2021-07-12
Added · Updated
The Central Bank of Jordan issued Instructions No. (3/ 2021) establishing consumer protection standards for licensed Electronic Payment and Transfer of Funds Companies, excluding banks and exchange companies. The regulations mandate transparent advertising, clear disclosure of commissions and fees with 30 days' notice for changes, and standardized contractual agreements detailing rights, obligations, and termination procedures. Providers are required to implement robust personal data protection policies, including encryption, access controls, risk assessments, and breach notification protocols, while ensuring transaction confidentiality and consumer data rights.
No.: 27/4/3781 Date: 19/7/1442 Hijri Corresponding to: 3/3/2021 Instructions of Financial Consumer Protection for Electronic Payment and Transfer of Funds Companies No. (3/ 2021) Issued pursuant to the provisions of Paragraph (b/ 13) of Article (4) of the Central Bank of Jordan Law No. (23) of 1971 and its amendments, and to the provisions of Articles (34/ b), (36), (37) and (38) of the Electronic Payment and Money Transfer Bylaw No. (111) of 2017 ــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــــ Article (1): a. These instructions shall be called “Instructions of Financial Consumer Protection for Electronic Payment and Transfer of Funds Companies”, and they shall be enforced after three months from the date of their issuance. b. These instructions apply to all Electronic Payment and Transfer of Funds Companies in the Kingdom licensed to engage in any of the activities of payment services or to manage and operate electronic payment systems (to the extent that they apply to them) in accordance with the provisions of the Electronic Payment and Money Transfer Bylaw No. (111) of 2017. c. These instructions do not apply to both banks and exchange companies. Article (2): a. The following terms and expressions shall have the meanings assigned thereto below wherever mentioned in these instructions, unless the context indicates otherwise: The Central Bank : The Central Bank of Jordan (CBJ) Payment service provider : Any of the companies licensed to practice any of the payment services activities in accordance with the provisions of the Electronic Payment and Money Transfer Bylaw No. (111) of 2017. Electronic payment system manager : Any of the companies licensed to practice any of the activities of managing and operating electronic payment systems in accordance with the provisions of the Electronic Payment and MoneyTransfer Bylaw No. (111) of 2017. The Company : Payment service provider and electronic payment system manager.
2 The Consumer : The natural or legal person who owns the electronic payment account. Electronic payment account : The account that the consumer owns with the payment service provider with which any of the payment tools are linked and/ or through which electronic money is issued. The services : Any of the payment services licensed to be provided by the payment service provider under the license granted to it in accordance with the provisions of the Electronic Payment and MoneyTransfer Bylaw No. (111) of 2017. The products : Any program that has certain characteristics and conditions which distinguish it from the services provided by the payment service provider. Personal Data : All data related to the consumer, irrespective of their shape or source, which may distinguish the identity of that consumer or lead to knowing him/ her, or recognize any of his/ her dealings whether directly or indirectly, except for data available and known to the public. Personal Data Processing : The conducting of a procedure or a group of procedures in any form on the personal data, such as collecting, receiving, recording, organizing, storing, formatting, modifying, retrieving, using, exploiting, revealing, publishing, conveying, concealing, disposing, deleting, and cancelling. A credit payment instrument : Any electronic mean approved by the Central Bank that enables its holder to make payments or electronic transfer of funds, issued by the payment service provider to the consumer without having a balance in the electronic payment account, and the consumer may have to pay additional interests and commissions as a result of owning it. b. The definitions mentioned in the Central Bank Law, the Electronic Transactions Law, the Electronic Crimes Law, and the Electronic Payment and MoneyTransfer Bylaw are adopted wherever stated in these instructions, unless the context indicates otherwise. Disclosure and Transparency Article (3): a. The payment service provider shall be committed, when advertising or marketing its products and services, to make the information provided to the consumer about its products and services sufficient and clear, whether the information is provided on paper, electronically or orally. This shall be done in a way that enables the
3 consumer to gain sufficient knowledge about these products and services and match that with his/ her needs. The payment service provider must ensure the following, as a minimum:
4 b. That all commissions obtained by the payment service provider are clearly defined in the agreements concluded with consumers, including the conditions that must be met in case of raising these commissions. c. Providing the consumer with a list of commissions that he/ she shall be liable to in return for obtaining any of the products or services. d. Informing the consumer in advance when providing a product or service to him/ her of any additional fees or commissions that the consumer will bear, or of any additional interests that the consumer must pay upon obtaining one of the credit payment instruments, or as a result of the presence of a third party associated with the mechanism of providing the product or service. Such shall be included in the pricing policy. e. Informing consumers, by appropriate means including electronic means and text messages, of any amendment to pricing policies or the list of commissions that affect consumers 30 days prior to enforcing the new rates and commissions. f. Not to deduct any additional commissions or fees from the consumer that are not declared as per the published pricing policy. Contracts Article (5): The payment service provider must regulate the relationship