Jordan Draft Personal Data Protection Law (2022)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
JO PDPL Breach Notification
Article 19 of the Jordan PDPL establishes the Personal Data Breach Notification framework. (1) Personal Data Breach Definition: (a) Breach of security leading to accidental or unlawful (i) destruction; (ii) loss; (iii) alteration; (iv) unauthorised disclosure; (v) access to personal data; (b) Covers all data states - at rest + in transit + in use; (c) Covers both technical (cyber) + human (insider + negligence) + physical (theft + loss); (d) Covers controller + processor breaches. (2) Council Notification Duty: (a) Notification required to Personal Data Protection Council without undue delay; (b) Where feasible within 72 HOURS of becoming aware; (c) If delayed beyond 72 hours - reasons must accompany notification; (d) Phased notification allowed if full information not available; (e) Ongoing updates as investigation progresses. (3) Notification Information Required per Article 19: (a) Na
- Breach detection + SIEM/DLP/EDR/insider + records + per incident + audit trail
- Council notification + 72-hour + Article 19 + records + per breach + phased updates
- Subject notification + high-risk + records + per breach + clear Arabic language
- Breach documentation + ALL breaches + records + audit-ready + Council inspection
- Processor notification + Article 14 + records + per sub-processor + escalation
- Breach detection passive (manual reports only)
- Council notification beyond 72 hours without explanation
- Subject notification skipped (high-risk underestimated)
- Documentation only for notified breaches
- Processor notification absent in contracts
JO PDPL Council + MoDEE
Articles 4-6 of the Jordan PDPL establish the Personal Data Protection Council (Majlis Himayat al-Bayanat al-Shakhsiyya مجلس حماية البيانات الشخصية) as the primary regulatory authority. (1) Article 4 Establishment: (a) Council established as independent regulatory body; (b) Affiliated with Ministry of Digital Economy and Entrepreneurship (MoDEE); (c) Legal personality + independent budget; (d) Authority over public + private sector controllers and processors; (e) Reports annually to Prime Minister and House of Representatives. (2) Article 5 Composition: (a) Chair appointed by Council of Ministers on Prime Minister recommendation; (b) Term 4 years renewable; (c) Members include - Government representatives (Justice + Interior + Foreign Affairs); (d) Private sector representation; (e) Academic representation; (f) Civil society representation; (g) Technical experts (cybersecurity + ICT); (h
- Council registration + notification + records + per establishment + Council awareness
- Investigation cooperation + Article 6 + records + per inquiry + document production
- Compliance Notice response + records + per Notice + remediation + timeline
- Administrative penalty defence + Article 22-23 + records + mitigation evidence
- Code of Conduct + industry + records + per sector + Council approval
- Council registration absent (not on register where required)
- Investigation cooperation defensive (reluctant document production)
- Compliance Notice missed or response inadequate
- Administrative penalty defence unprepared (no mitigation evidence)
- Industry Code of Conduct not utilised
JO PDPL Cross-Border + Council Approval
Articles 20-21 of the Jordan PDPL govern cross-border transfers of personal data closely modelled on EU GDPR Chapter V. (1) Article 20 General Prohibition: Cross-border transfer prohibited unless one of these grounds applies (a) Adequacy Determination by Council; (b) Appropriate Safeguards approved by Council; (c) Specific Derogations; (d) Council Authorisation. (2) Adequacy Determinations: (a) Council determines third country provides adequate level of protection; (b) Consideration includes (i) rule of law + respect for human rights; (ii) data protection legislation + enforcement; (iii) supervisory authority independence; (iv) international commitments; (v) Convention 108+ accession; (c) Council has discretion + may issue partial or sectoral adequacy; (d) Emerging Jordan adequacy assessment process + EU EDPB engagement (Jordan as Adequacy candidate); (e) GCC Gulf Cooperation Council coo
- Transfer map + per destination + records + per data flow + per category
