2021-03-03

Added · Updated

Financial Consumer Protection Instructions for Payment and Electronic Money Transfer Companies No. (3/2021)

The Central Bank of Jordan issued Instructions No. (3/2021) imposing consumer protection obligations on licensed payment service providers and electronic payment system managers. The document mandates transparent advertising, clear disclosure of fees with 30 days' notice for changes, and standardized written contracts. It establishes strict requirements for personal data protection, including encryption, access controls, and breach notification, while defining customer rights to data access and revocation. Additionally, providers are held liable for damages resulting from system malfunctions or fraud occurring without customer negligence.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

In the Name of Allah, the Most Gracious, the Most Merciful

[Logo of the Central Bank of Jordan]

Number: 4/27/3781 Date: 19/7/1442 AH Corresponding to: 3/3/2021 AD

Financial Consumer Protection Instructions for Payment and Electronic Money Transfer Companies No. (3/2021)

Issued pursuant to the provisions of Paragraph (b/13) of Article (4) of the Central Bank of Jordan Law No. (23) of 1971 and its amendments, and Articles (34/b), (36), (37), and (38) of the Payment and Electronic Money Transfer System No. (111) of 2017.


Article (1): a. These Instructions shall be known as the "Financial Consumer Protection Instructions for Payment and Electronic Money Transfer Companies" and shall come into effect three months after their approval. b. These Instructions apply to all payment and electronic money transfer companies in the Kingdom licensed to conduct any of the payment service activities or manage and operate electronic payment systems (to the extent applicable to them) under the provisions of the Payment and Electronic Money Transfer System No. (111) of 2017. c. These Instructions do not apply to banks and exchange companies.

Article (2): a. The following words and expressions shall have the meanings assigned to them wherever they appear in these Instructions, unless the context indicates otherwise:

  • Central Bank: The Central Bank of Jordan.
  • Payment Service Provider: Any company licensed to conduct any of the payment service activities under the provisions of the Payment and Electronic Money Transfer System No. (111) of 2017.
  • Electronic Payment System Manager: Any company licensed to conduct any of the activities of managing and operating electronic payment systems under the provisions of the Payment and Electronic Money Transfer System No. (111) of 2017.
  • Company: Payment Service Provider and Electronic Payment System Manager.
  • Customer: The natural or legal person who owns the electronic payment account.
  • Electronic Payment Account: The account owned by the Customer with the Payment Service Provider, to which any payment instruments and/or through which electronic money is issued.
  • Services: Any of the payment services licensed to the Payment Service Provider to provide under the license granted to it in accordance with the provisions of the Payment and Electronic Money Transfer System (111) of 2017.
  • Products: Any program that possesses specific characteristics and conditions that distinguish it from the services provided by the Payment Service Provider.
  • Personal Data: All data related to the Customer, regardless of its source or form, through which the Customer's identity can be determined or recognized, or any of their transactions can be identified directly or indirectly, excluding information available and known to the general public.
  • Processing of Personal Data: Performing any process or set of processes in any form on personal data, such as collection, receipt, registration, organization, preparation, modification, retrieval, use, exploitation, disclosure, publication, transfer, blocking, disposal, erasure, and cancellation.
  • Credit Payment Instrument: Any electronic means approved by the Central Bank that enables its holder to conduct payment or electronic money transfer operations. It is issued by the Payment Service Provider to the Customer without a balance in the electronic payment account, and the Customer may incur additional interest and commissions as a result of possessing it.

b. The definitions contained in the Central Bank of Jordan Law, the Electronic Transactions Law, the Cybercrimes Law, and the Payment and Electronic Money Transfer System shall apply wherever the text refers to them in these Instructions, unless the context indicates otherwise.


