The Appointment of a Data Protection Officer in Government Entities under Jordanian Law and the General Data Protection Regulation (GDPR): A Comparative Study

The appointment of a Data Protection Officer is considered one of the most significant mechanisms adopted by modern legal systems to ensure compliance with personal data protection rules and to promote the principles of transparency and accountability. This issue has received considerable attention under the General Data Protection Regulation (GDPR), which clearly and expressly specifies the circumstances in which a controller is required to appoint a Data Protection Officer through unambiguous legal provisions. In contrast, the Jordanian legislator adopted a different approach in the Personal Data Protection Law No. 24 of 2023, giving rise to both practical and interpretative challenges, particularly regarding whether ministries and other governmental and public entities are legally required to appoint a Data Protection Officer.
- The Position of the General Data Protection Regulation
- Article (37/1) of the General Data Protection Regulation states as follows:
“1- The controller and the processor shall designate a data protection officer in any case where:
- the processing is carried out by a public authority or body, except for courts acting in
their judicial capacity”.
- Article (4) of the General Data Protection Regulation sets out several key definitions, including the following:
- Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data, where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
- Processor: a natural or legal person, public authority, agency or other body which processes
personal data on behalf of the controller.
- The Position of the Jordanian Personal Data Protection Law
- Article (11) of the Jordanian Personal Data Protection Law No. (24) provides as follows:
“A. The controller shall appoint a data protection officer in the following cases:
- Where the controller’s principal activity is the processing of personal data.
- Where sensitive personal data are processed.”
- Article (1) of the Jordanian Personal Data Protection Law No. (24) also sets out several definitions, including:
- Controller: Any natural or legal person, whether inside or outside the Kingdom, who has personal data in their custody.
- Processor: A natural or legal person responsible for processing personal data.
- Data Protection Officer: A natural person appointed to supervise databases and data processing in accordance with the provisions of this Law.
The difference in wording between the Jordanian law and the General Data Protection Regulation ensures the existence of a practical issue in the application of Article (11) of the Jordanian Personal Data Protection Law. This raises the question of whether ministries and governmental or public authorities are legally required to appoint a Data Protection Officer. The provision does not expressly impose such an obligation on ministries or public authorities, rather, it places this obligation on the “controller”, which the Jordanian Personal Data Protection Law defines as “any natural or legal person, whether inside or outside the Kingdom, who has personal data in their custody”.
Accordingly, ministries and governmental or public authorities may be required to appoint a Data Protection Officer where the conditions set out in Article (11) are satisfied—namely, where they continuously process sensitive personal data or where the processing of personal data constitutes a core part of their functions and activities. However, this obligation is not based on an explicit legislative provision specifically requiring governmental and public authorities to appoint a Data Protection Officer. The Law does not even define such authorities, instead, it adopts a general formulation directed at the “controller.” Consequently, the applicability of this obligation to governmental and public authorities depends on whether they satisfy the conditions prescribed in Article 11, rather than on an express statutory provision specifically mandating them to appoint a Data Protection Officer.
A closer reading of Article 37 of the General Data Protection Regulation demonstrates that it is substantially similar to Article 11 of the Jordanian Personal Data Protection Law, with the notable exception of the provision requiring public authorities and public bodies to appoint a Data Protection Officer. This requirement appears expressly in the GDPR but is absent from the Jordanian law. This suggests that the Jordanian legislature deliberately chose not to impose a mandatory obligation on governmental and public authorities to appoint a Data Protection Officer. The legislature adopted those elements of the European provision that it sought to incorporate, while omitting those elements that it did not intend to adopt. Had the legislature intended to require governmental and public authorities to appoint a Data Protection Officer, it would have stated so expressly in the legislation. This interpretation is further supported by a well-established principle of statutory interpretation: had the legislature intended such an obligation, it would have expressly stated for it, as the legislature is presumed not to use language without purpose. Accordingly, the omission of such a provision constitutes evidence that the legislature did not intend to impose this obligation.
With regard to Article (11) of the Jordanian law, the absence of an express provision requiring governmental entities to appoint a Data Protection Officer, and the reliance instead on general criteria that allow broad room for interpretation, raises practical issues in application.
