2025-08-07

Added · Updated

Central Bank of Jordan Decision on Data Processing for Supervised Entities

The Central Bank of Jordan issued Decision No. 2025/831 to regulate data processing by supervised entities, including banks, insurance companies, and exchange firms, under the Personal Data Protection Law No. 24 of 2023. The decision permits data processing without prior consent for specific purposes such as anti-money laundering compliance, fraud prevention, and cybersecurity, while strictly prohibiting unauthorized disclosure of client data. It mandates rigorous assessments and Board of Directors approval for transferring data to countries lacking adequate protection levels and requires entities to implement robust security measures and appoint Data Protection Officers.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

CENTRAL BANK OF JORDAN

Central Bank of Jordan

No.: 218/6/9 Date: 1447 AH Corresponding to: 2025 AD

Circular to Licensed Exchange Companies

Greetings,

Based on the provisions of Item (6) of Paragraph (a) of Article (6) of Personal Data Protection Law No. (24) of 2023, we attach to you Decision No. (2025/831) dated 2025/08/04 concerning data processing by entities subject to the supervision and oversight of the Central Bank of Jordan, to be implemented in accordance with its contents.

Please accept our highest respect,

Governor Dr. Adel Al-Sharkas

Classification Level: Internal Use Page 1 of 1


CENTRAL BANK OF JORDAN

Central Bank of Jordan Governor's Decisions

No.: 2025/831 Date: 10 Safar 1447 AH Corresponding to: 2025/08/04

Decision Concerning Data Processing by Entities Subject to the Supervision and Oversight of the Central Bank of Jordan Issued pursuant to the provisions of Article (6/a) of Personal Data Protection Law No. (24) of 2023

In the context of the Central Bank's efforts to enhance the personal data protection system in accordance with the provisions of Personal Data Protection Law No. (24) of 2023 among all entities under its supervision, and its keenness to achieve alignment between consolidating the basic principles of personal data protection and the necessity of continuity and stability in the efficient and effective operation of entities subject to the Central Bank's supervision; serving the clients dealing with them to the fullest extent, while respecting the privacy and nature of the operations of these entities, and within a methodology consistent with regulatory and legislative requirements, and based on the provisions of Item (6) of Paragraph (a) of Article (6) of the Personal Data Protection Law; the Central Bank of Jordan decides the following:

Article (1)

a) The following words and phrases wherever they appear in this Decision shall have the meanings assigned to them below unless the context indicates otherwise: -

The Bank: The Central Bank of Jordan.

The Entity: Any of the entities subject to the supervision and oversight of the Central Bank in accordance with the provisions of prevailing legislation, including banks, insurance and reinsurance companies, insurance service providers and the unified office, exchange companies, payment and electronic money transfer companies, financing companies, and credit information companies.

Board of Directors: The Board of Directors or the Regional Manager if the entity is a public or private joint-stock company, the General Manager or the Board of Directors of the entity if it is a limited liability company, and the authorized partners or the company manager if the entity is a partnership company.

b) The definitions contained in the Personal Data Protection Law of 2023 shall be adopted wherever the text refers to them unless the context indicates otherwise.

Scope of Application

Article (2)

a) The provisions of this Decision shall apply to all entities subject to the supervision and oversight of the Bank operating in the Kingdom.

b) Subject to the provisions contained in this Decision, all entities subject to the supervision and oversight of the Bank are committed to applying the provisions of the Personal Data Protection Law and the legislation issued pursuant to it.

Data Protection and Transaction Confidentiality

Article (3)

a) All entities must observe full compliance with the confidentiality provisions stipulated in the legislation regulating their operations. The application of any legal provisions regulating data processing without the consent or notification of the concerned person as stipulated in Article (6/a) of the Personal Data Protection Law 2023 or any legislation issued pursuant to it shall not be considered a reason or justification for deviating from the confidentiality provisions stipulated in the legislation regulating the entity's operations.

b) For the purposes of complying with the Personal Data Protection Law and the provisions of this Decision, the entity is committed to determining the scope and limits of processing operations for customer and client data accurately, such that they include only the operations necessary to achieve the legitimate purposes of the services and operations licensed by the Bank to provide.

c) The entity is prohibited from publishing, distributing, disclosing, or making available customer or client data to others except in legally permitted cases or with prior consent from the concerned person, while adhering to security and privacy standards.

d) Credit information companies are committed to the legal provisions regulating their work as specified in the prevailing Credit Information Law and the systems and instructions issued pursuant to it.