Disclosure and Transparency

Article (3): a. The Payment Service Provider is committed to ensuring that when advertising, marketing, or providing information to the Customer regarding its products and services, the information is sufficient and clear, whether provided in writing, electronically, or verbally. The information must enable the Customer to acquire adequate knowledge about these products and services and match their needs. The Payment Service Provider must ensure, as a minimum, the following:

  1. Providing an explicit, clear, comprehensive, and expressive explanation of facts regarding products and services, including terms and conditions, benefits, and key specifications, in a manner that prevents vague, misleading, or ambiguous promises and phrases for the Customer.
  2. Ensuring that brochures and advertising materials regarding products and services are drafted in understandable Arabic for the average person and in readable font, including margins.
  3. In the event of an offer related to a specific product or service for a limited period, the Payment Service Provider must clarify the expiration date of this offer when advertising it.
  4. If the Customer is unable to understand the Arabic language or read written information, they must be provided with appropriate methods and means for verbal interpretation in a language they can understand. b. The Payment Service Provider is committed to not including in the advertisement of a product or service any offense in any form to other competing Payment Service Providers or to others. c. The Payment Service Provider may advertise its products and services with brief phrases through electronic means or through visual, audio, and written advertising media, provided that all details related to the advertisement are available on its website, branches, offices, and agency network, in accordance with the provisions of Paragraph (a) of this Article.

Commissions and Fees

Article (4): The Payment Service Provider is committed to the following: a. Disclosing to Customers transparently and through all available means the prices of commissions, fees, and interest charged by the Payment Service Provider for all products and services, keeping them continuously updated, and displaying them prominently in the main administration, branches, offices, agency network, and electronic media. b. Ensuring that all commissions received by the Payment Service Provider are clearly specified in agreements concluded with Customers, including the conditions that must be met in case of increasing these commissions. c. Providing the Customer with a list of commissions they will bear in exchange for obtaining any of the products or services. d. Notifying the Customer in advance when providing a product or service that entails any additional fees or commissions borne by the Customer, or any additional interest the Customer must pay for obtaining one of the credit payment instruments, or due to the existence of a third party related to the mechanism of providing the product or service, including this in the pricing policy. e. Informing Customers through appropriate means, including electronic means and text messages, of any modification to pricing policies or the list of commissions that affects Customers, at least (30) days before the date of applying the new prices and commissions. f. Not deducting any additional commissions or fees from the Customer that are not disclosed according to the published pricing policy.


Contracts

Article (5): The Payment Service Provider must organize the relationship between itself and the Customer through written agreements in clear Arabic understandable to the average person, printed in a clear and readable font, and the texts must be drafted clearly without ambiguity or multiple interpretations (not subject to interpretation). The contract must include, as a minimum, the following: a. The provisions and conditions related to providing the product or service and the mechanism for dealing with them. b. The role and responsibilities of the Payment Service Provider, including specifying the cases in which the Payment Service Provider has the right to suspend the electronic payment account or any of the payment instruments or electronic media associated with it. c. The rights and obligations of the Customer and the consequences for them in case of breach of their contractual obligations towards the Payment Service Provider. d. The commissions and fees the Customer will bear, and the mechanisms for informing the Customer through appropriate means of any modification to them. The clauses related to fees, commissions, and interest borne by the Customer must be clarified, and the Customer must sign next to them. e. How the Customer is notified of transactions made on their electronic payment account or the periodicity and nature of the account statement. f. Statement of the Customer's right to file complaints and methods for receiving complaints, without bearing any commissions or fees and without imposing any conditions or restrictions that hinder their right to file a complaint. g. Procedures to be followed in the event of the Customer's death, freezing or closing the electronic payment account, or suspending any of the payment instruments or electronic media associated with it. h. Methods for calculating and crediting interest, if any. i. Financial transactions the Customer is allowed to execute. j. The mechanism for refunding amounts in case the Payment Service Provider ceases operations. k. Clauses confirming the confidentiality of Customer information and data and not using them for any purposes outside the scope of the business relationship and/or sharing them with any third party without the prior written consent of Customers or due to one of the cases permitted under the provisions of prevailing legislation and these Instructions. l. The Customer's acknowledgment stating the validity of the information and documents provided to the Payment Service Provider for the purpose of opening the electronic payment account, and the confirmation of the necessity to inform the Payment Service Provider of any modification or change to their address or phone number or any information of importance at the time or upon request by the Payment Service Provider. If it is found otherwise, this is considered a breach of the contract, and the Payment Service Provider has the right to suspend the product or service provided or close the electronic payment account as appropriate, after notifying the Customer through appropriate means.

