Jordan
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.
The answer
Jordan lets personal data leave the country, but only after the paperwork. You must judge that the people receiving it protect it as well as Jordanian law does, run a written risk assessment first, and appoint a data protection officer who is a Jordanian citizen. You must also join a government register. The regulator is real and busy, but has published no fines yet.
Data governance in Jordan
The eight things that decide how you handle data about people in Jordan. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The law follows the data, not the office. It covers anyone, anywhere, who holds data about people in Jordan, and it says so in the definition of a controller. There is no revenue or headcount floor to duck under, and a foreign company is expected to sign up on the government register just like a local one.
The law defines a Controller as any natural or legal person 'located inside or outside the Kingdom' who has the data in their custody, and applies the same definition to a Recipient. It also reaches back in time: it applies to data collected or processed before it came into force. The register instructions issued by the Council in 2025 include a specific field set for a controller who is not of Jordanian nationality, and the registration portal at pdp.gov.jo lists 'the controller (natural or legal person) outside the Hashemite Kingdom of Jordan' as one of the two beneficiary categories of the service. The only carve-out is a person handling their own data for purely personal purposes. There is no express requirement to appoint a local legal representative, but the data protection officer requirement effectively puts a Jordanian national in the loop whenever databases leave the country.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
“Controller: Any natural or legal person, located inside or outside the Kingdom, who has the Data under their custody.”
Link checked 18 August 2026
- Official sourcePersonal Data Protection Directorate, Ministry of Digital Economy and EntrepreneurshipRegister of data controllers, processors and data protection officers — live registration portal
pdp.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipInstructions on the Register of Data Controllers, Processors and Data Protection Officers (Official Gazette issue 5980, pages 1197-1198)
modee.gov.jo
Link checked 18 August 2026
Where the data is allowed to live
In general, yes. Data may go abroad if the organisation receiving it protects the data at least as well as Jordanian law requires, and the sender has to check that before sending. Some industries are stricter. Government bodies may not send data marked Secret or Sensitive out of the country at all, and any organisation that sends databases abroad must have a data protection officer who is a Jordanian citizen.
Headline rating: conditional. The rule is a quality test on the receiving end, not a ban and not a list of blessed countries. The law adds six escape hatches where the test does not have to be met, including judicial and police cooperation under treaties, sharing medical data where it is needed to treat the person, epidemic and public-health data, the person's own consent after being told the protection is not adequate, and banking operations and transfers of funds outside the Kingdom. Sector by sector, as checked on 18 August 2026: GOVERNMENT AND PUBLIC SECTOR - the hardest wall. Under the Cloud Policy of 2020, data classified Secret must be kept and processed 'within the Kingdom' in secure government data centres, and data classified Sensitive must also stay within the Kingdom; only the Private and Ordinary levels may sit abroad, and then only where the host country's privacy law matches Jordan's. Rating: closed for the top two levels. TELECOMS AND INFORMATION TECHNOLOGY, ENERGY, WATER, HEALTH, TRANSPORT - no storage ban found, but named companies in these five sectors sit on a critical-infrastructure list and cannot appoint a data protection officer until the Council approves the individual. Rating: conditional with an extra approval step. BANKING, PAYMENTS AND INSURANCE - the Central Bank of Jordan is named as the body that accredits the data protection officer for the firms it supervises, and the ministry states that Central Bank supervised entities are not exempt from registration, officer, security and breach duties. No banking or payment storage-localisation instruction was located on the Central Bank's own site during this run; the site blocked automated access for long stretches, so this is recorded as unconfirmed rather than as an absence. SECURITIES, EDUCATION, GAMING, MAPPING, DEFENCE - no sector-specific transfer or storage rule found, checked 18 August 2026, confidence medium.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
“Data shall not be transferred to any person outside the Kingdom, including to a Recipient, if the level of protection provided by them for such Data is less than that stipulated in this law, except in the following cases...”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipJordan Cloud (Platforms and Services) Policy 2020 — official English translation
modee.gov.jo
“The first level (Secret): then the place of preservation and processing is limited within the Kingdom to the secure data centers in the government... The second level (Sensitive): The place of preservation and processing is limited within the Kingdom...”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipCriteria for accrediting Personal Data Protection Officers, issued by the Personal Data Protection Council
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipList of critical-infrastructure sectors and named companies whose data protection officer must be accredited by the Council
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
Link checked 18 August 2026
- Official sourceCentral Bank of JordanCentral Bank of Jordan — regulatory frameworks and guidance for the national payments system
cbj.gov.jo
Link checked 18 August 2026
Sending data out of the country
Before data leaves Jordan you need three things: a written risk assessment, a check that the receiving organisation protects the data properly, and a data protection officer. There is no approved-country list to rely on yet. The Council is required by law to publish one and has not done so, so for now the judgement call, and the blame if it is wrong, sits with you.