with its consumers via contractual agreements drafted in plain and legible Arabic language that is understandable to the normal person, and printed in clear and legible handwriting. Texts shall be clearly formulated so that they cannot be confused or misinterpreted. However, the contract must encompass at least the following: a. Terms and conditions related to providing the product or service and the mechanism for dealing with it. b. The role and responsibilities of the payment service provider, including defining the cases in which the payment service provider has the right to suspend the electronic payment account or any of the payment tools or electronic means associated with it. c. The consumer's rights and duties and what he/ she will entail in the event of a breach of his/ her contractual obligations towards the payment service provider. d. Commissions and fees that the consumer shall be liable to, and the mechanisms for informing the consumer by appropriate means of any amendments that occur to them, provided that the terms related to fees, commissions and interests that the consumer bear are clarified, and that the consumer signs alongside them.
5 e. How to inform the consumer of the transactions that take place on his/ her electronic payment account or the periodicity and nature of the account statement. f. Statement of the consumer's right to file complaints and methods of receiving complaints, without incurring any commissions or fees and without imposing any conditions or restrictions that hinder his/ her right to file a complaint. g. The procedures followed in the event of the death of the consumer, the freezing or closing of the electronic payment account, or the suspension of any of the payment tools or electronic means associated with it. h. Methods of calculating and recording interests, if any. i. Financial transactions that the consumer is allowed to execute. j. Refund mechanism in case of suspending the service. k. Clauses confirming maintaining the confidentiality of consumers' information and data, and not using them for any purposes outside the scope of the business relationship, and/ or sharing them with any third party without the consumers’ prior written consent or because of one of the permitted cases under the provisions of the legislations in force and the provisions of these instructions. l. Consumer’s confirmation of the accuracy of all information and documents provided to the payment service provider for the purposes of opening an electronic payment account, and the need to inform the payment service provider of any amendment or change to his/ her address or phone number or any important information at the time or upon its request from the payment service provider. Any act to the contrary will be considered a breach of the contract and the payment service provider has the right to stop the product or service provided or close the electronic payment account, as the case may be, after notifying the consumer by the appropriate methods. Article (6): The payment service provider shall, before signing the contract with the consumer, give him/ her sufficient time to review the content of the contract and review all its terms and any related attachments, answer his/ her inquiries, and ensure that he/ she understands all rights, obligations and all information, terms and conditions related to the product or service subject of the contract. Article (7): a. The payment service provider must provide the consumer with a copy of the contract and its attachments after duly signing it with the consumer or his/ her representative, and obtain a proof that the consumer has received that copy.
6 b. The payment service provider shall commit to terminate the contract upon request by the consumer at any time he/ she wishes without charging him/ her any commissions for that, while ensuring that the necessary procedures are made to return the amounts due to the consumer. c. The payment service provider may not terminate the contract except in the event that the consumer breaches the terms of the contract or if any of the documents submitted are found to be incorrect or finding that the consumer is listed on any of the sanctions lists issued under UN Security Council resolutions in addition to the national list issued by the Technical Committee to implement the obligations contained in Security Council Resolution no. 1373 (2001) and other relevant resolutions, or because of the consumer's illegal business that requires the payment service provider to terminate the contract. The termination shall be after notifying the consumer of that, whether on paper or electronically, to the approved address, and after confirming, by appropriate means, that the consumer has received the notification. It is to be taken into consideration that the payment service provider notifies the AML/ CTF unit immediately if there is a suspicion of this being related to money laundering or terrorist financing in accordance with the form or method approved by the unit for this purpose, and in line with the provisions of the AntiMoney Laundering and Counter Terrorist Financing Law in force and the relevant instructions issued pursuant thereto. d. The contract must not include a condition that gives the payment service provider the right to amend any clause of the contract unilaterally and without obtaining the consumer's prior consent. Protection of Personal Data Article (8): The company is committed to developing the necessary policies and procedures to protect the personal data of consumers, so that they include the following requirements as a minimum: a. The procedures for the protection of the electronic and physical personal data and the precautions necessary for their maintenance and protection from loss, damage, modification, disclosure, theft, abuse, access or accidental or illegal usage. b. The permissions for accessing and using personal data, including that the payment service provider informs the consumer that his/ her personal data will be collected, stored and maintained for purposes related to the company’s business, and that their disclosure will not occur unless in exceptional cases in accordance with the provisions of these instructions and in a manner that does not conflict with the provisions of legislations in force.