Article (6): The Payment Service Provider is committed, before signing the contract with the Customer, to giving them sufficient time to review the content of the contract and all its clauses and any related attachments, answering their inquiries, and ensuring their understanding of all rights, obligations, information, provisions, and conditions related to the product or service subject to the contract.

Article (7): a. The Payment Service Provider must provide the Customer with a copy of the contract and its attachments after signing it with the Customer or their authorized representative, and obtain proof that the Customer received those copies. b. The Payment Service Provider is committed to terminating the contract upon the Customer's request at any time without charging any commissions for this, ensuring the necessary arrangements are made to return amounts due to the Customer. c. The Payment Service Provider may not terminate the contract unless the Customer breaches the contract terms, or it is found that any of the submitted documents are false, or it is discovered that the Customer is listed on any of the blocking lists issued by the Technical Committee for implementing the obligations contained in UN Security Council Resolution 1373 (2001) and other related resolutions, or the Customer engages in illegal activities requiring the Payment Service Provider to terminate the contract. This must be done after notifying the Customer, whether in writing or electronically, to the approved address, and after verifying through appropriate means that the Customer received the notification. The Payment Service Provider must also immediately notify the Anti-Money Laundering and Combating the Financing of Terrorism Unit if there is suspicion of connection to money laundering or terrorism financing, according to the model or means approved by the Unit for this purpose, in accordance with the provisions of the prevailing Anti-Money Laundering and Combating the Financing of Terrorism Law and related Instructions. d. The contract must not include a clause granting the Payment Service Provider the right to modify any clause of the contract unilaterally without obtaining the Customer's prior consent.


Personal Data Protection

Article (8): The Company is committed to establishing the necessary policies and procedures to protect Customers' personal data, which must include, as a minimum, the following requirements: a. Personal data protection procedures, whether electronic or physical, and the necessary precautions to preserve and protect them from loss, damage, modification, disclosure, theft, tampering, unauthorized access, or use for casual, illegal, or unauthorized purposes. b. Access rights to personal data and its use, whereby the Payment Service Provider informs the Customer that their data will be collected, stored, and retained for purposes related to the Payment Service Provider's business, and that disclosure will only occur in exceptional cases in accordance with these Instructions and prevailing legislation. c. Evaluation and monitoring procedures for the policies and procedures specified to protect personal data and compliance with them, and reporting any violations of procedures aimed at protecting them. d. Procedures for sharing personal data with third parties and how sharing is conducted; this must include the data subject's consent where necessary, in accordance with these Instructions and prevailing legislation, specifying the entity with which sharing will occur and the purpose of sharing, which must be compatible with the interests of all parties. e. Procedures for data archiving, destruction, and protection of backup systems. f. The accountability and liability framework in case of intentional or unintentional infringement on personal data. g. Procedures to inform Customers immediately in the event of any breach of their personal data or any threat to Customer personal data, as soon as the Payment Service Provider becomes aware of it. h. Reviewing privacy protection procedures before introducing new processing operations. i. Mechanisms for identifying processors responsible for protecting personal data.

Article (9): a. The Company is committed to maintaining strict confidentiality regarding all transactions related to Customers. Members of its Board of Directors, any current or former employees, any third party contracted with it, and anyone privy to such information by virtue of their position are prohibited from providing any data about them directly or indirectly, disclosing them, or enabling others to access them. This prohibition remains in effect even if the relationship between the Customer and the Payment Service Provider ends for any reason. b. The following cases are exempt from the confidentiality provisions stipulated in Paragraph (a) of this Article:

  1. Obtaining written consent from the Customer or one of their heirs.
  2. Issuance of a decision by a competent judicial authority in an existing legal dispute.
  3. Duties imposed by law on the Company's auditors.
  4. Actions and procedures performed by the Central Bank under the provisions of the prevailing Payment and Electronic Money Transfer System or any prevailing legislation, including the provisions of these Instructions.
  5. Issuing a certificate or statement of reasons for rejecting the execution of a payment or financial transfer operation upon the request of the right holder.
  6. Exchange of information related to Customers to execute their operations, and any exchange of information approved by the Central Bank under special arrangements aimed at developing the national payment system in the Kingdom.
  7. Publishing data and information related to Customers in the form of statistical data or disclosing them to competent regulatory authorities in accordance with prevailing legislation.
  8. Disclosure of all or part of the Customer's transaction data necessary to prove their right in a legal dispute arising between the Payment Service Provider and their Customer regarding these transactions.
  9. Disclosure by the Payment Service Provider of all or part of the data related to their Customers' transactions for the purpose of agreeing on the sale of the Payment Service Provider's assets or its merger.

Article (10): The Payment Service Provider is committed, when collecting and processing personal data, to observing the following requirements as a minimum: a. Obtaining only the necessary data for the purpose of providing the product or service and committing to processing or using it within the scope of the purpose for which it was collected. b. Processing data fairly, honestly, and legally in accordance with prevailing legislation and these Instructions. c. Ensuring that data is documented, correct, and accurate, verifying its correctness before processing and use by the Payment Service Provider, and updating it whenever necessary, while observing the provisions of prevailing legislation. d. Informing the Customer of the necessity to update their data with the Provider when necessary, including providing appropriate means to execute the required update, and informing them of any updates made to their data.

Article (11): a. The Company is committed, when retaining personal data, to observing the following requirements as a minimum:

  1. The data retained must be sufficient, accurate, and directly related only to the purpose for which it was stored.
  2. Commitment to deleting data records at the end of the retention period in a manner that prevents their retrieval, use, or benefit, and not retaining data for a period exceeding that specified in relevant prevailing legislation. b. The Company must provide the appropriate technological environment for processing and protecting personal data and reviewing it continuously, observing the following requirements as a minimum:
  3. Using encryption technologies to protect the confidentiality and integrity of data, selecting encryption technology appropriate to the nature and importance of the data and the required level of protection.
  4. Restricting access rights to this data to specialized employees.
  5. Taking all necessary technical and technical controls and measures to protect their systems and networks to prevent unauthorized access to such data or disclosure, and protecting them from tampering, sabotage, or misuse.
  6. Periodic review of procedure and system security testing operations - for example, penetration testing - and continuous monitoring of developments in security systems in this field, downloading and preparing appropriate software updates and service packs, and necessary measures after conducting required tests, and documenting these tests.
  7. Encrypting the process from the device used to perform the operation to the servers (Servers) responsible for executing the service.

Article (12): The Company must apply a policy of segregation of duties and dual control in the management of personal data to ensure that no employee within the Company can perform any unauthorized work and conceal it. This includes, for example, user account management, executing transactions, storing and managing system encryption keys, and system administration and operations. Security procedures must also be established, including as a minimum the following: a. Providing necessary protection to prevent unauthorized persons from entering the work environment containing all vital systems, network servers, databases, applications, communications, and the Company's security systems. b. Regulating the rights of specialized employees able to access personal data. c. The ability to restore personal data after tampering, sabotage, deletion, or similar cases. d. Company employees signing a commitment to maintain the confidentiality of personal data and related information, ensuring their commitment not to misuse or disclose it during their employment and even after leaving their jobs.

Article (13): The Company must identify and assess risks related to personal data protection and establish necessary procedures to manage them and ways to mitigate them. It must continuously verify the effective implementation of those procedures and ensure that procedures are continuously updated in response to emerging risks. In conducting risk assessments, the Company must consider the following: a. Identifying risks at all levels, including remote personal access levels. b. Authorized and specialized persons accessing data, classifying them, and assessing risks associated with unauthorized access (hacking). c. Data used through a third party, identifying the entity responsible for data security, and reporting any breaches, violations, or risks.