Model: case-by-case self-assessment, not a government permit and not a published list. The law obliges the controller to verify the level of protection provided by the recipient outside the Kingdom before starting the transfer, and separately obliges the Council to issue and keep updated a list of countries, bodies and international or regional organisations recognised as offering an adequate level of protection. The ministry's own guidance still describes that list in the future tense ('the Council will issue a list'), and no list appears in the ministry's published library of instruments as at 18 August 2026, so the list is NOT populated. Two further requirements bite. First, the 2025 security instructions require a written Data Protection Impact Assessment whenever sensitive personal data is processed or data is transferred outside the Kingdom; it must be kept, updated at least once a year and handed to the regulator on request. Second, the law requires a data protection officer whenever databases are transferred outside the Kingdom. Contracts with processors and recipients must carry defined security measures, breach-notification channels, and a clause on how copies stored outside the Kingdom will be deleted at the end of processing. The law also lets the Council issue licences and permits for the storage, processing, profiling and transfer of data, but the Council of Ministers regulation that would define those licence types is not in the published library, so no transfer permit is being issued or demanded today.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
“Before starting the Data transfer process, the Controller shall verify the level of protection provided by the recipient outside the Kingdom to ensure the security of the Data.”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
“يمكن نقل البيانات وتخزينها خارج المملكة ... حيث سيصدر مجلس حماية البيانات الشخصية قائمة بالدول والهيئات والمنظمات التي تتمتع بمستوى حماية كاف”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipTechnical and Organisational Security Measures Instructions of 2025 (Official Gazette pages 1882-1886)
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipThe law and all regulations, instructions, guidance and forms issued under it
modee.gov.jo
Link checked 18 August 2026
The regulator, and whether it actually acts
Two bodies, and both are real. The Personal Data Protection Council sets the rules and takes the decisions; it is chaired by the Minister of Digital Economy and Entrepreneurship and its members are named in public. Day to day work is done by the Personal Data Protection Directorate inside that ministry, which runs the register, takes complaints and runs training. We found no published fine or naming decision yet, so enforcement is waking up rather than active.
The Council is fully constituted. Its published membership as at 18 August 2026: the Minister of Digital Economy and Entrepreneurship as chair (Sami Smairat), the Information Commissioner as deputy chair (Dr Nidal Al-Ahmad), the Commissioner General for Human Rights (Jamal Al-Shamayleh), the head of the National Cyber Security Centre (Mohammad Al-Samadi), a Central Bank of Jordan representative (Moataz Abu Zanad), two unnamed security-service representatives, and sector representatives for information technology, telecoms and banking plus one independent expert. That composition is itself a finding: the regulator is chaired by a government minister and includes two intelligence and security officials, so it is not independent in the European sense. The Directorate has four sections, including one dedicated to licences, permits and registers and one to public service. Observable activity: instructions on Council procedure, on the register and on security measures all issued in 2025; officer accreditation criteria and a named critical-infrastructure list published; consent, withdrawal and data-subject-request forms adopted by formal Council decision; a live register at pdp.gov.jo; complaints routed through the national government services portal; and a public log of awareness workshops delivered to named companies, universities and regulators running through 6 and 7 July 2026. What is missing is the other half: no published enforcement decision, no fine, and no use of the power to publish the violator's name at the violator's expense could be found on the ministry's site during this run. Rating: waking.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Council — mandate and current named members
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — about us, sections and duties
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — services: complaints, register, officer accreditation
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — log of awareness workshops delivered to named organisations
modee.gov.jo
Link checked 18 August 2026
- Official sourcePersonal Data Protection Directorate, Ministry of Digital Economy and EntrepreneurshipRegister of data controllers, processors and data protection officers — live registration portal
pdp.gov.jo
Link checked 18 August 2026
How long you must keep it — and when to delete it
The ceiling is strict: once you have finished the purpose you collected data for, you must delete it, unless another law tells you to keep it. Deleting means the backups and any copies your suppliers hold abroad, and your contract has to say so. Floors come from other laws, such as five years for medical records and separate rules for telephone and internet records.
