Skip to content

Evidence request lists

Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cross-Border + Vendor + Marketing + Retention

LB81-Cross-Border-Vendor-Marketing-Retention-Articles-116-122-LB81-12-13-15-16-Adequacy-MoET-Authorisation
Lebanon Law 81/2018 Cross-Border + Vendor + Marketing + Retention + Articles 116-122

Lebanon Law 81/2018 Articles 116-122 + LB81-12 + LB81-13 + LB81-15 + LB81-16 Cross-Border + Vendor + Marketing + Retention. Article 116 Cross-Border Data Transfer (LB81-12) - transfer of personal data outside Lebanon permitted only where: (a) destination jurisdiction provides adequate level of protection (MoET assessment + Article 116 White List) + recognised jurisdictions: EU + EEA + UK + Switzerland + Canada + Japan + Convention 108 parties + GCC convergence; (b) explicit informed consent of data subject; (c) Performance of contract; (d) Vital interests; (e) Compelling public interest authorised by law; (f) MoET-approved Standard Contractual Clauses + Binding Corporate Rules equivalent for intra-group transfers; (g) MoET-approved Codes of Conduct + Certification. Sensitive personal data cross-border requires additional MoET Minister authorisation. Article 117 Data Retention (LB81-13) -

Artefacts an auditor will ask for
  • Cross-border transfer inventory
  • Article 116 lawful-basis documentation
  • MoET-approved SCC executed copies
  • Sensitive data Minister authorisation
  • Vendor contracts (Article 118 compliant)
  • Retention schedule by sector
  • Marketing opt-in evidence + spam prohibition compliance
Where this commonly fails
  • Transfer without lawful basis
  • Sensitive cross-border without Minister authorisation
  • No vendor contracts
  • Marketing without opt-in
  • No retention schedule

E-Commerce + Electronic Contracts + Consumer Protection

LB81-E-Commerce-Disclosures-Electronic-Contracts-Consumer-Protection-Articles-26-44-LB81-4-5-LEB-3-4
Lebanon Law 81/2018 E-Commerce + Electronic Contracts + Consumer Protection + Articles 26-44

Lebanon Law 81/2018 Articles 26-44 + LB81-4 + LB81-5 + LEB-3 + LEB-4 E-Commerce and Electronic Contracts. Article 26-31 E-Commerce Disclosures (LB81-4) - pre-contractual information requirements including identity + geographic address + email + telephone + commercial register number + Ministry of Economy and Trade licence + clear price + delivery terms + payment methods + cancellation rights + dispute resolution + Lebanese applicable law + Arabic + French + English language requirements. Articles 32-37 Electronic Contracts (LB81-5) - validity + formation + offer and acceptance + electronic signature integration + click-wrap + browse-wrap recognition + record retention + Article 35 distance contracts + Article 36 right of withdrawal (cooling-off period typically 14 days) + Article 37 returns + refunds. Articles 38-44 Consumer Protection in E-Commerce (LEB-4) - integration with Consumer Pr

Artefacts an auditor will ask for
  • Pre-contractual disclosure compliance evidence
  • Contract formation audit (click-wrap/browse-wrap)
  • Cooling-off period evidence
  • Consumer Protection Law 659/2005 alignment
  • Privacy policy + terms of service + cookies banner
  • Cross-border consumer protection records
Where this commonly fails
  • No pre-contractual disclosures
  • No cooling-off period
  • No cookies banner
  • Not Arabic-language compliant
  • No consumer complaint procedure

E-Signature + Certified Providers + Articles 15-25

LB81-Electronic-Signature-Validity-Certified-Providers-Articles-15-25-LB81-2-3-Trust-Services
Lebanon Law 81/2018 Electronic Signature Validity + Certified Providers + Articles 15-25

Lebanon Law 81/2018 Articles 15-25 + LB81-2 + LB81-3 Electronic Signature and Trust Services. Article 15-19 Electronic Signature Validity - electronic signatures recognised with same legal effect as handwritten signatures provided meeting requirements: (a) uniquely identifies signatory + (b) created by means under sole control of signatory + (c) linked to signed data in such manner that any subsequent change is detectable + (d) supported by qualified electronic certificate where required. Article 17 Advanced Electronic Signature with PKI infrastructure. Article 18 Qualified Electronic Signature requires Certified Electronic Signature Provider (CESP) authorisation. Articles 20-25 Certified Electronic Signature Providers (Muqaddimi Khadamat al Tasdiq) - Ministry of Economy and Trade licensing + accreditation + supervision + Article 21 minimum capital + insurance + technical capacity + ISO

