Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Law No. 24 of 2023, Art. 20
stage IN FORCE in force since 2024-03-17
binds public and private bodies
source official bilingual statute text, Ministry of Digital Economy and Entrepreneurship
What it requires →
Article 20(A) requires the Controller, on discovering a serious breach of data security and safety that could cause significant harm to the Data Subject, to notify the affected Data Subjects within 24 hours of discovery, and to notify the Unit (MoDEE's internal data-protection unit) within 72 hours of discovery about the breach's source, mechanism, affected Data Subjects, and any other available related information. This is a materiality-gated duty with two distinct fixed timelines.
Article 20(B) separately makes the Controller liable to compensate the affected Data Subject in case of gross negligence or misconduct, a direct statutory compensation right tied to a breach.
Comprehensive regime
cite Law No. 24 of 2023, Arts. 1-2, 11
stage IN FORCE in force since 2024-03-17
binds public and private bodies
source official bilingual statute text, Ministry of Digital Economy and Entrepreneurship
What it requires →
The Personal Data Protection Law, 23 articles, is Jordan's first comprehensive personal-data statute.
Processing generally requires consent, with an enumerated list of alternative lawful bases covering medical necessity, vital-interest protection, crime prevention and prosecution, statutory or court-ordered disclosure, Central Bank-supervised entity functions, regulation-specified cases, scientific or historical research, statistical, national-security, or public-interest purposes, and publicly available data.
A Controller must appoint a data-protection lead in specified cases, including when processing Sensitive Personal Data or transferring to databases outside the Kingdom (Art. 11(A)(5)). A general storage-limitation principle applies to all processing: data "shall not be retained after the purpose of the Processing is fulfilled, unless otherwise specified by legislation."
Cross border transfer
cite Law No. 24 of 2023, Art. 14
stage IN FORCE in force since 2024-03-17
binds public and private bodies
source official bilingual statute text, Ministry of Digital Economy and Entrepreneurship
What it requires →
No adequacy test, whitelist, or data-localization requirement was found anywhere in the untruncated text, searched directly for "adequate," "localiz," and "stored within the Kingdom" with zero hits.
Article 14 sets a general transfer or exchange-to-a-recipient rule, not framed specifically as cross-border, requiring the Data Subject's consent plus three conditions: legitimate interest of both parties, the Data Subject having sufficient knowledge of the purpose, and no use for marketing without separate consent, with a record-keeping duty on the Controller and a carve-out for public-entity-to-public-entity transfers.
This reads as a consent-based transfer regime rather than an adequacy-gated one on the primary text alone, more permissive in structure than the carried strict seed; it remains possible that unread implementing regulations supply a stricter, cross-border-specific rule the base Law defers to, a deferral pattern also seen in Oman.
Data subject rights
What it requires →
A numbered rights list confirms, read verbatim: erasure or concealment of data (item 5), objection to processing and profiling that are unnecessary, excessive, discriminatory, prejudiced, or unlawful for the purposes collected (item 6), transfer of a copy of the data from one controller to another, i.e. portability (item 7), and being notified of any data breach or violation regarding the security and integrity of the data (item 8).
Items 1-4 of the same list, likely including access and correction rights, were not individually extracted in this research pass, though the numbering implies they exist.
Enforcement supervision
cite Law No. 24 of 2023, Arts. 21-22
stage IN FORCE in force since 2024-03-17
binds public and private bodies
source official bilingual statute text, Ministry of Digital Economy and Entrepreneurship
What it requires →
Article 21 is administrative: for a violation, the Unit issues a warning first, and if uncured, the Council may impose licence suspension or revocation, or a fine up to 500 Dinars per day of continuing violation, capped at 3% of the violator's prior-fiscal-year annual revenue, and the Unit may publish a statement of proven violations at the violator's expense.
Article 22 is criminal-adjacent: a fine of 1,000 to 10,000 Dinars, doubled on repeat violation, without prejudice to any stricter penalty elsewhere in Jordanian law. Article 22(B), read verbatim, lets the relevant court, on request of the public prosecution, the affected party, or its own initiative, order the destruction of data or the cancellation of a database following a final conviction, naming the affected data subject as a party with standing to petition alongside the public prosecution.
Combined with Article 20(B)'s compensation clause, Jordan is the clearest case in this batch of a statute naming the data subject as a party with standing to seek a remedy, though neither clause is a freestanding tort-style private right of action: both are narrower and tied to specific triggers, compensation for gross-negligence breach harm, and a court petition following a criminal conviction, rather than a blanket civil cause of action.
Sensitive categories
cite Law No. 24 of 2023, Art. 2 definitions
stage IN FORCE in force since 2024-03-17
binds public and private bodies
source official bilingual statute text, Ministry of Digital Economy and Entrepreneurship
What it requires →
Biometric data is explicitly named within the Sensitive Personal Data definition, alongside origin, race, political opinions, religious beliefs, financial status, health, physical or mental condition, genetic data, criminal record, and any information deemed sensitive by regulation, the same structural pattern as the UAE and Saudi Arabia.
Unlike the UAE, Oman, and ADGM statutes, no standalone "Biometric Data" definition with worked examples was found, the same lighter-touch pattern found in Saudi Arabia's Art. 1(11).
Processing Sensitive Personal Data, including biometric data, falls under the same consent-plus-enumerated-exceptions structure as general personal data; whether a heightened, explicit-consent standard specifically applies to sensitive or biometric processing (as in Bahrain and Saudi Arabia) was not independently confirmed in this research pass. The general storage-limitation principle applies to biometric data as much as any other category, though it is not biometric-specific.