CEILING. The 2025 security instructions require the controller to build internal mechanisms that erase data when the processing period ends, unless legislation in force says otherwise, and to erase or hide data on request of the person or the regulator. When erasing, the controller must notify anyone it disclosed the data to, and must erase all stored copies and backups, 'including making sure the processor and the recipient erase databases stored outside the Kingdom', with that duty written into the contract. Results of processing may be kept after the period ends only if everything identifying the person has been erased. The ministry states the general rule plainly: personal data may not be kept after the purpose of processing has ended unless legislation provides otherwise. FLOORS. The ministry itself gives two worked examples: medical committees must keep their records and registers for at least five years under the Medical Reports and Committees Regulation, and telecommunications record-keeping is governed by separate instructions on retaining communications records. A data protection impact assessment must be kept and refreshed at least annually. Register entries must be kept accurate and updated within fifteen days of any change. CONFLICT RULE. The law resolves it in favour of the floor: the erasure duty is expressly subject to any other legislation in force. Tax, company and anti-money-laundering minimum retention periods were not verified against their own regulators' sites during this run.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipTechnical and Organisational Security Measures Instructions of 2025 (Official Gazette pages 1882-1886)
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
“لا يجوز الاحتفاظ بالبيانات الشخصية التي تمت معالجتها بعد انتهاء الغرض من المعالجة ما لم تنص التشريعات على خلاف ذلك”
Link checked 18 August 2026
- Official sourceMinistry of HealthMinistry of Health — published instructions, including electronic medical file and prescription rules
moh.gov.jo
Link checked 18 August 2026
If something goes wrong
There are two clocks and the shorter one is unusual. You have twenty-four hours to tell the people whose data was exposed, and seventy-two hours to tell the regulator. Most countries put the regulator first; Jordan puts the individual first. Your suppliers must tell you the moment they discover a problem.
The trigger is a breach of the security and integrity of data that could cause serious harm to the person. Within twenty-four hours of discovering it, the controller must notify the affected people and tell them what to do to avoid the consequences. Within seventy-two hours of discovering it, the controller must notify the Personal Data Protection Directorate of the source of the breach, how it happened, who was affected and any other available information. A controller who caused the breach through gross fault or trespass owes compensation to the person. The 2025 security instructions add a contractual clock: processors and recipients must notify the controller immediately on discovering any breach, leak or cyber incident, and controllers must handle incidents in line with measures issued by the National Cyber Security Centre. That is the third clock, and its own deadlines could not be verified: the National Cyber Security Centre's website was unreachable from this network during the run. Financial firms have a fourth potential channel through the Central Bank's financial-sector incident response team, JO-FinCERT, whose reporting deadlines were not verified.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
“Notify the affected Data Subjects, whose data has been impacted, within (24) hours from the discovery of the breach... Notify The Unit within (72) hours from the discovery of the breach...”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipTechnical and Organisational Security Measures Instructions of 2025 (Official Gazette pages 1882-1886)
modee.gov.jo
Link checked 18 August 2026
What catches people out
Five things catch people out: the twenty-four hour clock to warn individuals, a rule that your data protection officer must be a Jordanian citizen, criminal fines that fall on people and not just companies, a register you must join within thirty days of starting to process, and government-issued consent forms you are expected to use.
