Data Protection in Jordan

Data protection officers in Jordan

The Data Protection Officer is the appointed natural person overseeing databases and processing in accordance with the provisions of the law.

According to Article (11) of the Law:

  • The Controller shall appoint a Data Protection Officer in the following cases:
    • If the primary activity of the Controller involves processing Personal Data.
    • When Processing Sensitive Personal Data.
    • When Processing Data of individuals who lack legal capacity.
    • When Processing Data that includes financial information.
    • When transferring to databases outside the Kingdom.
    • In any other case determined by the Council requiring the Controller to appoint a Data Protection Officer.
  • The Data Protection Officer shall assume the following tasks and responsibilities:
    • Monitoring the procedures put in place by the Controller related to Data protection and documenting their compliance with the provisions of this law and related legislations.
    • Ensuring the execution of periodic assessments and reviews of database systems, data processing systems, and systems for maintaining the security, safety, and protection of data, and documenting the assessment results and issuing necessary recommendations for data protection, and monitoring the implementation of these recommendations.
    • Acting as a direct liaison with the Unit and other security and judicial authorities regarding compliance with the provisions of the law.
    • Developing internal instructions for receiving and studying complaints, Data access requests, requests for correction, erasure, hiding, or transfer of Data, and ensuring that such access is provided to the Data Subject in accordance with the provisions of the Law.
    • Enabling the Data Subject to exercise their rights as provided in this law.
    • Organising necessary training programs for the staff of the Controller and Processors to equip them to handle Data in line with the requirements of this law and the regulations and instructions issued accordingly.
    • Any other tasks or responsibilities assigned to the Data Protection Officer in accordance with the provisions of the law and the regulation and instructions issued pursuant to it.

Continue reading

  • no results

Previous topic
Back to top