Jordan Draft Personal Data Protection Law (2022)
JO PDPL Scope + Application

Jordan Draft Personal Data Protection Law (2022) JO-PDPL-Scope-Application-Article2-3-Personal-Data-Definition-Hashemite-Kingdom-MoDEE-Council-No24-2023-17March2024: Jordan Personal Data Protection Law (PDPL) No. 24 of 2023 - Scope + Application + Articles 2-3 + Personal Data Definition + Hashemite Kingdom + Ministry of Digital Economy and Entrepreneurship (MoDEE) + Personal Data Protection Council + Effective 17 March 2024 + 6-Month Transition Expired 17 September 2024

Jordan Personal Data Protection Law (Qanun Himayat al-Bayanat al-Shakhsiyya قانون حماية البيانات الشخصية) No. 24 of 2023 published in the Official Gazette 17 September 2023 + entered into force 17 March 2024 with a 6-month transition period for full compliance expiring 17 September 2024. The Hashemite Kingdom of Jordan's first comprehensive data protection statute + significantly modelled on EU GDPR + UAE PDPL + Saudi PDPL with Arabic legal tradition adaptation. (1) Origin and Draft 2022 History: (a) Draft Personal Data Protection Law circulated for public consultation 2022; (b) Refinements through Ministry of Digital Economy and Entrepreneurship (MoDEE وزارة الاقتصاد الرقمي والريادة) review; (c) Council of Ministers approval; (d) House of Representatives + Senate passage; (e) Royal Decree promulgation; (f) Published Official Gazette 17 September 2023 as Act No. 24 of 2023; (g) Entry into force 17 March 2024 + 6-month transition completion 17 September 2024. (2) Article 2 Definitions: (a) Personal Data (al-Bayanat al-Shakhsiyya البيانات الشخصية) - any information relating to identified or identifiable natural person whether direct or indirect; (b) Sensitive Personal Data (Article 6) - health + genetic + biometric + racial + ethnic + religious + philosophical + political + trade union + sexual life + sexual orientation + criminal convictions; (c) Data Subject (Sahib al-Bayanat صاحب البيانات) - natural person to whom personal data relate; (d) Data Controller (Al-Mutahakim al-Bayanat المتحكم بالبيانات) - person determining purposes and means; (e) Data Processor (Al-Mu'alij al-Bayanat المعالج بالبيانات) - person processing on behalf of controller; (f) Processing - operations on personal data including collection + use + storage + organisation + transmission + disclosure + erasure; (g) Consent - freely given specific informed unambiguous indication; (h) Personal Data Breach - security breach causing accidental or unlawful destruction + loss + alteration + unauthorised disclosure or access. (3) Article 3 Scope and Application: (a) Material Scope - applies to processing of personal data of natural persons whether automated or non-automated; (b) Territorial Scope - applies to (i) processing in context of activities of controller/processor established in Jordan; (ii) processing of personal data of data subjects in Jordan by controller/processor not established in Jordan where related to offering goods/services to data subjects in Jordan or monitoring behaviour in Jordan; (c) Excluded - (i) processing by natural persons in course of purely personal or household activity; (ii) certain national security + law enforcement subject to safeguards; (iii) journalism + literary + artistic with public interest. (4) Personal Data Protection Council (Majlis Himayat al-Bayanat al-Shakhsiyya مجلس حماية البيانات الشخصية) per Articles 4-6: (a) established as independent regulatory body affiliated with MoDEE; (b) Chair appointed by Council of Ministers; (c) Members from Government + Private + Academia + Civil Society; (d) Functions - issue regulations + monitor compliance + investigate complaints + issue administrative penalties + cooperate internationally; (e) Powers - access information + premises inspection + interview + corrective orders + administrative penalties up to JOD 100,000 + JOD 200,000 for repeated violations. (5) Ministry of Digital Economy and Entrepreneurship (MoDEE) Coordination: (a) sponsoring ministry for PDPL; (b) Digital Economy Strategy 2021-2025 integration; (c) e-Government services + Sanad National Digital ID; (d) Cybersecurity National Centre coordination; (e) Coordination with Telecommunications Regulatory Commission (TRC). (6) International Influences + Coordination: (a) EU GDPR Regulation 2016/679 (significant alignment); (b) UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021); (c) Saudi Personal Data Protection Law (Royal Decree M/19 of 1443); (d) Kuwait Data Privacy Protection Regulation 2021; (e) Bahrain PDPL 30 of 2018; (f) Council of Europe Convention 108+ (Jordan accession candidate); (g) Arab Convention on Combatting Information Technology Offences. (7) Constitutional Anchor: (a) Jordan Constitution 1952 (amended) Article 7 personal liberty + Article 18 inviolability of correspondence; (b) Jordan Universal Declaration of Human Rights ratification; (c) International Covenant on Civil and Political Rights (ICCPR) ratification + Article 17 privacy. (8) Sectoral Coordination: (a) Central Bank of Jordan financial sector cybersecurity + customer data; (b) Telecommunications Regulatory Commission (TRC); (c) Jordan Securities Commission; (d) Ministry of Health for health data + JCI compliance; (e) Ministry of Education for student data; (f) Department of Civil Status and Passports for identity data + Personal Number; (g) Department of Lands and Survey for property data. (9) AML/CFT Coordination: (a) Anti-Money Laundering and Counter-Financing of Terrorism Act 2007 + Anti-Money Laundering Unit; (b) FATF MENAFATF member; (c) Banking secrecy + AML data sharing balance; (d) Customer Due Diligence (CDD) records. (10) Penalties Framework per Articles 22-24: (a) Article 22 administrative violations - JOD 1,000 to JOD 50,000 per violation; (b) Article 23 severe violations - JOD 50,000 to JOD 100,000; (c) Article 24 repeat violations - doubled penalties + license revocation; (d) Criminal liability for willful + gross negligence - imprisonment up to 3 years + JOD 200,000 fine; (e) Article 23 dispute resolution + civil compensation. Coordinates with EU GDPR + UAE PDPL + Saudi PDPL + Kuwait DPL + Bahrain PDPL + Council of Europe Convention 108+ + ICCPR Article 17 + Jordan Constitution Articles 7 + 18 + Anti-Money Laundering Act 2007 + Jordan AML Unit + FATF MENAFATF + Central Bank of Jordan + Telecommunications Regulatory Commission + Jordan Securities Commission + Sanad National Digital ID + Cybersecurity National Centre + Arab Convention on Cybercrime + ISO/IEC 27701 PIMS + ISO/IEC 29100 Privacy Framework. Jordan PDPL Scope + Application + Articles 2-3 + Personal Data Protection Council apply.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.