1. THE OFFICER MUST BE JORDANIAN. The Council's accreditation criteria require the data protection officer to hold Jordanian nationality, to be of good conduct with no criminal or dishonesty conviction, and never to have been dismissed for a data protection failure. The officer can be an employee or an outside contractor, and one outside officer may serve several organisations. 2. YOU NEED AN OFFICER MORE OFTEN THAN YOU THINK. The law requires one where processing personal data is your main activity, where you process sensitive data, where you process data of people without legal capacity, where the data includes financial information, and where you transfer databases outside the Kingdom. That last trigger means almost any company using a foreign cloud service needs a Jordanian officer. 3. CRIMINAL LIABILITY, NOT JUST FINES. On top of administrative penalties, a court can impose a criminal fine of one thousand to ten thousand Jordanian dinars, roughly one thousand four hundred to fourteen thousand United States dollars, doubled for a repeat, and can order the destruction of the database that was the subject of the conviction. 4. THIRTY DAYS TO REGISTER. The register instructions give the controller thirty days from the start of actual processing to fill in the register, fifteen days to reflect any change, fourteen days to produce documents the regulator asks for, and five working days to answer a request for extra information. 5. CONSENT IS FORMAL AND SO ARE THE FORMS. Consent must be explicit, documented in writing or electronically, and limited by both duration and purpose, and the Council has formally adopted model consent, withdrawal and data-subject-request forms. Requests from individuals must be answered within fifteen working days. 6. THE ACCREDITED-OFFICER LIST NAMES YOU BY NAME. The critical-infrastructure list is not a description of sectors, it is a list of companies: the three mobile operators, three electricity distributors, three water companies, more than twenty named hospitals and laboratories, and delivery and ride-hailing firms including Uber, Talabat, Careem, FedEx, DHL and Aramex. If you are on it, the Council must approve your officer before you appoint them, and approval lasts two years.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipCriteria for accrediting Personal Data Protection Officers, issued by the Personal Data Protection Council
modee.gov.jo
“أن يكون أردني الجنسية”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipList of critical-infrastructure sectors and named companies whose data protection officer must be accredited by the Council
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipInstructions on the Register of Data Controllers, Processors and Data Protection Officers (Official Gazette issue 5980, pages 1197-1198)
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
“...punished with a fine not less than one thousand (1000) Dinars and not exceeding ten thousand (10000) Dinars. The penalty shall be doubled in repeated cases.”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
Link checked 18 August 2026
What's changing next
Nothing is scheduled with a date. The things to watch are powers the government already holds. The Council can publish its list of approved countries at any time, can add categories of data it treats as sensitive, and can add companies to the list that needs approved officers. The bigger switch is a licensing system written into the law but not yet switched on.
DORMANT SWITCHES, in order of how much they would hurt. 1. LICENCES AND PERMITS. The law empowers the Council to issue licences and permits for the storage, processing, profiling and transfer of data, and instructs the Council of Ministers to make a regulation setting out the types of licence, their conditions and when they can be suspended or cancelled. No such regulation appears in the ministry's published library as at 18 August 2026, and the Directorate already has a standing section for licences, permits and registers. If that regulation lands, cross-border transfer moves overnight from self-assessment to permission. 2. THE ADEQUACY LIST. The Council is under a standing duty to publish and periodically update a list of countries and organisations with adequate protection. Publishing it would help exporters to listed countries and immediately expose exporters to unlisted ones. 3. SENSITIVE-DATA EXPANSION. The Council can declare any further category of information sensitive where disclosure or misuse would harm the person; sensitive data triggers a mandatory impact assessment and an officer. 4. THE NAMED-COMPANY LIST. The Council may add or update any case where an accredited officer is required, so the critical-infrastructure list can grow without consultation. 5. NAMING AND SHAMING. The Directorate may publish a statement of proven violations at the violator's expense. It has not used this power yet, which is exactly why the first use will be newsworthy. Nothing found suggests an amendment to the law itself in the next twelve months, checked 18 August 2026.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
“The Council of Ministers shall issue the necessary regulations to implement the provisions of this law, including the following: 1. Types of licenses and permits issued in accordance with the provisions of this law...”
