Law note · Jordan

Personal Data Protection Law, cross-border transfer

cite Law No. 24 of 2023, Art. 14 stage IN FORCE in force since 2024-03-17 kind Cross border transfer binds public and private bodies reviewed 2026-08-29

What it requires

  • An app transferring or exchanging the personal data of an individual in Jordan with another recipient must obtain the Data Subject's consent, confirm a legitimate interest on both sides, ensure the Data Subject has sufficient knowledge of the purpose, and must not use the data for marketing without a separate consent; Jordan's base Law does not impose an adequacy or localization gate on the transfer.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

No adequacy test, whitelist, or data-localization requirement was found anywhere in the untruncated text, searched directly for "adequate," "localiz," and "stored within the Kingdom" with zero hits.

Article 14 sets a general transfer or exchange-to-a-recipient rule, not framed specifically as cross-border, requiring the Data Subject's consent plus three conditions: legitimate interest of both parties, the Data Subject having sufficient knowledge of the purpose, and no use for marketing without separate consent, with a record-keeping duty on the Controller and a carve-out for public-entity-to-public-entity transfers.

This reads as a consent-based transfer regime rather than an adequacy-gated one on the primary text alone, more permissive in structure than the carried strict seed; it remains possible that unread implementing regulations supply a stricter, cross-border-specific rule the base Law defers to, a deferral pattern also seen in Oman.

← Back to the example  ·  Lint your app →