Back to Frameworks

Jordan Personal Data Protection Law (Law No. 24 of 2023)

Jordan
vPersonal Data Protection Law No. 24 of 2023 (Official Gazette, September 2023), in force six months after publication (March 2024); Data Disclosure Regulation No. 28 of 2025; DPO Accreditation Criteria
5 domains
53 controls

Jordan's Personal Data Protection Law No. 24 of 2023, in force since March 2024, with the Data Disclosure Regulation No. 28 of 2025 and the Council's DPO Accreditation Criteria: prior consent or a listed exception for all processing, eight data subject rights, seven processing requirements, controller security under Council instructions and published complaint procedures, notice before processing, data protection officers in six cases with registration and accreditation, processor duties, consented data sharing with records, transfers abroad only to equivalent protection or six exceptions, breach notice to data subjects within 24 hours and the regulator within 72, and daily fines capped at 3 percent of revenue. Built from the Law's own text.

Verified

Jordan Personal Data Protection Law (Law No. 24 of 2023) is a compliance framework from Jordan with 5 domains and 53 controls that map to 30 other frameworks. The largest domains are Articles 7 to 13: processing requirements and the duties of controllers, processors and data protection officers – Jordan Personal Data Protection Law (Law No. 24 of 2023) (22 controls), Articles 1 to 6: citation, definitions, scope, rights, consent and exceptions – Jordan Personal Data Protection Law (Law No. 24 of 2023) (13 controls), Instruments under the Law: Data Disclosure Regulation No. 28 of 2025 and the DPO Accreditation Criteria – Jordan Personal Data Protection Law (Law No. 24 of 2023) (9 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Articles 1 to 6: citation, definitions, scope, rights, consent and exceptions – Jordan Personal Data Protection Law (Law No. 24 of 2023)

13 controls
Controls in the Articles 1 to 6: citation, definitions, scope, rights, consent and exceptions – Jordan Personal Data Protection Law (Law No. 24 of 2023) domain of Jordan Personal Data Protection Law (Law No. 24 of 2023) — 13 controls
CodeTitle
jordan-personal-data-protection-law-law-no-24-of-2023::4(A)Article 4(A): no processing without prior consent unless the law permits it
jordan-personal-data-protection-law-law-no-24-of-2023::4(B)(1)Article 4(B)(1): the right to know, review, access and obtain the data
jordan-personal-data-protection-law-law-no-24-of-2023::4(B)(2)Article 4(B)(2): the right to withdraw prior consent
jordan-personal-data-protection-law-law-no-24-of-2023::4(B)(3)Article 4(B)(3): the right to correction, amendment, addition or update
jordan-personal-data-protection-law-law-no-24-of-2023::4(B)(4)Article 4(B)(4): the right to restrict processing to a defined scope
jordan-personal-data-protection-law-law-no-24-of-2023::4(B)(5)Article 4(B)(5): the right to erasure or concealment
jordan-personal-data-protection-law-law-no-24-of-2023::4(B)(6)Article 4(B)(6): the right to object to processing and profiling
jordan-personal-data-protection-law-law-no-24-of-2023::4(B)(7)Article 4(B)(7): the right to have a copy of the data transferred from one controller to another
jordan-personal-data-protection-law-law-no-24-of-2023::4(B)(8)Article 4(B)(8): the right to know of any breach of the security and integrity of one's data
jordan-personal-data-protection-law-law-no-24-of-2023::4(C)Article 4(C): exercising rights carries no financial or contractual consequence
jordan-personal-data-protection-law-law-no-24-of-2023::5(A)Article 5(A): conditions for valid prior consent
jordan-personal-data-protection-law-law-no-24-of-2023::5(B)Article 5(B): consent is void if obtained by deception or if the processing changes
jordan-personal-data-protection-law-law-no-24-of-2023::6(B)Article 6(B): no retention after the purpose is fulfilled

Articles 14 and 15: transfers, exchanges and transfers outside the Kingdom – Jordan Personal Data Protection Law (Law No. 24 of 2023)

