Back to blog

CBJ Data Protection Requirements — A Compliance Checklist for Banks in Jordan

Banks and financial institutions in Jordan operate under Central Bank of Jordan expectations for cybersecurity and data protection. This practical checklist walks through the governance, controls, documentation and reporting obligations that supervised institutions need to meet.

June 3, 20269 min readBy Digital Protection Technologies

Banks and financial institutions in Jordan operate in one of the most tightly supervised sectors in the country. The Central Bank of Jordan (CBJ) issues instructions and circulars that shape how licensed institutions govern information security, protect customer data and respond to incidents. Meeting CBJ compliance requirements is not a one-time project; it is an ongoing discipline that touches governance, technology, people and documentation across the entire organisation.

This article sets out a practical checklist that banks, payment service providers and other supervised entities can use to assess where they stand. It focuses on the recurring themes found across CBJ instructions on cybersecurity and data protection, alongside the broader expectations created by Jordan's Personal Data Protection Law. Because supervisory instructions are updated over time, treat this as a working framework rather than a substitute for the official texts, and confirm the current details before you act on them.

Understanding the CBJ regulatory landscape

The CBJ supervises banks, electronic payment and money transfer companies, exchange houses and other financial institutions. Over recent years its instructions have placed growing emphasis on cyber resilience, information security governance and the protection of customer information. Rather than a single rulebook, these expectations are distributed across several instructions and circulars covering areas such as information security frameworks, risk management, outsourcing, business continuity and incident reporting.

For most institutions, the practical effect is that the board and senior management are held accountable for an information security and data protection programme that is documented, risk-based and independently reviewed. Two forces reinforce one another here: the CBJ's prudential and operational-risk expectations, and the personal data obligations that now apply to every organisation in Jordan. A gap assessment against both frameworks is often the fastest way to see the full picture.

The PDPL Carve-Out for CBJ-Supervised Entities and Decision No. 2025/831

One provision of the Personal Data Protection Law matters more than any other to the financial sector. Article 6/A/6 allows entities subject to Central Bank of Jordan supervision to process personal data in the course of performing their functions as determined by the Central Bank — including transferring or exchanging that data inside or outside the Kingdom — without the data subject’s prior consent. This carve-out recognises that banking supervision, payment operations, and financial-crime controls cannot depend on individual consent.

The CBJ implemented this carve-out through Central Bank of Jordan Decision No. 2025/831, dated 4 August 2025, which governs the processing of personal data by entities under CBJ supervision. It sets out the conditions under which supervised institutions may process personal data without prior consent, and the conditions for transferring that data across borders. In practice, Jordanian banks now reference both the Personal Data Protection Law No. 24 of 2023 and this CBJ Decision in their privacy notices and internal policies. Confirm the current text of the Decision against official CBJ sources, as its detailed requirements may be updated.

Governance and accountability

CBJ instructions consistently expect information security and data protection to be owned at the top of the organisation. Governance is where most supervisory reviews begin, and where many findings are raised.

Governance checklist

  • A board-approved information security and data protection policy framework that is reviewed and updated on a defined cycle.
  • Clear roles and responsibilities, including a senior information security function that is independent of day-to-day IT operations.
  • A risk committee or equivalent that receives regular reporting on cyber and data risks.
  • Defined accountability for personal data, including consideration of whether a Data Protection Officer is required under the Personal Data Protection Law.
  • Documented management approval of the risk appetite for information and cyber risk.
  • Security and privacy objectives that are integrated into the institution's wider governance, not treated as a purely technical concern.

Risk management and data classification

A recurring expectation across CBJ instructions is that controls are proportionate to risk. That requires a living risk management process and a clear understanding of what data the institution holds.

Risk and classification checklist

  • A documented information security risk management methodology with defined roles, scoring and treatment plans.
  • A current inventory of information assets and the systems that process them.
  • A data classification scheme that distinguishes public, internal, confidential and highly sensitive information, including personal and financial data.
  • Handling rules for each classification level covering storage, transmission, retention and disposal.
  • Regular risk assessments that feed into remediation planning and management reporting.
  • Data protection impact assessments for higher-risk processing activities, in line with the Personal Data Protection Law.

