2025-08-07
Added · Updated
The Central Bank of Jordan issued Decision No. 2025/831 to regulate data processing by supervised entities, including banks, insurance companies, and exchange firms, under the Personal Data Protection Law No. 24 of 2023. The decision permits data processing without prior consent for specific purposes such as anti-money laundering compliance, fraud prevention, and cybersecurity, while strictly prohibiting unauthorized disclosure of client data. It mandates rigorous assessments and Board of Directors approval for transferring data to countries lacking adequate protection levels and requires entities to implement robust security measures and appoint Data Protection Officers.
CENTRAL BANK OF JORDAN
Central Bank of Jordan
No.: 218/6/9 Date: 1447 AH Corresponding to: 2025 AD
Circular to Licensed Exchange Companies
Greetings,
Based on the provisions of Item (6) of Paragraph (a) of Article (6) of Personal Data Protection Law No. (24) of 2023, we attach to you Decision No. (2025/831) dated 2025/08/04 concerning data processing by entities subject to the supervision and oversight of the Central Bank of Jordan, to be implemented in accordance with its contents.
Please accept our highest respect,
Governor Dr. Adel Al-Sharkas
Classification Level: Internal Use Page 1 of 1
CENTRAL BANK OF JORDAN
Central Bank of Jordan Governor's Decisions
No.: 2025/831 Date: 10 Safar 1447 AH Corresponding to: 2025/08/04
Decision Concerning Data Processing by Entities Subject to the Supervision and Oversight of the Central Bank of Jordan Issued pursuant to the provisions of Article (6/a) of Personal Data Protection Law No. (24) of 2023
In the context of the Central Bank's efforts to enhance the personal data protection system in accordance with the provisions of Personal Data Protection Law No. (24) of 2023 among all entities under its supervision, and its keenness to achieve alignment between consolidating the basic principles of personal data protection and the necessity of continuity and stability in the efficient and effective operation of entities subject to the Central Bank's supervision; serving the clients dealing with them to the fullest extent, while respecting the privacy and nature of the operations of these entities, and within a methodology consistent with regulatory and legislative requirements, and based on the provisions of Item (6) of Paragraph (a) of Article (6) of the Personal Data Protection Law; the Central Bank of Jordan decides the following:
Article (1)
a) The following words and phrases wherever they appear in this Decision shall have the meanings assigned to them below unless the context indicates otherwise: -
The Bank: The Central Bank of Jordan.
The Entity: Any of the entities subject to the supervision and oversight of the Central Bank in accordance with the provisions of prevailing legislation, including banks, insurance and reinsurance companies, insurance service providers and the unified office, exchange companies, payment and electronic money transfer companies, financing companies, and credit information companies.
Board of Directors: The Board of Directors or the Regional Manager if the entity is a public or private joint-stock company, the General Manager or the Board of Directors of the entity if it is a limited liability company, and the authorized partners or the company manager if the entity is a partnership company.
b) The definitions contained in the Personal Data Protection Law of 2023 shall be adopted wherever the text refers to them unless the context indicates otherwise.
Scope of Application
Article (2)
a) The provisions of this Decision shall apply to all entities subject to the supervision and oversight of the Bank operating in the Kingdom.
b) Subject to the provisions contained in this Decision, all entities subject to the supervision and oversight of the Bank are committed to applying the provisions of the Personal Data Protection Law and the legislation issued pursuant to it.
Data Protection and Transaction Confidentiality
Article (3)
a) All entities must observe full compliance with the confidentiality provisions stipulated in the legislation regulating their operations. The application of any legal provisions regulating data processing without the consent or notification of the concerned person as stipulated in Article (6/a) of the Personal Data Protection Law 2023 or any legislation issued pursuant to it shall not be considered a reason or justification for deviating from the confidentiality provisions stipulated in the legislation regulating the entity's operations.
b) For the purposes of complying with the Personal Data Protection Law and the provisions of this Decision, the entity is committed to determining the scope and limits of processing operations for customer and client data accurately, such that they include only the operations necessary to achieve the legitimate purposes of the services and operations licensed by the Bank to provide.
c) The entity is prohibited from publishing, distributing, disclosing, or making available customer or client data to others except in legally permitted cases or with prior consent from the concerned person, while adhering to security and privacy standards.
d) Credit information companies are committed to the legal provisions regulating their work as specified in the prevailing Credit Information Law and the systems and instructions issued pursuant to it.
