Jordan
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Jordan — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send personal data out of Jordan, but only after you do the paperwork. You must check that whoever receives it protects it as well as Jordanian law does. You must run a written risk assessment first. You must appoint a data protection officer who is a Jordanian citizen. You must also join a government register. The regulator is real and busy, but it has published no fines yet.
Data governance in Jordan
The eight things that decide how you handle data about people in Jordan. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law follows the data, not the office. It covers anyone, anywhere, who holds data about people in Jordan. The law says so in its own definitions. There is no revenue or headcount floor to duck under. A foreign company is expected to join the government register just like a local one.
- What you have to do here:
- Register or notify · Appoint a data protection officer
The law covers any person or organisation 'located inside or outside the Kingdom' who has the data in their custody. It uses the same wording for anyone receiving the data. The law also reaches back in time. It applies to data you collected or used before it came into force. The register rules issued by the Council in 2025 include a set of fields for a company that is not Jordanian. The registration portal at pdp.gov.jo lists a company based outside the Hashemite Kingdom of Jordan as one of the two groups the service is for. The only exception is a person handling their own data for purely personal reasons. There is no express requirement to appoint a local legal representative. But the data protection officer rule puts a Jordanian national in the loop whenever databases leave the country.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
“Controller: Any natural or legal person, located inside or outside the Kingdom, who has the Data under their custody.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection Directorate, Ministry of Digital Economy and EntrepreneurshipRegister of data controllers, processors and data protection officers — live registration portal
pdp.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipInstructions on the Register of Data Controllers, Processors and Data Protection Officers (Official Gazette issue 5980, pages 1197-1198)
modee.gov.jo
Link checked 18 August 2026
Where the data is allowed to live
In general, yes. Data may go abroad if the organisation receiving it protects the data at least as well as Jordanian law requires. You have to check that before you send. Some industries are stricter. Government bodies may not send data marked Secret or Sensitive out of the country at all. And any organisation that sends databases abroad must have a data protection officer who is a Jordanian citizen.
- Ways to send data out:
- Official 'this country is safe' decision · Explicit consent · Legal claims · Important public interest
The rule is a test on the receiving end. It is not a ban, and it is not a list of blessed countries. The law adds six exceptions where the test does not have to be met. They include court and police cooperation under treaties. They include sharing medical data where it is needed to treat the person. They include epidemic and public health data. They include the person's own consent, after being told the protection is not good enough. And they include banking operations and transfers of money out of the Kingdom. Here is what we found sector by sector on 18 August 2026. Government and the public sector are the strictest. Under the Cloud Policy of 2020, data classified Secret must be kept and used 'within the Kingdom' in secure government data centres. Data classified Sensitive must also stay within the Kingdom. Only the Private and Ordinary levels may sit abroad, and then only where the host country's privacy law matches Jordan's. The top two levels are closed. Telecoms and information technology, energy, water, health and transport. We found no ban on storing data abroad. But named companies in these five sectors sit on a critical-infrastructure list. They cannot appoint a data protection officer until the Council approves the individual. So there is an extra approval step. Banking, payments and insurance. The Central Bank of Jordan is named as the body that approves the data protection officer for the firms it supervises. The ministry says firms supervised by the Central Bank still have to register, appoint an officer, meet the security rules and report breaches. We found no rule on the Central Bank's own site requiring data to stay in Jordan. But we could not read that site in full, so treat this as unconfirmed rather than settled. Securities, education, gaming, mapping and defence. We found no rule about where data may be stored or sent. We checked on 18 August 2026 and our confidence is medium.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
“Data shall not be transferred to any person outside the Kingdom, including to a Recipient, if the level of protection provided by them for such Data is less than that stipulated in this law, except in the following cases...”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipJordan Cloud (Platforms and Services) Policy 2020 — official English translation
modee.gov.jo
“The first level (Secret): then the place of preservation and processing is limited within the Kingdom to the secure data centers in the government... The second level (Sensitive): The place of preservation and processing is limited within the Kingdom...”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipCriteria for accrediting Personal Data Protection Officers, issued by the Personal Data Protection Council
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipList of critical-infrastructure sectors and named companies whose data protection officer must be accredited by the Council
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
Link checked 18 August 2026
- Official sourceCentral Bank of JordanCentral Bank of Jordan — regulatory frameworks and guidance for the national payments system
cbj.gov.jo
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Jordan.
