Law / Jordan

Jordan

privacy

Jordan's Personal Data Protection Law (Law No. 24 of 2023, PDPL) was read in full at primary source, a bilingual official Ministry of Digital Economy and Entrepreneurship document, untruncated. This is the best-documented commencement structure in the batch: the Law was published in the Official Gazette 17 September 2023, entered into force 17 March 2024, and Article 23, read verbatim, confirms entities must adjust their affairs within one year of the effective date, ending 17 March 2025.

Biometric data is explicitly named within the Sensitive Personal Data definition, the same structural pattern as the UAE and Saudi Arabia, but unlike them Jordan has no standalone "Biometric Data" definition with worked examples, the same lighter-touch pattern found in Saudi Arabia.

No adequacy test, whitelist, or data-localization requirement was found anywhere in the untruncated text for cross-border transfer; Article 14's consent-plus-conditions structure reads as more permissive than the carried strict seed.

Jordan is the clearest case in this batch of a statute naming the data subject as a party with standing to seek a remedy: Article 20(B) makes a Controller liable to compensate the affected Data Subject for a breach caused by gross negligence or misconduct, and Article 22(B) lets "the affected party" petition the court for a data-destruction or database-cancellation remedy following a criminal conviction.

Both are narrower than a blanket private right of action, tied to specific triggers rather than framed as a freestanding tort claim.

12 instruments named 6 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Personal Data Protection Law, breach notification

cite Law No. 24 of 2023, Art. 20 stage IN FORCE in force since 2024-03-17 binds public and private bodies source official bilingual statute text, Ministry of Digital Economy and Entrepreneurship
What it requires

Article 20(A) requires the Controller, on discovering a serious breach of data security and safety that could cause significant harm to the Data Subject, to notify the affected Data Subjects within 24 hours of discovery, and to notify the Unit (MoDEE's internal data-protection unit) within 72 hours of discovery about the breach's source, mechanism, affected Data Subjects, and any other available related information. This is a materiality-gated duty with two distinct fixed timelines.

Article 20(B) separately makes the Controller liable to compensate the affected Data Subject in case of gross negligence or misconduct, a direct statutory compensation right tied to a breach.

Comprehensive regime

Personal Data Protection Law, comprehensive regime and lawful basis

cite Law No. 24 of 2023, Arts. 1-2, 11 stage IN FORCE in force since 2024-03-17 binds public and private bodies source official bilingual statute text, Ministry of Digital Economy and Entrepreneurship
What it requires

The Personal Data Protection Law, 23 articles, is Jordan's first comprehensive personal-data statute.

Processing generally requires consent, with an enumerated list of alternative lawful bases covering medical necessity, vital-interest protection, crime prevention and prosecution, statutory or court-ordered disclosure, Central Bank-supervised entity functions, regulation-specified cases, scientific or historical research, statistical, national-security, or public-interest purposes, and publicly available data.

A Controller must appoint a data-protection lead in specified cases, including when processing Sensitive Personal Data or transferring to databases outside the Kingdom (Art. 11(A)(5)). A general storage-limitation principle applies to all processing: data "shall not be retained after the purpose of the Processing is fulfilled, unless otherwise specified by legislation."

Cross border transfer

Personal Data Protection Law, cross-border transfer

cite Law No. 24 of 2023, Art. 14 stage IN FORCE in force since 2024-03-17 binds public and private bodies source official bilingual statute text, Ministry of Digital Economy and Entrepreneurship
What it requires

No adequacy test, whitelist, or data-localization requirement was found anywhere in the untruncated text, searched directly for "adequate," "localiz," and "stored within the Kingdom" with zero hits.

Article 14 sets a general transfer or exchange-to-a-recipient rule, not framed specifically as cross-border, requiring the Data Subject's consent plus three conditions: legitimate interest of both parties, the Data Subject having sufficient knowledge of the purpose, and no use for marketing without separate consent, with a record-keeping duty on the Controller and a carve-out for public-entity-to-public-entity transfers.

This reads as a consent-based transfer regime rather than an adequacy-gated one on the primary text alone, more permissive in structure than the carried strict seed; it remains possible that unread implementing regulations supply a stricter, cross-border-specific rule the base Law defers to, a deferral pattern also seen in Oman.

Data subject rights

Personal Data Protection Law, data subject rights

cite Law No. 24 of 2023, data subject rights list stage IN FORCE in force since 2024-03-17 binds public and private bodies source official bilingual statute text, Ministry of Digital Economy and Entrepreneurship
What it requires

A numbered rights list confirms, read verbatim: erasure or concealment of data (item 5), objection to processing and profiling that are unnecessary, excessive, discriminatory, prejudiced, or unlawful for the purposes collected (item 6), transfer of a copy of the data from one controller to another, i.e. portability (item 7), and being notified of any data breach or violation regarding the security and integrity of the data (item 8).

Items 1-4 of the same list, likely including access and correction rights, were not individually extracted in this research pass, though the numbering implies they exist.

Enforcement supervision

Personal Data Protection Law, enforcement and data subject remedies

cite Law No. 24 of 2023, Arts. 21-22 stage IN FORCE in force since 2024-03-17 binds public and private bodies source official bilingual statute text, Ministry of Digital Economy and Entrepreneurship
What it requires

Article 21 is administrative: for a violation, the Unit issues a warning first, and if uncured, the Council may impose licence suspension or revocation, or a fine up to 500 Dinars per day of continuing violation, capped at 3% of the violator's prior-fiscal-year annual revenue, and the Unit may publish a statement of proven violations at the violator's expense.

Article 22 is criminal-adjacent: a fine of 1,000 to 10,000 Dinars, doubled on repeat violation, without prejudice to any stricter penalty elsewhere in Jordanian law. Article 22(B), read verbatim, lets the relevant court, on request of the public prosecution, the affected party, or its own initiative, order the destruction of data or the cancellation of a database following a final conviction, naming the affected data subject as a party with standing to petition alongside the public prosecution.

Combined with Article 20(B)'s compensation clause, Jordan is the clearest case in this batch of a statute naming the data subject as a party with standing to seek a remedy, though neither clause is a freestanding tort-style private right of action: both are narrower and tied to specific triggers, compensation for gross-negligence breach harm, and a court petition following a criminal conviction, rather than a blanket civil cause of action.

Sensitive categories

Personal Data Protection Law, sensitive personal data and biometric data

cite Law No. 24 of 2023, Art. 2 definitions stage IN FORCE in force since 2024-03-17 binds public and private bodies source official bilingual statute text, Ministry of Digital Economy and Entrepreneurship
What it requires

Biometric data is explicitly named within the Sensitive Personal Data definition, alongside origin, race, political opinions, religious beliefs, financial status, health, physical or mental condition, genetic data, criminal record, and any information deemed sensitive by regulation, the same structural pattern as the UAE and Saudi Arabia.

Unlike the UAE, Oman, and ADGM statutes, no standalone "Biometric Data" definition with worked examples was found, the same lighter-touch pattern found in Saudi Arabia's Art. 1(11).

Processing Sensitive Personal Data, including biometric data, falls under the same consent-plus-enumerated-exceptions structure as general personal data; whether a heightened, explicit-consent standard specifically applies to sensitive or biometric processing (as in Bahrain and Saudi Arabia) was not independently confirmed in this research pass. The general storage-limitation principle applies to biometric data as much as any other category, though it is not biometric-specific.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.