Law note · Jordan
Personal Data Protection Law, cross-border transfer
What it requires
- An app transferring or exchanging the personal data of an individual in Jordan with another recipient must obtain the Data Subject's consent, confirm a legitimate interest on both sides, ensure the Data Subject has sufficient knowledge of the purpose, and must not use the data for marketing without a separate consent; Jordan's base Law does not impose an adequacy or localization gate on the transfer.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
What we found
No adequacy test, whitelist, or data-localization requirement was found anywhere in the untruncated text, searched directly for "adequate," "localiz," and "stored within the Kingdom" with zero hits.
Article 14 sets a general transfer or exchange-to-a-recipient rule, not framed specifically as cross-border, requiring the Data Subject's consent plus three conditions: legitimate interest of both parties, the Data Subject having sufficient knowledge of the purpose, and no use for marketing without separate consent, with a record-keeping duty on the Controller and a carve-out for public-entity-to-public-entity transfers.
This reads as a consent-based transfer regime rather than an adequacy-gated one on the primary text alone, more permissive in structure than the carried strict seed; it remains possible that unread implementing regulations supply a stricter, cross-border-specific rule the base Law defers to, a deferral pattern also seen in Oman.