GDPR Compliance for Jordanian Companies — When and How It Applies
Many Jordanian companies assume the EU's General Data Protection Regulation stops at Europe's borders. It does not. This guide explains when GDPR applies to businesses in Jordan, what it requires, and how to align it with Jordan's own data protection law.
It is a common misconception among Jordanian business owners that the European Union's General Data Protection Regulation (GDPR) only concerns companies established in Europe. In reality, the regulation was deliberately written to follow personal data wherever it flows. A software firm in Amman selling subscriptions to customers in Berlin, a Jordanian e-commerce store shipping to Paris, or an outsourcing provider processing records on behalf of a Dutch client can all fall squarely within its scope, even without a single office, server, or employee inside the EU.
Understanding GDPR compliance Jordan obligations has become a practical necessity rather than a theoretical exercise. With Jordan now operating its own Personal Data Protection Law No. 24 of 2023, many organisations face a dual-compliance reality: meeting local rules while also satisfying European requirements for any activity that touches individuals in the EU. This article explains exactly when the GDPR reaches Jordanian companies, what it demands, how it compares with the Jordanian framework, and the practical steps for getting both right.
When Does the EU GDPR Apply to a Jordanian Company?
The reach of the GDPR beyond Europe's borders is defined by Article 3, which sets out the regulation's territorial scope. For a company based in Jordan, three distinct situations can trigger GDPR obligations. Understanding which one applies to you is the starting point for any compliance effort.
Offering Goods or Services to People in the EU
If your business intentionally offers goods or services to individuals located in the EU, whether paid or free, the GDPR applies to that processing. The key word is intention. Merely having a website that a European happens to visit is not enough. Regulators look for signals that you are targeting the EU market: displaying prices in euros, offering delivery to European countries, providing content in the languages of EU member states, or running marketing campaigns aimed at European audiences. A Jordanian travel agency advertising tour packages in German and accepting bookings from clients in Vienna is a clear example of targeting.
Monitoring the Behaviour of People in the EU
The second trigger concerns monitoring the behaviour of individuals while they are in the EU. This captures a wide range of modern digital activity: tracking users with cookies and analytics for profiling, behavioural advertising, location tracking, or building consumer profiles to predict preferences. A Jordanian mobile app that analyses how European users interact with it, or a marketing platform that profiles EU visitors, is monitoring behaviour and therefore falls within scope.
Acting as a Processor for an EU Controller
Many Jordanian firms provide outsourced services such as software development, cloud hosting, customer support, payroll, or data entry to European clients. When you process personal data on the instructions of an EU-based controller, you act as a processor and inherit direct obligations under the GDPR. This is one of the most overlooked routes to GDPR exposure in Jordan, and it typically surfaces during client due diligence, when a European customer asks you to sign a data processing agreement and prove your safeguards.
Key GDPR Requirements Jordanian Companies Must Meet
Once you determine that the GDPR applies, a defined set of obligations follows. These requirements are demanding, but they map onto sound information governance practices that benefit any organisation. The core elements are summarised below and expanded in the sections that follow.
- A valid lawful basis for every processing activity, such as consent, contract, legal obligation, or legitimate interests.
- Freely given, specific, informed, and unambiguous consent where consent is the chosen basis, with an equally simple way to withdraw it.
- Mechanisms to honour data subject rights, including access, rectification, erasure, restriction, portability, and objection.
- Records of processing activities that document what data you hold, why, and with whom you share it.
- Data protection impact assessments (DPIAs) for high-risk processing such as large-scale profiling or sensitive data.
- Breach notification to the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach.
- A Data Protection Officer (DPO) where your processing meets the thresholds that make one mandatory.
- An EU representative under Article 27 when you have no establishment in the EU but are caught by Article 3.
- Appropriate safeguards for international data transfers out of the EU, most commonly Standard Contractual Clauses (SCCs).
Lawful Basis, Consent, and Data Subject Rights
Every act of processing must rest on one of the six lawful bases in Article 6. Where you rely on consent, the standard is high: it must be a clear affirmative action, never pre-ticked boxes or silence, and withdrawal must be as easy as giving it. Alongside this, individuals hold enforceable rights. You must be able to locate a person's data, correct it, delete it, hand it over in a portable format, or stop processing it, usually within one month of a request. Building repeatable internal processes for these requests is far more reliable than improvising each time one arrives, and it connects directly to disciplined privacy and regulatory compliance.
Records, DPIAs, and Breach Notification
Documentation is the backbone of GDPR accountability. Records of processing activities give you and regulators a clear map of your data flows, while DPIAs force a structured risk analysis before you launch anything high-risk. Perhaps the most time-sensitive obligation is breach notification: once you become aware of a personal data breach that poses a risk to individuals, the clock starts on a 72-hour deadline to inform the competent supervisory authority. Meeting that window is only realistic if you have detection, escalation, and response procedures rehearsed in advance, which is where a structured security risk and exposure assessment proves its value.
DPO and the Article 27 EU Representative
Two roles frequently catch Jordanian companies off guard. A Data Protection Officer becomes mandatory when your core activities involve large-scale monitoring or large-scale processing of special category data. Separately, and often confused with the DPO, is the Article 27 EU representative: if you have no establishment in the EU but the GDPR still applies to you, you must appoint a representative located in an EU member state to act as a contact point for individuals and regulators. These are two different obligations, and a Jordanian company may need both at once.