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipThe law and all regulations, instructions, guidance and forms issued under it
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Council — mandate and current named members
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipCriteria for accrediting Personal Data Protection Officers, issued by the Personal Data Protection Council
modee.gov.jo
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries1 rule
If your product does one of these things, read this group first — industry rules beat the general position.
سياسة الحوسبة السحابية (المنصات والخدمات) 2020 (Jordan Cloud (Platforms and Services) Policy 2020)
Government policy document · Jordan Cloud (Platforms and Services) Policy 2020, read with the Government Data Classification and Management Policy 2020; issued 2020, exact adoption date unverified
The one hard wall in Jordan. Government bodies must classify data before it moves to the cloud, and the top two classification levels, Secret and Sensitive, cannot leave the country. Anything a government body sends abroad must sit in a country whose privacy law matches Jordan's.
Enforced by Ministry of Digital Economy and Entrepreneurship
Transfer model: Not allowed · Accepted routes: Nothing required
What it makes you do
- Keep the data in the countryGovernment data classified Secret must stay in secure government data centres inside Jordan. Data classified Sensitive must also stay inside Jordan. Private and Ordinary data may sit abroad.
- Prove the data stays under local controlWhere a government body contracts with a cloud provider outside Jordan, the provider's data centres must be in countries whose privacy and data protection law complies with Jordanian legislation.
- Hold a security certificateCloud providers are expected to hold recognised information security certifications; the telecoms regulator sets standards for providers.
- Assess high-risk projectsGovernment bodies must run a risk assessment before outsourcing to a cloud provider and refresh it.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipJordan Cloud (Platforms and Services) Policy 2020 — official English translation
modee.gov.jo
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
قانون حماية البيانات الشخصية رقم (24) لسنة 2023 (Personal Data Protection Law No. 24 of 2023)
Act of parliament · Law No. 24 of 2023, Official Gazette, 17 September 2023, page 6228
Jordan's general data protection law. Consent-based, with rights for individuals, a mandatory data protection officer in five situations, a twenty-four hour duty to warn people about a serious breach, and cross-border transfer allowed where the sender verifies the recipient protects the data as well as Jordanian law does. In force since 17 March 2024; organisations that already held data had until 17 March 2025 to comply.
Enforced by Personal Data Protection Council
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Important public interest, Legal claims, Someone's life is at risk
What it makes you do
- Get consentConsent must be explicit, written or electronic, and limited by duration and purpose. Public bodies, medical care, employment, legal duties and a few other cases are exempt from consent but not from the rest of the law.
- Tell people what you do
- Let people see their dataFifteen working days to answer a request from an individual, counted from the day after it arrives.
- Let people correct their data
- Let people delete their data
- Let people object
- Let people take their data elsewhere
- Tell affected people — within 24 hours
- Report breaches to the regulator — within 72 hours
- Appoint a data protection officer — applies at: Main activity is processing personal data; sensitive data; data of people without legal capacity; financial information; or transferring databases outside Jordan
- Secure the data
- Put a transfer safeguard in placeController must verify the recipient's level of protection before any transfer abroad.
- Get a parent's consent for children — applies at: Anyone lacking legal capacity; a judge may consent instead on the regulator's application
- Keep records of processingRecords of what was transferred or exchanged, to whom, why, and the consents relied on.
