2021-03-03
Added · Updated
The Central Bank of Jordan issued Instructions No. (3/2021) imposing consumer protection obligations on licensed payment service providers and electronic payment system managers. The document mandates transparent advertising, clear disclosure of fees with 30 days' notice for changes, and standardized written contracts. It establishes strict requirements for personal data protection, including encryption, access controls, and breach notification, while defining customer rights to data access and revocation. Additionally, providers are held liable for damages resulting from system malfunctions or fraud occurring without customer negligence.
In the Name of Allah, the Most Gracious, the Most Merciful
[Logo of the Central Bank of Jordan]
Number: 4/27/3781 Date: 19/7/1442 AH Corresponding to: 3/3/2021 AD
Financial Consumer Protection Instructions for Payment and Electronic Money Transfer Companies No. (3/2021)
Issued pursuant to the provisions of Paragraph (b/13) of Article (4) of the Central Bank of Jordan Law No. (23) of 1971 and its amendments, and Articles (34/b), (36), (37), and (38) of the Payment and Electronic Money Transfer System No. (111) of 2017.
Article (1): a. These Instructions shall be known as the "Financial Consumer Protection Instructions for Payment and Electronic Money Transfer Companies" and shall come into effect three months after their approval. b. These Instructions apply to all payment and electronic money transfer companies in the Kingdom licensed to conduct any of the payment service activities or manage and operate electronic payment systems (to the extent applicable to them) under the provisions of the Payment and Electronic Money Transfer System No. (111) of 2017. c. These Instructions do not apply to banks and exchange companies.
Article (2): a. The following words and expressions shall have the meanings assigned to them wherever they appear in these Instructions, unless the context indicates otherwise:
b. The definitions contained in the Central Bank of Jordan Law, the Electronic Transactions Law, the Cybercrimes Law, and the Payment and Electronic Money Transfer System shall apply wherever the text refers to them in these Instructions, unless the context indicates otherwise.
Disclosure and Transparency
Article (3): a. The Payment Service Provider is committed to ensuring that when advertising, marketing, or providing information to the Customer regarding its products and services, the information is sufficient and clear, whether provided in writing, electronically, or verbally. The information must enable the Customer to acquire adequate knowledge about these products and services and match their needs. The Payment Service Provider must ensure, as a minimum, the following:
Commissions and Fees
Article (4): The Payment Service Provider is committed to the following: a. Disclosing to Customers transparently and through all available means the prices of commissions, fees, and interest charged by the Payment Service Provider for all products and services, keeping them continuously updated, and displaying them prominently in the main administration, branches, offices, agency network, and electronic media. b. Ensuring that all commissions received by the Payment Service Provider are clearly specified in agreements concluded with Customers, including the conditions that must be met in case of increasing these commissions. c. Providing the Customer with a list of commissions they will bear in exchange for obtaining any of the products or services. d. Notifying the Customer in advance when providing a product or service that entails any additional fees or commissions borne by the Customer, or any additional interest the Customer must pay for obtaining one of the credit payment instruments, or due to the existence of a third party related to the mechanism of providing the product or service, including this in the pricing policy. e. Informing Customers through appropriate means, including electronic means and text messages, of any modification to pricing policies or the list of commissions that affects Customers, at least (30) days before the date of applying the new prices and commissions. f. Not deducting any additional commissions or fees from the Customer that are not disclosed according to the published pricing policy.