Sending data out of the country
Before data leaves Jordan you need three things. A written risk assessment. A check that the receiving organisation protects the data properly. And a data protection officer. There is no list of approved countries to rely on yet. The law requires the Council to publish one, and it has not. So the judgement is yours, and so is the blame if you get it wrong.
- What you have to do here:
- Assess high-risk projects · Written vendor contract · Appoint a data protection officer · Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Explicit consent
You judge each case yourself. There is no government permit and no published list. The law makes you check how well the recipient outside the Kingdom protects the data, before you start sending. Separately, the law makes the Council publish a list of countries and organisations that are recognised as protecting data well enough. The Council must keep that list updated. The ministry's own guidance still talks about that list in the future tense. It says the Council will issue a list. No list appears in the ministry's published library as at 18 August 2026, so the list is empty. Two further requirements matter. First, the 2025 security rules require a written data protection impact assessment whenever you handle sensitive personal data, or send data outside the Kingdom. You must keep it, update it at least once a year, and hand it to the regulator on request. Second, the law requires a data protection officer whenever databases are sent outside the Kingdom. Your contracts with suppliers and recipients must set out the security measures. They must say how a breach gets reported to you. And they must say how copies stored outside the Kingdom will be deleted when the work ends. The law also lets the Council issue licences and permits for storing, using, profiling and transferring data. But the Council of Ministers regulation that would define those licence types is not in the published library. So no transfer permit is being issued or demanded today.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
“Before starting the Data transfer process, the Controller shall verify the level of protection provided by the recipient outside the Kingdom to ensure the security of the Data.”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
“يمكن نقل البيانات وتخزينها خارج المملكة ... حيث سيصدر مجلس حماية البيانات الشخصية قائمة بالدول والهيئات والمنظمات التي تتمتع بمستوى حماية كاف”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipTechnical and Organisational Security Measures Instructions of 2025 (Official Gazette pages 1882-1886)
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipThe law and all regulations, instructions, guidance and forms issued under it
modee.gov.jo
Link checked 18 August 2026
The regulator, and whether it actually acts
Two bodies, and both are real. The Personal Data Protection Council sets the rules and takes the decisions. It is chaired by the Minister of Digital Economy and Entrepreneurship, and its members are named in public. The day-to-day work is done by the Personal Data Protection Directorate inside that ministry. The Directorate runs the register, takes complaints and runs training. We found no published fine or naming decision yet. So enforcement is waking up rather than active.
The Council is fully set up. Here is its published membership as at 18 August 2026. The Minister of Digital Economy and Entrepreneurship chairs it (Sami Smairat). The Information Commissioner is deputy chair (Dr Nidal Al-Ahmad). Then come the Commissioner General for Human Rights (Jamal Al-Shamayleh) and the head of the National Cyber Security Centre (Mohammad Al-Samadi). There is also a Central Bank of Jordan representative (Moataz Abu Zanad). There are also two unnamed security-service representatives. Finally there are industry members for information technology, telecoms and banking, plus one independent expert. That mix is itself worth knowing. A government minister chairs the regulator, and two intelligence and security officials sit on it. It is not independent in the way European regulators are. The Directorate has four sections. One handles licences, permits and registers. One handles public service. What it has actually done. It issued rules on Council procedure, on the register and on security measures, all in 2025. It published the criteria for approving data protection officers, and a named critical-infrastructure list. It adopted model consent, withdrawal and request forms by formal Council decision. It runs a live register at pdp.gov.jo. It routes complaints through the national government services portal. It publishes a log of awareness workshops given to named companies, universities and regulators, running through 6 and 7 July 2026. What is missing is the other half. We found no published enforcement decision, no fine, and no use of the power to publish a violator's name at the violator's expense.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Council — mandate and current named members
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — about us, sections and duties
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — services: complaints, register, officer accreditation
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — log of awareness workshops delivered to named organisations
modee.gov.jo
Link checked 18 August 2026
- Official sourcePersonal Data Protection Directorate, Ministry of Digital Economy and EntrepreneurshipRegister of data controllers, processors and data protection officers — live registration portal
pdp.gov.jo
Link checked 18 August 2026
How long you must keep it — and when to delete it
Once you have finished the purpose you collected data for, you must delete it. The only exception is where another law tells you to keep it. Deleting means the backups too, and any copies your suppliers hold abroad. Your contract has to say so. Minimum keeping times come from other laws. Examples are five years for medical records, and separate rules for telephone and internet records.
