Guide
AI and personal data in Lebanon: Law 81/2018 and the GDPR
What the two laws ask of you when an AI assistant reads people’s messages, and a checklist for before you switch it on.
Published:
This guide is general information, not legal advice. Laws change and every case is different. Before you decide, ask a Lebanese lawyer, and your own data protection adviser if you have one.
In short
- Lebanon has a personal data law: Law No. 81 of 10 October 2018. It covers private and public bodies.
- The EU’s GDPR may apply to you too, and it is the best yardstick even when it does not.
- An AI assistant that reads messages processes personal data. The same rules apply as for any other system.
- Start with four questions: what data, for what purpose, who else sees it, and how a person can see, correct or delete it.
- Health data, children’s data or ID numbers? Ask a lawyer before you switch anything on.
The checklist: 14 checks before you start
If you cannot tick one, write down who will fix it, and by when. Open any line for the details.
List the personal data
Write down what the assistant will see: names, phone numbers, messages, bookings. Decide what it must never receive: ID numbers, card numbers, medical details.
Write the purpose in one sentence, and keep to what you need
For example: “answer opening-hours questions and take booking requests.” Collect nothing that this purpose does not need.
Name your legal ground
Under the GDPR, one of the six lawful bases. Under Law 81/2018, a legitimate, explicit and specific purpose. A public body usually relies on its public task or a legal obligation.
Tell people
The first message says it is an automated assistant, with a link to a short privacy notice: who you are, why you use the data, who receives it, and how to ask for access or deletion.
Ask a lawyer about the declaration and licence
Is a declaration to the Ministry of Economy and Trade needed, or an exemption? Is a licence needed, for example for health data?
Keep sensitive data out unless you must
Health, children, religion, money, ID numbers. If you must handle them, consider your own servers, and take legal advice first.
Sign a data processing agreement with every provider that touches the data
Check it covers the Article 28 points above: instructions, confidentiality, security, sub-processors, help with requests, deletion or return.
Get the list of providers and where the data goes
The assistant provider, the AI model provider, the host and the messaging platform. In writing. If data leaves the EU or EEA, ask which mechanism covers it.
Ask in writing that your data is not used to train AI models
Paid services with clear terms are safer than free ones. Keep the answer.
Test access, correction and deletion
Can you find one person’s chats, correct them and delete them within days? Can you export everything if you leave?
Set a retention period, and make deletion automatic
Decide how long chats are kept and who deletes them. “Forever” is not an answer.
Keep a person in the loop
Customers can always reach a person. The assistant alone decides nothing with legal or significant effect. A named person reviews the chats and updates the assistant’s information.
Protect access, and plan for a leak
Named accounts, two-step login, roles and a log. Decide who you call and what you do if data leaks. Under the GDPR, the authority is told within 72 hours where feasible.
Test with invented data first, and write down your decisions
A short note: what data, why, which providers, who decided, when. It is your proof if anyone asks.
The two laws, in more detail
What Law 81/2018 says, for an AI assistant
The Law has two halves: electronic transactions, and personal data. The personal data half applies to processing in Lebanon, by private and public bodies, whether on paper or by computer. Using data only for your own personal needs is excluded.
Collect for a clear purpose, and only what you need (Art. 87)
Data must be collected in good faith, for legitimate, explicit and specific purposes, limited to what those purposes need, and not used for other purposes (with exceptions for statistics, history and research).
Tell people (Art. 88)
A person can ask who is processing their data, why, whether answering is compulsory, who receives the data, and how to access and correct it. In practice: say it at the first contact.
Declaration and licence (Art. 94, 95, 97)
In principle, whoever decides how data is processed informs the Ministry of Economy and Trade before starting. Some processing is exempt: according to DLA Piper’s summary, for example by public authorities, by non-profits for their members, by schools for their students, and by businesses for their own staff or clients within legal limits. A licence is needed for data about state security, about criminal offences and court cases, and about health, genetic identity or sexual life. Whether your project is exempt is a question for a lawyer.
Protect the data (Art. 93)
Whoever processes data must protect it against loss, damage and unauthorised access. The Law does not list specific measures.
People’s rights (Art. 86, 92, 99, 101)
A person can object for legitimate reasons (including to marketing), ask what is held about them and why, and ask for data to be corrected, completed, updated or deleted when it is wrong, incomplete, out of date or should not have been collected or used. The organisation may refuse requests that are abusive.
