Englishالعربية Soon
Under attack?
Personal data protection

You are accountable for personal data you cannot currently locate.

Compliance with Jordan’s Personal Data Protection Law and the regional regimes you trade under, built from an actual data inventory, not a policy template. Discovery first, because every obligation below depends on knowing what you hold and where.

Jordan PDPL
Law No. 24 of 2023
GCC regimes
Saudi PDPL, UAE, Bahrain, Qatar
GDPR
Where you process EU resident data
Sector rules
Central bank and health data
Obligations

Nine obligations, and the evidence each one requires

Regulators do not ask whether you have a privacy policy. They ask you to demonstrate the obligation is met, which means artefacts rather than intentions.

Lawful basis
Every processing activity has a stated legal basis, recorded before it starts rather than reconstructed during an inquiry.
✓ Processing register✓ Consent records
Consent
Freely given, specific, informed and withdrawable, with proof of when and how it was obtained, per subject and per purpose.
✓ Consent capture✓ Withdrawal mechanism
Purpose limitation
Data used only for what it was collected for. The marketing use of a dataset gathered for service delivery is where most breaches of the law occur.
✓ Purpose mapping✓ Secondary use control
Data minimisation
Only what is necessary. Fields collected because a form template had them are a liability with no offsetting benefit.
✓ Form review✓ Field justification
Retention
A defined period per data category, with deletion that actually happens. “We keep everything” is not a retention policy.
✓ Retention schedule✓ Automated deletion
Subject rights
Access, correction, deletion, objection and portability, answered within the statutory window, through a process rather than an improvisation.
✓ Rights workflow✓ Response templates
Security
Technical and organisational measures proportionate to the risk, and demonstrable. This is where our defensive work meets the legal obligation.
✓ Encryption & access✓ Monitoring
Breach notification
Detection, assessment and notification to the regulator and affected individuals within the statutory deadline, which starts before you have full facts.
✓ Breach procedure✓ Notification templates
Cross-border transfer
Transfers permitted only under a lawful mechanism. Cloud services outside the country are transfers, whether or not anyone calls them that.
✓ Transfer register✓ Safeguards
Where we start

Discovery, because you cannot govern what you have not found

Almost every organisation underestimates where personal data lives. It is rarely confined to the systems that were designed to hold it.

The inventory is the deliverable everything else is built on, and it is the one most compliance projects skip in favour of writing policy first.

Core systems
Core banking, CRM, HR and ERP: the places you expect it.
Databases
Production, replicas, test environments loaded with copied live data.
File shares
Spreadsheets, scanned identity documents, exports nobody deleted.
Email
Attachments and correspondence, retained indefinitely by default.
Cloud and SaaS
Tools adopted by departments without a transfer assessment.
Endpoints
Local copies on laptops belonging to people who have since left.
Third parties
Data you sent to suppliers and no longer control.
Backups
Archives holding data you deleted from production years ago.
Programme

Six stages, in an order that does not waste the first three

Writing policy before discovery produces a document that describes an organisation you do not have.

01

Discover

Automated and manual discovery across systems, databases, file shares, email, cloud and endpoints. Output is a data inventory and data flow map showing what you hold, where it sits, who touches it and where it goes.

02

Classify

Personal data separated from sensitive categories, health, financial, biometric, identity documents, because the obligations and the penalties differ sharply between them.

03

Assess

Current practice measured against the law: lawful basis per activity, consent quality, retention reality, subject rights capability, security measures and transfer mechanisms. Output is a gap register with severity and effort.

04

Design

Policies, notices, procedures and records built around your actual processing rather than a template. Data protection impact assessments for high-risk activities. A DPO appointed or provided.

05

Implement

Technical controls put in place: classification labels, access restriction, encryption, retention automation, leakage prevention and monitoring on the systems the inventory identified as material.

06

Operate

Rights requests answered within the window, breach procedure rehearsed, third parties assessed on a cycle, and evidence produced continuously so an inquiry is a search rather than a project.

Accountability

Data protection officer as a service

A named DPO holding the statutory role: monitoring compliance, advising on impact assessments, acting as contact point for the regulator and for data subjects, and reporting to your board. Provided as a retained arrangement rather than a full-time salary.

vCISO and DPO services →

Accountability

Controller, processor, or both

Most organisations are both, on different datasets, and the obligations differ. We establish which role you hold for each processing activity, because contractual liability and regulatory duty follow that classification.

Talk to a consultant →

Related

The controls that make compliance real

Data leakage prevention

A retention and purpose policy is only enforceable if something stops data leaving.

Database security

Most personal data sits in a database. Access there is the control the regulator asks about.

Incident response

Breach notification has a statutory clock. It starts whether or not you have the facts yet.

Find out what you are actually holding.

Start with discovery on one business unit. It reliably finds personal data in three places nobody expected.