A structured security risk and exposure assessment helps validate that the risk picture reflects reality rather than assumptions, and that the most significant exposures are being addressed first.

Access control and identity governance

Uncontrolled access is one of the most common root causes behind data incidents in the financial sector. CBJ expectations around access control map closely to strong identity and privileged access practices.

Access control checklist

  • Role-based access aligned to the principle of least privilege, with access granted on a need-to-know basis.
  • Multi-factor authentication for remote access, administrative accounts and sensitive systems.
  • Formal joiner, mover and leaver processes so access is provisioned and revoked promptly.
  • Controls over privileged and administrative accounts, including monitoring and session control.
  • Periodic access reviews and recertification, with evidence retained for audit.
  • Segregation of duties to prevent any single individual from controlling an end-to-end sensitive process.

Many banks close these gaps by strengthening their identity and access governance programme, bringing IAM and privileged access management under consistent policy and monitoring.

Encryption and technical controls

Technical safeguards give effect to the policies above. CBJ instructions expect institutions to protect data in transit and at rest, and to maintain a hardened, monitored environment.

Technical controls checklist

  • Encryption of sensitive data at rest and in transit using current, recognised standards.
  • Secure key management with defined ownership and lifecycle controls.
  • Network segmentation separating critical systems, and protection at network and application layers.
  • Vulnerability management, timely patching and regular penetration testing.
  • Centralised logging and security monitoring capable of detecting suspicious activity.
  • Secure configuration baselines for servers, endpoints and network devices.

Reviewing network and application security controls against these expectations helps confirm that technical defences match the sensitivity of banking data and the threats facing the sector.

Incident response and breach notification

How an institution detects, responds to and reports incidents is a central supervisory concern. CBJ instructions typically require timely notification of significant cyber and operational incidents, and the Personal Data Protection Law adds its own breach obligations.

Incident and reporting checklist

  • A documented incident response plan with defined severity levels, roles and escalation paths.
  • Procedures to notify the CBJ of significant incidents within the required timeframes.
  • A process to assess and report personal data breaches under the Personal Data Protection Law.
  • Regular testing of the incident response plan through exercises and simulations.
  • Retention of incident records, decisions and evidence for review and audit.
  • Post-incident reviews that feed lessons learned back into controls and training.

Third-party and outsourcing risk

Financial institutions rely heavily on service providers, cloud platforms and technology vendors. CBJ instructions on outsourcing expect institutions to manage this risk actively rather than transferring accountability to a supplier.

Outsourcing checklist

  • Due diligence on providers before engagement, covering security and data protection capability.
  • Contracts that set out security obligations, data handling rules, audit rights and breach notification duties.
  • An inventory of material outsourcing arrangements and the data each provider can access.
  • Ongoing monitoring of provider performance and security posture.
  • Consideration of data location and any cross-border transfer requirements.
  • Exit and continuity arrangements so services can be recovered or replaced if a provider fails.

Business continuity and resilience

Operational resilience runs throughout CBJ expectations. Institutions are expected to keep critical services running and to recover quickly from disruption, whether caused by a cyber attack or another event.

Continuity checklist

  • A business continuity and disaster recovery plan aligned to defined recovery objectives.
  • Regular backups that are tested for integrity and recoverability.
  • Redundancy for critical systems and communication channels.
  • Scenario testing that includes cyber incidents such as ransomware.
  • Clear crisis communication procedures for regulators, customers and staff.

Documentation the CBJ expects to see

Supervisory reviews are evidence-driven. If a control is not documented, it is difficult to demonstrate that it operates consistently. Institutions should maintain a coherent, current documentation set rather than isolated files.

Documentation checklist

  • Board-approved information security and data protection policies, with defined owners and review dates.
  • Standards and procedures that translate policy into day-to-day practice.
  • A record of processing activities and an information asset register.
  • Data protection impact assessments for higher-risk processing.
  • Access records, audit trails and system logs retained for defined periods.
  • Risk registers, remediation plans and management reports.
  • Training records and evidence of staff awareness activities.