Enforcement (Art. 102)
Through the courts, including the judge of urgent matters. There is no independent data protection authority: the Ministry of Economy and Trade receives declarations and issues licences. A 2022 law-firm survey records no administrative enforcement actions. That is no reason to relax: people can still go to court, and EU partners will expect GDPR-level practice anyway.
What the Law does not say
The sources we read note that the Law does not define consent, does not oblige you to name a data protection officer, has no general rule on telling people about a data breach, and is silent on sending data abroad. Good practice, your contracts and, for EU matters, the GDPR fill those gaps.
What the GDPR adds, and when it applies to you
The GDPR can apply to a Lebanese business or public body when it offers goods or services to people in the EU or monitors their behaviour there (Art. 3(2)). It also reaches you through contracts: EU clients, EU-funded projects and EU-based providers ask for GDPR terms. Its main ideas:
A lawful basis (Art. 6)
Every use of personal data needs one of six bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests. Public authorities cannot use legitimate interests for what they do as authorities.
Minimum data and purpose (Art. 5)
Data must be adequate, relevant and limited to what is necessary, collected for specified purposes, kept accurate, and kept no longer than necessary.
Rights (Art. 15 to 22)
People can access their data (Art. 15), have it corrected (16) or erased (17), object (21), and ask not to be subject to a decision taken only by automated means when it significantly affects them (22).
Processors and Article 28
If a provider handles data for you, a written contract must say that it acts only on your documented instructions, keeps the data confidential and secure, uses sub-processors only with your authorisation, helps you answer people’s requests, and deletes or returns the data at the end.
Transfers outside the EU (Art. 44 to 46)
Sending personal data outside the EU or EEA needs a mechanism: an adequacy decision, or safeguards such as the European Commission’s standard contractual clauses (the 2021 version). Lebanon was not on the Commission’s list of adequate countries when we checked in October 2026.
Impact assessments and breaches (Art. 35 and 33)
A data protection impact assessment is needed for high-risk uses. A breach must be notified to the authority without undue delay and, where feasible, within 72 hours of becoming aware of it.
Law 81/2018 and the GDPR at a glance
| Topic | Law 81/2018 | GDPR |
|---|---|---|
| Regulator | No independent authority. The Ministry of Economy and Trade receives declarations and issues licences. | An independent supervisory authority in each EU country. |
| Legal ground | Legitimate, explicit and specific purposes. Consent is not defined. | One of six lawful bases. |
| Registration | Declaration to the Ministry, in principle, with exemptions. Licence for some sensitive data. | No general registration. You must be able to show your decisions, and assess high-risk uses. |
| People’s rights | Object, be informed (access), correct, complete, update, delete. | Also portability, restriction and rights about automated decisions. |
| Providers | Processors must protect the data. A processor contract is not described in the sources we read, but is good practice. | Written Article 28 contract required. |
| Sending data abroad | Described as silent in the sources we read. | Adequacy decision or safeguards (Art. 44 to 46). |
| Data breach | No general notification rule described. | Notify the authority within 72 hours where feasible. |
How Baladi Labs handles this
We describe what we do today, and what comes next.
- Data is encrypted in transit and at rest. Access is only for named people, each with their own account and two-step login.
- Hosting in the EU (Frankfurt) or on your own servers. Paid AI services only, and no training on your data.
- Data is deleted on request. For the WhatsApp Assistant, chats are kept 90 days and then deleted automatically. You can export your data before you leave, and we delete it within 30 days.
- We do not look at your data to give support unless you approve it in writing first.
- A data processing agreement and a security addendum: the templates are under legal review. Ask us for the status.
See the security page, the privacy policy and the prices.
Sources
Read in October 2026. The Law’s article numbers follow the law-firm summary below: check them against the official Arabic text in the Official Gazette. This guide does not quote the Law word for word.
- Law No. 81/2018 on Electronic Transactions and Personal Data, English version (Arab Legislations Portal, UN ESCWA)
- Madkour Law Firm, “Quick overview: Lebanese Data Protection Law (Law no. 81/2018)”
- DLA Piper, Data Protection Laws of the World: Lebanon (last reviewed 2022)
- Regulation (EU) 2016/679 (GDPR), official text on EUR-Lex
- GDPR Article 5, principles (readable copy)
- GDPR Article 6, lawfulness of processing (readable copy)
- GDPR Article 28, processor (readable copy)
- European Commission, adequacy decisions
- European Commission, standard contractual clauses
This guide is general information, not legal advice.
Want to use an AI assistant, and do it properly?
Tell us what you have in mind. We will go through this checklist with you, in a free first call.