Where the dates stand

The law was published in the Official Gazette in September 2023 and came into effect in March 2024, with a one-year transition for existing organisations. That transition ended in March 2025. There is no grace period left to wait out.

It applies to you if you process personal data in Jordan, and personal data means far more than a national ID number. Employee records, CVs from people you did not hire, customer phone numbers, CCTV footage, the WhatsApp group you use to coordinate deliveries — all of it counts.

Six things you actually need

Not a compliance programme. Six things, most of which a competent person can put in place in a few weeks.

1. A register of what you hold

One document listing what personal data you hold, why you hold it, where it lives, who can see it and how long you keep it. It is unglamorous and it is the foundation of everything else, because you cannot protect or delete what you have not written down. Most companies discover during this exercise that they hold employee data in four places nobody remembered.

2. A lawful reason for having it — and real consent where you need it

Consent has to be given, not assumed. This bites hardest on marketing: sending offers to a list you bought, or to people who once bought something from you years ago, is the most common exposure we find in an ordinary company.

3. A data protection officer, if you trigger the criteria

The criteria catch more companies than people expect. You need one if processing personal data is your main activity, if you handle sensitive data, if you process financial information, or if you transfer data outside Jordan. That last one applies to almost anybody using an overseas cloud service, which is almost everybody. The role does not have to be a full-time hire, but it does have to be a named person with the authority to say no.

4. A breach procedure with the clock written into it

This is the requirement almost nobody has, and it is the tightest. Affected individuals must be notified within 24 hours of the breach being discovered, and the regulator within 72 hours.

Twenty-four hours is not a legal problem. It is a detection problem. You cannot notify inside a day if it takes you a week to realise anything happened, and it usually does. Which means the answer to a legal requirement turns out to be logging, alerting and somebody watching. This is the point where data protection stops being a document exercise and becomes a security one.

5. Contracts with everyone who touches the data for you

Your cloud provider, your external accountant, your payroll bureau, your marketing agency, the developer who still has a copy of the production database on his laptop. Each of them processes personal data on your behalf and each relationship needs terms covering it. The developer’s laptop is not a joke; we find it most times we look.

6. A position on data leaving the country

Transfers to jurisdictions with a lower level of protection are restricted. In practice this means knowing which of your systems store data abroad and being able to explain the basis on which they do.

What it costs to ignore

Administrative fines run to JOD 500 per day, capped at 3% of annual revenue, with criminal penalties in the range of JOD 1,000 to 10,000. For most mid-sized companies the fine is not the real exposure. The real exposure is a customer who asks for your data protection position during a tender, or a breach you have to explain publicly with no procedure to point at.

Five questions to ask yourself this week

  1. If a laptop with employee records were stolen tonight, who would find out, and how long would it take?
  2. Who is allowed to say no to a request for personal data inside this company?
  3. Which of our systems store data outside Jordan, and do we know which ones?
  4. When did we last delete anything, on purpose, on a schedule?
  5. If a customer asked today for our data protection policy, what would we send them?

If four of those five have no answer, you are in the same position as most companies your size in Amman. It is a few weeks of work, not a crisis, but it stops being a few weeks of work the day something goes wrong.

The PDPL work sits under Compliance & Certification. If the exposure you are worried about is what your staff are pasting into AI tools, that is covered separately on the AI page.

Before you rely on this: reconfirm the dates, the DPO criteria, the notification windows and the penalty figures against the published text of Law No. 24 of 2023. This article is a summary, not legal advice.