- What you have to do here:
- Delete data after a period · Keep data for a minimum period · Let people delete their data · Written vendor contract
How long you may keep data. The 2025 security rules make you build internal systems that erase data when the work you collected it for ends. The only exception is where a law in force says otherwise. You must also erase or hide data when the person or the regulator asks. When you erase, you must tell anyone you gave the data to. You must erase all stored copies and backups, 'including making sure the processor and the recipient erase databases stored outside the Kingdom'. That duty has to be written into your contract. You may keep the results of the work after the period ends, but only if you have erased everything that identifies the person. The ministry states the general rule plainly. You may not keep personal data after the purpose you collected it for has ended. The only exception is where a law says otherwise. How long you must keep data. The ministry gives two worked examples. Medical committees must keep their records and registers for at least five years under the Medical Reports and Committees Regulation. Keeping telecoms records is covered by separate rules. Two other clocks run as well. A data protection impact assessment must be kept and refreshed at least once a year. Your register entry must be kept accurate and updated within fifteen days of any change. Which rule wins. The minimum keeping time wins. The duty to erase is expressly subject to any other law in force. We did not check the minimum keeping periods under tax, company and anti-money-laundering law against those regulators.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipTechnical and Organisational Security Measures Instructions of 2025 (Official Gazette pages 1882-1886)
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
“لا يجوز الاحتفاظ بالبيانات الشخصية التي تمت معالجتها بعد انتهاء الغرض من المعالجة ما لم تنص التشريعات على خلاف ذلك”
Link checked 18 August 2026
- Official sourceMinistry of HealthMinistry of Health — published instructions, including electronic medical file and prescription rules
moh.gov.jo
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There are two clocks. You have twenty-four hours to tell the people whose data was exposed. You have seventy-two hours to tell the regulator. Most countries put the regulator first. Jordan puts the individual first. Your suppliers must tell you the moment they discover a problem.
- What you have to do here:
- Tell affected people · Report breaches to the regulator · Report cyber incidents · Written vendor contract
The trigger is a breach of the security or integrity of data that could seriously harm the person. Within twenty-four hours of finding out, you must tell the people affected. You must also tell them what to do to avoid the consequences. Within seventy-two hours of finding out, you must tell the Personal Data Protection Directorate. Tell it where the breach came from, how it happened, who was affected, and anything else you know. If the breach happened through your gross fault or trespass, you owe the person compensation. The 2025 security rules add a contract clock. Your suppliers and anyone receiving the data must tell you immediately when they discover any breach, leak or cyber incident. You must handle incidents in line with the measures issued by the National Cyber Security Centre. That is a third clock, and we could not confirm its own deadlines. Financial firms may have a fourth route, through the Central Bank's incident response team for the financial sector, JO-FinCERT. We could not confirm its reporting deadlines either.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
“Notify the affected Data Subjects, whose data has been impacted, within (24) hours from the discovery of the breach... Notify The Unit within (72) hours from the discovery of the breach...”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipTechnical and Organisational Security Measures Instructions of 2025 (Official Gazette pages 1882-1886)
modee.gov.jo
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things catch people out. The twenty-four hour clock to warn individuals. The rule that your data protection officer must be a Jordanian citizen. Criminal fines that fall on people, not just companies. A register you must join within thirty days of starting to handle data. And government-issued consent forms you are expected to use.
