Back to blog

Jordan's Data Protection Law (No. 24/2023) — Complete Guide for Businesses

Jordan's Personal Data Protection Law No. 24 of 2023 reshapes how organisations collect, use, and transfer personal data. This guide explains the law's core concepts, obligations, penalties, and the practical steps your business should take now to reach compliance.

May 20, 202611 min readBy Digital Protection Technologies

For years, businesses in Jordan handled personal data under a patchwork of sector-specific rules and constitutional privacy principles, with no single comprehensive statute governing how organisations collect, store, and share information about individuals. That changed with the enactment of the Personal Data Protection Law No. 24 of 2023, the first dedicated data protection law Jordan has adopted at the national level. The law establishes clear obligations for organisations, meaningful rights for individuals, and a supervisory framework to enforce both.

This guide walks through what the law covers, the terms every organisation needs to understand, the legal grounds for processing personal data, the rights it grants to individuals, the rules for transferring data outside Jordan, and the concrete actions your business should take now. It is written for decision-makers and compliance teams who need a practical orientation rather than a line-by-line legal commentary. It is not legal advice: always verify specific requirements and article numbers against the official text published in the Official Gazette, and consult Digital Protection Technologies for guidance on your particular situation.

Overview of the Personal Data Protection Law No. 24 of 2023

The Personal Data Protection Law No. 24 of 2023 sets out a general framework for the lawful processing of personal data in Jordan. It applies broadly to organisations that collect and use information about identifiable individuals, whether those organisations operate in the public or private sector. The law introduces principles that will be familiar to anyone who has worked with modern privacy regimes: personal data must be processed lawfully and fairly, collected for specified and legitimate purposes, kept accurate, retained only as long as necessary, and protected by appropriate security measures.

Rather than replacing every existing sectoral rule, the law functions as an overarching baseline. Organisations already regulated by the Central Bank of Jordan, telecommunications authorities, or health-sector rules must read the new law alongside those obligations. For a closer look at how banking and payment institutions should align, see our guide on Central Bank of Jordan data protection compliance.

Key Definitions Every Organisation Should Know

Understanding the law starts with its vocabulary. The definitions determine who bears which obligations and which data attracts stronger protection. The terms below reflect the substance of the law's provisions; you should confirm the exact statutory wording against the published text.

Personal data

Personal data means any information relating to an identified or identifiable natural person. This includes obvious identifiers such as a name, national number, address, phone number, or email, as well as data that can identify a person when combined with other information, such as location data or online identifiers.

Sensitive or special-category data

The law gives heightened protection to certain categories of especially sensitive information, commonly described as sensitive or special-category data. This typically covers data revealing health conditions, genetic or biometric information, racial or ethnic origin, religious or political beliefs, and data concerning criminal records. Processing this data usually requires stronger justification and additional safeguards.

Data controller and data processor

A data controller is the entity that determines the purposes and means of processing personal data; it decides why and how the data is used. A data processor is a party that processes personal data on the controller's behalf, such as a cloud hosting provider, payroll bureau, or marketing agency. The distinction matters because controllers carry the primary accountability, while processors have their own obligations and must act only on documented instructions.

Consent

Consent is one of the legal grounds for processing and, where relied upon, must generally be a freely given, specific, and informed expression of the individual's agreement to the processing of their data. Consent obtained through pre-ticked boxes, bundled terms, or coercion is unlikely to meet the standard. Crucially, individuals must be able to withdraw consent as easily as they gave it.

Lawful Basis for Processing: Consent and Its Exceptions

Jordan's law takes a consent-first approach that sets it apart from some other regimes. Under Article 4/A, processing personal data requires the data subject's prior consent, unless the processing falls within a case permitted by law. In other words, consent is the default legal basis, and an organisation that cannot point to a specific statutory exception must obtain valid consent before it processes personal data.

Article 6/A sets out the specific situations in which personal data may be processed lawfully without the data subject’s prior consent. These exceptions are narrow and purpose-bound. They cover the following cases:

  • Processing by a competent public entity where necessary to carry out tasks legally assigned to it.
  • Processing for preventive medical purposes, medical profiling, or the provision of healthcare by a licensed practitioner or medical institution.
  • Processing necessary to protect the life or vital interests of the data subject.
  • Processing necessary to prevent, detect, disclose, or prosecute a crime, carried out by a competent authority.
  • Processing required or permitted by legislation in force or by a decision of a competent court.
  • Processing by entities subject to Central Bank of Jordan supervision in performing their functions as determined by the Central Bank, including transferring or exchanging data inside or outside the Kingdom (Article 6/A/6).
  • Processing carried out under regulations issued pursuant to the law.
  • Processing for scientific or historical research, provided the results are not used to take decisions or measures against a specific person.
  • Processing for statistical purposes, national security, or a public interest recognised by law.
  • Processing of personal data that the data subject has deliberately made available to the public.

