statute. Hybrid scope covering Title I Electronic Transactions (Articles 1-44) and Title II Personal Data Protection (Articles 87-125) plus consumer protection + electronic payments + cybercrime + intermediary liability. Ministry of Economy and Trade (MoET - Wizarat al Iqtisad wa al Tijara) competent authority for both e-transactions and personal data protection + Minister authorisation system for sensitive personal data + Higher Privacy Committee under MoET pending establishment of independent Data Protection Authority. Const
- Applicability assessment
- Personal data inventory
- MoET engagement records
- Arabic + French + English notices
- Higher Privacy Committee engagement
- Banking Secrecy Law 1956 coordination evidence
- Notices not in Arabic
- Treating Law 81/2018 as data-protection-only ignoring e-transactions title
- No MoET engagement
- Missing Banking Secrecy coordination
Security + Confidentiality + Cybercrime + Articles 106-115
Lebanon Law 81/2018 Articles 106-115 + LB81-10 + LB81-11 + LB81-14 + LEB-8 Security + Confidentiality + Cybercrime. Article 106 Security of Processing (LB81-10) - controllers must implement appropriate technical + organisational measures proportionate to risk + nature of data + state-of-the-art + encryption at rest and in transit + access control + RBAC + MFA + logging + monitoring + vulnerability management + patching + secure SDLC + physical security + backup + business continuity + incident response capability. Article 107 Confidentiality of Communications (LB81-11 + LEB-8) - electronic communications + their content + metadata subject to absolute confidentiality except + with explicit consent of all parties + judicial warrant for criminal investigation + Banking Secrecy Law 1956 banking communications + Penal Code Article 579 criminal sanctions for unauthorised disclosure. Article 10
- Security baseline configuration
- Encryption at rest + in transit evidence
- Confidentiality attestations
- Internal Security Forces Cyber Crime Bureau coordination
- Penal Code Article 579 awareness training
- Incident response runbook
- Lebanese Cybersecurity Coordination Committee coordination
- No encryption
- No confidentiality attestations
- No IR runbook
- No Cyber Crime Bureau liaison
- Penal Code 579 awareness gap
Sensitive + MoET Authorisation + Subject Rights
Lebanon Law 81/2018 Articles 93-105 + LB81-7 + LB81-9 + LEB-9 + LEB-10 + LEB-11 Sensitive Data and Data Subject Rights. Article 93 Sensitive Personal Data (Bayanat Hassasa) - racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union or association membership + health + genetic data + biometric data + sexual life + criminal record + administrative sanctions. Article 94 Sensitive Data Processing - prohibited except with MINISTER OF ECONOMY AND TRADE PRIOR AUTHORISATION (LEBANESE-UNIQUE) + explicit consent of data subject + vital interests + healthcare by professional bound by professional secrecy + research with safeguards + judicial proceedings. Articles 95-105 Data Subject Rights (Huquq Sahib al Bayanat) - LEB-9 Right of Access (Haqq al Wusul) - to know what personal data held + purposes + categories + recipients + Cross-Border destinations + 30-day
- Sensitive data inventory
- MoET Minister authorisation evidence for sensitive processing
- Subject rights request SLAs (30-day)
- Healthcare professional secrecy attestations
- Banking Secrecy 1956 alignment
- Appeals to MoET + Council of State procedure
- Sensitive processing without MoET authorisation
- No subject rights procedure
- Slow response
- No healthcare professional secrecy
- No appeals path
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.