Skip to the content
Global Data RulesData governance rules, country by country

Jordan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Jordan — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Waking up

You can send personal data out of Jordan, but only after you do the paperwork. You must check that whoever receives it protects it as well as Jordanian law does. You must run a written risk assessment first. You must appoint a data protection officer who is a Jordanian citizen. You must also join a government register. The regulator is real and busy, but it has published no fines yet.

Data governance in Jordan

The eight things that decide how you handle data about people in Jordan. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law follows the data, not the office. It covers anyone, anywhere, who holds data about people in Jordan. The law says so in its own definitions. There is no revenue or headcount floor to duck under. A foreign company is expected to join the government register just like a local one.

What you have to do here:
Register or notify · Appoint a data protection officer

Where the data is allowed to live

In general, yes. Data may go abroad if the organisation receiving it protects the data at least as well as Jordanian law requires. You have to check that before you send. Some industries are stricter. Government bodies may not send data marked Secret or Sensitive out of the country at all. And any organisation that sends databases abroad must have a data protection officer who is a Jordanian citizen.

Ways to send data out:
Official 'this country is safe' decision · Explicit consent · Legal claims · Important public interest

What to do: Get the paperwork for one of the routes below signed before any data leaves Jordan.

Sending data out of the country

Before data leaves Jordan you need three things. A written risk assessment. A check that the receiving organisation protects the data properly. And a data protection officer. There is no list of approved countries to rely on yet. The law requires the Council to publish one, and it has not. So the judgement is yours, and so is the blame if you get it wrong.

What you have to do here:
Assess high-risk projects · Written vendor contract · Appoint a data protection officer · Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Explicit consent

The regulator, and whether it actually acts

Two bodies, and both are real. The Personal Data Protection Council sets the rules and takes the decisions. It is chaired by the Minister of Digital Economy and Entrepreneurship, and its members are named in public. The day-to-day work is done by the Personal Data Protection Directorate inside that ministry. The Directorate runs the register, takes complaints and runs training. We found no published fine or naming decision yet. So enforcement is waking up rather than active.

How long you must keep it — and when to delete it

Once you have finished the purpose you collected data for, you must delete it. The only exception is where another law tells you to keep it. Deleting means the backups too, and any copies your suppliers hold abroad. Your contract has to say so. Minimum keeping times come from other laws. Examples are five years for medical records, and separate rules for telephone and internet records.

What you have to do here:
Delete data after a period · Keep data for a minimum period · Let people delete their data · Written vendor contract

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There are two clocks. You have twenty-four hours to tell the people whose data was exposed. You have seventy-two hours to tell the regulator. Most countries put the regulator first. Jordan puts the individual first. Your suppliers must tell you the moment they discover a problem.

What you have to do here:
Tell affected people · Report breaches to the regulator · Report cyber incidents · Written vendor contract

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things catch people out. The twenty-four hour clock to warn individuals. The rule that your data protection officer must be a Jordanian citizen. Criminal fines that fall on people, not just companies. A register you must join within thirty days of starting to handle data. And government-issued consent forms you are expected to use.

What you have to do here:
Appoint a data protection officer · Register or notify · Get consent
What it costs if you get it wrong:
Criminal liability

What's changing next

Nothing is scheduled with a date. The things to watch are powers the government already holds. The Council can publish its list of approved countries at any time. It can add categories of data it treats as sensitive. It can add companies to the list that needs approved officers. The bigger one is a licensing system written into the law but not yet switched on.

What you have to do here:
Register or notify
Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries1 rule

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: سياسة الحوسبة السحابية (المنصات والخدمات) 2020 (Jordan Cloud (Platforms and Services) Policy 2020) · Jordan Cloud (Platforms and Services) Policy 2020, read with the Government Data Classification and Management Policy 2020; issued 2020, exact adoption date unverified · Government policy document

In forceNo — it stays put

The one place where data must stay in Jordan. Government bodies must classify data before it moves to the cloud. The top two levels, Secret and Sensitive, cannot leave the country. Anything a government body does send abroad must sit in a country whose privacy law matches Jordan's.

Enforced by Ministry of Digital Economy and Entrepreneurship

How this country controls where data goes: Not allowed · Accepted routes: Nothing required

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: قانون حماية البيانات الشخصية رقم (24) لسنة 2023 (Personal Data Protection Law No. 24 of 2023) · Law No. 24 of 2023, Official Gazette, 17 September 2023, page 6228 · Act of parliament

In forceYes, with paperwork

Jordan's general data protection law. It is built on consent and gives individuals rights. You must appoint a data protection officer in five situations. You have twenty-four hours to warn people about a serious breach. You may send data abroad if you check that the recipient protects it as well as Jordanian law does. It has been in force since 17 March 2024. Organisations that already held data had until 17 March 2025 to comply.

In force since 17 March 2024Enforced from 17 March 2025

Enforced by Personal Data Protection Council

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Important public interest, Legal claims, To save someone’s life

General data protection law

Official name: تعليمات التدابير الأمنية التقنية والتنظيمية لسنة 2025 (Technical and Organisational Security Measures Instructions of 2025) · Issued under Article 8(b) of Law No. 24 of 2023; printed at Official Gazette pages 1882-1886; takes effect on publication in the Official Gazette, exact date unverified · Government rules

In forceYes, with paperwork

The rulebook that turns the law's one-line security duty into concrete requirements. The sharpest part for foreign business: you need a written data protection impact assessment before personal data leaves Jordan. Your contracts must also spell out how a supplier will delete copies stored abroad.