What it costs if you get it wrong
- Daily fine until fixed: JOD 500 per day — about $705Continuing violation after a warning has expired
- Percentage of global turnover: 3% of the previous financial year's total annual revenueCap on the total daily fine
- Order to stopFailure to comply with a warning: licence or permit suspended in whole or in part
- Loss of your licenceLicence or permit cancelled in whole or in part
- Criminal liability: JOD 1,000 to JOD 10,000, doubled on repeat — about $14 thousandAny violation of the law, its regulations or instructions; the court may also order destruction of the database
- Claims by individualsCompensation claim by the affected person, including for gross fault in a breach
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Law No. (24) of 2023 — official English translation
modee.gov.jo
Link checked 18 August 2026
- Official sourceTelecommunications Regulatory CommissionPersonal Data Protection Law No. (24) of 2023 — Arabic text as printed in the Official Gazette
trc.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
Link checked 18 August 2026
تعليمات التدابير الأمنية التقنية والتنظيمية لسنة 2025 (Technical and Organisational Security Measures Instructions of 2025)
Government rules · Issued under Article 8(b) of Law No. 24 of 2023; printed at Official Gazette pages 1882-1886; takes effect on publication in the Official Gazette, exact date unverified
The rulebook that turns the law's one-line security duty into concrete obligations. Its sharpest edge for foreign business: a written data protection impact assessment is required before personal data is transferred out of Jordan, and contracts must spell out how a supplier will delete copies stored abroad.
Enforced by Personal Data Protection Council
Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision
What it makes you do
- Assess high-risk projectsMandatory where sensitive personal data is processed or data is transferred outside Jordan. Must be kept, refreshed at least yearly and produced to the regulator on request.
- Secure the dataPhysical, technical and organisational measures, including access control, encryption, pseudonymisation and monitoring.
- Written vendor contractContracts must fix purpose, duration, scope, retention, breach-notification channels and how the supplier will erase or return data, including copies held outside Jordan.
- Delete data after a periodErase when the processing period ends unless other legislation requires retention; erase backups too.
- Report cyber incidentsIncident handling must line up with measures issued by the National Cyber Security Centre.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipTechnical and Organisational Security Measures Instructions of 2025 (Official Gazette pages 1882-1886)
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipThe law and all regulations, instructions, guidance and forms issued under it
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
Link checked 18 August 2026
تعليمات سجل مسؤولي ومعالجي ومراقبي حماية البيانات (Instructions on the Register of Controllers, Processors and Data Protection Officers)
Government rules · Issued under Article 18(d) of Law No. 24 of 2023; Official Gazette issue 5980, pages 1197-1198; takes effect on publication in the Official Gazette, exact date unverified
Every organisation that handles personal data in Jordan, including one with no office there, must enter itself on a public-facing government register and keep the entry current. The portal is live at pdp.gov.jo and asks where data is stored and who abroad receives it.
Enforced by Personal Data Protection Directorate (the Unit)
What it makes you do
- Register or notifyFill in the register within 30 days of starting actual processing; update within 15 days of any change; produce documents within 14 days; answer extra questions within 5 working days.
- Keep records of processingRegister entry must state purposes, sources, legal basis, recipients including any abroad, type and volume of data, and where and for how long it is kept.
What it costs if you get it wrong
- Fixed maximum fine: JOD 1,000 to JOD 10,000 — about $14 thousandFailure to comply with instructions issued under the law
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipInstructions on the Register of Data Controllers, Processors and Data Protection Officers (Official Gazette issue 5980, pages 1197-1198)
modee.gov.jo
Link checked 18 August 2026
- Official sourcePersonal Data Protection Directorate, Ministry of Digital Economy and EntrepreneurshipRegister of data controllers, processors and data protection officers — live registration portal
pdp.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — services: complaints, register, officer accreditation
modee.gov.jo
Link checked 18 August 2026
معايير اعتماد مراقب حماية البيانات الشخصية (Criteria for accrediting Personal Data Protection Officers)
Regulator guideline · Issued by the Personal Data Protection Council under Article 17(b) of Law No. 24 of 2023; takes effect on approval by the Council, exact date unverified
Jordan does not require a local representative, but it does require a local person: your data protection officer must be a Jordanian citizen. On top of that, named companies in telecoms and information technology, energy, water, health and transport cannot appoint their officer until the Council approves the individual, and for firms supervised by the Central Bank of Jordan the Central Bank does that approving.
Enforced by Personal Data Protection Council
What it makes you do
- Appoint a data protection officerThe officer must be a Jordanian national with no relevant conviction and proven data protection knowledge. For named companies in telecoms and information technology, energy, water, health and transport the Council must approve the individual first; approval lasts two years. For entities supervised by the Central Bank of Jordan, the Central Bank is the approving body.
