Doing Business In... 2025

LIBYA Law and Practice Contributed by: Salaheddin El Busefi, Heba Gedwar and Mahmud Zahaf, Zahaf & Partners

relation to the cross-border, digital processing of personal information, and access thereto. Positive signs are on the horizon however, with legislation focused on combatting cybercrime issued in 2022 seen as a pivotal piece of law that addresses how the internet and electronic infor - mation can be accessed in certain areas, par - ticularly those concerning hacking and unlawful access to guarded information and prohibited websites that contravene public order. Given this progress in regulating cyberspace, it is likely that further legal developments will emerge, poten - tially extending into more defined and robust data protection provisions in the near future. 8.2 Geographical Scope The main essence of data protection, whether in Libya or globally, is centred on consent. This is covered under the mentioned legislation con - cerning Cybercrime or Law No 6 (2022), which stipulates that any public entity or service pro - vider may collect personal data from a person only after their express consent. Consequently, any foreign companies looking to engage with local customers must first secure consent from these individuals before collecting any of their data or personal information. It is vital to note that this consent requirement carries a caveat in that the data received must only be used for the purposes of issuing or facilitating a certificate. This essentially does not include receiving data for other means or with a purpose not directly linked to the initial transaction. 8.3 Role and Authority of the Data Protection Agency The National Information Security & Safety Authority, or NIISA is an agency established under Decree No 28 (2013) to “preserve the confidentiality, integrity and availability of an organisation’s information assets” according to its website. The agency’s mission statement is

focused on safeguarding the resilience of Infor - mational and Communication Technologies (ICT) and does not appear to cover data protection in other areas such as administrative data protec - tion and unauthorised disclosure. At the moment, it appears that NIISA’s mandate is focused on promoting the secure use and protection of electronic information assets that relate to Libyan state entities. It remains to be seen if or when this will be a more comprehen - sive agency that is responsible for ensuring data protection on a more national level for all natural persons outside of governmental and commer - cial enterprises. Libya has undoubtedly seen significant advance - ments in cybercrime legislation and electronic transactions, a direct consequence of the surge in digital interactions and the pervasive use of the internet for communication and business. Therefore, we think that as Libya’s political land - scape improves and the economy opens up, this will certainly bring with it major legislative reforms in areas that are not currently active. For example, when the mining industry develops or tourism opens up, this will inevitably bring leg - islative changes to regulate and facilitate their appropriate development. Another example of how developments in inter - national commerce and the environment can impact legal reforms in Libya can be seen in the issuing of Decree No 40 of 2025 or The National Programme for Artificial Intelligence and Digital Transformation. Perhaps an extension of the electronic transaction laws mentioned earlier, this decree allows for the government and its 9. Looking Forward 9.1 Upcoming Legal Reforms

468 CHAMBERS.COM

Powered by