Enforced by Personal Data Protection Council

How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision

Government data rules

Official name: تعليمات سجل مسؤولي ومعالجي ومراقبي حماية البيانات (Instructions on the Register of Controllers, Processors and Data Protection Officers) · Issued under Article 18(d) of Law No. 24 of 2023; Official Gazette issue 5980, pages 1197-1198; takes effect on publication in the Official Gazette, exact date unverified · Government rules

In forceYes, with paperwork

Every organisation that handles personal data in Jordan must put itself on a public government register and keep the entry current. That includes an organisation with no office in Jordan. The portal is live at pdp.gov.jo. It asks where data is stored and who abroad receives it.

Enforced by Personal Data Protection Directorate (the Unit)

Who you would hear from

  • مجلس حماية البيانات الشخصية

    Decides sanctions, approves instructions and forms, accredits data protection officers, and is required to publish the list of countries with adequate protection

    Set up, with its members named in public as at 18 August 2026. It is chaired by the Minister of Digital Economy and Entrepreneurship. The Information Commissioner is deputy. The other members are the Commissioner General for Human Rights, the head of the National Cyber Security Centre, and a Central Bank of Jordan representative. There are also two security-service representatives and four industry members. It approved rules in 2025 and formal decisions adopting model forms. We found no published fine and no naming decision.

  • مديرية حماية البيانات الشخصية

    Day-to-day regulator: keeps the register, takes complaints and reports, investigates, recommends decisions to the Council, and runs awareness work

    Staffed and visibly active. It has four sections, including one for licences, permits and registers. It runs the live register at pdp.gov.jo. It takes complaints through the national services portal. It published a log of awareness workshops given to named companies and public bodies through July 2026.

  • وزارة الاقتصاد الرقمي والريادة

    Parent ministry; owner of the government cloud and data classification policies

  • البنك المركزي الأردني

    Banks, payment and electronic money transfer firms, microfinance and, since 2021, insurance. Accredits the data protection officer for the entities it supervises and sits on the Personal Data Protection Council

    Working, and still issuing rules and circulars into 2026. Ask the bank directly if it supervises you.

  • هيئة تنظيم قطاع الاتصالات

    Telecoms, post and cloud service provider standards; a telecoms representative sits on the Personal Data Protection Council

  • المركز الوطني للأمن السيبراني

    Cyber incident handling under the Cybersecurity Law of 2019; its head sits on the Personal Data Protection Council

    It is working. Its head sits on the Personal Data Protection Council, and the 2025 security rules require you to follow its incident measures. We could not confirm its reporting deadlines. The link here is the Council page that names its head.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • Whether banking, payment or insurance rules require customer data or payment systems to be kept inside Jordan

    We found no rule requiring customer data or payment systems to stay in Jordan. We read the Central Bank of Jordan's payments legislation and regulatory indexes, and its licensing guide for payment service providers. We could not read the electronic payment bylaw or the Central Bank's information security and outsourcing rules in full. Treat finance as unresolved, not as unrestricted. If the Central Bank supervises you, ask it directly.

  • The reporting deadlines that the National Cyber Security Centre imposes under the Cybersecurity Law of 2019

    We could not confirm this deadline. The Centre's own website was unreachable, and the copy of the Cybersecurity Law published by the ministry is a scanned image with no searchable text. The 2025 security rules confirm that the Centre's measures apply, so there is probably a clock. Ask the Centre if you need the number.

  • The exact publication dates of the 2025 instructions and of Data Disclosure Regulation No. 40 of 2025

    We could not confirm these dates. The rules say they take effect on publication in the Official Gazette, and they carry gazette page numbers (1197, 1882, 2222). The register rules carry gazette issue 5980. Jordan's legislation portal at the Legislation and Opinion Bureau sits behind bot protection, so we could not check the issue dates. The in-force dates in this record are 2025 placeholders.

  • Whether the Personal Data Protection Council has issued any fine, suspension or public naming decision

    We found none on the ministry's site or the Directorate's pages as at 18 August 2026. Jordan has no public register of enforcement decisions. So we can show that nothing has been published, not that nothing has happened.

  • The full content and legal number of the regulation on the mechanisms and procedures of the Unit

    We could not find this rule. The Directorate's services page relies on it when it tells complainants to go to the organisation first. But the rule itself does not appear in the ministry's published library.

  • Minimum retention periods under tax, company and anti-money-laundering law

    We confirmed the deletion duty and two minimum keeping periods that the ministry itself cites. Those are five years for medical committee records, and separate rules for telecoms records. We did not check the tax and company book-keeping minimums with the Income and Sales Tax Department or the Companies Control Department. Ask them if you need those numbers.

  • The text of the instructions on retaining telecommunications records

    We could not find these rules. The ministry's guidance names them as an example of a minimum keeping period. But they do not appear in the telecoms regulator's published lists of laws, bylaws, rules or consumer decisions.

  • Whether any sector rule exists for securities, education, online gaming, mapping or defence

    We found no rule for these industries, checked 18 August 2026. That rests on nothing appearing in the ministry's and the telecoms regulator's published libraries. That is weaker than a positive finding, so check with your regulator before you rely on it.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.