- Publish a complaints contactThe officer's contact details must be published so individuals can reach them.
- Independent auditThe officer must run periodic assessments of database and processing systems and track the fixes.
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipCriteria for accrediting Personal Data Protection Officers, issued by the Personal Data Protection Council
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipList of critical-infrastructure sectors and named companies whose data protection officer must be accredited by the Council
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipPersonal Data Protection Directorate — Frequently Asked Questions
modee.gov.jo
Link checked 18 August 2026
نظام الإفصاح عن البيانات رقم (40) لسنة 2025 (Data Disclosure Regulation No. 40 of 2025)
Directly binding regulation · Regulation No. 40 of 2025, issued under Article 24(c) of Law No. 24 of 2023 on a Council of Ministers decision of 8 June 2025; takes effect on publication in the Official Gazette, exact date unverified
The rules for handing personal data to someone else, whether that is another company or a public body. Disclosure must be proportionate, must not identify a third person, and must be cut back to the minimum needed for the purpose.
Enforced by Personal Data Protection Council
What it makes you do
- Tell people what you doDisclosure must keep the data safe, be proportionate to the purpose, not harm the person's rights, not identify anyone else directly or indirectly, and be limited to the minimum data needed.
- Keep records of processing
Sources
- Official sourceMinistry of Digital Economy and EntrepreneurshipData Disclosure Regulation No. (40) of 2025
modee.gov.jo
Link checked 18 August 2026
- Official sourceMinistry of Digital Economy and EntrepreneurshipThe law and all regulations, instructions, guidance and forms issued under it
modee.gov.jo
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
Whether banking, payment or insurance rules require customer data or payment systems to be kept inside Jordan
The Central Bank of Jordan's website blocked automated access for most of this run. We read its payments-legislation and regulatory-framework indexes and its licensing guide for payment service providers and found no storage-localisation clause, but we could not review the electronic payment bylaw or the Central Bank's information-security and outsourcing instructions in full. Treat the finance sector as unresolved, not as unrestricted.
The reporting deadlines that the National Cyber Security Centre imposes under the Cybersecurity Law of 2019
The Centre's own website was unreachable from this network, and the copy of the Cybersecurity Law published by the ministry is a scanned image with no machine-readable text. The 2025 security instructions confirm the Centre's measures apply, but the clock could not be read.
The exact publication dates of the 2025 instructions and of Data Disclosure Regulation No. 40 of 2025
The instruments state that they take effect on publication in the Official Gazette and carry gazette page numbers (1197, 1882, 2222) and, for the register instructions, gazette issue 5980, but Jordan's legislation portal at the Legislation and Opinion Bureau sits behind bot protection, so the issue dates could not be confirmed. In-force dates in this record are given as 2025 placeholders.
Whether the Personal Data Protection Council has issued any fine, suspension or public naming decision
None was found on the ministry's site or the Directorate's pages as at 18 August 2026. Jordan has no public register of enforcement decisions, so we can evidence the absence of publication, not the absence of enforcement.
The full content and legal number of the regulation on the mechanisms and procedures of the Unit
The Directorate's services page relies on it when it requires complainants to go to the organisation first, but the instrument itself does not appear in the ministry's published library.
Minimum retention periods under tax, company and anti-money-laundering law
We verified the deletion ceiling and two floors that the ministry itself cites (five years for medical committee records, and separate instructions for telecoms records), but did not verify the tax and company book-keeping floors against the Income and Sales Tax Department or the Companies Control Department.
The text of the instructions on retaining telecommunications records
The ministry's guidance names them as an example of a retention floor, but they do not appear in the telecoms regulator's published lists of laws, bylaws, instructions or consumer rulings.
Whether any sector rule exists for securities, education, online gaming, mapping or defence
No rule found, checked 18 August 2026. Coverage of these sectors rests on the absence of anything in the ministry's and the telecoms regulator's published libraries, which is weaker evidence than a positive finding.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Jordan versus
Compare