Article (14): a. The Payment Service Provider must establish procedures ensuring that no information related to Customers or their electronic payment accounts is disclosed when responding to their inquiries, except after verifying their personal identity. b. The Customer has the following rights:

  1. To revoke their previously given consent regarding the sharing of their personal data, whether in writing, electronically, or verbally, with verbal revocation being recorded.
  2. To object to the processing of their personal data or request the deletion of their personal data or part of it if it is not necessary to achieve the purposes for which it was collected, if it exceeds requirements, or if it violates prevailing legislation.
  3. To review their personal data, object to it, and request correction, attaching all supporting documents for the request.

Protection of Electronic Payment Accounts from Fraud or Hacking

Article (15): The Payment Service Provider is committed to the following: a. Establishing procedures to prevent the electronic payment account from being hacked or used in fraudulent ways. b. Taking necessary measures to educate and train Customers when providing the product or service, continuously, regarding their duties and obligations to maintain their personal security data (such as passwords and usernames) to prevent electronic payment accounts, including associated payment instruments or electronic media, from being hacked or used in fraudulent ways, and mechanisms for dealing with cases of theft, loss, fraud, or hacking. c. Bearing any damages that may be incurred by the Customer due to a system malfunction, or due to any third party dealing with the Payment Service Provider's Customers for the benefit of the Payment Service Provider, or due to fraud and/or hacking operations occurring without negligence or fault on the part of the Customer.

Article (16): For the purposes of protecting and securing the personal security data of Customers stipulated in Article (15) of these Instructions, the Payment Service Provider is committed to providing advice and guidance to the Customer, as a minimum, as follows: a. Not allowing any other person to use their payment instrument or electronic media, or their electronic payment account data, or to know any of their personal security data. b. Keeping personal security data in a place difficult for others to access, and it is best to keep it in the Customer's memory. c. Properly disposing of any notifications received by the Customer containing any of their personal security data immediately. d. Not writing any personal security data in a place easily accessible to others. e. Not keeping personal security data associated with the payment instrument or electronic media. f. Not using personal security data related to dates, numbers, or easily guessable names, such as passport numbers or dates of birth. g. Changing passwords regularly. h. Publishing advice for Customers through appropriate means regarding fraudulent methods to alert them and inform them of how to avoid them and not fall victim to them.

Article (17): The Payment Service Provider must provide suitable communication channels and electronic means, including a free phone line available around the clock, to enable the Customer to easily report cases of theft, loss, fraud, or hacking, and any suspicious operations related to their personal security data, payment accounts, payment instruments, and electronic media.

Article (18): The Company is committed to notifying the Central Bank and relevant authorities of any cases of hacking or fraud of personal data, personal security data, electronic payment accounts, payment instruments, and associated electronic media immediately upon occurrence and awareness. The Company must continue to implement the following requirements: a. Determining how the hacking, fraud, or unauthorized access occurred, its cause, how it was addressed, and how to prevent recurrence. b. Addressing the hacking, fraud, or unauthorized access, evaluating the speed of response and procedures followed, and continuously updating policies, procedures, and necessary controls.


Dealing with Customers Fairly and Respectfully

Article (19): a. The Payment Service Provider is committed to the following:

  1. Treating all Customers fairly and without discrimination, prohibiting favoritism and discrimination in dealing with Customers at any stage of service provision based on religion, race, gender, or any other reason.
  2. Providing advice and consultation to its Customers, whether those in difficulty or those facing financial hardships, to overcome those difficulties before proceeding with legal measures against them.
  3. Establishing clear procedures specifically for dealing with Customers in difficulty, humanitarian cases, or Customers with urgent financial difficulties.
  4. Establishing clear and specific procedures for dealing with Customers who cannot read, Customers who cannot write, or Customers with disabilities, in accordance with Financial Consumer Protection Instructions for Customers with Disabilities No. (18/2018) and/or any Instructions replacing or amending them.
  5. Training employees, especially those on the front lines, on methods of dealing with Customers fairly, transparently, and respectfully, ensuring the application of the provisions of these Instructions. b. The Payment Service Provider must establish a special policy or include in its policies principles of dealing with Customers fairly and respectfully, meeting all requirements of these Instructions, and obtaining Board of Directors approval. It must review this policy at least every three years or whenever necessary, taking into account Customer needs through complaints, feedback from Customers and related parties, and the Central Bank.

