Law / Jordan

Jordan

11 of 12 named instruments researched to a stage, across five of the six areas of law we track: 11 in force. As of 16 September 2026.

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (214 words)

Jordan has not enacted a binding statute imposing AI-transparency or output-labeling duties (disclosure that content is AI-generated, labeling or watermarking of synthetic output, or disclosure that a user is talking to a bot) as of the date below.

The one binding provision located that reaches AI-generated output specifically is the Cybercrime Law's ban on real, virtual, or simulated sexual depictions of a person under eighteen, which by its own terms extends beyond an authentic photograph to a synthetic or computer-generated image.

Jordan's AI-policy landscape otherwise runs through non-binding instruments: the National Artificial Intelligence Strategy and Implementation Plan 2023-2027 and the National Charter of Ethics for Artificial Intelligence, both issued by the Ministry of Digital Economy and Entrepreneurship, set government-facing goals and ethical principles without creating an enforceable duty on a private developer, and the Central Bank of Jordan's Artificial Intelligence Framework for the Banking Sector (Version 1.0, July 2025) is framed throughout as guidance for how a CBJ-regulated bank should govern its own AI use, carrying no statutory citation, no mandatory-compliance clause, and no stated penalty for departing from it.

Jordan's Personal Data Protection Law, Law No. 24 of 2023, includes duties that constrain a personal-data-driven AI system; those duties are researched under the privacy topic for this jurisdiction and are not repeated here.

AI prohibited practices

Cybercrime Law, Ban on Real, Virtual, and Simulated Depictions of a Minor

Law No. 17 of 2023 on Cybercrime, Art. 13Unofficial English translation of the Cybercrime Law, Law No. 17 of 2023, published by the Jordan Open Source Association (JOSA)

In force. Binds public and private bodies.

What this law does

Article 13(b) punishes, with imprisonment of at least one year and a fine of 6,000 to 30,000 Dinars, sending, publishing, producing, or possessing content that is a sexually stimulating image, recording, or drawing of sexual organs, or a real, virtual, or simulated sexual act, of a juvenile under eighteen years of age.

The same article raises the penalty to at least two years' imprisonment and a fine of 9,000 to 30,000 Dinars where the content is designed to lure the juvenile or the purpose is to incite or exploit him, and separately punishes mere possession of such content with imprisonment of at least six months or a fine of 3,000 to 6,000 Dinars.

Because the offense names "virtual" and "simulated" sexual acts alongside "real" ones, it reaches a synthetic or computer-generated depiction of a minor exactly as it reaches an authentic photograph or recording, without requiring proof that any real child was involved in producing the image.

What it requires

Privacy law6 instruments, 6 in force

Research summary (236 words)

Jordan's Personal Data Protection Law (Law No. 24 of 2023, PDPL) was read in full at primary source, a bilingual official Ministry of Digital Economy and Entrepreneurship document, untruncated. This is the best-documented commencement structure in the batch: the Law was published in the Official Gazette 17 September 2023, entered into force 17 March 2024, and Article 23, read verbatim, confirms entities must adjust their affairs within one year of the effective date, ending 17 March 2025.

Biometric data is explicitly named within the Sensitive Personal Data definition, the same structural pattern as the UAE and Saudi Arabia, but unlike them Jordan has no standalone "Biometric Data" definition with worked examples, the same lighter-touch pattern found in Saudi Arabia.

No adequacy test, whitelist, or data-localization requirement was found anywhere in the untruncated text for cross-border transfer; Article 14's consent-plus-conditions structure reads as more permissive than the carried strict seed.

Jordan is the clearest case in this batch of a statute naming the data subject as a party with standing to seek a remedy: Article 20(B) makes a Controller liable to compensate the affected Data Subject for a breach caused by gross negligence or misconduct, and Article 22(B) lets "the affected party" petition the court for a data-destruction or database-cancellation remedy following a criminal conviction.

Both are narrower than a blanket private right of action, tied to specific triggers rather than framed as a freestanding tort claim.

Breach notification

Personal Data Protection Law, breach notification

Law No. 24 of 2023, Art. 20official bilingual statute text, Ministry of Digital Economy and Entrepreneurship

In force since 17 March 2024. Binds public and private bodies.