7 c. The procedures for the assessment and monitoring of the policies and procedures set for the protection of the personal data and the level of adhering to them, and reporting any violation of the procedures that aim to protect such data. d. Procedures for sharing personal data with others and the method of conducting the sharing; so that they include the consent of the owner of the personal data, wherever necessary, in accordance with the provisions of these instructions and in a manner that does not conflict with the provisions of the legislations in force. The Procedures also shall determine the entity that the data will be shared with and the purpose of this sharing, which must be achieving lawful interests to all parties. e. Procedures for archiving and destroying data and protecting backup systems. f. The framework of accountability and responsibility in the event of intentional or unintentional assault on personal data. g. Procedures for informing consumers upon any breach of their personal data or the occurrence of any danger threatening the consumer’s personal data in any way as soon as the payment service provider becomes aware of this. h. The review of the privacy protection measures before introducing new processes. i. Mechanisms for identifying processors responsible for protecting personal data. Article (9): a. The company must take into consideration the complete confidentiality of all transactions related to consumers. It is prohibited for members of its board of directors, any of its current or former employees, or any third party contracted with it, and every person familiar with it by virtue of his/ her job to give any data about such transactions, whether directly or indirectly, disclose them or enable others to access them. The prohibition remains valid even if the relation between the consumer and the payment service provider is terminated for any reason. b. The following cases are excluded from the confidentiality provisions stipulated in paragraph (a) of this Article:
8 5. Issuance of a certificate or highlighting the reasons to refuse the execution of a payment or financial transfer entry upon request by the entitled person. 6. Exchanging necessary information related to consumers in order to implement its operations and any exchange of information agreed by the Central Bank according to ad hoc arrangements in order to develop the national payment system in the Kingdom. 7. Publishing the data and information related to consumers in the form of statistics or disclosing the same to the competent supervisory authorities according to the valid legislation. 8. Disclosing all or some of the consumer’s transaction data necessary to prove his/ her right in a judicial dispute triggered between the payment service provider and its consumer regarding these transactions. 9. The payment service provider discloses all or some of the data of its consumers’ transactions for the purposes of agreeing on selling the assets of the payment service provider or its merger. Article (10): When collecting and processing personal data, the payment service provider shall take into consideration the following requirements as a minimum: a. Obtaining the data required for the purposes related to providing the product or service only, and the obligation to process or use them within the scope of the purpose for which they were collected. b. Processing personal data fairly, legally, and with integrity in accordance with the provisions of valid legislations and the provisions of these instructions. c. The data must be documented, correct and accurate, so that they are verified and confirmed before they are processed and used by the payment service provider, and that they are updated whenever necessary, taking into account the provisions of the legislations in force. d. Notifying the consumer of the need to update his/ her data if necessary, including providing the appropriate means to implement the required update, and notifying him/ her of any updates made to his/ her data with it. Article (11): a. When maintaining personal data, the company shall take into consideration the following requirements as a minimum:
9 2. Commitment to delete the data record at the end of its retention period in a way that completely prevents retrieval, use, or benefitting from such data, and not to retain data for a period longer than what is specified in the relevant legislation in force. b. The company shall provide the appropriate technological environment for processing and protecting personal data and reviewing them continuously, taking into account the following requirements as a minimum:
10 d. Company employees should sign an Undertaking for keeping the confidentiality of personal data and related information, in a manner that guarantees their commitment not to misuse or disclose them throughout and after their work. Article (13): The company must identify and evaluate the risks associated with the protection of personal data and set the necessary procedures to manage these risks and ways to reduce them, and to verify permanently that these procedures are effectively implemented, and to ensure that the procedures are constantly updated in response to the emerging risks. The company shall take into account, when conducting the risk assessment, the following: a. Identify the risks on all levels, including the levels of remote personal access. b. The people authorized to and specialized in accessing data, as well as their classification and evaluation of risks associated with the illegal access/ breach. c. The data that are used by a contractual third party, and identification of the party responsible for the safety of the data along with notification of any breaches or risks. Article (14): a. The payment service provider shall put procedures to ensure that no information related to consumers or their electronic payment accounts is disclosed when responding to inquiries received from them except after verifying their personal identity. b. The consumer has the right to:
11 Protecting Electronic Payment Accounts from Fraud or Hacking Article (15): The payment service provider is committed to: a. Establish procedures to ensure that the Consumer’s account is not breached or hacked (used for fraud purposes). b. Take the necessary procedures to continuously enlighten and educate consumers, when providing the product or service, about their duties and obligations to maintain their personal security data (such as passwords and usernames) to prevent electronic payment accounts, including payment tools or associated electronic means, from being hacked or used in fraudulent ways, and about the mechanisms for dealing with cases of theft, loss, fraud or breaching. c. Be responsible for any damages that the consumer may incur due to a system failure or because of any third party dealing with the consumers of the payment service provider for the benefit of the payment service provider or due to fraud and/ or hacking that can occur without the negligence or failure of the consumer. Article (16): For the purposes of protecting and securing the consumers' personal security data stipulated in Article (15) of these instructions, the payment service provider shall continuously provide advice and guidance to the consumer, with a minimum of the following: a. Not to allow any other person to use his/ her payment tool or electronic means, or his/ her electronic payment account data, or to know any of his/ her personal security data. b. Saving personal security data in a place difficult to access by others, and it is better to save it in the consumer’s memory. c. Proper disposal of any notices under which consumer receives any of their personal security data immediately. d. Not to write any of the personal security data in a place that is easily accessible by others. e. Not to keep personal security data associated with a payment tool or electronic means. f. Not to use personal security data associated with easy-to-guess dates, numbers, or names, such as passport number or date of birth. g. Changing passwords regularly. h. Giving advice to consumers in the appropriate methods about fraudulent methods to alert them and inform them of how to avoid them and not fall into them.
12 Article (17): The payment service provider shall provide appropriate electronic communication channels and means, including a free phone line available 24/7 days, to enable the consumer to easily report cases of theft, loss, fraud or hacking and any suspicious operations related to his/ her personal security data, electronic payment accounts, payment tools and electronic means. Article (18): The company is committed to notify the Central Bank and other relevant authorities of any breaches or fraud of personal data, personal security data, electronic payment accounts, payment tools and electronic means associated with it as soon as they occur and the company becomes aware of them, while the company continues to implement the following requirements: a. Determining how the breach, fraud, or unauthorized access occurred, its reason, and how to treat and limit its repetition. b. Treating the breaching, fraud or unauthorized access, and evaluating the promptness of response and measures that were taken as well as the updates and procedures that are built upon it. Fair and Respectful Treatment of Consumers Article (19): a. The payment service provider is committed to:
13 b. The payment service provider shall develop a specified policy for fair and respectful treatment of consumers or include the principles of such in its policies, where the policy shall fulfill the requirements of these instructions and shall be approved by the board. The payment service provider shall review the policy at least every (3) years or when necessary, taking into consideration consumers’ needs based on their complaints, as well as their feedback and the feedback of other relevant parties and the Central Bank. Article (20): a. All the payment service provider employees, in particular those responsible for collecting payments due on credit payment instruments, are prohibited from:
14
15 c. The period required for providing the consumer with a clearance letter of the credit payment instrument after paying the balance thereof. d. Providing the consumer with a card that includes the telephone numbers that can be called in case of losing the credit payment instrument. One of such numbers shall be available 24/7 days. e. Suspending withdraw and usage on the credit payment instrument promptly in case the consumer informs the payment service provider of the credit payment instrument loss and exempting the consumer from any liability for any transactions since the moment of informing. f. Providing the consumer with a monthly statement to show the installment which shall be paid (payment), the maturity date, the interest/ return rate and the period of objecting to any transaction in the statement, as well as explaining the mechanism of objection or reporting the errors. g. The period during which the consumer can apply for not renewing the credit payment instrument without incurring any additional costs. Reliability in Electronic Payment Tools and Means Article (24): a. The payment service provider shall ensure that the payment tools issued by it and the electronic means associated with electronic payment accounts are available to all consumers, and are available for service 24/7 days, according to the nature of the services provided through it. b. Payment tools and electronic means that are temporarily inaccessible due to an emergency situation beyond the control of the payment service provider and at times when electronic means are subject to periodic or emergency maintenance shall be excluded from Paragraph (A) of this Article. Consumers shall be notified in advance, by all appropriate methods including text messages and the website, and for a period of no less than (24) hours of the times when payment tools and electronic means will be unavailable to provide services. Handling Consumers’ Complaints Article (25): The “Instructions of Internal Procedures for Handling Consumers’ Complaints of Financial and Banking Services Providers” No. (1/ 2017) dated 28/8/2017 (or any superseding instructions) are applied for handling consumers’ complaints of payment service providers.