6 controls
Controls in the Articles 14 and 15: transfers, exchanges and transfers outside the Kingdom – Jordan Personal Data Protection Law (Law No. 24 of 2023) domain of Jordan Personal Data Protection Law (Law No. 24 of 2023) — 6 controls
CodeTitle
jordan-personal-data-protection-law-law-no-24-of-2023::14(A)Article 14(A) and (C): transfer or exchange only with consent, a legitimate interest, informed data subjects and no marketing purpose
jordan-personal-data-protection-law-law-no-24-of-2023::14(B)Article 14(B): records of data transferred or exchanged and of the consents
jordan-personal-data-protection-law-law-no-24-of-2023::14(D)Article 14(D): recipients carry the controller's duties
jordan-personal-data-protection-law-law-no-24-of-2023::14(E)Article 14(E): controller, processor and recipient secure the data and can detect and trace breaches
jordan-personal-data-protection-law-law-no-24-of-2023::15(A)Article 15(A): no transfer outside the Kingdom to a lower level of protection save six cases
jordan-personal-data-protection-law-law-no-24-of-2023::15(B)Article 15(B): verify the recipient's level of protection before transferring

Articles 16 to 25: Council, Unit, breaches, sanctions, transition and bylaws – Jordan Personal Data Protection Law (Law No. 24 of 2023)

3 controls
Controls in the Articles 16 to 25: Council, Unit, breaches, sanctions, transition and bylaws – Jordan Personal Data Protection Law (Law No. 24 of 2023) domain of Jordan Personal Data Protection Law (Law No. 24 of 2023) — 3 controls
CodeTitle
jordan-personal-data-protection-law-law-no-24-of-2023::20(A)(1)Article 20(A)(1): notify affected data subjects within 24 hours of a serious-harm breach
jordan-personal-data-protection-law-law-no-24-of-2023::20(A)(2)Article 20(A)(2): report to the Unit within 72 hours
jordan-personal-data-protection-law-law-no-24-of-2023::23Article 23: existing processors conform within one year of entry into force

Articles 7 to 13: processing requirements and the duties of controllers, processors and data protection officers – Jordan Personal Data Protection Law (Law No. 24 of 2023)

22 controls
Controls in the Articles 7 to 13: processing requirements and the duties of controllers, processors and data protection officers – Jordan Personal Data Protection Law (Law No. 24 of 2023) domain of Jordan Personal Data Protection Law (Law No. 24 of 2023) — 22 controls
CodeTitle
jordan-personal-data-protection-law-law-no-24-of-2023::10Article 10: erasure or concealment on request of the data subject or the Unit
jordan-personal-data-protection-law-law-no-24-of-2023::11(A)Article 11(A): appointing a data protection officer in six cases
jordan-personal-data-protection-law-law-no-24-of-2023::11(B)Article 11(B): the data protection officer's duties
jordan-personal-data-protection-law-law-no-24-of-2023::12(A)Article 12(A): processors process under the Law's requirements
jordan-personal-data-protection-law-law-no-24-of-2023::12(B)Article 12(B): processors keep to the specified purpose and duration
jordan-personal-data-protection-law-law-no-24-of-2023::12(C)Article 12(C): processors erase or return the data at the end of the processing period
jordan-personal-data-protection-law-law-no-24-of-2023::12(D)Article 12(D): processors make neither the data nor the results available except as the law permits
jordan-personal-data-protection-law-law-no-24-of-2023::13Article 13: processed data are confidential
jordan-personal-data-protection-law-law-no-24-of-2023::7(A)Article 7(A): a legitimate, specific and clear purpose
jordan-personal-data-protection-law-law-no-24-of-2023::7(B)Article 7(B): processing consistent with the purposes of collection
jordan-personal-data-protection-law-law-no-24-of-2023::7(C)Article 7(C): processing by lawful and legitimate means
jordan-personal-data-protection-law-law-no-24-of-2023::7(D)Article 7(D): processing based on true, accurate and up-to-date data
jordan-personal-data-protection-law-law-no-24-of-2023::7(E)Article 7(E): no identification of the data subject once the purpose is exhausted
jordan-personal-data-protection-law-law-no-24-of-2023::7(F)Article 7(F): processing must not harm the data subject or impair their rights
jordan-personal-data-protection-law-law-no-24-of-2023::7(G)Article 7(G): confidentiality and integrity of the information
jordan-personal-data-protection-law-law-no-24-of-2023::8(A)Article 8(A): protect the data in custody, including data received from others
jordan-personal-data-protection-law-law-no-24-of-2023::8(B)Article 8(B): security, technical and organisational measures under the Council's instructions
jordan-personal-data-protection-law-law-no-24-of-2023::8(C)Article 8(C): processing and complaint procedures, published on the website
jordan-personal-data-protection-law-law-no-24-of-2023::8(D)Article 8(D): means for data subjects to exercise their rights
jordan-personal-data-protection-law-law-no-24-of-2023::8(E)Article 8(E): correct incomplete or inaccurate data before processing
jordan-personal-data-protection-law-law-no-24-of-2023::8(F)Article 8(F): enable objection, consent withdrawal, access and update by safe means
jordan-personal-data-protection-law-law-no-24-of-2023::9Article 9: written or electronic notice before processing begins

