Skip to content

Guide

AI and personal data in Lebanon: Law 81/2018 and the GDPR

What the two laws ask of you when an AI assistant reads people’s messages, and a checklist for before you switch it on.

Published:

This guide is general information, not legal advice. Laws change and every case is different. Before you decide, ask a Lebanese lawyer, and your own data protection adviser if you have one.

In short

  • Lebanon has a personal data law: Law No. 81 of 10 October 2018. It covers private and public bodies.
  • The EU’s GDPR may apply to you too, and it is the best yardstick even when it does not.
  • An AI assistant that reads messages processes personal data. The same rules apply as for any other system.
  • Start with four questions: what data, for what purpose, who else sees it, and how a person can see, correct or delete it.
  • Health data, children’s data or ID numbers? Ask a lawyer before you switch anything on.

The checklist: 14 checks before you start

If you cannot tick one, write down who will fix it, and by when. Open any line for the details.

List the personal data

Write down what the assistant will see: names, phone numbers, messages, bookings. Decide what it must never receive: ID numbers, card numbers, medical details.

Write the purpose in one sentence, and keep to what you need

For example: “answer opening-hours questions and take booking requests.” Collect nothing that this purpose does not need.

Name your legal ground

Under the GDPR, one of the six lawful bases. Under Law 81/2018, a legitimate, explicit and specific purpose. A public body usually relies on its public task or a legal obligation.

Tell people

The first message says it is an automated assistant, with a link to a short privacy notice: who you are, why you use the data, who receives it, and how to ask for access or deletion.

Ask a lawyer about the declaration and licence

Is a declaration to the Ministry of Economy and Trade needed, or an exemption? Is a licence needed, for example for health data?

Keep sensitive data out unless you must

Health, children, religion, money, ID numbers. If you must handle them, consider your own servers, and take legal advice first.

Sign a data processing agreement with every provider that touches the data

Check it covers the Article 28 points above: instructions, confidentiality, security, sub-processors, help with requests, deletion or return.

Get the list of providers and where the data goes

The assistant provider, the AI model provider, the host and the messaging platform. In writing. If data leaves the EU or EEA, ask which mechanism covers it.

Ask in writing that your data is not used to train AI models

Paid services with clear terms are safer than free ones. Keep the answer.

Test access, correction and deletion

Can you find one person’s chats, correct them and delete them within days? Can you export everything if you leave?

Set a retention period, and make deletion automatic

Decide how long chats are kept and who deletes them. “Forever” is not an answer.

Keep a person in the loop

Customers can always reach a person. The assistant alone decides nothing with legal or significant effect. A named person reviews the chats and updates the assistant’s information.

Protect access, and plan for a leak

Named accounts, two-step login, roles and a log. Decide who you call and what you do if data leaks. Under the GDPR, the authority is told within 72 hours where feasible.

Test with invented data first, and write down your decisions

A short note: what data, why, which providers, who decided, when. It is your proof if anyone asks.

The two laws, in more detail

What Law 81/2018 says, for an AI assistant

The Law has two halves: electronic transactions, and personal data. The personal data half applies to processing in Lebanon, by private and public bodies, whether on paper or by computer. Using data only for your own personal needs is excluded.

Collect for a clear purpose, and only what you need (Art. 87)

Data must be collected in good faith, for legitimate, explicit and specific purposes, limited to what those purposes need, and not used for other purposes (with exceptions for statistics, history and research).

Tell people (Art. 88)

A person can ask who is processing their data, why, whether answering is compulsory, who receives the data, and how to access and correct it. In practice: say it at the first contact.

Declaration and licence (Art. 94, 95, 97)

In principle, whoever decides how data is processed informs the Ministry of Economy and Trade before starting. Some processing is exempt: according to DLA Piper’s summary, for example by public authorities, by non-profits for their members, by schools for their students, and by businesses for their own staff or clients within legal limits. A licence is needed for data about state security, about criminal offences and court cases, and about health, genetic identity or sexual life. Whether your project is exempt is a question for a lawyer.

Protect the data (Art. 93)

Whoever processes data must protect it against loss, damage and unauthorised access. The Law does not list specific measures.

People’s rights (Art. 86, 92, 99, 101)

A person can object for legitimate reasons (including to marketing), ask what is held about them and why, and ask for data to be corrected, completed, updated or deleted when it is wrong, incomplete, out of date or should not have been collected or used. The organisation may refuse requests that are abusive.

Enforcement (Art. 102)

Through the courts, including the judge of urgent matters. There is no independent data protection authority: the Ministry of Economy and Trade receives declarations and issues licences. A 2022 law-firm survey records no administrative enforcement actions. That is no reason to relax: people can still go to court, and EU partners will expect GDPR-level practice anyway.

What the Law does not say

The sources we read note that the Law does not define consent, does not oblige you to name a data protection officer, has no general rule on telling people about a data breach, and is silent on sending data abroad. Good practice, your contracts and, for EU matters, the GDPR fill those gaps.

What the GDPR adds, and when it applies to you

The GDPR can apply to a Lebanese business or public body when it offers goods or services to people in the EU or monitors their behaviour there (Art. 3(2)). It also reaches you through contracts: EU clients, EU-funded projects and EU-based providers ask for GDPR terms. Its main ideas:

A lawful basis (Art. 6)

Every use of personal data needs one of six bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests. Public authorities cannot use legitimate interests for what they do as authorities.

Minimum data and purpose (Art. 5)

Data must be adequate, relevant and limited to what is necessary, collected for specified purposes, kept accurate, and kept no longer than necessary.

Rights (Art. 15 to 22)

People can access their data (Art. 15), have it corrected (16) or erased (17), object (21), and ask not to be subject to a decision taken only by automated means when it significantly affects them (22).

Processors and Article 28

If a provider handles data for you, a written contract must say that it acts only on your documented instructions, keeps the data confidential and secure, uses sub-processors only with your authorisation, helps you answer people’s requests, and deletes or returns the data at the end.

Transfers outside the EU (Art. 44 to 46)

Sending personal data outside the EU or EEA needs a mechanism: an adequacy decision, or safeguards such as the European Commission’s standard contractual clauses (the 2021 version). Lebanon was not on the Commission’s list of adequate countries when we checked in October 2026.

Impact assessments and breaches (Art. 35 and 33)

A data protection impact assessment is needed for high-risk uses. A breach must be notified to the authority without undue delay and, where feasible, within 72 hours of becoming aware of it.

Law 81/2018 and the GDPR at a glance
How Baladi Labs handles this

We describe what we do today, and what comes next.

  • Data is encrypted in transit and at rest. Access is only for named people, each with their own account and two-step login.
  • Hosting in the EU (Frankfurt) or on your own servers. Paid AI services only, and no training on your data.
  • Data is deleted on request. For the WhatsApp Assistant, chats are kept 90 days and then deleted automatically. You can export your data before you leave, and we delete it within 30 days.
  • We do not look at your data to give support unless you approve it in writing first.
  • A data processing agreement and a security addendum: the templates are under legal review. Ask us for the status.

See the security page, the privacy policy and the prices.

Want to use an AI assistant, and do it properly?

Tell us what you have in mind. We will go through this checklist with you, in a free first call.

Talk to usTalk to the founderWhatsApp: coming soon