Purposes of Processing without Prior Consent of the Concerned Person

Article (4)

a- Any entity may process data without obtaining prior consent or notification from the concerned person if such processing is necessary for the performance of its operations and for any of the following purposes:

  1. If required or authorized by legislation, or in implementation thereof, or by a decision of a competent judicial authority.

  2. Compliance with legal requirements under the prevailing Anti-Money Laundering and Counter-Terrorism Financing Law and the systems and instructions issued pursuant to it, including purposes of verifying lists of sanctions and penalties issued by decisions of the UN Security Council and requests and instructions from competent regulatory authorities legally authorized to do so and law enforcement authorities.

  3. If the processing is necessary to comply with regulatory requirements issued by competent authorities legally authorized to do so, including requirements issued by those authorities to protect financial system stability or the public interest.

  4. If the processing is necessary for the entity to take necessary measures to combat financial fraud within its operations or in implementation of measures issued by competent authorities legally authorized to do so.

  5. If the processing is necessary for the entity to verify the integrity and security of the operations it performs.

  6. For the purposes of the entity carrying out anonymization or pseudonymization operations.

  7. For the purposes of the entity carrying out necessary measures for cybersecurity purposes and its operations and services; including scanning operations related to cyberattacks and analyzing network traffic to detect threats and suspicious activities.

  8. Verifying data provided by the client regarding the identity of individuals who do not have a direct relationship with the entity, such as the beneficiary of the business relationship or transaction, guarantor, agent, trustee, or legal representative, shareholders, partners, managers, representatives, authorized persons, and employees of corporate clients, family members, general/special heirs, rights holders, reference contacts, and details of persons to be contacted in emergencies.

  9. If the processing is necessary and related to the implementation of the business, services, and products provided by the entity to the concerned person or similar or related operations, or to implement a contract between the entity and the concerned person.

  10. If the processing is necessary for the purposes of reinsurance arrangements.

  11. To achieve a vital interest of the concerned person or to protect their vital interests.

  12. To achieve a legitimate interest of the entity; provided that the entity balances the interest of the concerned person with its legitimate interest, such that the entity's legitimate interest does not affect the rights or interests of the concerned person, whereby the entity is committed, before starting processing based on legitimate interest, to conduct and document a legitimacy assessment, which shall include in particular the following: a- Determining the purpose of the processing. b- Evaluating the purpose by ensuring its legitimacy and that it does not violate any prevailing legislation in the Kingdom. c- Verifying that this processing is necessary to achieve the purpose for the entity. d- Conducting an assessment of whether the processing will cause any harm to the rights and interests of the concerned person. e- Granting the concerned person the right to object to the processing in case it is proven that the entity has not complied with any of the items mentioned above.

b- Intermediary entities in executing financial, banking, and monetary operations, including correspondent banks and licensed or authorized payment and electronic money transfer companies, are permitted to obtain data from participating parties without obtaining prior consent or notification from the concerned person and to process it to the extent necessary to execute those operations and to implement legislative and regulatory requirements.

Sources of Obtaining Data without Consent of the Concerned Person

Article (5)

In compliance with the due diligence requirements stipulated in the Anti-Money Laundering and Counter-Terrorism Financing Law and the instructions issued pursuant to it, the entity is permitted, for the purposes of carrying out processing in accordance with the provisions of this Decision, to obtain data without the consent or notification of the concerned person from any neutral, reliable, and official sources through which entities subject to this Decision can exercise due diligence towards the concerned person, whether they are clients, customers, beneficial owners, or any other persons whose identities and data are required by law to be verified in accordance with the Anti-Money Laundering and Counter-Terrorism Financing Law and the instructions issued pursuant to it, from any of the following entities:

  1. Civil Status and Passports Department.
  2. Companies Control Department.
  3. General Security Directorate, including the Residency and Borders Directorate, the Electronic Crimes Combating Unit, and the Criminal Investigation Department.
  4. Ministry of Labor.
  5. Ministry of Industry and Trade.
  6. Ministry of Social Development and the Registrar of Associations and the Jordanian Cooperative Institution.
  7. Greater Amman Municipality or any other municipalities.
  8. Ministry of Digital Economy and Entrepreneurship.
  9. Ministry of Investment.
  10. Free Zones and Development Areas Group.
  11. Aqaba Special Economic Zone Authority.
  12. Licensed or legally authorized entities to disclose data, including sanctions and penalty lists issued by international entities, competent entities, and competent regulatory authorities legally authorized to do so.
  13. Public service providers (Utilities).
  14. Competent entities issuing official documents confirming the data and information obtained by the entity from the client and clients, for the purpose of verifying the authenticity of these documents.
  15. Any other entities approved by the Bank.