Note an important gap for organisations used to the EU model: the law provides no general “legitimate interests” basis and no standalone “performance of a contract” basis for ordinary processing. Legitimate interest appears in the law only in a narrow role — as one of the conditions that can justify a cross-border data transfer under Article 14 — not as a general ground for processing. Choosing and documenting the correct basis is therefore a strategic decision; a structured privacy and regulatory compliance review can help you map each activity to consent or to a specific Article 6/A exception. Verify the exact wording of these provisions against the Official Gazette text.

Data Subject Rights

A defining feature of the law is the set of enforceable rights it grants individuals over their own data. Article 4/B gives the data subject eight rights, and organisations must be able to recognise, verify, and respond to these requests within the timeframes the law and its regulations set. The eight rights are:

  • The right to be aware of and access their personal data, including whether it is being processed and how it is used.
  • The right to withdraw consent to processing.
  • The right to correct, amend, add to, or update their personal data.
  • The right to restrict processing of their data to a specific scope.
  • The right to have their personal data erased or concealed.
  • The right to object to the processing of their data or to profiling.
  • The right to obtain a copy of their personal data and transfer it from one controller to another (data portability).
  • The right to be notified of any breach affecting their personal data.

Meeting these obligations requires more than good intentions. You need reliable identity verification, searchable records of where personal data lives, and defined internal workflows so that a request received by one team does not stall. Weaknesses in these processes are often exposed only when the first serious request arrives, which is why a proactive security risk and exposure assessment is valuable before problems surface.

Data Breach Notification (Article 20)

Article 20 sets firm timelines for responding to a serious personal data breach. The controller must notify the affected data subjects within 24 hours of becoming aware of a breach that seriously threatens their personal data, and must notify the Personal Data Protection Unit within 72 hours. Where a breach results from the controller’s gross negligence or misconduct, the controller is liable to compensate those who suffer harm. Organisations therefore need an incident response process that can detect, assess, and escalate a breach quickly enough to meet the 24-hour and 72-hour deadlines. Verify the current wording and any implementing rules against the Official Gazette.

Cross-Border Data Transfer Rules

Many organisations in Jordan rely on international cloud services, group companies abroad, or overseas processors, so the rules on transferring personal data outside the country are among the most commercially significant parts of the law. In broad terms, the law restricts transfers of personal data outside Jordan unless appropriate conditions are met to ensure the data continues to receive an adequate level of protection.

In practice this means an organisation must assess the destination country and recipient, put in place suitable safeguards such as contractual protections, and in some cases obtain consent or approval before exporting data. Because the precise mechanisms and any list of approved destinations are set out in the law and its implementing regulations, you should verify the current requirements against the official text before relying on any particular transfer route. Reviewing your vendor and intra-group arrangements through network and application security controls and contractual safeguards helps ensure transfers remain defensible.

The Supervisory Body and Enforcement

Oversight of the law sits within the framework of the Ministry of Digital Economy and Entrepreneurship. The law provides for a supervisory body, commonly referred to as the Personal Data Protection Council or unit, responsible for issuing guidance, receiving complaints, investigating violations, and overseeing enforcement. Organisations should treat this body as the primary point of reference for registration duties, complaints handling, and any approvals the law may require.

Because the institutional structure, its exact name, and its powers are defined in the statute and subsequent decisions, confirm the current arrangements and any procedural rules against the official published sources rather than relying on summaries.

Penalties for non-compliance (Articles 21 and 22)

The law provides two enforcement tracks. Under Article 21, after a prior warning, the supervisory authority can impose administrative measures, including suspending or revoking the entity’s licence, or a fine of up to 500 Jordanian dinars for each day the violation continues, capped at 3% of the entity’s total annual revenue for the previous fiscal year. Under Article 22, a court may impose a judicial fine of between 1,000 and 10,000 Jordanian dinars, doubled for repeat offences, and may order the destruction of the data or the cancellation of the database. Beyond these penalties, non-compliance carries reputational damage and the loss of customer and partner trust. Confirm the current figures against the Official Gazette text, as they may be amended.

Enforcement Timeline: the Transition Period Has Ended

The law was published in the Official Gazette on 17 September 2023 and came into effect on 17 March 2024. Article 23 granted organisations a one-year transition period to bring their operations into compliance, and that period ended on 17 March 2025. The practical takeaway has changed: this is no longer a grace period to plan around. The deadline has passed, full compliance is now mandatory, and organisations that remain non-compliant are exposed to the enforcement measures described above. Any business that has not yet mapped its data, established a lawful basis for each processing activity, and put breach-response and data subject request processes in place should treat remediation as urgent. Confirm the exact dates and any subsequent ministerial decisions against the official text.

