privacy
Lebanon has one comprehensive personal-data statute in force, Part V (Articles 85-106, "Personal Data Protection") of Law No. 81 of 10 October 2018 on Electronic Transactions and Personal Data, which by its own terms takes effect three months after Official Gazette publication (commencing 31 March 2019 per convergent secondary sources).
The operative finding is a gap between a law that binds on paper and one nobody administers: Law 81/2018 never established an independent supervisory authority, the Ministry of Economy and Trade holds the interim licensing role, and roughly six years after enactment the Ministry has not issued the implementing decrees that would make the licensing and registration regime actually work, so enforcement is concentrated in a single executive ministry with no independent oversight of it.
Two corrections to the carried derivation seed, both confirmed by a full 99,918 character read of the statute's own primary text: the sensitive-category list at Article 91 covers only health status, genetic identity, and sexual life, with no biometric category and zero occurrences of "biometric," "voice," "facial," or "face" anywhere in the text, so this document records sensitive_biometric_restriction as false rather than the seed's true; and the cross-border provisions at Articles 96(12) and 98(8) only require a permit applicant to disclose an intended transfer and the Ministry's public registry to record it, a disclosure duty rather than a substantive transfer restriction, so this document records cross_border_restriction as none rather than the seed's moderate.
Article 102 gives a data owner a real, court-enforceable path to compel access and correction through the Magistrate of Summary Justice, but this is procedural, not a general private right to sue for damages; Part V's penal provisions (fines and imprisonment for unlicensed processing) are state-prosecuted.