Artefacts an auditor will ask for
  • E-signature deployment evidence
  • CESP licence/accreditation
  • CRL maintenance evidence
  • Qualified electronic certificate documentation
  • ISO 27001 + Common Criteria certificates
  • eIDAS equivalence assessment
Where this commonly fails
  • E-signatures without qualified certificates
  • CESP not MoET-licensed
  • No CRL maintenance
  • No ISO 27001/Common Criteria certification

Incident + Supervisory + Penalties + Electronic Payment

LB81-Incident-Supervisory-Penalties-Training-Articles-123-125-LB81-17-18-19-20-LEB-12-13-Electronic-Payment-Client
Lebanon Law 81/2018 Incident + Supervisory + Penalties + Articles 123-125 + Electronic Payment

Lebanon Law 81/2018 Articles 123-125 + LB81-17 + LB81-18 + LB81-19 + LB81-20 + LEB-12 + LEB-13 Incident Response + Supervisory + Sanctions + Electronic Payment. Article 123 Incident Detection and Handling (LB81-17) - documented incident response plan + 72-hour notification to Ministry of Economy and Trade + Higher Privacy Committee + notification to affected data subjects without undue delay where high-risk + Lebanese Cybersecurity Coordination Committee notification + Internal Security Forces Cyber Crime Bureau coordination + tabletop exercises + sectoral CSIRT participation. Article 124 Supervisory Authority Cooperation (LB81-18) - MoET inspections + investigations + production orders + on-site access + cooperation with international DPAs + Arab League Data Protection Cooperation + Convention 108+ Committee observer status + reciprocal arrangements with Arab states. Article 125 Penalti

Artefacts an auditor will ask for
  • Incident response plan + 72-hour notification evidence
  • MoET investigation response plan
  • Sanctions exposure register (LBP 5M-500M + criminal Article 109-115)
  • BdL/Banking Control Commission coordination for electronic payment
  • EPSP licensing evidence
  • Annual training records
  • Higher Privacy Committee engagement
Where this commonly fails
  • No 72-hour notification
  • No MoET response plan
  • No sanctions exposure analysis
  • Electronic payment without BdL coordination
  • No annual training

Lawful Processing + Consent + Notice + Articles 87-92

LB81-Personal-Data-Lawful-Processing-Consent-Notice-Purpose-Articles-87-92-LB81-6-8-LEB-5-6-7
Lebanon Law 81/2018 Personal Data Lawful Processing + Consent + Notice + Articles 87-92

Lebanon Law 81/2018 Articles 87-92 + LB81-6 + LB81-8 + LEB-5 + LEB-6 + LEB-7 Personal Data Lawful Processing. Article 87 Lawful Basis - personal data must be processed lawfully + consent of data subject + performance of contract + legal obligation + vital interests + public interest task + legitimate interests not overridden by data subject fundamental rights. Article 88 Consent (Muafaqa) - explicit + specific + informed + free + unambiguous + withdrawable + verifiable + special form for minors via legal guardian (children under 18 Lebanese age of majority). Article 89 Information Duty - notice to data subject must cover: identity of controller + Lebanese establishment + purposes + categories + recipients + retention + Cross-Border transfer destinations + safeguards + data subject rights + MoET complaint avenue + free Arabic + French + English notice. Article 90 Purpose Limitation - pers

Artefacts an auditor will ask for
  • Lawful basis register
  • Consent records (explicit + verifiable + withdrawable)
  • Arabic + French + English privacy notices
  • Purpose specification documentation
  • Data accuracy procedures
  • Withdrawal mechanism evidence
Where this commonly fails
  • Bundled consent
  • Notices not in Arabic
  • No purpose limitation policy
  • Data not regularly updated
  • Withdrawal harder than giving

Scope + Law 81/2018 + Lebanese Parliament + MoET

LB81-Scope-Law-No-81-2018-10-October-2018-Lebanese-Parliament-Electronic-Transactions-Personal-Data-MoET
Lebanon Law 81/2018 Scope + 10 October 2018 + Lebanese Parliament + E-Transactions + Personal Data + MoET

Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018) (Qanun al Mu amalat al Iliktruniyya wa Hamayat al Bayanat al Shakhsiyya) enacted by Lebanese Parliament on 10 October 2018 + published Official Gazette of the Republic of Lebanon (Al Jarida al Rasmiyya). First comprehensive Lebanese e-commerce + e-signature + personal data protection statute. Hybrid scope covering Title I Electronic Transactions (Articles 1-44) and Title II Personal Data Protection (Articles 87-125) plus consumer protection + electronic payments + cybercrime + intermediary liability. Ministry of Economy and Trade (MoET - Wizarat al Iqtisad wa al Tijara) competent authority for both e-transactions and personal data protection + Minister authorisation system for sensitive personal data + Higher Privacy Committee under MoET pending establishment of independent Data Protection Authority. Const

Artefacts an auditor will ask for
  • Applicability assessment
  • Personal data inventory
  • MoET engagement records
  • Arabic + French + English notices
  • Higher Privacy Committee engagement
  • Banking Secrecy Law 1956 coordination evidence
Where this commonly fails
  • Notices not in Arabic
  • Treating Law 81/2018 as data-protection-only ignoring e-transactions title
  • No MoET engagement
  • Missing Banking Secrecy coordination

Security + Confidentiality + Cybercrime + Articles 106-115

LB81-Security-Confidentiality-Cybercrime-Articles-106-115-LB81-10-11-14-LEB-8-Unauthorised-Access
Lebanon Law 81/2018 Security + Confidentiality + Cybercrime + Articles 106-115

Lebanon Law 81/2018 Articles 106-115 + LB81-10 + LB81-11 + LB81-14 + LEB-8 Security + Confidentiality + Cybercrime. Article 106 Security of Processing (LB81-10) - controllers must implement appropriate technical + organisational measures proportionate to risk + nature of data + state-of-the-art + encryption at rest and in transit + access control + RBAC + MFA + logging + monitoring + vulnerability management + patching + secure SDLC + physical security + backup + business continuity + incident response capability. Article 107 Confidentiality of Communications (LB81-11 + LEB-8) - electronic communications + their content + metadata subject to absolute confidentiality except + with explicit consent of all parties + judicial warrant for criminal investigation + Banking Secrecy Law 1956 banking communications + Penal Code Article 579 criminal sanctions for unauthorised disclosure. Article 10

Artefacts an auditor will ask for
  • Security baseline configuration
  • Encryption at rest + in transit evidence
  • Confidentiality attestations
  • Internal Security Forces Cyber Crime Bureau coordination
  • Penal Code Article 579 awareness training
  • Incident response runbook
  • Lebanese Cybersecurity Coordination Committee coordination
Where this commonly fails
  • No encryption
  • No confidentiality attestations
  • No IR runbook
  • No Cyber Crime Bureau liaison
  • Penal Code 579 awareness gap

Sensitive + MoET Authorisation + Subject Rights

LB81-Sensitive-Data-Authorisation-Data-Subject-Rights-Articles-93-105-LB81-7-9-LEB-9-10-11-MoET-Permit
Lebanon Law 81/2018 Sensitive Data + Data Subject Rights + Articles 93-105

Lebanon Law 81/2018 Articles 93-105 + LB81-7 + LB81-9 + LEB-9 + LEB-10 + LEB-11 Sensitive Data and Data Subject Rights. Article 93 Sensitive Personal Data (Bayanat Hassasa) - racial or ethnic origin + political opinions + religious or philosophical beliefs + trade union or association membership + health + genetic data + biometric data + sexual life + criminal record + administrative sanctions. Article 94 Sensitive Data Processing - prohibited except with MINISTER OF ECONOMY AND TRADE PRIOR AUTHORISATION (LEBANESE-UNIQUE) + explicit consent of data subject + vital interests + healthcare by professional bound by professional secrecy + research with safeguards + judicial proceedings. Articles 95-105 Data Subject Rights (Huquq Sahib al Bayanat) - LEB-9 Right of Access (Haqq al Wusul) - to know what personal data held + purposes + categories + recipients + Cross-Border destinations + 30-day

Artefacts an auditor will ask for
  • Sensitive data inventory
  • MoET Minister authorisation evidence for sensitive processing
  • Subject rights request SLAs (30-day)
  • Healthcare professional secrecy attestations
  • Banking Secrecy 1956 alignment
  • Appeals to MoET + Council of State procedure
Where this commonly fails
  • Sensitive processing without MoET authorisation
  • No subject rights procedure
  • Slow response
  • No healthcare professional secrecy
  • No appeals path
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.