Purposes of Processing without Prior Consent of the Concerned Person
Article (4)
a- Any entity may process data without obtaining prior consent or notification from the concerned person if such processing is necessary for the performance of its operations and for any of the following purposes:
If required or authorized by legislation, or in implementation thereof, or by a decision of a competent judicial authority.
Compliance with legal requirements under the prevailing Anti-Money Laundering and Counter-Terrorism Financing Law and the systems and instructions issued pursuant to it, including purposes of verifying lists of sanctions and penalties issued by decisions of the UN Security Council and requests and instructions from competent regulatory authorities legally authorized to do so and law enforcement authorities.
If the processing is necessary to comply with regulatory requirements issued by competent authorities legally authorized to do so, including requirements issued by those authorities to protect financial system stability or the public interest.
If the processing is necessary for the entity to take necessary measures to combat financial fraud within its operations or in implementation of measures issued by competent authorities legally authorized to do so.
If the processing is necessary for the entity to verify the integrity and security of the operations it performs.
For the purposes of the entity carrying out anonymization or pseudonymization operations.
For the purposes of the entity carrying out necessary measures for cybersecurity purposes and its operations and services; including scanning operations related to cyberattacks and analyzing network traffic to detect threats and suspicious activities.
Verifying data provided by the client regarding the identity of individuals who do not have a direct relationship with the entity, such as the beneficiary of the business relationship or transaction, guarantor, agent, trustee, or legal representative, shareholders, partners, managers, representatives, authorized persons, and employees of corporate clients, family members, general/special heirs, rights holders, reference contacts, and details of persons to be contacted in emergencies.
If the processing is necessary and related to the implementation of the business, services, and products provided by the entity to the concerned person or similar or related operations, or to implement a contract between the entity and the concerned person.
If the processing is necessary for the purposes of reinsurance arrangements.
To achieve a vital interest of the concerned person or to protect their vital interests.
To achieve a legitimate interest of the entity; provided that the entity balances the interest of the concerned person with its legitimate interest, such that the entity's legitimate interest does not affect the rights or interests of the concerned person, whereby the entity is committed, before starting processing based on legitimate interest, to conduct and document a legitimacy assessment, which shall include in particular the following: a- Determining the purpose of the processing. b- Evaluating the purpose by ensuring its legitimacy and that it does not violate any prevailing legislation in the Kingdom. c- Verifying that this processing is necessary to achieve the purpose for the entity. d- Conducting an assessment of whether the processing will cause any harm to the rights and interests of the concerned person. e- Granting the concerned person the right to object to the processing in case it is proven that the entity has not complied with any of the items mentioned above.
b- Intermediary entities in executing financial, banking, and monetary operations, including correspondent banks and licensed or authorized payment and electronic money transfer companies, are permitted to obtain data from participating parties without obtaining prior consent or notification from the concerned person and to process it to the extent necessary to execute those operations and to implement legislative and regulatory requirements.
Sources of Obtaining Data without Consent of the Concerned Person
Article (5)
In compliance with the due diligence requirements stipulated in the Anti-Money Laundering and Counter-Terrorism Financing Law and the instructions issued pursuant to it, the entity is permitted, for the purposes of carrying out processing in accordance with the provisions of this Decision, to obtain data without the consent or notification of the concerned person from any neutral, reliable, and official sources through which entities subject to this Decision can exercise due diligence towards the concerned person, whether they are clients, customers, beneficial owners, or any other persons whose identities and data are required by law to be verified in accordance with the Anti-Money Laundering and Counter-Terrorism Financing Law and the instructions issued pursuant to it, from any of the following entities:
Transfer and Exchange of Data Inside and Outside the Kingdom
Article (6)
Entities subject to the supervision and oversight of the Bank are not permitted to transfer or exchange data inside or outside the Kingdom except in cases permitted by the provisions of the legislation regulating their operations and the provisions of this Decision. Entities are also committed to obtaining prior written consent from the Central Bank if the legislation regulating them requires it.
Article (7)
Entities are permitted, for the purposes of carrying out their operations, to transfer data outside the Kingdom borders if the entity to which the data is to be transferred is located in one of the countries mentioned in the lists approved by the Personal Data Protection Board, concerning countries that have an adequate level of data protection, subject to the following conditions:
a) Determining the legal basis for the transfer, such as:
b) Stating the justification for the transfer outside the Kingdom, which is required by the nature of the entity's work, such as:
c) Establishing necessary procedures to determine the location of data storage, collection, and processing, including systems, applications, and data flow maps.
d) Adherence to all relevant legislation and instructions and circulars issued by the Bank.