Contracts
Article (5): The Payment Service Provider must organize the relationship between itself and the Customer through written agreements in clear Arabic understandable to the average person, printed in a clear and readable font, and the texts must be drafted clearly without ambiguity or multiple interpretations (not subject to interpretation). The contract must include, as a minimum, the following: a. The provisions and conditions related to providing the product or service and the mechanism for dealing with them. b. The role and responsibilities of the Payment Service Provider, including specifying the cases in which the Payment Service Provider has the right to suspend the electronic payment account or any of the payment instruments or electronic media associated with it. c. The rights and obligations of the Customer and the consequences for them in case of breach of their contractual obligations towards the Payment Service Provider. d. The commissions and fees the Customer will bear, and the mechanisms for informing the Customer through appropriate means of any modification to them. The clauses related to fees, commissions, and interest borne by the Customer must be clarified, and the Customer must sign next to them. e. How the Customer is notified of transactions made on their electronic payment account or the periodicity and nature of the account statement. f. Statement of the Customer's right to file complaints and methods for receiving complaints, without bearing any commissions or fees and without imposing any conditions or restrictions that hinder their right to file a complaint. g. Procedures to be followed in the event of the Customer's death, freezing or closing the electronic payment account, or suspending any of the payment instruments or electronic media associated with it. h. Methods for calculating and crediting interest, if any. i. Financial transactions the Customer is allowed to execute. j. The mechanism for refunding amounts in case the Payment Service Provider ceases operations. k. Clauses confirming the confidentiality of Customer information and data and not using them for any purposes outside the scope of the business relationship and/or sharing them with any third party without the prior written consent of Customers or due to one of the cases permitted under the provisions of prevailing legislation and these Instructions. l. The Customer's acknowledgment stating the validity of the information and documents provided to the Payment Service Provider for the purpose of opening the electronic payment account, and the confirmation of the necessity to inform the Payment Service Provider of any modification or change to their address or phone number or any information of importance at the time or upon request by the Payment Service Provider. If it is found otherwise, this is considered a breach of the contract, and the Payment Service Provider has the right to suspend the product or service provided or close the electronic payment account as appropriate, after notifying the Customer through appropriate means.
Article (6): The Payment Service Provider is committed, before signing the contract with the Customer, to giving them sufficient time to review the content of the contract and all its clauses and any related attachments, answering their inquiries, and ensuring their understanding of all rights, obligations, information, provisions, and conditions related to the product or service subject to the contract.
Article (7): a. The Payment Service Provider must provide the Customer with a copy of the contract and its attachments after signing it with the Customer or their authorized representative, and obtain proof that the Customer received those copies. b. The Payment Service Provider is committed to terminating the contract upon the Customer's request at any time without charging any commissions for this, ensuring the necessary arrangements are made to return amounts due to the Customer. c. The Payment Service Provider may not terminate the contract unless the Customer breaches the contract terms, or it is found that any of the submitted documents are false, or it is discovered that the Customer is listed on any of the blocking lists issued by the Technical Committee for implementing the obligations contained in UN Security Council Resolution 1373 (2001) and other related resolutions, or the Customer engages in illegal activities requiring the Payment Service Provider to terminate the contract. This must be done after notifying the Customer, whether in writing or electronically, to the approved address, and after verifying through appropriate means that the Customer received the notification. The Payment Service Provider must also immediately notify the Anti-Money Laundering and Combating the Financing of Terrorism Unit if there is suspicion of connection to money laundering or terrorism financing, according to the model or means approved by the Unit for this purpose, in accordance with the provisions of the prevailing Anti-Money Laundering and Combating the Financing of Terrorism Law and related Instructions. d. The contract must not include a clause granting the Payment Service Provider the right to modify any clause of the contract unilaterally without obtaining the Customer's prior consent.
