Law / Iran

Iran

privacy

Iran has no comprehensive personal-data-protection law. The closest thing is a limited chapter of the Electronic Commerce Law of 2003, Articles 58 to 61, read in full from an official WIPO Lex-hosted text (72,766 characters, not truncated); this corrects a derivation candidate that cited the personal-data chapter as "Arts. 58-63," which sweeps in Articles 62-63, the Act's separate copyright chapter.

A broader "Protection of Personal Data" bill has been under Majlis review since approximately 2018 and remains unenacted as of a fresh check; no citable primary bill text was located, so it is not authored here.

By direct reading of the full chapter, biometrics, cross-border transfer, and breach notification are confirmed absent rather than merely unresearched: Article 58's sensitive-category list (tribal or ethnic origin, religious or moral belief, ethical characteristics, physical, psychological, or sexual condition) names no biometric category, and the chapter contains no cross-border-transfer provision and no security-incident notification duty (the only "breach" heading found is the criminal-offense section title, meaning violation of the law, not a notification duty).

Iran also operates a mandatory biometric national identity card program, but no citable statute or regulation establishing it could be located within this research; that is recorded as a checked-and-not-found gap, not an authored instrument.

8 instruments named 1 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Sensitive categories

Electronic Commerce Law (2003), Personal Data Chapter

cite Electronic Commerce Law, approved by the Islamic Consultative Assembly, 2003, Arts. 58-61 (personal-data chapter) stage IN FORCE in force since 2004-01-01 binds private bodies source Electronic Commerce Law official text hosted by WIPO Lex, a UN-agency legal database republishing verbatim government-supplied texts
What it requires

Article 58 requires explicit consent before storing, processing, or distributing data revealing tribal or ethnic origin, religious or moral belief, ethical characteristics, or physical, psychological, or sexual condition; this is Iran's complete sensitive-category list and it names no biometric category.

Article 59 sets a general consent-based processing standard (specified purpose, data minimization, accuracy) and gives the data subject access to their own files with a right to correct or completely remove them. Article 60 defers medical and health-record data to separate, unlocated regulations, and Article 61 defers exceptions and "supervision and control" to other chapters without spelling out a dedicated regulator.

Enforcement is criminal only, one to three years' imprisonment under Article 71 (enhanced for institutional offenders under Article 72), with no described administrative penalty scheme and no private right of action found. No cross-border-transfer provision and no breach-notification duty were found anywhere in the chapter.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.