- Lawful mechanism + Adequacy/SCC/BCR + records + per transfer + per recipient
- TIA + per transfer + records + per destination + periodic review
- Supplementary measures + encryption/pseudonymisation + records + per transfer
- Council approval + records + per transfer mechanism + per material change
- Transfers without mapping (cloud sprawl)
- Lawful mechanism not chosen per transfer
- TIA absent (Schrems II ignored)
- Supplementary measures not implemented
- Council approval absent or expired
JO PDPL Data Subject Rights
Articles 16-19 of the Jordan PDPL establish comprehensive data subject rights closely modelled on EU GDPR + UAE PDPL + with Arabic legal tradition adaptation. (1) Article 16 Right to Information: (a) Information at point of collection - Privacy Notice content per Article 11; (b) Information about processing throughout lifecycle; (c) Information about rights and how to exercise; (d) Plain Arabic language + accessible; (e) Free of charge for initial information; (f) Just-in-time notice for material changes. (2) Article 17 Right of Access: (a) Right to confirmation whether personal data being processed; (b) Right to copy of personal data; (c) Right to supplementary information (purposes + categories + recipients + retention + rights + sources + automated decision-making); (d) Response within 30 calendar days; (e) Extension up to 60 days for complex requests with notification; (f) Free for f
- DSAR portal + Article 17 + 30-day SLA + records + per request + audit trail
- Rights implementation + Articles 16-19 + 7 rights + records + per type
- Identity verification + proportionate + records + per DSAR + per access level
- Downstream propagation + recipients + records + per action + audit trail
- DPO oversight + escalation + records + per request + decisions
- DSAR portal absent (email-only handling)
- 30-day SLA frequently missed
- Rights implementation incomplete (portability + restriction + objection)
- Identity verification weak (impersonation risk)
- Downstream propagation absent (siloed responses)
JO PDPL Scope + Application
Jordan Personal Data Protection Law (Qanun Himayat al-Bayanat al-Shakhsiyya قانون حماية البيانات الشخصية) No. 24 of 2023 published in the Official Gazette 17 September 2023 + entered into force 17 March 2024 with a 6-month transition period for full compliance expiring 17 September 2024. The Hashemite Kingdom of Jordan's first comprehensive data protection statute + significantly modelled on EU GDPR + UAE PDPL + Saudi PDPL with Arabic legal tradition adaptation. (1) Origin and Draft 2022 History: (a) Draft Personal Data Protection Law circulated for public consultation 2022; (b) Refinements through Ministry of Digital Economy and Entrepreneurship (MoDEE وزارة الاقتصاد الرقمي والريادة) review; (c) Council of Ministers approval; (d) House of Representatives + Senate passage; (e) Royal Decree promulgation; (f) Published Official Gazette 17 September 2023 as Act No. 24 of 2023; (g) Entry int
- Scope assessment + per processing + records + per business unit + per system
- Territorial application + per data subject + Jordan + records + per market
- Definitions mapping + Article 2 + records + per system + per data flow
- Compliance status + 17 September 2024 + records + per controller/processor + audit trail
- Council engagement + records + per inquiry + complaint + cooperation
- Scope misjudged (paper records or out-of-Jordan operations only)
- Extraterritorial application unrecognised (foreign offering to Jordan data subjects)
- Definitions not mapped (sensitive personal data unflagged)
- Compliance status pre-17 September 2024 (enforcement exposure)
- Council engagement absent (no proactive cooperation)
JO PDPL Sensitive Data + Children
Articles 6 and 8 of the Jordan PDPL establish enhanced protections for Sensitive Personal Data and children's data. (1) Article 6 Sensitive Personal Data Categories: (a) Racial or ethnic origin; (b) Political opinion or party membership; (c) Religious beliefs; (d) Philosophical beliefs; (e) Trade union membership; (f) Physical or mental health condition (medical records + treatments + diagnoses + medications); (g) Genetic data (DNA + heritability + family genetic conditions); (h) Biometric data (fingerprint + facial recognition + iris + voice + behavioural); (i) Sexual life + sexual orientation; (j) Criminal convictions + offences + arrests; (k) Any other category Council specifies through regulation. (2) Sensitive Data Processing Conditions per Article 6 (PROHIBITED unless one applies): (a) Explicit Consent of data subject (heightened consent standard - specific to sensitive data + info