On the one hand, determining what is meant by “the main activity” may vary depending on the nature and functions of the governmental or official entity concerned. On the other hand, the classification of certain data as sensitive personal data may be subject to differing interpretations in practice. This creates room for inconsistent interpretations among administrative bodies and leads to variations in the extent to which the obligation to appoint a Data Protection Officer is fulfilled.
Accordingly, leaving this obligation subject to administrative or judicial interpretation is inconsistent with the requirements of legal certainty, which requires legal obligations to be clear and precisely defined, particularly where such obligations are imposed on public entities. Furthermore, inconsistent application of this obligation among government institutions may negatively affect the level of personal data protection and undermine the principle of equality in the application of the law.
Therefore, expressly providing in the Personal Data Protection Law for the obligation of all ministries, government departments, and official entities to appoint a Data Protection Officer would constitute a legislative approach more consistent with the philosophy and objectives of the Personal Data Protection Law. Such an amendment would eliminate any ambiguity regarding the scope of the obligation, ensure uniform application among public entities, and provide a higher level of protection for personal data collected and processed by the Country in the course of exercising its functions.
It should be noted at the outset that the Jordanian Personal Data Protection Law has drawn, to a significant extent, upon the provisions of the European General Data Protection Regulation (GDPR). This legislative approach is, in principle, considered sound and consistent, given the prominent position occupied by the European Regulation as one of the most significant modern legal frameworks in the field of personal data protection.
However, benefiting from a leading legislative experience requires that legal borrowing be based on study and analysis rather than merely on the literal reproduction of legal texts. If the Jordanian legislature chose to draw upon the European Regulation, it would have been preferable either to adopt it in a more comprehensive manner, while excluding provisions that are inconsistent with the Jordanian Constitution or with the particularities of Jordanian society, including its values, customs, and traditions, or to adopt a more advanced approach based on monitoring subsequent legislative amendments, as well as judicial and administrative interpretations that emerge within the European framework, and then adapting them to the national legal environment.
Legislative borrowing does not operate through mere textual transplantation, rather, it requires conscious utilization of comparative legal experiences and their reformulation in a manner that ensures compatibility with the domestic legal system and responds to its practical needs. Such an approach would contribute to the enactment of legislation that is more mature and coherent, while reducing the likelihood of legislative gaps or practical difficulties in implementation.
Given that the Jordanian legislature adopted a substantial part of the provisions of the European data protection framework, it would have been preferable to adopt the provision requiring governmental entities to appoint a Data Protection Officer, as this obligation constitutes a fundamental element of an effective data protection regime. Its omission from the Jordanian law may undermine the effectiveness of the legal framework and limit the practical achievement of its intended objectives.
The primary objective of legislations, particularly legislation of a rights-based nature, is to provide protection for individuals, whether in their relationships with each other or in their relationship with public authorities. Accordingly, if the law was initially enacted to safeguard individuals in both contexts, such protection should begin with the country itself, given that it is the entity vested with powers and privileges that may affect individual’s rights and freedoms. Therefore, subjecting the country to the provisions of the law and ensuring that it does not abuse its authority are fundamental conditions for achieving the legislative objective of safeguarding rights and freedoms and reinforcing the principle of the rule of law.
Accordingly, governmental entities must be fully aware that they process vast amounts of data, which entails significant risks requiring an understanding of their potential impact on individual’s rights and freedoms. The broader the scope of data retained or processed by a governmental entity, the greater the likelihood of infringing individual’s privacy in the event of misuse or failure to comply with data protection safeguards. From this perspective, the safeguards established under the Personal Data Protection Law should be more stringent when the governmental entity acts as the “data controller”, given the extensive legal powers it possesses and its ability to collect, retain, and process enormous quantities of personal data relating to large numbers of individuals. This necessarily imposes a higher level of responsibility and obligation upon such entities to ensure the protection of this data and prevent its misuse.
This is because governmental entities generally do not limit their activities to retaining basic identifying information, rather, they collect and process a broad range of personal data and sensitive personal data, including health, financial, tax, educational, and biometric data, in addition to civil status records, criminal records, and other types of information. The misuse, unlawful disclosure, or breach of such data may adversely affect individual’s fundamental rights and freedoms and cause serious harm to their legal and personal status.
