Executive summary
Compiled from public sources · not legal adviceLibya has no comprehensive data protection law and no data protection authority. Privacy protection rests on scattered provisions: the Constitutional Declaration protects private life (Article 12) and the confidentiality of correspondence and communications (Article 13), and the 1953 Penal Code contains general protections for private correspondence and the home.
The closest things to modern data rules are sectoral and digital-economy statutes. Law No. 6/2022 on Electronic Transactions and Law No. 5/2022 on Combating Cybercrime introduce some data-handling and security obligations, though it remains unclear how far the Electronic Transactions Law binds private entities. In June 2025 the Central Bank of Libya issued Circular No. 18, a 'Data Protection System and Executive Regulation' creating data protection requirements specifically for the banking and financial sector — the most concrete data protection instrument in the country to date.
There is no supervisory authority for personal data; the National Information Security & Safety Authority (NISSA) handles information security rather than privacy enforcement. Organizations operating in Libya face contractual and sectoral obligations (especially in banking) rather than a general compliance regime, and no comprehensive bill was identified as pending as of mid-2026.
Sources
Note: The Central Bank of Libya's June 2025 Circular No. 18 created a data protection regime for the financial sector only; no general law or bill was identified.
Help improve this page
Governance Atlas is community-maintained. Corrections and official sources for Libya are always welcome — contribute on GitHub ↗
Compare
Open the comparison tool → see how Libya compares side by side