Law / Jordan

Cybercrime Law, Unauthorized Access to Information Systems

Law No. 17 of 2023 on Cybercrime, Arts. 3-4, 6-7

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A computer misuse rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Do not access a website, information network, information system, or information technology means, in whole or in part, without authorization or in excess of an authorization granted.
  • Do not use a program or program command to disable, alter, damage, or gain unauthorized access to an information system, and do not intercept or capture data transmitted through one.
  • Accessing a network, system, or website belonging to a government, security, financial, or banking institution without permission, or in excess of a permit, carries a heightened penalty where it reaches non-public data affecting national security, foreign relations, public safety, or the national economy.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Article 3's base offense (accessing an information system, network, or website without authorization or in excess of an authorization) carries imprisonment of one week to three months or a fine of 300 to 600 Dinars, or both; the fine rises to 600 to 3,000 Dinars where the access targets data for alteration or disclosure, and to 3,000 to 15,000 Dinars where that result is achieved. Article 4's aggravated offense, reaching a government, security, financial, or banking system, carries a separate range of 2,500 to 25,000 Dinars, rising to temporary servitude and a fine of 5,000 to 25,000 Dinars where the access is also used to alter or disclose the data, and to temporary servitude of at least five years and a 25,000-Dinar fine if that result is achieved. Article 6 (disabling or interfering with an information system) carries 2,500 to 10,000 Dinars, and Article 7 (interception) carries 1,500 to 6,000 Dinars, rising to 15,000 to 45,000 Dinars and temporary servitude of at least five years where the interception targets an official authority.

Penalty structure

Article 3 alone carries three tiers: 300-600 Dinars for the base unauthorized-access offense, 600-3,000 Dinars where the access targets data for alteration or disclosure, and 3,000-15,000 Dinars where that result is achieved. Articles 4, 6, and 7 carry separate, higher fine ranges (up to 25,000, 10,000, and 45,000 Dinars respectively) for access to government or financial systems, system interference, and interception; those figures are set out in criminal_exposure_note rather than folded into this fixed_cap.

Rule
Fixed only
As of
6 September 2026
Minimum
300
Currency
JOD
Fixed cap
15,000

What it reaches

Obligation class

Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 3 punishes whoever intentionally accesses a website, information network, information system, or information technology means, or any part of it, without authorization or in excess of an authorization, with imprisonment of one week to three months or a fine of 300 to 600 Dinars, or both.

The penalty rises to three months to one year and a fine of 600 to 3,000 Dinars where the access is for the purpose of cancelling, deleting, damaging, disclosing, or otherwise altering data, and to one to three years and a fine of 3,000 to 15,000 Dinars where that result is achieved.

Article 4 raises the penalty to six months to three years and a fine of 2,500 to 25,000 Dinars where the access reaches an information network, system, or website belonging to a ministry, government department, public institution, or a security, financial, or banking institution, and affects non-public data touching national security, the Kingdom's foreign relations, public safety, or the national economy; where that access is also used to cancel, damage, destroy, or otherwise alter or disclose the data, Article 4 raises the penalty further to temporary servitude and a fine of 5,000 to 25,000 Dinars, or temporary servitude of at least five years and a fine of 25,000 Dinars if the result is achieved.

Article 6 separately punishes intentionally using a program or program command to disable, alter, or gain unauthorized access to an information system, with imprisonment of at least six months and a fine of 2,500 to 10,000 Dinars.

Article 7 punishes unlawfully intercepting or capturing a data flow with imprisonment of at least six months and a fine of 1,500 to 6,000 Dinars, rising to temporary servitude of at least five years and a fine of 15,000 to 45,000 Dinars where the interception targets an official authority's communications. None of these articles names a web crawler, an automated collection tool, or the robots exclusion protocol.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Unofficial English translation of the Cybercrime Law, Law No. 17 of 2023, published by the Jordan Open Source Association (JOSA)
Arabic is the statute's authentic language and an official Arabic or English text was not independently read within this visit's tools

Back to the example  ·  Lint your app