What this law does

Article 20(A) requires the Controller, on discovering a serious breach of data security and safety that could cause significant harm to the Data Subject, to notify the affected Data Subjects within 24 hours of discovery, and to notify the Unit (MoDEE's internal data-protection unit) within 72 hours of discovery about the breach's source, mechanism, affected Data Subjects, and any other available related information. This is a materiality-gated duty with two distinct fixed timelines.

Article 20(B) separately makes the Controller liable to compensate the affected Data Subject in case of gross negligence or misconduct, a direct statutory compensation right tied to a breach.

What it requires

Comprehensive regime

Personal Data Protection Law, comprehensive regime and lawful basis

Law No. 24 of 2023, Arts. 1-2, 11official bilingual statute text, Ministry of Digital Economy and Entrepreneurship

In force since 17 March 2024. Binds public and private bodies.

What this law does

The Personal Data Protection Law, 23 articles, is Jordan's first comprehensive personal-data statute.

Processing generally requires consent, with an enumerated list of alternative lawful bases covering medical necessity, vital-interest protection, crime prevention and prosecution, statutory or court-ordered disclosure, Central Bank-supervised entity functions, regulation-specified cases, scientific or historical research, statistical, national-security, or public-interest purposes, and publicly available data.

A Controller must appoint a data-protection lead in specified cases, including when processing Sensitive Personal Data or transferring to databases outside the Kingdom (Art. 11(A)(5)). A general storage-limitation principle applies to all processing: data "shall not be retained after the purpose of the Processing is fulfilled, unless otherwise specified by legislation."

What it requires

Cross border transfer

Personal Data Protection Law, cross-border transfer

Law No. 24 of 2023, Art. 14official bilingual statute text, Ministry of Digital Economy and Entrepreneurship

In force since 17 March 2024. Binds public and private bodies.

What this law does

No adequacy test, whitelist, or data-localization requirement was found anywhere in the untruncated text, searched directly for "adequate," "localiz," and "stored within the Kingdom" with zero hits.

Article 14 sets a general transfer or exchange-to-a-recipient rule, not framed specifically as cross-border, requiring the Data Subject's consent plus three conditions: legitimate interest of both parties, the Data Subject having sufficient knowledge of the purpose, and no use for marketing without separate consent, with a record-keeping duty on the Controller and a carve-out for public-entity-to-public-entity transfers.

This reads as a consent-based transfer regime rather than an adequacy-gated one on the primary text alone, more permissive in structure than the carried strict seed; it remains possible that unread implementing regulations supply a stricter, cross-border-specific rule the base Law defers to, a deferral pattern also seen in Oman.

What it requires

Data subject rights

Personal Data Protection Law, data subject rights

Law No. 24 of 2023, data subject rights listofficial bilingual statute text, Ministry of Digital Economy and Entrepreneurship

In force since 17 March 2024. Binds public and private bodies.

What this law does

A numbered rights list confirms, read verbatim: erasure or concealment of data (item 5), objection to processing and profiling that are unnecessary, excessive, discriminatory, prejudiced, or unlawful for the purposes collected (item 6), transfer of a copy of the data from one controller to another, i.e. portability (item 7), and being notified of any data breach or violation regarding the security and integrity of the data (item 8).

Items 1-4 of the same list, likely including access and correction rights, were not individually extracted, though the numbering implies they exist.

What it requires

Enforcement supervision

Personal Data Protection Law, enforcement and data subject remedies

Law No. 24 of 2023, Arts. 21-22official bilingual statute text, Ministry of Digital Economy and Entrepreneurship

In force since 17 March 2024. Binds public and private bodies.

What this law does

Article 21 is administrative: for a violation, the Unit issues a warning first, and if uncured, the Council may impose licence suspension or revocation, or a fine up to 500 Dinars per day of continuing violation, capped at 3% of the violator's prior-fiscal-year annual revenue, and the Unit may publish a statement of proven violations at the violator's expense.