Article (8)
Subject to verifying the conditions stipulated in Article (7) of this Decision, before transferring or exchanging data with any other entity located in one of the countries not mentioned in the lists approved by the Personal Data Protection Board - concerning countries that have an adequate level of data protection - the entity must verify that the level of protection applied by that entity is not less than the level of protection provided by the prevailing legislation in the Kingdom, and observe the following:
a) Conducting an assessment of the level of protection provided by the external entity to ensure that the level of protection applied by that entity is not less than the level of protection provided by the prevailing legislation in the Kingdom, such that the assessment includes potential effects and risks and reputational risks, and takes into account the following criteria:
b) Presenting the assessment results to the Board of Directors to determine the acceptable level of risk and approve it.
c) Completing the assessment from legal aspects to ensure the determination of mechanisms to implement the Board of Directors' decisions regarding the assessment, and to verify that the external entity's country has legislation protecting data subjects and ensuring that contracting parties can comply with contracts. The assessment shall take into account whether the external entity's country is a party to international agreements for the protection of personal data or adopts international standards and principles for its protection, and whether this country adopts behavioral codes, general practices, or specific standards for the protection of personal data.
d) Presenting all the above results to the Board of Directors to obtain its approval for contracting with the external entity and according to the conditions and provisions it approves for this purpose.
e) Preparing a plan to terminate the contract and transfer data in the event of any amendment to the legislation in the receiving country that reduces or conflicts with the level of protection provided by the prevailing legislation in the Kingdom, or in necessary cases, and not including in contracts any provisions that limit the entity's ability to terminate the contract immediately.
Article (9)
Notwithstanding what was stated in Article (7) of this Decision; if banking operations or money transfers abroad require the transfer of data to an entity in a country that does not provide the level of protection for personal data stipulated in the Personal Data Protection Law or the level of confidentiality stipulated in the legislation regulating the operations of entities subject to it, the entity must take all appropriate safeguards to protect the rights of data subjects, including but not limited to:
a- Identifying and documenting the data transferred outside the Kingdom for the purposes of banking operations and money transfers abroad, and the data must be limited to what is necessary only.
b- The entity must, before starting the data transfer process, verify the level of protection provided by the data recipient to ensure the protection and security of the data.
Data Storage
Article (10)
a- Subject to the conditions stipulated in Article (7), entities subject to the provisions of this Decision are committed to including in agreements related to data storage with any entity inside or outside the Kingdom a clause prohibiting the service provider or any of its contractors or any third party or any authority or official entity in its country from accessing the data and information stored therein; otherwise, the entity is committed to obtaining the consent of the concerned person for storing their data.
b- The prohibition provisions contained in Paragraph (a) above do not apply to entities responsible for supervising the foreign branch operating in the Kingdom in its home country.
c- The entity is committed to including in agreements and contracts related to storage an explicit clause on the non-transfer of data ownership or disposal rights to the storage service provider or any of its contractors, any third party, or any authority or official entity in its country, in addition to explicitly stating the right of the Central Bank of Jordan to obtain the data upon request.
d- Entities are committed to determining the data storage period in agreements and contracts related to storage, and not exceeding the periods stipulated in the prevailing legislation in the Kingdom.
Data Security
Article (11)
In addition to legislative and regulatory requirements related to data security and protection, including legislation issued based on the Personal Data Protection Law to regulate security, technical, and organizational measures, all entities subject to the provisions of this Decision are required to apply the necessary technical, organizational, and regulatory procedures and measures to protect data, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage. Those measures and procedures must ensure a level of security appropriate to the risks posed by the processing and the nature of the data to be protected.
Board of Directors Responsibilities
Article (12)
The Board of Directors or the committees emanating from it are considered responsible for the entity's compliance with the application of the provisions of the Personal Data Protection Law and the legislation issued pursuant to it, including this Decision, and for this purpose, they undertake the following tasks:
a) Adopting clear data protection policies, within a clear and effective framework that includes the basic principles of personal data protection, thereby ensuring enhancing trust between the entity and its clients.
b) Verifying the comprehensiveness of the adopted policies regarding the role of the entity's internal audit, risk, and compliance departments concerning personal data protection.
c) Forming committees or establishing regulatory frameworks that ensure that relevant administrative bodies provide the Board of Directors with the necessary information to exercise its role in effective supervision of compliance with personal data protection legislation, including data breach statistics.
d) Appointing a Data Protection Officer to monitor compliance with data protection principles and perform the tasks assigned to them under the Personal Data Protection Law.
e) Following up on the results of periodic risk assessments related to data processing, and updating policies based on these results.
f) Adopting training plans for Board of Directors members and employees to enhance the concept of data protection and compliance with the Personal Data Protection Law, and monitoring progress in implementing the plan at least annually.
g) Conducting periodic compliance reviews.
h) Cooperating with competent regulatory authorities and verifying the provision of required information in the event of any data breaches.
