Personal Data Protection: What the Law Means for Your Business
Jordan's Personal Data Protection Law No. 24 of 2023 took effect on 17 March 2024, and its transition period ended on 17 March 2025. So the question is no longer "will it become mandatory".
What Changed — and Why This Is Not Legal Advice
**Jordan's Personal Data Protection Law No. 24 of 2023 was published in the Official Gazette on 17
September 2023, took effect on 17 March 2024, and its transition period ended on 17 March 2025.**
So the question is no longer "will it become mandatory" — the period has ended.
The sentence this book rests on
You cannot protect what you do not know you hold.
And what surprises business owners most is not the law — it is inventorying their own data.
Because when someone sits down and writes what they actually hold, they find things they never considered:
customer numbers on a former employee's phone, photographs of identity documents in old chats, **and a file
carrying the details of everyone who ever messaged them over five years**.
And that is this book: knowing, then reducing, then protecting what remains.
What the published sources say about the obligations
And I will report what is published, and not interpret it:
- Informed consent before processing personal data
- Fair, transparent processing for a lawful purpose
- Security measures protecting the data
- Data accuracy, and enabling individuals to access and correct it
- A clear and accessible privacy policy
- Restrictions on cross-border transfers unless adequate protection exists
- Maintaining processing records
- Reporting breaches to the designated authority
- And appointing a data protection officer for those processing sensitive data at scale
And the published penalties: from JOD 1,000 to 10,000, and JOD 500 daily for a continuing
violation, up to a maximum of 3% of annual revenues; doubling on repetition, **and a court may order
the destruction of unlawfully processed data or the cancellation of a database following a final
conviction**.
And the scope is wide: it applies to personal data within Jordan regardless of when it was collected —
including data gathered before the law took effect — **and to foreign businesses offering services to
residents of Jordan**.
This book is not legal advice
And I say it in chapter one rather than in a closing footnote:
I am an engineer, not a lawyer. What I know is the practical side: where your data lives, who reaches
it, how you reduce it, and what you do when you are asked about it.
And what I do not know and will not rule on: interpreting a text, **determining what applies to you
specifically, drafting a privacy policy or a contract, a binding retention period, or whether you
are required to appoint a data protection officer**.
Read this book to know what to ask your lawyer — not to do without one.
And you will find at the end of each chapter what goes to them, and it is not a formality: **an error here
is measured in a fine and in trust, and neither is easily recovered**.
When this book does not concern you
Three cases, and I will say them before you continue:
1. You hold no personal data at all. Cash sales with no names, no numbers and no accounts ← **your
inventory will be empty, and that is the best position**.
2. Your problem is technical security rather than data protection. If your concern is passwords, accounts
and intrusion ← that is the "Protecting Your Business Accounts" course and "Cybersecurity for Small
Business", and this book is something else.
3. You are a clinic or a health facility. ← patient data has its own sensitivity and context, and
that is "Protecting Patient Data in Clinics". This book is for general business: a shop, an office, a
workshop, a services company.
What this book is — and is not
It is about the practical layer: the inventory, reduction, the notice, people's rights, access, suppliers,
retention, and a breach.
It is not about technical security — that is the two cybersecurity courses.
Nor about business accounts and their permissions — that is "Protecting Your Business Accounts", **which I
assume in chapter seven**.
Nor about what may pass through an AI tool — that is the "Your Data and AI" course.
Nor about clinics — that is "Protecting Patient Data".
And I will not name a program or a service. Tools change, **and the question "what do you hold and why"
does not**.
Start with this today
Twenty minutes, and it is the first thing that reveals the size of the matter:
Write on a page every place holding people's data in your business. Not the kinds of data — **the
places**:
your phone, your employees' phones, the email account, the invoice book, work chats, the system, Excel
files, the backups, and anything held at an external supplier.
And correct nothing now. Just write. And chapter two turns that page into an inventory.
Action steps
- Write the sentence: you cannot protect what you do not know you hold.
- Know that the transition period has ended — the question became "how" rather than "when".
- Read the published obligations, and do not interpret them yourself.
- Go through "when this book does not concern you" — starting with the third if you are a clinic.
- Write the list of places holding people's data — twenty minutes.
- Correct nothing yet — the inventory comes first.
- Name a person who owns this file in your business.
- Book a meeting with a lawyer after finishing chapter two — **with an inventory in hand the session is
far more useful**.
That was the full sample — here is the rest
What you just read is one part. The full edition includes:
- All 12 chapters — the inventory, reduction, the notice, rights, access, suppliers, retention, breach, employees, and measurement
- A 36-question audit and a ninety-day plan whose first month is inventory with no policy writing
- A 20-term glossary and a print-ready PDF
- Two editions, Arabic and English, in a reader that saves your progress