Article (20): a. It is prohibited for employees of the Payment Service Provider, specifically those responsible for following up on the collection of dues on credit payment instruments, to do any of the following:

  1. Contact any third party related to the Customer or visit them at their workplace to request information about the Customer, including their financial solvency.
  2. Provide the Customer with incorrect or other information, whether in writing or verbally, regarding the consequences of default.
  3. Write on postal correspondence and other communications sent to the Customer in a way that appears to relate to the collection of dues or any other private financial matters.
  4. Send a notice to more than one Customer in a single notice, including personal information belonging to other Customers.
  5. Using inappropriate or arbitrary means to collect dues. b. The Payment Service Provider is also prohibited from doing any of the following:
  6. Performing any verbal or written act that leads to misleading the Customer.
  7. Requesting the Customer in any way to purchase any other product or service as a condition for obtaining any of its services or products.
  8. Requesting the Customer in any way to waive any of their rights as a condition for their subscription or obtaining any of its products or services.
  9. Requesting the Customer in any way to terminate contracts with other companies for the purpose of obtaining any of its products or services.

Dealing with Credit Payment Instruments

Article (21): The Payment Service Provider is committed to preparing the following bases and procedures: a. Written bases and procedures for designing credit payment instruments in a manner that limits the risks of over-indebtedness, including the following:

  1. Identifying the target Customer segment in accordance with the Payment Service Provider's strategy and competitive ability.
  2. Work procedures to be followed when launching a new credit payment instrument, including decision-making authority to approve that instrument and evaluating its suitability for the needs and capabilities of target Customers.
  3. Controlling risks associated with the credit payment instrument at all stages, including development, pricing, marketing, and sales.
  4. Procedures for assessing Customer solvency and their ability to repay. b. A credit policy and work procedures approved by the Board of Directors, which must include, as a minimum, the maximum debt burden ratio (the sum of what is deducted from the Customer's regular income for granted credit or a percentage of it to the Customer's total regular income, where regular income means the Customer's monthly net salary and any other income from a known and specific source), the maximum maturity period for credit, the maximum interest/yield ratio, and a clear mechanism for conditions for rescheduling defaulted credit.

Article (22): The Payment Service Provider must investigate - before granting a credit payment instrument and signing the contract - the Customer's credit status from reliable sources such as the licensed credit information company, and obtain a duly acknowledged statement of all the Customer's obligations and the burden of repaying those obligations. This applies whether granting a credit payment instrument to a new Customer or renewing a credit payment instrument for an existing Customer, and reliance must not be placed on information collected when granting a credit payment instrument for the first time.

Article (23): The Payment Service Provider must include the following clauses in contracts related to issuing credit payment instruments, clarifying to the Customer what is stated therein upon contracting: a. The upper limit of interest/yield shall not exceed (1.75%) monthly. b. The cost of granting/renewing the credit payment instrument, the interest/yield rate approved by the Payment Service Provider, the minimum amount due monthly and/or its percentage of the balance, and any costs imposed for late payment or exceeding the credit instrument limit, and the cost of cash withdrawals. c. The time period required to provide the Customer with a clearance certificate for the credit payment instrument after completing the repayment of the balance. d. Providing the Customer with an information card containing phone numbers that can be contacted in case of loss of the credit payment instrument, with one of these numbers available around the clock. e. Suspending the credit payment instrument immediately if the Customer notifies the Payment Service Provider of the loss of the credit payment instrument, and exempting the Customer from any responsibility for any transactions after the moment of notification. f. Providing the Customer with a monthly account statement, which must include the Q