Article 22 is criminal-adjacent: a fine of 1,000 to 10,000 Dinars, doubled on repeat violation, without prejudice to any stricter penalty elsewhere in Jordanian law. Article 22(B), read verbatim, lets the relevant court, on request of the public prosecution, the affected party, or its own initiative, order the destruction of data or the cancellation of a database following a final conviction, naming the affected data subject as a party with standing to petition alongside the public prosecution.

Combined with Article 20(B)'s compensation clause, Jordan is the clearest case in this batch of a statute naming the data subject as a party with standing to seek a remedy, though neither clause is a freestanding tort-style private right of action: both are narrower and tied to specific triggers, compensation for gross-negligence breach harm, and a court petition following a criminal conviction, rather than a blanket civil cause of action.

What it requires

Sensitive categories

Personal Data Protection Law, sensitive personal data and biometric data

Law No. 24 of 2023, Art. 2 definitionsofficial bilingual statute text, Ministry of Digital Economy and Entrepreneurship

In force since 17 March 2024. Binds public and private bodies.

What this law does

Biometric data is explicitly named within the Sensitive Personal Data definition, alongside origin, race, political opinions, religious beliefs, financial status, health, physical or mental condition, genetic data, criminal record, and any information deemed sensitive by regulation, the same structural pattern as the UAE and Saudi Arabia.

Unlike the UAE, Oman, and ADGM statutes, no standalone "Biometric Data" definition with worked examples was found, the same lighter-touch pattern found in Saudi Arabia's Art. 1(11).

Processing Sensitive Personal Data, including biometric data, falls under the same consent-plus-enumerated-exceptions structure as general personal data; whether a heightened, explicit-consent standard specifically applies to sensitive or biometric processing (as in Bahrain and Saudi Arabia) is not independently confirmed. The general storage-limitation principle applies to biometric data as much as any other category, though it is not biometric-specific.

What it requires

Scraping law2 instruments, 2 in force

Research summary (282 words)

Jordan has no scraping-specific statute, so general law governs each dimension separately.

The Cybercrime Law, Law No. 17 of 2023, criminalizes unauthorized access to a website, information network, information system, or information technology means, with an aggravated tier where the access reaches a government, security, financial, or banking system and affects national security, foreign relations, public safety, or the national economy; on a plain reading, the base offense turns on accessing "without authorization or in violation or excess of an authorization," a term the Law does not define, so whether it reaches a crawler that reads only a public, unauthenticated page without defeating a technical control is untested by any reported Jordanian decision.

No Jordanian statute or reported decision addresses whether a browsewrap or clickwrap terms-of-service restriction against scraping is enforceable as a matter of contract law.

The Copyright Protection Law, Law No. 22 of 1992 as amended, permits a quotation exception for illustration, explanation, argument, criticism, education, or experimentation, to the extent justified by the purpose and with attribution, but its exceptions are a closed, enumerated list, and no provision read creates a text-and-data-mining-specific exception or a machine-readable opt-out mechanism. No sui generis database right was found in the text read.

Jordan's Personal Data Protection Law, Law No. 24 of 2023, reaches scraped personal data without a general carve-out for publicly available information; that reach, the sensitive-data rules, and cross-border transfer are researched under the privacy topic for this jurisdiction and are not repeated here.

No Jordanian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule; neither was reached within this visit's search budget.

Computer misuse

Cybercrime Law, Unauthorized Access to Information Systems

Law No. 17 of 2023 on Cybercrime, Arts. 3-4, 6-7Unofficial English translation of the Cybercrime Law, Law No. 17 of 2023, published by the Jordan Open Source Association (JOSA)

In force. Binds public and private bodies.

What this law does

Article 3 punishes whoever intentionally accesses a website, information network, information system, or information technology means, or any part of it, without authorization or in excess of an authorization, with imprisonment of one week to three months or a fine of 300 to 600 Dinars, or both.

The penalty rises to three months to one year and a fine of 600 to 3,000 Dinars where the access is for the purpose of cancelling, deleting, damaging, disclosing, or otherwise altering data, and to one to three years and a fine of 3,000 to 15,000 Dinars where that result is achieved.

