AcademyApproachFAQContact Request an assessment
AREN

Syria has a data-protection law — but is it actually in force today?

15 September 2026

The statute exists. Whether it is formally in force, and whether its dedicated authority is operating under the current government, is not confirmed in available sources. This is not “no law”. It is also not “a law clearly in force”.

Are my data legally protected — or not?

The question is usually answered in one of two ways, and neither is fully accurate. Some people say: of course there is a law. Others say: there is no law in this chaos. The facts sit between those two: a detailed statute is on the books, and as of today no source confirms that the body charged with applying it is actually operating under the current government, or that the law continues to apply in full.

This is not a puzzle without dates. The timeline is public. The ambiguity comes from stacking the text against the fall of the government that issued it, then against a change of constitutional framework, then against a narrower administrative circular.

The law exists, and it is highly detailed

Law No. 12 of 2024 (“Protection of Electronic Personal Data”) was issued by the former president, Bashar al-Assad. On the page it is a comprehensive statute. It creates a dedicated body named the Personal Data Protection Authority. It imposes strict conditions on cross-border transfers: explicit consent from the data subject, and an assessment of the level of protection in the receiving state. It requires a processing policy to be disclosed clearly before data are collected. And it sets penalties of up to a 12 million Syrian-pound fine and imprisonment of up to three years.

Detailed implementing instructions followed — Decision No. 29 — setting out the duties of the “controller” and the “processor”. This is not a framework without obligations. The text places measurable duties on those who collect, process and transfer data.

Why the status is ambiguous

The law was set to enter into force officially from 1 January 2025. The Assad government fell on 8 December 2024 — a few weeks before that official start date.

The constitutional framework then changed entirely. The 2012 constitution — under which Law No. 12 was issued — was formally repealed on 29 January 2025. A new transitional constitutional declaration was adopted on 13 March 2025, establishing a five-year transitional period. The first session of the new People’s Assembly convened on 12 July 2026.

The new government did act, but on a much narrower scope. The Presidency of the Transitional Council of Ministers issued “Circular No. 1 of 2025” on 7 January 2025. It is limited to requiring public bodies and professional unions not to collect personal data — especially data of state employees — except through official channels of the Ministry of Communications. That is a limited administrative measure. It is not a confirmation or a formal activation of comprehensive Law No. 12, nor of its dedicated authority.

And no source confirms, as of today, whether the Personal Data Protection Authority created by Law 12 actually exists and operates under the current government, or what the final official position is on continuing to apply the law in full.

What this means for your organisation

The real position is not “there is no law”. A detailed statute is ready. It is also not “a law clearly in force”: the body that would apply it, and its actual status under the new government, are not confirmed in public sources. It is a genuine grey zone between text and practice.

The safest operational approach for any company is to treat the principles of Law 12 as a working baseline regardless of the official activation status — explicit consent, disclosure of a processing policy before collection, caution with transfers outside the country, and reporting of breaches. That applies especially if you handle customer or employee data, or if you move data out of Syria through a cloud or a foreign service provider.

The reason is twofold. First: this is currently the most detailed legal framework available. Second: uncertainty about enforcement is not a guarantee against future accountability if the authority’s status later settles.

What we do — and what we do not claim

We do not give a final legal interpretation of this situation. That is a lawyer’s role, not a cybersecurity firm’s. What we do is help an organisation build practical data-protection practices that meet the highest standard available today — the principles of Law 12 plus international practice — instead of waiting for complete legal clarity that may be delayed.

In practice that means:

  • An inventory of what customer and employee data are collected, who processes them, and where they are stored.
  • A written processing policy shown before collection, and explicit consent where a cross-border transfer requires it.
  • Not assuming that Circular No. 1 covers a private company, or that the absence of a published authority means the absence of any standard.

The statute exists. The authority and the force-of-law status are not confirmed in available sources. The operating plan is built on the detailed principles already written, not on waiting for an announcement that may not come soon.

Abdulrahman

Abdulrahman

Founder & General Manager

Related

Contact

Need to order data protection in this phase?

Describe what you collect and where it is processed. We help with practical practices against the highest available standard, without claiming a final legal interpretation.

Request an assessment
Hours
Sunday — Thursday · 9:00 — 17:00