16 General Provisions Article (26): The payment service provider is committed to: a. Establishing a website through which all information related to the products and services it provides, the list of commissions and prices it charges, and other information that contribute to forming a clear understanding among consumers about the payment service provider and the nature of its services and products shall be published and disclosed. b. Clearly announcing the payment service providers' business locations, branches, agents' network, working hours and their contact information on the electronic means available to the payment service providers, including the website. c. Announcing in its branches, its agents’ network and electronic means, including its websites, advertisements, promotional materials, and any other communication channel it uses that it is licensed by the Central Bank. d. Publishing these instructions on its website. e. Providing sufficient human and operational resources to carry out their business and serve consumers all over the Kingdom. f. Informing the consumer of any transaction on his/ her account when it's executed without any delay through sending an SMS to the consumer’s mobile number approved by the payment service provider. The consumer can object in case there are acceptable reasons for that. In addition, the service provider shall specify the period during which the consumer can object to any transaction, so that the transaction becomes non- objectable after that period. g. Providing consumers with the forms of contracts signed with them and the statements related to their electronic payment accounts on a regular basis and upon the consumer’s request, even if a legal dispute is in place between it and the consumer. The statements shall include all necessary details and data with an indication of the deadline for objecting to any of the transactions mentioned in the statement, with clarification of the mechanism of objection or reporting errors. h. Putting in place clear procedures with regard to refunding amounts to the consumers in case of suspending the product or service, or in case of closing the electronic payment account, stopping the payment tool or the electronic means associated with it, or the occurrence of a transaction based on incorrect basis and other cases. i. In case that the consumer objects to any of the transaction that he/ she has been informed of or mentioned in the account statement, the payment service provider will verify this immediately and without delay, and will return the objected
17 amounts if the objection is proven to be correct. The payment service provider may collect any actual costs incurred in this regard if the objection is proven invalid. j. Providing the CBJ with the Hyperlinks to the interest rates/ returns, fees, commissions, and any costs related to the products and services provided by payment service provider which are listed in its website. Any modification on the hyperlinks must be submitted to the CBJ at least (7) working days prior to the activation date which shall be determined as well. The Central Bank may publish the link on its website. Article (27): It is the responsibility of the company to ensure that all third parties contracting with it comply with the provisions of these instructions. Article (28): In case of a violation by the company or the third party of any of the provisions of these instructions, the Central Bank may take any of the procedures and penalties contained in the Electronic Payment and MoneyTransfer Bylaw No. (111) of 2017 and any amendments thereto and/ or any bylaw that replaces it. Article (29): The following instructions shall be cancelled: a. Regulations of Financial Consumer Protection and Mechanism to Handle Complaints for the Jordan Mobile Payment – JoMoPay no. (1/1/5/4941) dated 30/3/2017. b. Instructions on the Protection of the Personal Data of the Clients of Payment Services and Electronic Transfer of Funds no. (1/1/5/5537) dated 12/4/2017. Governor Dr. Ziad Fariz