Article 19 of the Jordan PDPL establishes the Personal Data Breach Notification framework. (1) Personal Data Breach Definition: (a) Breach of security leading to accidental or unlawful (i) destruction; (ii) loss; (iii) alteration; (iv) unauthorised disclosure; (v) access to personal data; (b) Covers all data states - at rest + in transit + in use; (c) Covers both technical (cyber) + human (insider + negligence) + physical (theft + loss); (d) Covers controller + processor breaches. (2) Council Notification Duty: (a) Notification required to Personal Data Protection Council without undue delay; (b) Where feasible within 72 HOURS of becoming aware; (c) If delayed beyond 72 hours - reasons must accompany notification; (d) Phased notification allowed if full information not available; (e) Ongoing updates as investigation progresses. (3) Notification Information Required per Article 19: (a) Nature of the breach (i) categories of affected data subjects + approximate numbers; (ii) categories of personal data records + approximate numbers; (b) DPO contact details; (c) Likely consequences of the breach; (d) Measures taken or proposed to address the breach + mitigate possible adverse effects. (4) Notification to Affected Data Subjects: (a) Where breach likely to result in HIGH RISK to data subject rights and freedoms; (b) Without undue delay; (c) In clear and plain language; (d) Information - nature of breach + DPO contact + consequences + measures; (e) Exemptions - if controller implemented appropriate technical/organisational measures rendering data unintelligible (e.g. encryption); if controller subsequently mitigated risk; if would involve disproportionate effort + public communication instead; (f) Council may require notification if not done. (5) Processor Obligations: (a) Processor must notify controller WITHOUT UNDUE DELAY of breach; (b) Controller then has 72-hour Council SLA; (c) Article 14 processor contract should specify breach notification mechanism; (d) Sub-processor flow-down. (6) Documentation Requirement: (a) ALL breaches documented regardless of notification threshold; (b) Facts + effects + remedial action; (c) Enables Council compliance verification; (d) Supports trend analysis + organisational learning. (7) Risk Assessment for Notification: (a) Likelihood + severity assessment; (b) Factors include - type of breach + nature/sensitivity/volume of data + ease of identification + severity of consequences + special characteristics of subjects (children/vulnerable) + special characteristics of controller; (c) ENISA + EDPB methodology + emerging Jordan guidance; (d) Privacy Risk Score frameworks. (8) Cross-Border Breach Notification: (a) If affected data subjects in multiple jurisdictions - notify each Supervisory Authority; (b) Lead Supervisory Authority concept where applicable; (c) Council liaison with foreign DPAs; (d) GCC + Arab + EU coordination. (9) Breach Response Lifecycle: (a) Detection - SIEM + DLP + EDR + insider threat + user reports; (b) Containment - isolation + access revocation + system shutdown + business continuity; (c) Assessment - scope + impact + risk classification; (d) Notification - Council + subjects + others; (e) Eradication - root cause + fix + patches; (f) Recovery - restore + monitor; (g) Lessons learned - post-mortem + report + improvement. (10) Sector-Specific Notification: (a) Banking + Central Bank of Jordan; (b) Telecom + Telecommunications Regulatory Commission; (c) Health + Ministry of Health; (d) Securities + Jordan Securities Commission; (e) Cybersecurity + Cybersecurity National Centre; (f) AML/CFT + Anti-Money Laundering Unit. (11) Penalties for Notification Failures: (a) Article 22-23 administrative penalties up to JOD 100K; (b) Council escalation; (c) Civil compensation per Article 23; (d) Reputational damage + customer churn; (e) Potential class action. Coordinates with EU GDPR Articles 33 + 34 + UAE PDPL Article 9 + Saudi PDPL Article 14 + Convention 108+ + EDPB/WP29 Guidelines on Personal Data Breach Notification + ENISA Methodology + ISO/IEC 27035 + NIST SP 800-61 + Jordan Cybersecurity National Centre + JoCERT + Central Bank of Jordan + Telecommunications Regulatory Commission + Ministry of Health + Anti-Money Laundering Unit + GCC + Arab cyber breach reporting + International Telecom Union ITU. Jordan PDPL Breach Notification + Article 19 applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.