Transfer and Exchange of Data Inside and Outside the Kingdom

Article (6)

Entities subject to the supervision and oversight of the Bank are not permitted to transfer or exchange data inside or outside the Kingdom except in cases permitted by the provisions of the legislation regulating their operations and the provisions of this Decision. Entities are also committed to obtaining prior written consent from the Central Bank if the legislation regulating them requires it.

Article (7)

Entities are permitted, for the purposes of carrying out their operations, to transfer data outside the Kingdom borders if the entity to which the data is to be transferred is located in one of the countries mentioned in the lists approved by the Personal Data Protection Board, concerning countries that have an adequate level of data protection, subject to the following conditions:

a) Determining the legal basis for the transfer, such as:

  • Obtaining prior consent from the concerned person.
  • The need to implement a contract with the client or the concerned person.
  • Compliance with legal obligations imposed by legislation.

b) Stating the justification for the transfer outside the Kingdom, which is required by the nature of the entity's work, such as:

  • The existence of a regional extension outside the Kingdom's borders.
  • The need to transfer data due to the nature of the transaction or service.
  • To achieve a legitimate interest of the entity; provided that all requirements stipulated in Paragraph (12) of Article (4) of this Decision are adhered to.

c) Establishing necessary procedures to determine the location of data storage, collection, and processing, including systems, applications, and data flow maps.

d) Adherence to all relevant legislation and instructions and circulars issued by the Bank.

Article (8)

Subject to verifying the conditions stipulated in Article (7) of this Decision, before transferring or exchanging data with any other entity located in one of the countries not mentioned in the lists approved by the Personal Data Protection Board - concerning countries that have an adequate level of data protection - the entity must verify that the level of protection applied by that entity is not less than the level of protection provided by the prevailing legislation in the Kingdom, and observe the following:

a) Conducting an assessment of the level of protection provided by the external entity to ensure that the level of protection applied by that entity is not less than the level of protection provided by the prevailing legislation in the Kingdom, such that the assessment includes potential effects and risks and reputational risks, and takes into account the following criteria:

  1. The nature, type, value, size, and degree of sensitivity of the data, the purpose and scope of processing, and the time period of processing, and whether the transfer will be for a one-time, limited, or frequent, regular, and permanent period.
  2. The originator of the data and the stages at which the data is transferred.
  3. Administrative procedures, technical measures, and physical controls adopted in the information security policy, such as encryption, security controls, and international standards.
  4. Verifying the security and integrity of the data from any unauthorized or unauthorized access.

b) Presenting the assessment results to the Board of Directors to determine the acceptable level of risk and approve it.

c) Completing the assessment from legal aspects to ensure the determination of mechanisms to implement the Board of Directors' decisions regarding the assessment, and to verify that the external entity's country has legislation protecting data subjects and ensuring that contracting parties can comply with contracts. The assessment shall take into account whether the external entity's country is a party to international agreements for the protection of personal data or adopts international standards and principles for its protection, and whether this country adopts behavioral codes, general practices, or specific standards for the protection of personal data.

d) Presenting all the above results to the Board of Directors to obtain its approval for contracting with the external entity and according to the conditions and provisions it approves for this purpose.

e) Preparing a plan to terminate the contract and transfer data in the event of any amendment to the legislation in the receiving country that reduces or conflicts with the level of protection provided by the prevailing legislation in the Kingdom, or in necessary cases, and not including in contracts any provisions that limit the entity's ability to terminate the contract immediately.

Article (9)

Notwithstanding what was stated in Article (7) of this Decision; if banking operations or money transfers abroad require the transfer of data to an entity in a country that does not provide the level of protection for personal data stipulated in the Personal Data Protection Law or the level of confidentiality stipulated in the legislation regulating the operations of entities subject to it, the entity must take all appropriate safeguards to protect the rights of data subjects, including but not limited to:

a- Identifying and documenting the data transferred outside the Kingdom for the purposes of banking operations and money transfers abroad, and the data must be limited to what is necessary only.

b- The entity must, before starting the data transfer process, verify the level of protection provided by the data recipient to ensure the protection and security of the data.

