Skip to the content
Global Data RulesData governance rules, country by country

Jordan

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked yesterday.

The answer

Yes, with paperworkWork: HighEnforcement: Waking up

Jordan lets personal data leave the country, but only after the paperwork. You must judge that the people receiving it protect it as well as Jordanian law does, run a written risk assessment first, and appoint a data protection officer who is a Jordanian citizen. You must also join a government register. The regulator is real and busy, but has published no fines yet.

Data governance in Jordan

The eight things that decide how you handle data about people in Jordan. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The law follows the data, not the office. It covers anyone, anywhere, who holds data about people in Jordan, and it says so in the definition of a controller. There is no revenue or headcount floor to duck under, and a foreign company is expected to sign up on the government register just like a local one.

High confidenceNational rulesRegister or notifyAppoint a data protection officer

Where the data is allowed to live

In general, yes. Data may go abroad if the organisation receiving it protects the data at least as well as Jordanian law requires, and the sender has to check that before sending. Some industries are stricter. Government bodies may not send data marked Secret or Sensitive out of the country at all, and any organisation that sends databases abroad must have a data protection officer who is a Jordanian citizen.

High confidenceYes, with paperworkApproval each timeOfficial 'this country is safe' decisionExplicit consentLegal claimsImportant public interestGovernmentHealth and social careTelecomsBanking

Sending data out of the country

Before data leaves Jordan you need three things: a written risk assessment, a check that the receiving organisation protects the data properly, and a data protection officer. There is no approved-country list to rely on yet. The Council is required by law to publish one and has not done so, so for now the judgement call, and the blame if it is wrong, sits with you.

High confidenceApproval each timeOfficial 'this country is safe' decisionExplicit consentAssess high-risk projectsWritten vendor contractAppoint a data protection officerPut a transfer safeguard in place

The regulator, and whether it actually acts

Two bodies, and both are real. The Personal Data Protection Council sets the rules and takes the decisions; it is chaired by the Minister of Digital Economy and Entrepreneurship and its members are named in public. Day to day work is done by the Personal Data Protection Directorate inside that ministry, which runs the register, takes complaints and runs training. We found no published fine or naming decision yet, so enforcement is waking up rather than active.

High confidenceWaking upRegulator

How long you must keep it — and when to delete it

The ceiling is strict: once you have finished the purpose you collected data for, you must delete it, unless another law tells you to keep it. Deleting means the backups and any copies your suppliers hold abroad, and your contract has to say so. Floors come from other laws, such as five years for medical records and separate rules for telephone and internet records.

Medium confidenceDelete data after a periodKeep data for a minimum periodLet people delete their dataWritten vendor contractHealth data

If something goes wrong

There are two clocks and the shorter one is unusual. You have twenty-four hours to tell the people whose data was exposed, and seventy-two hours to tell the regulator. Most countries put the regulator first; Jordan puts the individual first. Your suppliers must tell you the moment they discover a problem.

High confidenceTell affected peopleReport breaches to the regulatorReport cyber incidentsWritten vendor contract

What catches people out

Five things catch people out: the twenty-four hour clock to warn individuals, a rule that your data protection officer must be a Jordanian citizen, criminal fines that fall on people and not just companies, a register you must join within thirty days of starting to process, and government-issued consent forms you are expected to use.

High confidenceCriminal liabilityAppoint a data protection officerRegister or notifyGet consentLocal representative

What's changing next

Nothing is scheduled with a date. The things to watch are powers the government already holds. The Council can publish its list of approved countries at any time, can add categories of data it treats as sensitive, and can add companies to the list that needs approved officers. The bigger switch is a licensing system written into the law but not yet switched on.

Medium confidenceIn forceApproval each timeRegister or notify

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries1 rule

If your product does one of these things, read this group first — industry rules beat the general position.

Government

سياسة الحوسبة السحابية (المنصات والخدمات) 2020 (Jordan Cloud (Platforms and Services) Policy 2020)

Government policy document · Jordan Cloud (Platforms and Services) Policy 2020, read with the Government Data Classification and Management Policy 2020; issued 2020, exact adoption date unverified

In forceNo — it stays put

The one hard wall in Jordan. Government bodies must classify data before it moves to the cloud, and the top two classification levels, Secret and Sensitive, cannot leave the country. Anything a government body sends abroad must sit in a country whose privacy law matches Jordan's.

Enforced by Ministry of Digital Economy and Entrepreneurship

Transfer model: Not allowed · Accepted routes: Nothing required

High confidence

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

قانون حماية البيانات الشخصية رقم (24) لسنة 2023 (Personal Data Protection Law No. 24 of 2023)

Act of parliament · Law No. 24 of 2023, Official Gazette, 17 September 2023, page 6228

In forceYes, with paperwork

Jordan's general data protection law. Consent-based, with rights for individuals, a mandatory data protection officer in five situations, a twenty-four hour duty to warn people about a serious breach, and cross-border transfer allowed where the sender verifies the recipient protects the data as well as Jordanian law does. In force since 17 March 2024; organisations that already held data had until 17 March 2025 to comply.

In force since 17 March 2024But only enforceable from 17 March 2025

Enforced by Personal Data Protection Council

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Important public interest, Legal claims, Someone's life is at risk

High confidence

تعليمات التدابير الأمنية التقنية والتنظيمية لسنة 2025 (Technical and Organisational Security Measures Instructions of 2025)

Government rules · Issued under Article 8(b) of Law No. 24 of 2023; printed at Official Gazette pages 1882-1886; takes effect on publication in the Official Gazette, exact date unverified

In forceYes, with paperwork

The rulebook that turns the law's one-line security duty into concrete obligations. Its sharpest edge for foreign business: a written data protection impact assessment is required before personal data is transferred out of Jordan, and contracts must spell out how a supplier will delete copies stored abroad.

