Data Protection in Libya

Definitions in Libya

While Libyan Law does not explicitly provide a specific definition for personal data, the National Information Security and Safety Authority (NISSA) Policy Manual offers a comprehensive understanding of personal information, categorizing it into three distinct categories. It is worth noting however that NISSA policies are only binding on the public sector at the moment, rather than the private sector.

Definition of Confidential Data

Information that is classified as confidential or restricted includes data that can be catastrophic to one or more individuals and / or organizations if compromised or lost. Such information is frequently provided on a “need to know” basis and might include:

Personal data, including personally identifiable information such as Social Security or national identification numbers, passport numbers, credit card numbers, driver's license numbers, and medical records.

  • Financial records, including financial account numbers such as checking or investment account numbers.
  • Business material, such as documents or data that is unique or specific intellectual property.
  • Legal data, including potential attorney-privileged material.
  • Authentication data, including private cryptography keys, username password pairs.

Definition of Sensitive Data

Information that is classified as being of medium sensitivity includes files and data that would not have a severe impact on an individual and / or organization if lost or destroyed. Such information might include:

  • Email, most of which can be deleted or distributed without causing a crisis (excluding mailboxes or email from individuals who are identified in the confidential classification).
  • Documents and files that do not include confidential data.
  • Anything that is not confidential. It can include most business data, because most files that are managed or used day-to-day can be classified as sensitive.

Definition of Public Data

Information that is classified as public includes data and files that are critical to business needs or operations. This classification can also include data that has deliberately been released to the public for their use, such as marketing material or press announcements. In addition, this classification can include data such as spam email messages sorted by an email service.

Back to top