Article 4 raises the penalty to six months to three years and a fine of 2,500 to 25,000 Dinars where the access reaches an information network, system, or website belonging to a ministry, government department, public institution, or a security, financial, or banking institution, and affects non-public data touching national security, the Kingdom's foreign relations, public safety, or the national economy; where that access is also used to cancel, damage, destroy, or otherwise alter or disclose the data, Article 4 raises the penalty further to temporary servitude and a fine of 5,000 to 25,000 Dinars, or temporary servitude of at least five years and a fine of 25,000 Dinars if the result is achieved.

Article 6 separately punishes intentionally using a program or program command to disable, alter, or gain unauthorized access to an information system, with imprisonment of at least six months and a fine of 2,500 to 10,000 Dinars.

Article 7 punishes unlawfully intercepting or capturing a data flow with imprisonment of at least six months and a fine of 1,500 to 6,000 Dinars, rising to temporary servitude of at least five years and a fine of 15,000 to 45,000 Dinars where the interception targets an official authority's communications. None of these articles names a web crawler, an automated collection tool, or the robots exclusion protocol.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (914 words)

Jordan's cyber-resilience framework rests on the Cyber Security Law No. (16) of 2019, which establishes the National Cyber Security Council and the National Cyber Security Center (the Center) and, in Article 8(b), imposes a duty that reaches beyond government: every ministry, government department, and official, public, private, or civil institution must adhere to the policies, standards, and controls the Center issues for its sector, provide the Center the information it needs to do its work, and inform the Center of any incident that threatens cybersecurity or the security of cyberspace, taking every step necessary to prevent or avoid it.

The Center's own Incident Classification Instructions (2023, amended by National Cyber Security Council Decision No. 37 of 2025) define the bound entity to include any ministry, public or private institution, government department, civil institution, association, company, or individually registered establishment in the Kingdom, which confirms the duty's reach to an ordinary private company rather than only a government-designated class, and set four incident-severity tiers (Critical, High, Medium, Low) keyed to whether an incident disrupts essential services, exposes sensitive data, or touches a critical-infrastructure, security, military, government, or higher-education target; an incident confined to a private company or an individual establishment with no such touchpoint is typically classified Medium or Low.

The Center's Cyber Security Incident Response and Reporting Policy (2025, twice amended that year) sets the operative clock: its Table 1 gives a Critical-tier incident a reporting window as short as 30 minutes, tapering through roughly 1 hour for High, 4 hours for Medium, and 1 day for Low, alongside separate containment and resolution windows in the same table, and names a hotline, an email address, and the JOCERT portal (jocert.ncsc.jo) as the reporting channels.

Where the Council designates an incident a threat to the Kingdom's own security and safety under Article 9, the Center directs the response and every institution involved must follow its instructions.

Layered on top of that general duty, the Center has separately identified critical-infrastructure sectors in its own sector-identification document and published a dedicated set of critical-infrastructure cybersecurity controls (guidance, a controls list, a sector-mapping annex, and a threat annex); because the bound party there is a government-designated critical-infrastructure operator rather than an activity this corpus's vocabulary can express, that sub-regime is deferred rather than flagged on a guess, the same treatment this profile gives DORA's financial entities and NY DFS Part 500's covered entities.

Article 10 separately prohibits providing cybersecurity services in Jordan without a Center-issued license, implemented by a 2024 Licensing System for Cybersecurity Service Providers and a 2025 instructions document grading fines by violation type (a range of roughly 500 to 5,000 dinars depending on the specific violation) and, separately, by an affected incident's own severity tier (up to a 50,000-to-100,000-dinar band where the incident is Severe), all within Article 16's own 500-to-100,000-dinar statutory range; because the bound party is a firm that sells cybersecurity services rather than an activity in this corpus's vocabulary, that licensing duty is deferred and named here rather than filed as an instrument.

The Central Bank of Jordan separately maintains bank-specific cyber-risk instructions, Instructions for Adapting to Cyber Risks No. (1984/1/1/26) of 6 February 2018 for licensed banks and Instructions for Adapting to Cyber Risks for Licensed Exchange Companies No. (17/2018), both listed on the Central Bank's own instructions page; because the bound party is a bank or a licensed money-exchange company, a role this corpus's activity vocabulary cannot express, this sector regime is deferred in the same way as New York's DFS Part 500.