International Transfer Mechanisms
The GDPR restricts transfers of personal data from the EU to countries that have not received an adequacy decision from the European Commission. Jordan does not currently benefit from such a decision, so transfers to a Jordanian entity generally require an appropriate safeguard. In practice this most often means Standard Contractual Clauses (SCCs), the pre-approved contract templates that bind the importer to EU-level protections, frequently supported by a transfer impact assessment and supplementary technical measures such as encryption.
GDPR Versus Jordan's Personal Data Protection Law No. 24 of 2023
Jordan's Personal Data Protection Law No. 24 of 2023 introduced a national framework built on principles that will feel familiar to anyone who has studied the GDPR: lawful processing, purpose limitation, data subject rights, and obligations on those who control and process personal data. For a fuller treatment of the local regime, see our dedicated guide to Jordan's data protection law. While the two regimes share DNA, they are not identical, and treating them as interchangeable is a mistake.
The GDPR applies specifically to the personal data of individuals in the EU and carries its own enforcement machinery, supervisory authorities, and the well-known ceiling of substantial administrative fines. Jordan's law governs processing connected to Jordan and is administered through its own national supervisory structure and permit requirements. The definitions, notification timelines, consent nuances, and cross-border transfer conditions differ in detail between the two. The practical consequence is that satisfying one does not automatically satisfy the other, even though a well-designed programme can address both together.
Practical Steps for Dual Compliance
The most efficient path is to build a single, well-governed data protection programme that meets the stricter requirement wherever the two laws diverge, rather than maintaining two disconnected sets of controls. A realistic sequence looks like this.
- Map your data flows and identify every activity that touches individuals in the EU as well as every activity connected to Jordan.
- Determine your role for each activity, whether controller or processor, and document the lawful basis you rely on.
- Maintain unified records of processing that satisfy both the GDPR and Law No. 24 of 2023.
- Update privacy notices, consent mechanisms, and cookie practices so they meet the higher standard.
- Put contracts in place, including SCCs for EU transfers and data processing agreements with clients and vendors.
- Appoint a DPO and, where required, an Article 27 EU representative.
- Rehearse breach detection and response so the 72-hour deadline is achievable.
- Align identity controls so that access to personal data is limited, logged, and reviewed, supported by sound identity and access governance.
Organisations that want an external benchmark for their privacy programme often pursue certification. Aligning your controls with a recognised privacy management standard can streamline both GDPR and local compliance, and our guide to ISO 27701 certification in Jordan explains how that framework supports demonstrable accountability to clients and regulators alike.
Common Mistakes Jordanian Companies Make
Across engagements with exporters, technology firms, and outsourcing providers, the same avoidable errors recur. Recognising them early saves considerable cost and reputational risk.
- Assuming the GDPR cannot apply because the company has no presence in Europe, ignoring the extraterritorial reach of Article 3.
- Overlooking processor obligations that arise from serving EU clients, until a customer audit exposes the gap.
- Relying on invalid consent, such as pre-ticked boxes or bundled terms, rather than a clear affirmative choice.
- Transferring data from the EU with no SCCs or other lawful transfer safeguard in place.
- Failing to appoint an Article 27 representative when one is legally required.
- Having no rehearsed breach response, making the 72-hour notification deadline impossible to meet.
- Treating Jordanian and EU compliance as one and the same, and missing the specific requirements of each.
How DP Technologies Helps With Cross-Border Compliance
Digital Protection Technologies works with Jordanian organisations to untangle exactly these questions. We begin by assessing whether and how the GDPR applies to your specific activities, then design a proportionate programme that satisfies both European and Jordanian obligations without duplicating effort. Our support spans data mapping, lawful basis analysis, records and DPIAs, consent and privacy notices, transfer mechanisms including SCCs, DPO and representative arrangements, and the technical safeguards that underpin them, drawing on our wider work in network and application security. Because every cross-border situation carries its own nuances, this article is general guidance and not legal advice; we recommend consulting DP Technologies or qualified counsel for a determination tailored to your circumstances.
If your company sells to Europe, serves EU-based clients, or handles the data of individuals in the EU, the safest assumption is that the GDPR may already apply to you. The next step is to establish exactly where you stand and close any gaps before a client audit or regulator does it for you. Reach out to DP Technologies to discuss your cross-border compliance and build a programme that protects your business on both sides of the map.
Related services
Frequently asked questions
Does the GDPR apply to a company based in Jordan?
Yes, it can. Under Article 3, the GDPR applies to Jordanian companies that offer goods or services to individuals in the EU, that monitor the behaviour of people in the EU, or that process personal data as a processor on behalf of an EU controller. No office or server in Europe is required for these obligations to arise.
Do we need an EU representative under Article 27?
If your Jordanian company has no establishment in the EU but the GDPR still applies to your processing, you generally must appoint a representative located in an EU member state. This representative serves as a contact point for data subjects and supervisory authorities. It is a separate role from a Data Protection Officer, and some companies need both.
Is complying with Jordan's Law No. 24 of 2023 enough to satisfy the GDPR?
No. The two regimes share many principles but differ in scope, definitions, timelines, and transfer rules. Meeting Jordan's Personal Data Protection Law does not automatically make you GDPR compliant. A unified programme built to the stricter standard is usually the most efficient way to satisfy both.
How can we legally receive personal data from the EU in Jordan?
Because Jordan does not currently hold an EU adequacy decision, transfers usually require an appropriate safeguard. The most common mechanism is Standard Contractual Clauses signed with the EU exporter, often accompanied by a transfer impact assessment and supplementary measures such as encryption. DP Technologies can help you put the right mechanism in place.
Need help with your compliance program?
Digital Protection Technologies helps organizations in Jordan meet CBJ, GDPR, and ISO 27701 requirements. Talk to our team for a tailored assessment.
Contact our team