Under Jordan's PDPL, all organizations processing personal data of individuals residing in Jordan must obtain explicit verifiable consent, establish statutory security measures, report data breaches to the Data Protection Board within 72 hours, and comply with strict cross-border data transfer restrictions.
1. Scope and Extraterritorial Reach of the PDPL
Jordan enacted the Personal Data Protection Law (Law No. 24 of 2023) to align the country’s digital economy with international benchmarks such as the EU GDPR. The law applies to any processing of personal data inside Jordan, as well as extraterritorial processing conducted by foreign entities targeting individuals residing in the Hashemite Kingdom.
2. Lawful Grounds for Processing & Explicit Consent
Processing personal data is unlawful under the PDPL unless based on explicit, informed, and documented prior consent from the data subject, or one of the narrow statutory exemptions (e.g. performance of a contract to which the data subject is a party, legal compliance, or legitimate public interest).
3. Cross-Border Data Transfers & Server Localization
Transferring personal data outside the Kingdom requires that the recipient country provides an adequate level of data protection, or that specific regulatory authorization is granted by the Personal Data Protection Board upon execution of standard contractual clauses and binding corporate rules.
This content is provided for general informational purposes only and does not constitute formal legal advice. For specific mandates, consult our attorneys directly.
Layla Mansour
Partner | Head of Technology, IP & Employment
Layla is a partner specializing in technology transactions, data privacy under Jordan's PDPL, intellectual property strategy, and corporate employment structuring, counseling leading tech hubs and multinational brands.
View Full Profile