Data Storage

Article (10)

a- Subject to the conditions stipulated in Article (7), entities subject to the provisions of this Decision are committed to including in agreements related to data storage with any entity inside or outside the Kingdom a clause prohibiting the service provider or any of its contractors or any third party or any authority or official entity in its country from accessing the data and information stored therein; otherwise, the entity is committed to obtaining the consent of the concerned person for storing their data.

b- The prohibition provisions contained in Paragraph (a) above do not apply to entities responsible for supervising the foreign branch operating in the Kingdom in its home country.

c- The entity is committed to including in agreements and contracts related to storage an explicit clause on the non-transfer of data ownership or disposal rights to the storage service provider or any of its contractors, any third party, or any authority or official entity in its country, in addition to explicitly stating the right of the Central Bank of Jordan to obtain the data upon request.

d- Entities are committed to determining the data storage period in agreements and contracts related to storage, and not exceeding the periods stipulated in the prevailing legislation in the Kingdom.

Data Security

Article (11)

In addition to legislative and regulatory requirements related to data security and protection, including legislation issued based on the Personal Data Protection Law to regulate security, technical, and organizational measures, all entities subject to the provisions of this Decision are required to apply the necessary technical, organizational, and regulatory procedures and measures to protect data, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage. Those measures and procedures must ensure a level of security appropriate to the risks posed by the processing and the nature of the data to be protected.

Board of Directors Responsibilities

Article (12)

The Board of Directors or the committees emanating from it are considered responsible for the entity's compliance with the application of the provisions of the Personal Data Protection Law and the legislation issued pursuant to it, including this Decision, and for this purpose, they undertake the following tasks:

a) Adopting clear data protection policies, within a clear and effective framework that includes the basic principles of personal data protection, thereby ensuring enhancing trust between the entity and its clients.

b) Verifying the comprehensiveness of the adopted policies regarding the role of the entity's internal audit, risk, and compliance departments concerning personal data protection.

c) Forming committees or establishing regulatory frameworks that ensure that relevant administrative bodies provide the Board of Directors with the necessary information to exercise its role in effective supervision of compliance with personal data protection legislation, including data breach statistics.

d) Appointing a Data Protection Officer to monitor compliance with data protection principles and perform the tasks assigned to them under the Personal Data Protection Law.

e) Following up on the results of periodic risk assessments related to data processing, and updating policies based on these results.

f) Adopting training plans for Board of Directors members and employees to enhance the concept of data protection and compliance with the Personal Data Protection Law, and monitoring progress in implementing the plan at least annually.

g) Conducting periodic compliance reviews.

h) Cooperating with competent regulatory authorities and verifying the provision of required information in the event of any data breaches.

Privacy Policy

Article (13)

The entity is committed to preparing a privacy policy for the data it processes, in clear and easy-to-understand language suitable for data subjects to perceive, such that the policy includes at a minimum the following:

a) Identifying the data to be collected and categorizing it into specific categories according to its type, such as identity data, family status data, contact data, banking and financial data, technical data, biometric data, and health data.

b) Stating the methods of data collection and categorizing them into the following categories: 1- Data collected directly from the concerned person and the means used for this purpose (for example: by filling out linear or electronic forms, direct communication, email, digital services and applications). 2- Data collected indirectly and the means used to collect it (for example: through the concerned person's interaction with the website and digital channels, cookie technologies, automatic collection of information and technical data about devices and browsing procedures, website and digital channel analytics, or interconnection with another entity). 3- Data collected about the concerned person from other parties: such as data provided by other parties (for example: the employer or a family member, legal representative, beneficiary of the transaction or contract, representatives of corporate entities, beneficial owner, property owner). 4- Sources available to the public.

c) Preparing a matrix showing how data is used, which shall include the following:

