Law note · Jordan
Personal Data Protection Law, sensitive personal data and biometric data
What it requires
- An app that processes biometric data about an individual in Jordan, including a faceprint or voiceprint, must treat it as Sensitive Personal Data and obtain consent or rely on one of the Law's enumerated exceptions, and must not retain it beyond the processing purpose unless legislation specifies otherwise; this document does not confirm whether Jordan requires a heightened, explicit-consent standard specifically for biometric processing beyond ordinary consent.
When LexLint raises it
processes_biometricsprocesses_voicecrawls_webtrains_models
What we found
Biometric data is explicitly named within the Sensitive Personal Data definition, alongside origin, race, political opinions, religious beliefs, financial status, health, physical or mental condition, genetic data, criminal record, and any information deemed sensitive by regulation, the same structural pattern as the UAE and Saudi Arabia.
Unlike the UAE, Oman, and ADGM statutes, no standalone "Biometric Data" definition with worked examples was found, the same lighter-touch pattern found in Saudi Arabia's Art. 1(11).
Processing Sensitive Personal Data, including biometric data, falls under the same consent-plus-enumerated-exceptions structure as general personal data; whether a heightened, explicit-consent standard specifically applies to sensitive or biometric processing (as in Bahrain and Saudi Arabia) was not independently confirmed in this research pass. The general storage-limitation principle applies to biometric data as much as any other category, though it is not biometric-specific.