Personal Data Protection
Article (8): The Company is committed to establishing the necessary policies and procedures to protect Customers' personal data, which must include, as a minimum, the following requirements: a. Personal data protection procedures, whether electronic or physical, and the necessary precautions to preserve and protect them from loss, damage, modification, disclosure, theft, tampering, unauthorized access, or use for casual, illegal, or unauthorized purposes. b. Access rights to personal data and its use, whereby the Payment Service Provider informs the Customer that their data will be collected, stored, and retained for purposes related to the Payment Service Provider's business, and that disclosure will only occur in exceptional cases in accordance with these Instructions and prevailing legislation. c. Evaluation and monitoring procedures for the policies and procedures specified to protect personal data and compliance with them, and reporting any violations of procedures aimed at protecting them. d. Procedures for sharing personal data with third parties and how sharing is conducted; this must include the data subject's consent where necessary, in accordance with these Instructions and prevailing legislation, specifying the entity with which sharing will occur and the purpose of sharing, which must be compatible with the interests of all parties. e. Procedures for data archiving, destruction, and protection of backup systems. f. The accountability and liability framework in case of intentional or unintentional infringement on personal data. g. Procedures to inform Customers immediately in the event of any breach of their personal data or any threat to Customer personal data, as soon as the Payment Service Provider becomes aware of it. h. Reviewing privacy protection procedures before introducing new processing operations. i. Mechanisms for identifying processors responsible for protecting personal data.
Article (9): a. The Company is committed to maintaining strict confidentiality regarding all transactions related to Customers. Members of its Board of Directors, any current or former employees, any third party contracted with it, and anyone privy to such information by virtue of their position are prohibited from providing any data about them directly or indirectly, disclosing them, or enabling others to access them. This prohibition remains in effect even if the relationship between the Customer and the Payment Service Provider ends for any reason. b. The following cases are exempt from the confidentiality provisions stipulated in Paragraph (a) of this Article:
Article (10): The Payment Service Provider is committed, when collecting and processing personal data, to observing the following requirements as a minimum: a. Obtaining only the necessary data for the purpose of providing the product or service and committing to processing or using it within the scope of the purpose for which it was collected. b. Processing data fairly, honestly, and legally in accordance with prevailing legislation and these Instructions. c. Ensuring that data is documented, correct, and accurate, verifying its correctness before processing and use by the Payment Service Provider, and updating it whenever necessary, while observing the provisions of prevailing legislation. d. Informing the Customer of the necessity to update their data with the Provider when necessary, including providing appropriate means to execute the required update, and informing them of any updates made to their data.
Article (11): a. The Company is committed, when retaining personal data, to observing the following requirements as a minimum:
Article (12): The Company must apply a policy of segregation of duties and dual control in the management of personal data to ensure that no employee within the Company can perform any unauthorized work and conceal it. This includes, for example, user account management, executing transactions, storing and managing system encryption keys, and system administration and operations. Security procedures must also be established, including as a minimum the following: a. Providing necessary protection to prevent unauthorized persons from entering the work environment containing all vital systems, network servers, databases, applications, communications, and the Company's security systems. b. Regulating the rights of specialized employees able to access personal data. c. The ability to restore personal data after tampering, sabotage, deletion, or similar cases. d. Company employees signing a commitment to maintain the confidentiality of personal data and related information, ensuring their commitment not to misuse or disclose it during their employment and even after leaving their jobs.
Article (13): The Company must identify and assess risks related to personal data protection and establish necessary procedures to manage them and ways to mitigate them. It must continuously verify the effective implementation of those procedures and ensure that procedures are continuously updated in response to emerging risks. In conducting risk assessments, the Company must consider the following: a. Identifying risks at all levels, including remote personal access levels. b. Authorized and specialized persons accessing data, classifying them, and assessing risks associated with unauthorized access (hacking). c. Data used through a third party, identifying the entity responsible for data security, and reporting any breaches, violations, or risks.
Article (14): a. The Payment Service Provider must establish procedures ensuring that no information related to Customers or their electronic payment accounts is disclosed when responding to their inquiries, except after verifying their personal identity. b. The Customer has the following rights:
Protection of Electronic Payment Accounts from Fraud or Hacking
Article (15): The Payment Service Provider is committed to the following: a. Establishing procedures to prevent the electronic payment account from being hacked or used in fraudulent ways. b. Taking necessary measures to educate and train Customers when providing the product or service, continuously, regarding their duties and obligations to maintain their personal security data (such as passwords and usernames) to prevent electronic payment accounts, including associated payment instruments or electronic media, from being hacked or used in fraudulent ways, and mechanisms for dealing with cases of theft, loss, fraud, or hacking. c. Bearing any damages that may be incurred by the Customer due to a system malfunction, or due to any third party dealing with the Payment Service Provider's Customers for the benefit of the Payment Service Provider, or due to fraud and/or hacking operations occurring without negligence or fault on the part of the Customer.