Instruments under the Law: Data Disclosure Regulation No. 28 of 2025 and the DPO Accreditation Criteria – Jordan Personal Data Protection Law (Law No. 24 of 2023)

9 controls
Controls in the Instruments under the Law: Data Disclosure Regulation No. 28 of 2025 and the DPO Accreditation Criteria – Jordan Personal Data Protection Law (Law No. 24 of 2023) domain of Jordan Personal Data Protection Law (Law No. 24 of 2023) — 9 controls
CodeTitle
jordan-personal-data-protection-law-law-no-24-of-2023::DDR-3Data Disclosure Regulation No. 28 of 2025, Article 3: conditions for disclosing data and disclosure without consent
jordan-personal-data-protection-law-law-no-24-of-2023::DDR-4Data Disclosure Regulation No. 28 of 2025, Article 4: the controller answers for disclosures to processors, recipients and authorised persons
jordan-personal-data-protection-law-law-no-24-of-2023::DDR-5Data Disclosure Regulation No. 28 of 2025, Article 5: requests from the data subject, the Unit, courts or authorities
jordan-personal-data-protection-law-law-no-24-of-2023::DPO-3(A)DPO Accreditation Criteria, Article 3(A) and (E): appoint and register the DPO in the Unit's registry
jordan-personal-data-protection-law-law-no-24-of-2023::DPO-3(B)DPO Accreditation Criteria, Article 3(B) to (D): Council approval before appointing a DPO for critical infrastructure; Central Bank accreditation for its supervised entities
jordan-personal-data-protection-law-law-no-24-of-2023::DPO-3(F)DPO Accreditation Criteria, Article 3(F): publish the DPO's contact details
jordan-personal-data-protection-law-law-no-24-of-2023::DPO-4DPO Accreditation Criteria, Article 4: DPO eligibility and internal or external appointment
jordan-personal-data-protection-law-law-no-24-of-2023::DPO-5DPO Accreditation Criteria, Article 5: independence, reporting line, resources, development and involvement
jordan-personal-data-protection-law-law-no-24-of-2023::DPO-6DPO Accreditation Criteria, Article 6: accreditation application, two-year validity, renewal and revocation

Your Compliance Coverage

If you comply with Jordan Personal Data Protection Law (Law No. 24 of 2023), you already cover:

Maps to 30 other frameworks

61 total controls
Vietnam Law on Cybersecurity (No. 116/2025/QH15)
2 source controls mapped|1 target controls covered
3%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
2 source controls mapped|2 target controls covered
3%
Russia Federal Law on Personal Data (152-FZ)
2 source controls mapped|1 target controls covered
3%
Privacy Act 1988 (Australia)
2 source controls mapped|2 target controls covered
3%
Pakistan Personal Data Protection Bill 2023
2 source controls mapped|2 target controls covered
3%
Ecuador Ley Orgánica de Protección de Datos Personales (LOPDP)
2 source controls mapped|1 target controls covered
3%
Law on Personal Data Protection (Official Gazette No. 42/2020)
2 source controls mapped|1 target controls covered
3%
Law No. 172-13 on the Protection of Personal Data
2 source controls mapped|1 target controls covered
3%
ISO/IEC 27400:2022
2 source controls mapped|2 target controls covered
3%
ISO 27799:2025
2 source controls mapped|3 target controls covered
3%
ISO/IEC 27011:2024
2 source controls mapped|3 target controls covered
3%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
2 source controls mapped|2 target controls covered
3%
Azerbaijan Law on Personal Data (2010)
2 source controls mapped|2 target controls covered
3%
Barbados Data Protection Act 2019
2 source controls mapped|2 target controls covered
3%
3%
ISO 26000:2010
2 source controls mapped|1 target controls covered
3%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
2 source controls mapped|5 target controls covered
3%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
2 source controls mapped|3 target controls covered
3%
Bahrain PDPL
2 source controls mapped|2 target controls covered
3%
ISO/IEC 23894:2023
2 source controls mapped|1 target controls covered
3%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
2 source controls mapped|1 target controls covered
3%
GDPR
2 source controls mapped|3 target controls covered
3%
Japan AI Guidelines
2 source controls mapped|1 target controls covered
3%
FTC GLBA Safeguards Rule (16 CFR Part 314)
2 source controls mapped|1 target controls covered
3%
Florida Digital Bill of Rights (FDBR)
2 source controls mapped|1 target controls covered
3%
ASD Strategies to Mitigate Cyber Security Incidents
2 source controls mapped|1 target controls covered
3%
US Consumer Product Safety Act (CPSC) Manufacturer and Importer Duties
2 source controls mapped|1 target controls covered
3%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|1 target controls covered
3%

Coverage is not the same as your position

This page shows what Jordan Personal Data Protection Law (Law No. 24 of 2023) overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is Jordan Personal Data Protection Law (Law No. 24 of 2023) and who does it apply to?

Jordan Personal Data Protection Law (Law No. 24 of 2023) is a compliance framework from Jordan with 5 domains and 53 controls. Jordan's Personal Data Protection Law No. 24 of 2023, in force since March 2024, with the Data Disclosure Regulation No. 28 of 2025 and the Council's DPO Accreditation Criteria: prior consent or a listed exception for all processing, eight data subject rights, seven processing requirements, controller security under Council instructions and published complaint procedures, notice before processing, data protection officers in six cases with registration and accreditation, processor duties, consented data sharing with records, transfers abroad only to equivalent protection or six exceptions, breach notice to data subjects within 24 hours and the regulator within 72, and daily fines capped at 3 percent of revenue. Built from the Law's own text. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Jordan Personal Data Protection Law (Law No. 24 of 2023) actually require?

Jordan Personal Data Protection Law (Law No. 24 of 2023) has 53 controls organised across 5 domains. The largest domains are Articles 7 to 13: processing requirements and the duties of controllers, processors and data protection officers – Jordan Personal Data Protection Law (Law No. 24 of 2023) (22 controls), Articles 1 to 6: citation, definitions, scope, rights, consent and exceptions – Jordan Personal Data Protection Law (Law No. 24 of 2023) (13 controls), Instruments under the Law: Data Disclosure Regulation No. 28 of 2025 and the DPO Accreditation Criteria – Jordan Personal Data Protection Law (Law No. 24 of 2023) (9 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Jordan Personal Data Protection Law (Law No. 24 of 2023) do I already cover?

Jordan Personal Data Protection Law (Law No. 24 of 2023) maps to 30 other compliance frameworks. The top mapping partners are Vietnam Law on Cybersecurity (No. 116/2025/QH15) (3% coverage), Vermont Artificial Intelligence and Consumer Data Act (AICDA) (3% coverage), Russia Federal Law on Personal Data (152-FZ) (3% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Jordan Personal Data Protection Law (Law No. 24 of 2023)?

Start your Jordan Personal Data Protection Law (Law No. 24 of 2023) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Jordan Personal Data Protection Law (Law No. 24 of 2023) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 53 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 705 frameworks.

Get Started Free →

Free forever — no credit card required