Enforced by Personal Data Protection Council

Transfer model: Approval each time (the list is currently empty) · Accepted routes: Official 'this country is safe' decision

High confidence

تعليمات سجل مسؤولي ومعالجي ومراقبي حماية البيانات (Instructions on the Register of Controllers, Processors and Data Protection Officers)

Government rules · Issued under Article 18(d) of Law No. 24 of 2023; Official Gazette issue 5980, pages 1197-1198; takes effect on publication in the Official Gazette, exact date unverified

In forceYes, with paperwork

Every organisation that handles personal data in Jordan, including one with no office there, must enter itself on a public-facing government register and keep the entry current. The portal is live at pdp.gov.jo and asks where data is stored and who abroad receives it.

Enforced by Personal Data Protection Directorate (the Unit)

High confidence

Who you would hear from

  • مجلس حماية البيانات الشخصية

    Decides sanctions, approves instructions and forms, accredits data protection officers, and is required to publish the list of countries with adequate protection

    Constituted and named in public as at 18 August 2026: chaired by the Minister of Digital Economy and Entrepreneurship, with the Information Commissioner as deputy, the Commissioner General for Human Rights, the head of the National Cyber Security Centre, a Central Bank of Jordan representative, two security-service representatives and four sector members. It has approved instructions in 2025 and formal decisions adopting model forms. No published fine or naming decision found.

  • مديرية حماية البيانات الشخصية

    Day-to-day regulator: keeps the register, takes complaints and reports, investigates, recommends decisions to the Council, and runs awareness work

    Staffed and visibly active. Four sections, including a licences, permits and registers section. Runs the live register at pdp.gov.jo, takes complaints through the national services portal, and published a log of awareness workshops delivered to named companies and public bodies through July 2026.

  • وزارة الاقتصاد الرقمي والريادة

    Parent ministry; owner of the government cloud and data classification policies

  • البنك المركزي الأردني

    Banks, payment and electronic money transfer firms, microfinance and, since 2021, insurance. Accredits the data protection officer for the entities it supervises and sits on the Personal Data Protection Council

    Fully operational and issuing instructions and circulars into 2026. Its site repeatedly refused automated access during this run, so its own data-storage and cloud instructions could not be read end to end.

  • هيئة تنظيم قطاع الاتصالات

    Telecoms, post and cloud service provider standards; a telecoms representative sits on the Personal Data Protection Council

  • المركز الوطني للأمن السيبراني

    Cyber incident handling under the Cybersecurity Law of 2019; its head sits on the Personal Data Protection Council

    Its head is a named sitting member of the Personal Data Protection Council, and the 2025 security instructions require controllers to follow its incident measures, so it is operational. Its own website could not be reached from this network, so its reporting deadlines are unverified and the link given here is the Council page that names its head.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • Whether banking, payment or insurance rules require customer data or payment systems to be kept inside Jordan

    The Central Bank of Jordan's website blocked automated access for most of this run. We read its payments-legislation and regulatory-framework indexes and its licensing guide for payment service providers and found no storage-localisation clause, but we could not review the electronic payment bylaw or the Central Bank's information-security and outsourcing instructions in full. Treat the finance sector as unresolved, not as unrestricted.

  • The reporting deadlines that the National Cyber Security Centre imposes under the Cybersecurity Law of 2019

    The Centre's own website was unreachable from this network, and the copy of the Cybersecurity Law published by the ministry is a scanned image with no machine-readable text. The 2025 security instructions confirm the Centre's measures apply, but the clock could not be read.

  • The exact publication dates of the 2025 instructions and of Data Disclosure Regulation No. 40 of 2025

    The instruments state that they take effect on publication in the Official Gazette and carry gazette page numbers (1197, 1882, 2222) and, for the register instructions, gazette issue 5980, but Jordan's legislation portal at the Legislation and Opinion Bureau sits behind bot protection, so the issue dates could not be confirmed. In-force dates in this record are given as 2025 placeholders.

  • Whether the Personal Data Protection Council has issued any fine, suspension or public naming decision

    None was found on the ministry's site or the Directorate's pages as at 18 August 2026. Jordan has no public register of enforcement decisions, so we can evidence the absence of publication, not the absence of enforcement.

  • The full content and legal number of the regulation on the mechanisms and procedures of the Unit

    The Directorate's services page relies on it when it requires complainants to go to the organisation first, but the instrument itself does not appear in the ministry's published library.

  • Minimum retention periods under tax, company and anti-money-laundering law

    We verified the deletion ceiling and two floors that the ministry itself cites (five years for medical committee records, and separate instructions for telecoms records), but did not verify the tax and company book-keeping floors against the Income and Sales Tax Department or the Companies Control Department.

  • The text of the instructions on retaining telecommunications records

    The ministry's guidance names them as an example of a retention floor, but they do not appear in the telecoms regulator's published lists of laws, bylaws, instructions or consumer rulings.

  • Whether any sector rule exists for securities, education, online gaming, mapping or defence

    No rule found, checked 18 August 2026. Coverage of these sectors rests on the absence of anything in the ministry's and the telecoms regulator's published libraries, which is weaker evidence than a positive finding.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Jordan versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.