Personal Data Protection: What the Law Means for Your Business
Jordan’s Personal Data Protection Law took effect in March 2024 and its transition period ended in March 2025. And what surprises owners is not the law — it is inventorying their own data.
$59Subscription — one-time, lifetime access
01 — Overview
Overview
When an owner sits down and writes what personal data they actually hold, they find things they never considered: customer numbers on a former employee’s phone, identity document images in old chats, and a file holding the details of everyone who messaged them over five years. You cannot protect what you do not know you hold — so the book starts with an inventory, not with a policy.
And the rule that carries half of it: the cheapest data to protect is the data you never collected. Reduction is not austerity, it is the strongest security measure and the cheapest — it needs no system and no budget, it needs a decision. Every field you drop removes a place to protect, a record to manage, a question to answer, and something that could leak.
It says plainly in chapter one that it is not legal advice: I am an engineer, not a lawyer, and interpreting the text, what applies to you, drafting a policy or a contract, binding retention periods and whether you need a data protection officer all go to your lawyer. Read it to know what to ask them — and walk into that meeting with an inventory rather than a blank page.
02 — What you will learn
What you will learn
Why data lives wherever you copied it — and the forgotten places: chats, backups, phones, old devices
A six-column inventory, and separating what is most harmful if it leaks
The sentence test: a reason for every field you could state to its owner in one line
Replacing with less — a recorded verification instead of an identity image, an area instead of an address
Separating verifying from retaining: seeing something is not keeping it
A notice people actually understand, written from your inventory rather than copied from another company
Why consent for one purpose does not serve another, and why marketing is separate
A rights-request procedure written before the first request — and how identity verification fails in both directions
Access by need, and why a shared account empties every other control of meaning
Your data at suppliers: it stays your responsibility, and the first question is the storage country
Deletion as a control, and why deleting from the system alone is not deletion
The first hour after a breach: stop the damage and do not erase the trail
03 — The chapters
The chapters
- What Changed — and Why This Is Not Legal Advice
- The Data Inventory: What You Actually Hold
- Why Are You Keeping It? Purpose and Reduction
- The Notice and Consent: That People Know
- People’s Rights — and How to Answer a Request
- Who Reaches What: Inside Your Business
- Suppliers: Your Data in Someone Else’s Hands
- Retention and Deletion: When to Let Go
- When a Breach Happens: The First Hours
- Employees: Training and Leaving
- Measurement and the Periodic Review
- The Full Audit: 36 Questions and a Ninety-Day Plan
04 — What you get
What you get
12 chapters + a 20-term glossary
A 36-question audit + a ninety-day plan
Not legal advice — written to prepare you for your lawyer
Print-ready PDF included (~45–61 pages)
05 — How subscribing works
No online payment — three simple steps
Send your request
Fill the short form: name, phone, email. This site never asks for any payment details.
I contact you personally
We confirm the details and arrange payment in cash or by local transfer — whatever suits you.
Your activation code arrives
A one-time code unlocks the product on one device, with lifetime access. Changing devices later is a message away.
06 — Questions, answered
Questions, answered
Does this book make me compliant?
No, and it says so in chapter one rather than in a closing footnote. I am an engineer, not a lawyer — compliance is decided by the law and by your lawyer, not by a book. What this does is the practical layer nobody else prepares for you: knowing where your data lives, reducing it to what you actually need, and walking into your lawyer’s office with an inventory instead of a blank page. An inventory with no lawyer leaves questions unanswered; a lawyer with no inventory gives you generalities.
How is it different from the patient data book?
That book is for clinics and health facilities, where patient data has its own sensitivity and context. This one is for general business — a shop, an office, a workshop, a services company. And chapter one says plainly: if you are a clinic, that is your book, not this one. Technical security is the two cybersecurity courses, managing accounts and permissions is the "Protecting Your Business Accounts" course, and what may pass through an AI tool is the "Your Data and AI" course.
I am a very small business. Does the law concern me?
That is exactly a question for your lawyer, and the book does not answer it for you. What it does say is that the published scope is wide — it covers personal data within Jordan regardless of when it was collected, including data gathered before the law took effect. And chapter one lists three cases where the book genuinely does not concern you, the first being that you hold no personal data at all: cash sales with no names, no numbers and no accounts. That is the best position to be in.
Does it explain how attacks happen?
No. It is a protection-only book: it does not explain how systems are broken into or how vulnerabilities are exploited, and that constraint is enforced by a test on the text itself. And it is the right shape for the subject, because most of what leaks does not come from an external attack — it comes from inside with no ill intent: a file sent to the wrong customer, a list copied to a personal phone, or access that stayed after someone left.
How do I pay and get access?
There is no online payment on this site. Send the request form, I contact you personally, we arrange payment (cash or local transfer), then you get a one-time activation code for one device with lifetime access.
07 — Send your request
Subscribe to Personal Data Protection: What the Law Means for Your Business
Send your details and I will contact you personally within hours to complete the subscription — payment happens after we talk, and no online payment is ever requested.