Article (16): For the purposes of protecting and securing the personal security data of Customers stipulated in Article (15) of these Instructions, the Payment Service Provider is committed to providing advice and guidance to the Customer, as a minimum, as follows: a. Not allowing any other person to use their payment instrument or electronic media, or their electronic payment account data, or to know any of their personal security data. b. Keeping personal security data in a place difficult for others to access, and it is best to keep it in the Customer's memory. c. Properly disposing of any notifications received by the Customer containing any of their personal security data immediately. d. Not writing any personal security data in a place easily accessible to others. e. Not keeping personal security data associated with the payment instrument or electronic media. f. Not using personal security data related to dates, numbers, or easily guessable names, such as passport numbers or dates of birth. g. Changing passwords regularly. h. Publishing advice for Customers through appropriate means regarding fraudulent methods to alert them and inform them of how to avoid them and not fall victim to them.
Article (17): The Payment Service Provider must provide suitable communication channels and electronic means, including a free phone line available around the clock, to enable the Customer to easily report cases of theft, loss, fraud, or hacking, and any suspicious operations related to their personal security data, payment accounts, payment instruments, and electronic media.
Article (18): The Company is committed to notifying the Central Bank and relevant authorities of any cases of hacking or fraud of personal data, personal security data, electronic payment accounts, payment instruments, and associated electronic media immediately upon occurrence and awareness. The Company must continue to implement the following requirements: a. Determining how the hacking, fraud, or unauthorized access occurred, its cause, how it was addressed, and how to prevent recurrence. b. Addressing the hacking, fraud, or unauthorized access, evaluating the speed of response and procedures followed, and continuously updating policies, procedures, and necessary controls.
Dealing with Customers Fairly and Respectfully
Article (19): a. The Payment Service Provider is committed to the following:
Article (20): a. It is prohibited for employees of the Payment Service Provider, specifically those responsible for following up on the collection of dues on credit payment instruments, to do any of the following:
Dealing with Credit Payment Instruments
Article (21): The Payment Service Provider is committed to preparing the following bases and procedures: a. Written bases and procedures for designing credit payment instruments in a manner that limits the risks of over-indebtedness, including the following:
Article (22): The Payment Service Provider must investigate - before granting a credit payment instrument and signing the contract - the Customer's credit status from reliable sources such as the licensed credit information company, and obtain a duly acknowledged statement of all the Customer's obligations and the burden of repaying those obligations. This applies whether granting a credit payment instrument to a new Customer or renewing a credit payment instrument for an existing Customer, and reliance must not be placed on information collected when granting a credit payment instrument for the first time.
Article (23): The Payment Service Provider must include the following clauses in contracts related to issuing credit payment instruments, clarifying to the Customer what is stated therein upon contracting: a. The upper limit of interest/yield shall not exceed (1.75%) monthly. b. The cost of granting/renewing the credit payment instrument, the interest/yield rate approved by the Payment Service Provider, the minimum amount due monthly and/or its percentage of the balance, and any costs imposed for late payment or exceeding the credit instrument limit, and the cost of cash withdrawals. c. The time period required to provide the Customer with a clearance certificate for the credit payment instrument after completing the repayment of the balance. d. Providing the Customer with an information card containing phone numbers that can be contacted in case of loss of the credit payment instrument, with one of these numbers available around the clock. e. Suspending the credit payment instrument immediately if the Customer notifies the Payment Service Provider of the loss of the credit payment instrument, and exempting the Customer from any responsibility for any transactions after the moment of notification. f. Providing the Customer with a monthly account statement, which must include the Q