- Sensitive data inventory + Article 6 + 11+ categories + records + per system
- Lawful basis sensitive + Article 6 + records + per processing + per condition
- Explicit consent sensitive + heightened + records + per subject + per category + audit
- Children age verification + Article 8 + records + per service + per touchpoint
- Parental consent + under 16 + records + per child + verification mechanism
- Sensitive data uncategorised (treated as general)
- Lawful basis sensitive same as general (Article 6 not applied)
- Explicit consent same as general consent (no heightened standard)
- Children age not verified (adult treatment by default)
- Parental consent absent for under-16
JO PDPL Standard 1 - Lawful Basis
Article 7 of the Jordan PDPL establishes the lawful basis requirement for all processing of personal data. (1) Lawful Basis Categories per Article 7: (a) Consent of data subject (freely given + specific + informed + unambiguous); (b) Necessary for performance of contract to which data subject is party + or for steps requested prior to contract; (c) Necessary for compliance with legal obligation to which controller is subject; (d) Necessary to protect vital interests of data subject or another natural person (life/limb); (e) Necessary for performance of task in public interest or exercise of official authority; (f) Necessary for legitimate interests of controller or third party (except where overridden by fundamental rights of data subject). (2) Consent Requirements: (a) Freely Given - not bundled with non-essential conditions; (b) Specific - to defined purposes; (c) Informed - data subje
- Lawful basis register + per processing + Article 7 + records + per activity
- Consent records + audit trail + withdrawal mechanism + records + per data subject + version
- Privacy Notice + Article 11 + identity/purpose/rights + records + per touchpoint + Arabic
- Sensitive data conditions + Article 6 + explicit consent + records + per category
- Parental consent + under 16 + Article 8 + age verification + records + per child
- Lawful basis selected after processing (consent bias)
- Consent records weak (bundled + pre-ticked)
- Privacy Notice English-only (no Arabic)
- Sensitive data without Article 6 explicit conditions
- Children's age verification + parental consent absent
JO PDPL Training + Penalties
Articles 22-24 of the Jordan PDPL establish the comprehensive penalty + enforcement framework. (1) Article 22 Administrative Violations - Standard: (a) Violations of general processing obligations; (b) Privacy Notice failures; (c) ROPA failures; (d) Lawful basis missing or inadequate; (e) Penalty range JOD 1,000 to JOD 50,000 per violation; (f) Considerations - nature + gravity + duration + intentional/negligent + mitigation + responsibility + previous + cooperation + categories of data + harm. (2) Article 23 Severe Violations - Heightened: (a) Processing of sensitive personal data without legal basis; (b) Violation of children's data protections; (c) Cross-border transfer without authorisation; (d) Failure to notify breach; (e) Failure to enable data subject rights; (f) Repeated standard violations; (g) Willful or grossly negligent conduct; (h) Penalty range JOD 50,000 to JOD 100,000 pe
- Penalty risk assessment + per article + records + per processing + quantified
- Reasonable care defence + records + per control + audit trail + training records
- D and O liability + Article 24 + insurance + records + per director/officer + Board
- Training + annual mandatory + role-based + records + per personnel + completion + refresher
- Board reporting + privacy risk statement + records + per quarter + Audit Committee
- Penalty risk not quantified (Board unaware of JOD 100K-200K exposure)
- Reasonable care defence undocumented
- D and O insurance excludes privacy claims
- Training generic + completed once only
- Board reporting infrequent or absent
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Jordan Draft Personal Data Protection Law (2022) framework page.