Personal Data Protection Law, breach notification
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 17 March 2024.
A breach notification rule binding public and private bodies.
As of 29 August 2026.
What it requires
- An app that suffers a serious breach of data security or safety that could cause significant harm to an individual in Jordan must notify the affected individuals within 24 hours of discovery and must notify the Unit within 72 hours of discovery with the source, mechanism, and affected individuals; a Controller found grossly negligent or engaged in misconduct in a breach is liable to compensate the affected Data Subject.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 20(A) requires the Controller, on discovering a serious breach of data security and safety that could cause significant harm to the Data Subject, to notify the affected Data Subjects within 24 hours of discovery, and to notify the Unit (MoDEE's internal data-protection unit) within 72 hours of discovery about the breach's source, mechanism, affected Data Subjects, and any other available related information. This is a materiality-gated duty with two distinct fixed timelines.
Article 20(B) separately makes the Controller liable to compensate the affected Data Subject in case of gross negligence or misconduct, a direct statutory compensation right tied to a breach.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometricsprocesses_voice
Read the law
official bilingual statute text, Ministry of Digital Economy and Entrepreneurship
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.