BookCyber SecurityArabic + English

Personal Data Protection: What the Law Means for Your Business

Jordan’s Personal Data Protection Law took effect in March 2024 and its transition period ended in March 2025. And what surprises owners is not the law — it is inventorying their own data.

$59Subscriptionone-time, lifetime access

01 — Overview

Overview

When an owner sits down and writes what personal data they actually hold, they find things they never considered: customer numbers on a former employee’s phone, identity document images in old chats, and a file holding the details of everyone who messaged them over five years. You cannot protect what you do not know you hold — so the book starts with an inventory, not with a policy.

And the rule that carries half of it: the cheapest data to protect is the data you never collected. Reduction is not austerity, it is the strongest security measure and the cheapest — it needs no system and no budget, it needs a decision. Every field you drop removes a place to protect, a record to manage, a question to answer, and something that could leak.

It says plainly in chapter one that it is not legal advice: I am an engineer, not a lawyer, and interpreting the text, what applies to you, drafting a policy or a contract, binding retention periods and whether you need a data protection officer all go to your lawyer. Read it to know what to ask them — and walk into that meeting with an inventory rather than a blank page.

02 — What you will learn

What you will learn

Why data lives wherever you copied it — and the forgotten places: chats, backups, phones, old devices

A six-column inventory, and separating what is most harmful if it leaks

The sentence test: a reason for every field you could state to its owner in one line

Replacing with less — a recorded verification instead of an identity image, an area instead of an address

Separating verifying from retaining: seeing something is not keeping it

A notice people actually understand, written from your inventory rather than copied from another company

Why consent for one purpose does not serve another, and why marketing is separate

A rights-request procedure written before the first request — and how identity verification fails in both directions

Access by need, and why a shared account empties every other control of meaning

Your data at suppliers: it stays your responsibility, and the first question is the storage country

Deletion as a control, and why deleting from the system alone is not deletion

The first hour after a breach: stop the damage and do not erase the trail

03 — The chapters

The chapters

  1. What Changed — and Why This Is Not Legal Advice
  2. The Data Inventory: What You Actually Hold
  3. Why Are You Keeping It? Purpose and Reduction
  4. The Notice and Consent: That People Know
  5. People’s Rights — and How to Answer a Request
  6. Who Reaches What: Inside Your Business
  7. Suppliers: Your Data in Someone Else’s Hands
  8. Retention and Deletion: When to Let Go
  9. When a Breach Happens: The First Hours
  10. Employees: Training and Leaving
  11. Measurement and the Periodic Review
  12. The Full Audit: 36 Questions and a Ninety-Day Plan

04 — What you get

What you get

12 chapters + a 20-term glossary

A 36-question audit + a ninety-day plan

Not legal advice — written to prepare you for your lawyer

Print-ready PDF included (~45–61 pages)

05 — How subscribing works

No online payment — three simple steps

01

Send your request

Fill the short form: name, phone, email. This site never asks for any payment details.

02

I contact you personally

We confirm the details and arrange payment in cash or by local transfer — whatever suits you.

03

Your activation code arrives

A one-time code unlocks the product on one device, with lifetime access. Changing devices later is a message away.

06 — Questions, answered

Questions, answered

Does this book make me compliant?

No, and it says so in chapter one rather than in a closing footnote. I am an engineer, not a lawyer — compliance is decided by the law and by your lawyer, not by a book. What this does is the practical layer nobody else prepares for you: knowing where your data lives, reducing it to what you actually need, and walking into your lawyer’s office with an inventory instead of a blank page. An inventory with no lawyer leaves questions unanswered; a lawyer with no inventory gives you generalities.

How is it different from the patient data book?

That book is for clinics and health facilities, where patient data has its own sensitivity and context. This one is for general business — a shop, an office, a workshop, a services company. And chapter one says plainly: if you are a clinic, that is your book, not this one. Technical security is the two cybersecurity courses, managing accounts and permissions is the "Protecting Your Business Accounts" course, and what may pass through an AI tool is the "Your Data and AI" course.

I am a very small business. Does the law concern me?

That is exactly a question for your lawyer, and the book does not answer it for you. What it does say is that the published scope is wide — it covers personal data within Jordan regardless of when it was collected, including data gathered before the law took effect. And chapter one lists three cases where the book genuinely does not concern you, the first being that you hold no personal data at all: cash sales with no names, no numbers and no accounts. That is the best position to be in.

Does it explain how attacks happen?

No. It is a protection-only book: it does not explain how systems are broken into or how vulnerabilities are exploited, and that constraint is enforced by a test on the text itself. And it is the right shape for the subject, because most of what leaks does not come from an external attack — it comes from inside with no ill intent: a file sent to the wrong customer, a list copied to a personal phone, or access that stayed after someone left.

How do I pay and get access?

There is no online payment on this site. Send the request form, I contact you personally, we arrange payment (cash or local transfer), then you get a one-time activation code for one device with lifetime access.

07 — Send your request

Subscribe to Personal Data Protection: What the Law Means for Your Business

Send your details and I will contact you personally within hours to complete the subscription — payment happens after we talk, and no online payment is ever requested.

Product: Personal Data Protection: What the Law Means for Your Business

Your details are stored securely and never shared with anyone.