Privacy Policy
Article (13)
The entity is committed to preparing a privacy policy for the data it processes, in clear and easy-to-understand language suitable for data subjects to perceive, such that the policy includes at a minimum the following:
a) Identifying the data to be collected and categorizing it into specific categories according to its type, such as identity data, family status data, contact data, banking and financial data, technical data, biometric data, and health data.
b) Stating the methods of data collection and categorizing them into the following categories: 1- Data collected directly from the concerned person and the means used for this purpose (for example: by filling out linear or electronic forms, direct communication, email, digital services and applications). 2- Data collected indirectly and the means used to collect it (for example: through the concerned person's interaction with the website and digital channels, cookie technologies, automatic collection of information and technical data about devices and browsing procedures, website and digital channel analytics, or interconnection with another entity). 3- Data collected about the concerned person from other parties: such as data provided by other parties (for example: the employer or a family member, legal representative, beneficiary of the transaction or contract, representatives of corporate entities, beneficial owner, property owner). 4- Sources available to the public.
c) Preparing a matrix showing how data is used, which shall include the following:
d) Provisions related to marketing.
e) Clarifying data storage methods and identifying the countries where data is stored, retention periods, and methods of destruction after the purpose is achieved.
f) A general description of the technical and organizational means and measures taken to protect data, in accordance with the legislation issued pursuant to the provisions of the Personal Data Protection Law and related prevailing legislation in the Kingdom.
g) Stating the rights of the concerned person and the means available to respond to their requests and inquiries, and clearly disclosing the inability to respond to any requests that conflict with the provisions of prevailing legislation or regulatory and supervisory requirements to which the entity is subject, or that may lead to concealing, modifying, or intentionally changing information necessary to identify the client and beneficial owner or the accuracy of their credit report, or affect due diligence requirements, or conflict with the security and integrity of the operations performed by the entity or expose it to risk.
h) Mechanisms for submitting complaints and objections, dedicated channels for this purpose, the expected timeframe for handling and responding to requests, and identifying the department responsible for receiving and processing them, and contact details of those responsible for following up, in accordance with the Personal Data Protection Law and the legislation issued pursuant to it.
i) Data related to the Data Protection Officer of the entity, including their name and contact details.
Article (14)
The entity is committed to publishing the privacy policy and making it available on its website, and reviewing and updating it periodically. The entity must notify its clients in the event of any fundamental amendment to this policy according to their contact details.
Commercial Exploitation and Marketing
Article (15)
a) The entity is prohibited from using the data of its clients and clients for commercial exploitation or selling data to others.
b) The entity may process its clients' data to market its services and products directly to them, within the scope of the business, services, and products provided to the concerned person under the contract concluded with the entity; or similar or related services and products, including services and products provided by wholly-owned companies, subject to the following:
Records of Processing Activities
Article (16)
a) The entity must maintain a record of data processing activities throughout the period during which such processing continues, and retain the record for any periods required by prevailing legislation, and not less than five years starting from the date of completion of processing.
b) The record of data processing activities must include at a minimum, all data processed by the entity according to the privacy policy approved by the entity, in detail, and stating the name and description of the unit that has access rights to that data, including those responsible for the processing activity, and the organizational, administrative, technical measures, and procedures that ensure the preservation of data.
c) The record of data processing activities is considered a tool for verifying the entity's compliance with the Personal Data Protection Law and the legislation issued pursuant to it.
Article (17)
The entity is committed to including data disclosure operations in its operation records and documenting their dates, methods, purposes, and legal basis.
Article (18)
The penalties stipulated in Personal Data Protection Law No. (24) of 2023 and the legislation regulating the operations of entities subject to the provisions of this Decision shall be applied as appropriate to any entity that violates the provisions of this Decision.
Article (19)
This Decision shall be implemented from the date of its approval; and entities subject to its provisions are committed to aligning their status with its provisions within a period of one hundred and twenty days from the date of its approval.
Governor Dr. Adel Al-Sharkas
Page 15 of 15