- What you have to do here:
- Appoint a data protection officer · Register or notify · Get consent
- What it costs if you get it wrong:
- Criminal liability
1. The officer must be Jordanian. The Council's approval criteria require the data protection officer to hold Jordanian nationality. The officer must be of good conduct, with no conviction for a crime or for dishonesty. And the officer must never have been dismissed for a data protection failure. The officer can be an employee or an outside contractor. One outside officer may serve several organisations. 2. You need an officer more often than you think. The law requires one if handling personal data is your main activity. It also requires one if you handle sensitive data, or data about people without legal capacity, or data that includes financial information. It requires one if you transfer databases outside the Kingdom. That last trigger means almost any company using a foreign cloud service needs a Jordanian officer. 3. Criminal liability, not just fines. On top of the penalties the regulator can impose, a court can impose a criminal fine. It runs from one thousand to ten thousand Jordanian dinars. That is roughly one thousand four hundred to fourteen thousand United States dollars. The fine doubles for a repeat. The court can also order the destruction of the database the conviction was about. 4. Thirty days to register. The register rules give you thirty days from the day you actually start handling data to fill in the register. You get fifteen days to reflect any change. You get fourteen days to produce documents the regulator asks for. And you get five working days to answer a request for extra information. 5. Consent is formal, and so are the forms. Consent must be explicit, written down on paper or electronically, and limited by both time and purpose. The Council has formally adopted model consent, withdrawal and request forms. You must answer a request from an individual within fifteen working days. 6. The list of companies that need an approved officer names you by name. The critical-infrastructure list is not a description of sectors. It is a list of companies. It names the three mobile operators, three electricity distributors and three water companies. It names more than twenty hospitals and laboratories. And it names delivery and ride-hailing firms including Uber, Talabat, Careem, FedEx, DHL and Aramex. If you are on it, the Council must approve your officer before you appoint them. Approval lasts two years.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipCriteria for accrediting Personal Data Protection Officers, issued by the Personal Data Protection Council
modee.gov.jo
“أن يكون أردني الجنسية”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipList of critical-infrastructure sectors and named companies whose data protection officer must be accredited by the Council
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipInstructions on the Register of Data Controllers, Processors and Data Protection Officers (Official Gazette issue 5980, pages 1197-1198)
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
“...punished with a fine not less than one thousand (1000) Dinars and not exceeding ten thousand (10000) Dinars. The penalty shall be doubled in repeated cases.”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
Link checked 18 August 2026
What's changing next
Nothing is scheduled with a date. The things to watch are powers the government already holds. The Council can publish its list of approved countries at any time. It can add categories of data it treats as sensitive. It can add companies to the list that needs approved officers. The bigger one is a licensing system written into the law but not yet switched on.
- What you have to do here:
- Register or notify
Powers the government already holds, in order of how much they would hurt. 1. Licences and permits. The law lets the Council issue licences and permits for storing, using, profiling and transferring data. It tells the Council of Ministers to make a regulation. That regulation would set out the types of licence, their conditions, and when they can be suspended or cancelled. No such regulation appears in the ministry's published library as at 18 August 2026. The Directorate already has a standing section for licences, permits and registers. If that regulation lands, sending data abroad changes overnight from your own judgement to needing permission. 2. The list of approved countries. The Council has a standing duty to publish and update a list of countries and organisations that protect data well enough. Publishing it would help anyone sending data to a listed country. It would also immediately expose anyone sending data to an unlisted one. 3. More types of sensitive data. The Council can declare any further category of information sensitive, where disclosure or misuse would harm the person. Sensitive data means you must do an impact assessment and appoint an officer. 4. The list of named companies. The Council may add to or update any case where an approved officer is required. So the critical-infrastructure list can grow without consultation. 5. Naming and shaming. The Directorate may publish a statement of proven violations at the violator's expense. It has not used this power yet, so the first use will be news. We found nothing suggesting a change to the law itself in the next twelve months, checked 18 August 2026.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
“The Council of Ministers shall issue the necessary regulations to implement the provisions of this law, including the following: 1. Types of licenses and permits issued in accordance with the provisions of this law...”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipThe law and all regulations, instructions, guidance and forms issued under it
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Council — mandate and current named members
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipCriteria for accrediting Personal Data Protection Officers, issued by the Personal Data Protection Council
modee.gov.jo
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries1 rule
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: سياسة الحوسبة السحابية (المنصات والخدمات) 2020 (Jordan Cloud (Platforms and Services) Policy 2020) · Jordan Cloud (Platforms and Services) Policy 2020, read with the Government Data Classification and Management Policy 2020; issued 2020, exact adoption date unverified · Government policy document
The one place where data must stay in Jordan. Government bodies must classify data before it moves to the cloud. The top two levels, Secret and Sensitive, cannot leave the country. Anything a government body does send abroad must sit in a country whose privacy law matches Jordan's.
