Law note · Jordan

Personal Data Protection Law, sensitive personal data and biometric data

cite Law No. 24 of 2023, Art. 2 definitions stage IN FORCE in force since 2024-03-17 kind Sensitive categories binds public and private bodies reviewed 2026-08-29

What it requires

  • An app that processes biometric data about an individual in Jordan, including a faceprint or voiceprint, must treat it as Sensitive Personal Data and obtain consent or rely on one of the Law's enumerated exceptions, and must not retain it beyond the processing purpose unless legislation specifies otherwise; this document does not confirm whether Jordan requires a heightened, explicit-consent standard specifically for biometric processing beyond ordinary consent.

When LexLint raises it

  • processes_biometrics
  • processes_voice
  • crawls_web
  • trains_models

What we found

Biometric data is explicitly named within the Sensitive Personal Data definition, alongside origin, race, political opinions, religious beliefs, financial status, health, physical or mental condition, genetic data, criminal record, and any information deemed sensitive by regulation, the same structural pattern as the UAE and Saudi Arabia.

Unlike the UAE, Oman, and ADGM statutes, no standalone "Biometric Data" definition with worked examples was found, the same lighter-touch pattern found in Saudi Arabia's Art. 1(11).

Processing Sensitive Personal Data, including biometric data, falls under the same consent-plus-enumerated-exceptions structure as general personal data; whether a heightened, explicit-consent standard specifically applies to sensitive or biometric processing (as in Bahrain and Saudi Arabia) was not independently confirmed in this research pass. The general storage-limitation principle applies to biometric data as much as any other category, though it is not biometric-specific.

← Back to the example  ·  Lint your app →