Maintaining this evidence manually is often where programmes strain. Compliance technology solutions can centralise policies, registers and audit trails so that evidence is ready when a supervisor or auditor asks for it.

Do you need a Data Protection Officer?

The question of DPO appointment sits at the intersection of the Personal Data Protection Law and good governance. Banks process large volumes of personal and financial data, which makes a dedicated data protection function valuable even where the precise legal trigger is being clarified. The role provides an accountable owner for privacy, a point of contact for regulators, and independent oversight of processing activities.

For institutions that lack the internal capacity to staff this fully, an outsourced or supported model can bridge the gap. Our overview of DPO services in Jordan explains how the function can be structured and what responsibilities it should carry.

Common compliance gaps banks face

Across engagements with financial institutions, a consistent set of weaknesses tends to surface. Recognising them early makes remediation far less costly.

  • Policies that exist on paper but are not reflected in day-to-day operations or evidence.
  • Incomplete data inventories, so the institution cannot fully account for the personal data it holds.
  • Excessive and stale access rights caused by weak joiner-mover-leaver processes and infrequent reviews.
  • Fragmented incident response that is untested and unclear on regulatory notification timelines.
  • Outsourcing arrangements with limited security due diligence and weak contractual protections.
  • Audit trails and logs that are incomplete or not retained long enough to support an investigation.
  • Treating CBJ instructions and the Personal Data Protection Law as separate projects rather than one integrated programme.

How Digital Protection Technologies helps

Digital Protection Technologies works with banks and financial institutions in Amman and across Jordan to translate supervisory expectations into a practical, auditable programme. That typically begins with a gap assessment against both CBJ instructions and the Personal Data Protection Law, followed by prioritised remediation across governance, controls and documentation. Where an institution is also aligning to international frameworks, our guide to ISO 27701 certification in Jordan and our work on GDPR compliance for Jordanian organisations show how these standards reinforce local obligations.

This article is general information and not legal advice; confirm the current CBJ requirements against the official CBJ instructions and circulars, and consult Digital Protection Technologies about your specific situation. If you are a bank or financial institution seeking to close gaps against CBJ compliance requirements, our team can help you build a defensible, evidence-based programme — contact us to arrange an initial discussion.

Frequently asked questions

What are the main CBJ compliance requirements for banks?

CBJ instructions on cybersecurity and data protection generally expect board-level governance, risk-based controls, data classification, strong access control, encryption, incident response and breach reporting, third-party risk management and business continuity. They also require supporting documentation such as policies, registers and audit trails. The exact obligations depend on the institution type and the latest CBJ instructions, which should always be verified.

Does the CBJ require banks to report data breaches?

CBJ instructions typically require institutions to notify the Central Bank of significant cyber and operational incidents within defined timeframes. Separately, Jordan's Personal Data Protection Law creates its own obligations for personal data breaches. Institutions should have a single incident process that satisfies both, and confirm current notification timelines against the official texts.

Do banks in Jordan need a Data Protection Officer?

Banks process large volumes of personal and financial data, so a dedicated data protection function is valuable and often expected as part of sound governance. Whether a formal DPO appointment is legally required depends on how the Personal Data Protection Law applies to the institution. Many banks adopt an internal, outsourced or hybrid model to ensure accountable oversight.

How can Digital Protection Technologies help our bank achieve compliance?

We assess your current posture against both CBJ instructions and the Personal Data Protection Law, identify gaps, and deliver a prioritised remediation roadmap across governance, technical controls and documentation. We can also support ongoing needs such as DPO services, access governance and compliance technology. The goal is a defensible, evidence-based programme that stands up to supervisory review.

Need help with your compliance program?

Digital Protection Technologies helps organizations in Jordan meet CBJ, GDPR, and ISO 27701 requirements. Talk to our team for a tailored assessment.

Contact our team