Enforced by Ministry of Digital Economy and Entrepreneurship
How this country controls where data goes: Not allowed · Accepted routes: Nothing required
What you have to do
- Keep the data in the countryGovernment data classified Secret must stay in secure government data centres inside Jordan. Data classified Sensitive must also stay inside Jordan. Private and Ordinary data may sit abroad.
- Prove the data stays under local controlA government body may use a cloud provider outside Jordan. But the provider's data centres must be in countries whose privacy and data protection law meets Jordanian law.
- Hold a security certificateCloud providers are expected to hold recognised information security certificates. The telecoms regulator sets the standards for providers.
- Assess high-risk projectsGovernment bodies must run a risk assessment before outsourcing to a cloud provider and refresh it.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipJordan Cloud (Platforms and Services) Policy 2020 — official English translation
modee.gov.jo
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: قانون حماية البيانات الشخصية رقم (24) لسنة 2023 (Personal Data Protection Law No. 24 of 2023) · Law No. 24 of 2023, Official Gazette, 17 September 2023, page 6228 · Act of parliament
Jordan's general data protection law. It is built on consent and gives individuals rights. You must appoint a data protection officer in five situations. You have twenty-four hours to warn people about a serious breach. You may send data abroad if you check that the recipient protects it as well as Jordanian law does. It has been in force since 17 March 2024. Organisations that already held data had until 17 March 2025 to comply.
Enforced by Personal Data Protection Council
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Important public interest, Legal claims, To save someone’s life
What you have to do
- Get consentConsent must be explicit, written on paper or electronically, and limited by time and purpose. Public bodies, medical care, employment, legal duties and a few other cases do not need consent. They still have to follow the rest of the law.
- Tell people what you do
- Let people see their dataFifteen working days to answer a request from an individual, counted from the day after it arrives.
- Let people correct their data
- Let people delete their data
- Let people object
- Let people take their data elsewhere
- Tell affected people — within 24 hours
- Report breaches to the regulator — within 72 hours
- Appoint a data protection officer — applies at: Main activity is processing personal data; sensitive data; data of people without legal capacity; financial information; or transferring databases outside Jordan
- Secure the data
- Put a transfer safeguard in placeYou must check how well the recipient protects the data before you send anything abroad.
- Get a parent's consent for children — applies at: Anyone lacking legal capacity; a judge may consent instead on the regulator's application
- Keep records of how you use dataKeep records of what you sent or exchanged, who received it, why, and the consents you relied on.
What it costs if you get it wrong
- Daily fine until fixed: JOD 500 per day — about $705Continuing violation after a warning has expired
- Percentage of global turnover: 3% of the previous financial year's total annual revenueCap on the total daily fine
- Order to stopFailure to comply with a warning: licence or permit suspended in whole or in part
- Loss of your licenceLicence or permit cancelled in whole or in part
- Criminal liability: JOD 1,000 to JOD 10,000, doubled on repeat — about $14 thousandAny violation of the law, its regulations or instructions; the court may also order destruction of the database
- Claims by individualsCompensation claim by the affected person, including for gross fault in a breach
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory CommissionPersonal Data Protection Law No. (24) of 2023 — Arabic text as printed in the Official Gazette
trc.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
Link checked 18 August 2026
General data protection law
Official name: تعليمات التدابير الأمنية التقنية والتنظيمية لسنة 2025 (Technical and Organisational Security Measures Instructions of 2025) · Issued under Article 8(b) of Law No. 24 of 2023; printed at Official Gazette pages 1882-1886; takes effect on publication in the Official Gazette, exact date unverified · Government rules
The rulebook that turns the law's one-line security duty into concrete requirements. The sharpest part for foreign business: you need a written data protection impact assessment before personal data leaves Jordan. Your contracts must also spell out how a supplier will delete copies stored abroad.