  1. Type of data (for example: identity, profile, financial data, technical or technical data, contact data, contact data).
  2. The purpose of collecting each of the above data and processing it clearly and specifically, and it must be directly related to the entity's work.
  3. The legal basis relied upon in collection and processing (and it may be based on one or more bases), and it shall be any of the following:
  • Consent of the concerned person.
  • Compliance with a legal requirement (including cases stipulated in Article (4) of this Decision).
  • Implementing a contract with the concerned person.
  • The entity's security purposes (such as television filming or video surveillance).
  • Judicial requirements or regulatory authorities.
  • Preserving the vital interest of the concerned person.
  • The legitimate interest of the entity; provided that the entity balances the interest of the concerned person with its legitimate interest, such that the entity's legitimate interest does not affect the rights or interests of the concerned person, and the entity shall explain the rationale for that interest (for example: developing products or services, keeping restrictions updated, debt recovery, raising security and technical standards, enabling the client to complete transactions).
  1. Stating whether data or any part of it will be disclosed to another entity, and identifying these entities, their status, the purpose and legal basis for disclosure, and whether the disclosure is for a one-time or regular basis.

d) Provisions related to marketing.

e) Clarifying data storage methods and identifying the countries where data is stored, retention periods, and methods of destruction after the purpose is achieved.

f) A general description of the technical and organizational means and measures taken to protect data, in accordance with the legislation issued pursuant to the provisions of the Personal Data Protection Law and related prevailing legislation in the Kingdom.

g) Stating the rights of the concerned person and the means available to respond to their requests and inquiries, and clearly disclosing the inability to respond to any requests that conflict with the provisions of prevailing legislation or regulatory and supervisory requirements to which the entity is subject, or that may lead to concealing, modifying, or intentionally changing information necessary to identify the client and beneficial owner or the accuracy of their credit report, or affect due diligence requirements, or conflict with the security and integrity of the operations performed by the entity or expose it to risk.

h) Mechanisms for submitting complaints and objections, dedicated channels for this purpose, the expected timeframe for handling and responding to requests, and identifying the department responsible for receiving and processing them, and contact details of those responsible for following up, in accordance with the Personal Data Protection Law and the legislation issued pursuant to it.

i) Data related to the Data Protection Officer of the entity, including their name and contact details.

Article (14)

The entity is committed to publishing the privacy policy and making it available on its website, and reviewing and updating it periodically. The entity must notify its clients in the event of any fundamental amendment to this policy according to their contact details.

Commercial Exploitation and Marketing

Article (15)

a) The entity is prohibited from using the data of its clients and clients for commercial exploitation or selling data to others.

b) The entity may process its clients' data to market its services and products directly to them, within the scope of the business, services, and products provided to the concerned person under the contract concluded with the entity; or similar or related services and products, including services and products provided by wholly-owned companies, subject to the following:

  1. The entity must inform the concerned person in clear, simple, and non-misleading language of their right to unsubscribe from direct marketing channels during the first communication, with clarification of how to unsubscribe.
  2. The entity must allow concerned persons to unsubscribe from all marketing channels without any financial or contractual consequences, and the cancellation must be easy and convenient.
  3. Confirming receipt of the cancellation request from the concerned person and informing them that their data will no longer be used for direct marketing purposes.
  4. Determining the retention period for data used for marketing purposes as one year at most, and deleting the data after the purpose is achieved unless there is a legislative or legal justification for retaining it.

Records of Processing Activities

Article (16)

a) The entity must maintain a record of data processing activities throughout the period during which such processing continues, and retain the record for any periods required by prevailing legislation, and not less than five years starting from the date of completion of processing.

b) The record of data processing activities must include at a minimum, all data processed by the entity according to the privacy policy approved by the entity, in detail, and stating the name and description of the unit that has access rights to that data, including those responsible for the processing activity, and the organizational, administrative, technical measures, and procedures that ensure the preservation of data.

c) The record of data processing activities is considered a tool for verifying the entity's compliance with the Personal Data Protection Law and the legislation issued pursuant to it.

Article (17)

The entity is committed to including data disclosure operations in its operation records and documenting their dates, methods, purposes, and legal basis.

Article (18)

The penalties stipulated in Personal Data Protection Law No. (24) of 2023 and the legislation regulating the operations of entities subject to the provisions of this Decision shall be applied as appropriate to any entity that violates the provisions of this Decision.

Article (19)

This Decision shall be implemented from the date of its approval; and entities subject to its provisions are committed to aligning their status with its provisions within a period of one hundred and twenty days from the date of its approval.

Governor Dr. Adel Al-Sharkas

Page 15 of 15