Law / Lebanon

Banque du Liban Basic Circular No. 144 (Prevention of Electronic Criminal Acts)

Banque du Liban Basic Decision No. 12725 of 28 November 2017 (Basic Circular No. 144 to Banks, also addressed to Financial Institutions) Prevention of Electronic Criminal Acts, Arts. 1-6

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 28 November 2017.

A sector security regimes rule binding private bodies.

As of 19 September 2026.

What it requires

  • This binds a bank or financial institution addressed by Banque du Liban's Basic Circular No. 144, in force since 28 November 2017.
  • Prepare policies and take preventive measures and procedures against crimes committed by electronic means, including a cybercrime risk analysis, a budget for an information-technology security policy, insurance covering electronic-crime risk, a continuously updated incident-response and business-continuity plan, a dedicated prevention team, and employee and customer awareness training.
  • Adopt at least two-factor authentication for any user accessing the system from outside the bank or financial institution, fully encrypt highly sensitive data, filter inbound email, verify the security of devices employees use outside the institution, run penetration testing, monitor network traffic, and verify data integrity.
  • On learning that a customer has fallen victim to a financially-natured electronic crime, notify Lebanon's Special Investigation Commission of the relevant technical information and direct the customer to file a judicial complaint.
  • Maintain a Compliance Department responsible for implementing this Decision.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Articles One through Six set no fine or criminal penalty of their own for a bank or financial institution's noncompliance; separate criminal exposure for the underlying electronic crime itself runs through Law No. 81/2018's own cybercrime chapter, recorded under Lebanon's scraping topic rather than here.

Who enforces it

Enforcement body

Banque du Liban, through the Compliance Department each bank or financial institution must maintain under Article Four; Lebanon's Special Investigation Commission additionally receives incident-specific technical information under Article Three.

Settledness

As of
19 September 2026
Open questions
Banque du Liban's own website returns a Cloudflare bot challenge to an automated reader and the most recent Basic and Intermediate Circular index reachable through the Internet Archive dates to 30 May 2023: has BDL issued a later circular amending or superseding Basic Circular No. 144 since then?

What it reaches

Obligation class

Security, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Banque du Liban (BDL), Lebanon's central bank, issued Basic Decision No. 12725 dated 28 November 2017 on the prevention of electronic criminal acts. BDL published the Decision as Basic Circular No. 144 to banks, also addressed to financial institutions. The Decision took effect immediately upon its issuance.

Article One requires every bank and financial institution to prepare policies and take preventive measures and procedures against crimes committed by electronic means, covering at minimum a defined list of general policies and technical measures.

Those general policies include analyzing potential cybercrime risk and continuously following developments in information-security technology, budgeting for an information-technology security policy, arranging insurance against electronic-crime risk, maintaining a continuously updated incident-response and business-continuity plan, forming a dedicated prevention team, sharing threat information with relevant parties inside and outside the institution, training employees and customers, monitoring employees with privileged system access, and vetting any external party entrusted with tasks touching the institution's electronic systems.

The required technical measures include adopting a technology that relies on at least two factors to verify the identity of a user accessing the system from outside the bank or financial institution, fully encrypting highly sensitive data, strictly filtering inbound email, verifying the security of any device an employee uses outside the institution, monitoring network traffic for unusual behavior, and verifying data integrity to detect and trace unlawful tampering.

They also include penetration testing to detect any potential vulnerability in the network. Upon learning that a customer has fallen victim to a financially-natured electronic crime, the bank or financial institution must notify Lebanon's Special Investigation Commission of technical information related to the incident. A dedicated Compliance Department established at each bank and financial institution implements the Decision.

The Decision sets no fixed fine or criminal penalty of its own, and Banque du Liban's own circular index shows no later Basic or Intermediate Circular amending or superseding it through the most recent reachable listing.

When LexLint raises it

  • provides_financial_services

Read the law

Official Arabic-language PDF of Banque du Liban Basic Decision No. 12725, served from BDL's own circular-download endpoint
bdl.gov.lb returns a Cloudflare bot challenge (HTTP 403) to every crawler tier, so this is read through the Internet Archive Wayback Machine's raw (id_) capture of the same PDF, cross-checked against BDL's Basic Circulars index (also read via Wayback), which lists Decision No. 12725 as Basic Circular No. 144, "Prevention of Cybercrime," 28-11-2017, Arabic only. No official English translation of this circular is published; English translations of the Arabic quotations below are given in parentheses.

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived August 15, 2022. Publisher's page: http://www.bdl.gov.lb/circulars/download/651/ar

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app