Enforced by Personal Data Protection Council
How this country controls where data goes: Approval each time (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision
What you have to do
- Assess high-risk projectsRequired if you handle sensitive personal data, or send data outside Jordan. Keep it, refresh it at least once a year, and hand it to the regulator on request.
- Secure the dataPhysical, technical and organisational measures. These include access control, encryption, monitoring, and stripping out names so the data cannot easily be traced back to a person.
- Written vendor contractContracts must set out the purpose, the duration and the scope. They must say how long data is kept, and how a breach gets reported to you. They must also say how the supplier will erase or return data, including copies held outside Jordan.
- Delete data after a periodErase the data when the work ends, unless another law requires you to keep it. Erase the backups too.
- Report cyber incidentsIncident handling must line up with measures issued by the National Cyber Security Centre.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipTechnical and Organisational Security Measures Instructions of 2025 (Official Gazette pages 1882-1886)
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipThe law and all regulations, instructions, guidance and forms issued under it
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
Link checked 18 August 2026
Government data rules
Official name: تعليمات سجل مسؤولي ومعالجي ومراقبي حماية البيانات (Instructions on the Register of Controllers, Processors and Data Protection Officers) · Issued under Article 18(d) of Law No. 24 of 2023; Official Gazette issue 5980, pages 1197-1198; takes effect on publication in the Official Gazette, exact date unverified · Government rules
Every organisation that handles personal data in Jordan must put itself on a public government register and keep the entry current. That includes an organisation with no office in Jordan. The portal is live at pdp.gov.jo. It asks where data is stored and who abroad receives it.
Enforced by Personal Data Protection Directorate (the Unit)
What you have to do
- Register or notifyFill in the register within 30 days of the day you actually start handling data. Update it within 15 days of any change. Produce documents within 14 days. Answer extra questions within 5 working days.
- Keep records of how you use dataYour register entry must state why you hold the data, where it came from, and what allows you to hold it. It must name who receives it, including anyone abroad. And it must give the type and volume of data, and where and for how long you keep it.
What it costs if you get it wrong
- Fixed maximum fine: JOD 1,000 to JOD 10,000 — about $14 thousandFailure to comply with instructions issued under the law
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipInstructions on the Register of Data Controllers, Processors and Data Protection Officers (Official Gazette issue 5980, pages 1197-1198)
modee.gov.jo
Link checked 18 August 2026
- Official sourcePersonal Data Protection Directorate, Ministry of Digital Economy and EntrepreneurshipRegister of data controllers, processors and data protection officers — live registration portal
pdp.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — services: complaints, register, officer accreditation
modee.gov.jo
Link checked 18 August 2026
Banking rules
Official name: معايير اعتماد مراقب حماية البيانات الشخصية (Criteria for accrediting Personal Data Protection Officers) · Issued by the Personal Data Protection Council under Article 17(b) of Law No. 24 of 2023; takes effect on approval by the Council, exact date unverified · Regulator guideline
Jordan does not require a local representative. But it does require a local person. Your data protection officer must be a Jordanian citizen. On top of that, some named companies cannot appoint their officer until the Council approves the individual. Those are in telecoms and information technology, energy, water, health and transport. For firms supervised by the Central Bank of Jordan, the Central Bank does that approving.
Enforced by Personal Data Protection Council
What you have to do
- Appoint a data protection officerThe officer must be a Jordanian national, with no relevant conviction and proven data protection knowledge. For named companies in telecoms and information technology, energy, water, health and transport, the Council must approve the individual first. Approval lasts two years. For firms supervised by the Central Bank of Jordan, the Central Bank does the approving.