The Telecommunications Regulatory Commission's own instructions listing serves no readable content to either a compliant or a stealth browser, so whether it publishes an equivalent telecom-specific cybersecurity instruction is not established; if one exists, it would in any event bind a licensed telecom operator, a role outside today's activity vocabulary.

No enacted Jordanian statute was found setting security requirements a connected device or software product must meet before or after it reaches the market, so the product-requirements dimension is recorded as a researched absence rather than a gap in coverage.

Enforcement of the Article 8 duty and the Law generally runs through the Center itself: Article 16 lets the Center impose a written warning, an order to correct the violation and reimburse the Center's resulting costs, blocking, cancellation, confiscation, or disabling of the offending communications network, information system, or device, a requirement that the institution take legal measures against a responsible employee, suspension or cancellation of a cybersecurity-services license, or a fine of not less than 500 and not more than 100,000 Jordanian dinars, doubled for a repeated violation; nothing in the Law creates a private right of action, and Article 16's own enumerated remedies are the only route to relief.

Article 13 gives the Center's president and delegated staff judicial-police powers, including a right to search premises and to organize the arrest of a violator, but this reaches an active cyber-attacker rather than an institution that merely misses its own reporting duty under Article 8, and the Law's own penalty ladder in Article 16 carries no criminal sentence of its own. No published enforcement record specific to Article 8 was located.

Jordan's data breach-notification duty, and any safeguards clause inside its comprehensive data-protection regime, already sit in this jurisdiction's privacy row (Personal Data Protection Law No. 24 of 2023, Article 20) and are not repeated here, and the Cybercrime Law No. 17 of 2023's unauthorized-access offenses already sit in this jurisdiction's scraping row rather than here.

Vulnerability and incident reporting

Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty

Cyber Security Law No. (16) of 2019, Article 8(b)National Cyber Security Center, unofficial English translation of Cyber Security Law No. 16 of 2019

In force. Binds public and private bodies.

What this law does

Any ministry, government department, or official, public, private, or civil institution must adhere to the National Cyber Security Center's sector-specific policies, standards and controls, provide the Center the information it needs to do its work, and inform the Center of any incident that threatens cybersecurity, taking every step necessary to prevent or avoid it.

A violation may draw a written warning, a correction order, network or system blocking, license suspension, or a fine of between 500 and 100,000 Jordanian dinars doubled on repeat, imposed administratively by the Center rather than through a private lawsuit.

The Law is plainly in force, evidenced by the Center's own dated subsidiary instruments from 2020 through 2025, but its own text sets commencement only as the date of Official Gazette publication (Article 1) without stating that date, and neither the Center's English translation nor its Arabic original states a specific Gazette issue or date; the commencement day is left unset rather than guessed.

What it requires

News aggregation law1 instrument, 1 in force

Research summary (255 words)

Jordan has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code.

The Copyright Protection Law, Law No. 22 of 1992 as amended, is the only framework reaching an aggregator's reproduction of news content: Article 17(d) permits quoting a published work, without the author's authorization, for illustration, explanation, argument, criticism, education, or experimentation, to the extent justified by the purpose and with attribution, carrying no headline-length or short-extract cap of its own and no restriction to the press industry.

Article 18 separately makes it unlawful to reproduce, in a newspaper or periodical, without the author's consent, serialized stories, news items, or any other work published in another newspaper or periodical, but permits a newspaper to reproduce another newspaper's articles on current political, economic, or religious affairs, provided the source newspaper has not expressly prohibited reproduction and the source is named; this exception runs between newspapers and reads as an opt-out mechanism rather than a modern press-publisher neighbouring right.

Article 19 permits publishing a speech, address, or interview already communicated to the public, without the author's authorization, provided the work and its author are named. No provision read addresses hyperlinking, framing, or inline display, and no reported Jordanian decision applies any of these provisions to a systematic news aggregator rather than a newspaper or an individual quoting a published work.

The Law predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists. A hot-news or misappropriation doctrine distinct from ordinary copyright law was not reached within this visit's search budget.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.