2011-07-17

Added · Updated

Regulations for the Implementation of the Law on the Protection of Personal Data

The Minister of Justice issued these regulations to implement the Law on the Protection of Personal Data, defining key terms such as Data Controller, Data Processor, and Sensitive Personal Data. The rules impose specific obligations on Data Controllers to ensure lawful, fair, and transparent processing, including requirements for data minimization, accuracy, limited retention, and appropriate security measures. Controllers must maintain detailed records of processing activities, restrict access to authorized personnel, and cooperate with the supervisory Authority. These regulations entered into force upon their publication in the Official Gazette on July 17, 2011.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

1 2011/17/7 No. 5102

Article 1: For the purpose of implementing the provisions of the Law on the Protection of Personal Data (hereinafter referred to as "the Law"), the following regulations are issued.

Article 2: The definitions of terms used in these regulations are as follows:

  1. Personal Data: Any information relating to an identified or identifiable natural person (hereinafter referred to as "the Data Subject").
  2. Data Controller: Any natural or legal person, public authority, agency, or other body which alone or jointly with others determines the purposes and means of the processing of personal data.
  3. Data Processor: Any natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Data Controller.
  4. Processing: Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  5. Sensitive Personal Data: Personal data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.
  6. Consent: Any freely given, specific, informed and unambiguous indication of the Data Subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Article 3: The Minister of Justice shall have the authority to issue necessary instructions and circulars to implement these regulations.

Article 4: The Data Controller shall ensure that the processing of personal data is lawful, fair, and transparent in relation to the Data Subject.

Article 5: Personal data shall be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.

Article 6: Personal data shall be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.

Article 7: Personal data shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.

Article 8: Personal data shall be kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed.

Article 9: Personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.

Article 10: The Data Controller shall implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

Article 11: The Data Controller shall ensure that any person acting under the authority of the Data Controller or the Data Processor who has access to personal data does not process them except on instructions from the Data Controller or Data Processor.

Article 12: The Data Controller shall cooperate with the Authority established under the Law and provide any information or documents requested by the Authority to ensure compliance with the Law and these regulations.

Article 13: The Data Controller shall maintain a record of processing activities under its responsibility and control, containing the name and contact details of the Data Controller, the purposes of the processing, the categories of data subjects and personal data, the categories of recipients, transfers to third countries, retention periods, and a general description of technical and organizational security measures.

Article 14: The provisions of these regulations shall come into force on the date of their publication in the Official Gazette.

Issued on 17/7/2011 corresponding to 5102 Minister of Justice