Concrete Steps Your Business Should Take Now

Compliance is a programme of work, not a single document. The following steps form a practical roadmap that most organisations in Jordan can follow, scaled to their size and the sensitivity of the data they handle.

1. Map your data

Begin with a data inventory. Identify what personal data you hold, where it comes from, why you process it, where it is stored, who it is shared with, and how long you keep it. This data mapping exercise underpins almost every other obligation, from responding to access requests to assessing cross-border transfers, and it usually reveals data flows the business did not know existed.

2. Appoint a data protection officer

Assign clear ownership of privacy compliance, whether through an internal data protection officer or an outsourced arrangement. A data protection officer coordinates your compliance programme, acts as a point of contact for individuals and the supervisory body, and keeps the organisation aligned as guidance evolves. Under Article 11/A, appointing a data protection officer is mandatory where any of six triggers applies:

  • The organisation’s primary activity is the processing of personal data.
  • The organisation processes sensitive personal data.
  • The organisation processes the personal data of persons lacking legal capacity.
  • The organisation processes financial information.
  • The organisation transfers personal data to databases located outside the Kingdom.
  • Any other case determined by the Personal Data Protection Council.

Our article on DPO services in Jordan explains how to resource the role, and organisations can support the function with identity and access governance to control who can reach personal data.

3. Update privacy notices

Review the privacy notices you present to customers, employees, and website visitors. They should clearly explain what data you collect, the purposes and legal bases for processing, how long you retain it, who you share it with, and how individuals can exercise their rights. Vague or outdated notices are one of the most visible signs of non-compliance.

4. Review contracts and data processing agreements

Wherever a third party processes personal data on your behalf, your contract should reflect the law's requirements through appropriate data processing clauses covering security, confidentiality, sub-processing, and cooperation on data subject requests. Review both the contracts where you are the controller and those where you act as a processor for others.

5. Carry out transfer assessments

For every flow of personal data outside Jordan, assess the legal basis for the transfer, the protections in the destination, and the safeguards in place. Document these assessments so you can demonstrate that transfers meet the law's conditions, and revisit them when you change vendors or add new cloud services.

6. Train your people

Most data incidents stem from human error rather than sophisticated attacks. Regular, role-appropriate training helps staff recognise personal data, handle it correctly, spot the signs of a breach, and route data subject requests to the right team. Embedding privacy awareness into everyday operations is one of the most cost-effective investments you can make, and it can be reinforced with compliance technology solutions that automate records, consent, and request handling.

How This Fits With Other Frameworks

Jordan's law does not exist in isolation. Organisations that serve customers in Europe should read it alongside their obligations under the EU regime, as explored in our guide to GDPR compliance in Jordan. Those pursuing formal privacy certifications may find that aligning with international standards streamlines compliance, a topic we cover in our overview of ISO 27701 certification in Jordan. Building on a recognised framework often makes local compliance faster and easier to demonstrate.

The Personal Data Protection Law No. 24 of 2023 marks a significant shift in how organisations in Jordan must handle personal data, and the organisations that act early will carry the least disruption and the most trust. Digital Protection Technologies helps businesses in Amman and across Jordan turn these requirements into a clear, prioritised compliance plan, from data mapping and gap assessments to DPO support and privacy notices. To discuss what the law means for your organisation and how to prepare, get in touch with our team.

Frequently asked questions

What is Jordan's data protection law?

It is the Personal Data Protection Law No. 24 of 2023, the first comprehensive national law governing how organisations collect, use, store, and transfer personal data in Jordan. It sets out principles for lawful processing, grants individuals rights over their data, restricts transfers abroad, and establishes a supervisory body under the Ministry of Digital Economy and Entrepreneurship. Organisations in both the public and private sectors fall within its scope.

Who must comply with the law?

The law applies broadly to organisations that process personal data about identifiable individuals, acting as either data controllers or data processors, across the public and private sectors. This includes companies that handle customer, employee, or user data, as well as service providers processing data on behalf of others. Businesses already regulated by sectoral authorities must apply the new law alongside their existing obligations.

Does the law restrict transferring data outside Jordan?

Yes. The law limits cross-border transfers of personal data unless appropriate conditions are met to ensure the data continues to receive adequate protection, which may involve contractual safeguards, an assessment of the destination, or consent or approval. Because the exact mechanisms are set out in the law and its regulations, you should verify the current requirements against the official text before exporting data.

What should my business do first to comply?

Start by mapping your personal data to understand what you hold and how it flows, then assign clear ownership of compliance through a data protection officer. From there, update your privacy notices, review contracts and data processing agreements, assess your cross-border transfers, and train your staff. Digital Protection Technologies can help you turn these steps into a prioritised plan for your organisation.

Need help with your compliance program?

Digital Protection Technologies helps organizations in Jordan meet CBJ, GDPR, and ISO 27701 requirements. Talk to our team for a tailored assessment.

Contact our team