- Publish a complaints contactThe officer's contact details must be published so individuals can reach them.
- Independent auditThe officer must check your databases and data systems from time to time, and track the fixes.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipCriteria for accrediting Personal Data Protection Officers, issued by the Personal Data Protection Council
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipList of critical-infrastructure sectors and named companies whose data protection officer must be accredited by the Council
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
Link checked 18 August 2026
General data protection law (Regulation No. 40 of 2025, issued under Article 24(c) of Law No. 24 of 2023 on a Council of Ministers decision of 8 June 2025; takes effect on publication in the Official Gazette, exact date unverified)
Official name: نظام الإفصاح عن البيانات رقم (40) لسنة 2025 (Data Disclosure Regulation No. 40 of 2025) · Regulation No. 40 of 2025, issued under Article 24(c) of Law No. 24 of 2023 on a Council of Ministers decision of 8 June 2025; takes effect on publication in the Official Gazette, exact date unverified · Directly binding regulation
The rules for handing personal data to someone else. This covers another company or a public body. What you hand over must be proportionate. It must not identify anyone else. And it must be cut back to the minimum needed for the purpose.
Enforced by Personal Data Protection Council
What you have to do
- Tell people what you doWhen you hand data over, keep it safe. Give only what is proportionate to the purpose. Do not harm the person's rights. Do not identify anyone else, directly or indirectly. Give the minimum data needed.
- Keep records of how you use data
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipData Disclosure Regulation No. (40) of 2025
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipThe law and all regulations, instructions, guidance and forms issued under it
modee.gov.jo
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
Whether banking, payment or insurance rules require customer data or payment systems to be kept inside Jordan
We found no rule requiring customer data or payment systems to stay in Jordan. We read the Central Bank of Jordan's payments legislation and regulatory indexes, and its licensing guide for payment service providers. We could not read the electronic payment bylaw or the Central Bank's information security and outsourcing rules in full. Treat finance as unresolved, not as unrestricted. If the Central Bank supervises you, ask it directly.
The reporting deadlines that the National Cyber Security Centre imposes under the Cybersecurity Law of 2019
We could not confirm this deadline. The Centre's own website was unreachable, and the copy of the Cybersecurity Law published by the ministry is a scanned image with no searchable text. The 2025 security rules confirm that the Centre's measures apply, so there is probably a clock. Ask the Centre if you need the number.
The exact publication dates of the 2025 instructions and of Data Disclosure Regulation No. 40 of 2025
We could not confirm these dates. The rules say they take effect on publication in the Official Gazette, and they carry gazette page numbers (1197, 1882, 2222). The register rules carry gazette issue 5980. Jordan's legislation portal at the Legislation and Opinion Bureau sits behind bot protection, so we could not check the issue dates. The in-force dates in this record are 2025 placeholders.
Whether the Personal Data Protection Council has issued any fine, suspension or public naming decision
We found none on the ministry's site or the Directorate's pages as at 18 August 2026. Jordan has no public register of enforcement decisions. So we can show that nothing has been published, not that nothing has happened.
The full content and legal number of the regulation on the mechanisms and procedures of the Unit
We could not find this rule. The Directorate's services page relies on it when it tells complainants to go to the organisation first. But the rule itself does not appear in the ministry's published library.
Minimum retention periods under tax, company and anti-money-laundering law
We confirmed the deletion duty and two minimum keeping periods that the ministry itself cites. Those are five years for medical committee records, and separate rules for telecoms records. We did not check the tax and company book-keeping minimums with the Income and Sales Tax Department or the Companies Control Department. Ask them if you need those numbers.
The text of the instructions on retaining telecommunications records
We could not find these rules. The ministry's guidance names them as an example of a minimum keeping period. But they do not appear in the telecoms regulator's published lists of laws, bylaws, rules or consumer decisions.
Whether any sector rule exists for securities, education, online gaming, mapping or defence
We found no rule for these industries, checked 18 August 2026. That rests on nothing appearing in the ministry's and the telecoms regulator's published libraries. That is weaker than a positive finding, so check with your regulator before you rely on it.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.