In addition to the obligation of official and governmental entities to appoint a Data Protection Officer, it should be emphasized that the collection and retention of such data within country institutions necessarily means that public employees are authorized to access and handle this information. Accordingly, access to such data must be subject to strict controls and procedures to ensure that it is not misused or accessed without authorization.
Therefore, the relevant entities must establish and implement all security, technical, and organizational measures stipulated under the Personal Data Protection Law to ensure the protection, confidentiality, and integrity of data. This should be achieved through the adoption of appropriate monitoring and protection systems, such as surveillance systems, antivirus programs, access-control mechanisms, and other technical measures that ensure a high level of information security and personal data protection.
Based on the foregoing, the country, as the entity entrusted with establishing legal protection for rights and freedoms, should be the first to adhere to the highest standards of personal data protection and to serve as a model of compliance with the provisions of the law. This can be achieved through the establishment of an effective institutional data governance framework based on a clear allocation of responsibilities and the activation of oversight and compliance mechanisms. Among the most important of these mechanisms is the appointment of a Data Protection Officer, who is responsible for overseeing compliance with the Personal Data Protection Law, monitoring the integrity and lawfulness of processing activities, and strengthening the measures necessary to safeguard and protect the rights of individuals whose personal data is processed.
The importance of appointing a Data Protection Officer within governmental and official entities becomes even more evident in light of Article (6) of the Personal Data Protection Law, which grants public entities an exception allowing them to process personal data in certain cases without the need to obtain prior consent from the data subject, provided that such processing is based on a lawful basis authorizing it.
This exception should not be understood as a diminution of the protection afforded to personal data, rather, it requires enhanced oversight and stronger compliance safeguards. Since public entities are exempted from the requirement to obtain consent, this exemption must be accompanied by stricter obligations to prevent the misuse of such authority or the exceeding of its legally defined limits. Moreover, this exception is not absolute, rather, it is subject to the conditions set out in Article (6/1), which requires that processing be carried out by a competent public entity within the scope of its duties and in accordance with applicable legislation, or through contracted entities, provided that the relevant contracts include an obligation to comply with the provisions of the law and the regulations and instructions issued thereunder. Accordingly, the processing of personal data by the State must be based on a lawful basis and be limited to what is necessary and proportionate to achieve the legitimate purpose for which the data is processed, thereby ensuring an appropriate balance between the requirements of the public interest and the protection of the rights of data subjects.
Accordingly, the broad scope of the powers conferred upon governmental entities to collect and process personal data, together with the resulting increase in the volume of data under their control, necessitates the establishment of an internal oversight mechanism responsible for supervising those entities’ compliance with the provisions of the Personal Data Protection Law. In this context, the appointment of a Data Protection Officer assumes fundamental importance, serving as the internal mechanism of compliance and bearing responsibility for overseeing the lawfulness of processing activities and ensuring that they conform to the principles and safeguards established by the Law.
Government entities are responsible for the daily collection and processing of millions of records and personal data. They also exchange such data among themselves and with other entities within the country, and this exchange may extend to foreign entities, international organizations, diplomatic missions, or international bodies, in accordance with applicable legislation and relevant agreements. The expansion of the scope of data processing and transfers increases the possibility of risks associated with the misuse of data, unlawful disclosure, or data breaches.
These risks are further amplified by the expansion of digital transformation projects and e-government initiatives, along with the increasing reliance on centralized databases, electronic archiving systems, closed-circuit television (CCTV) systems, and other modern technological tools that require specialized technical and legal expertise for their management and oversight. As the technological environment becomes more complex, the need increases for qualified individuals who possess the necessary legal and technical knowledge to ensure the security of data processing operations and compliance with the safeguards imposed by the Personal Data Protection Law.
Accordingly, addressing these challenges cannot be achieved solely through the enactment of legal rules, rather, it requires the establishment of an effective institutional oversight mechanism that ensures the practical implementation of those rules within governmental entities. From this perspective, the role of the Data Protection Officer is not limited to verifying legal compliance, it also extends to promoting a culture of data protection within the institution, training employees on proper practices for handling personal data, developing internal policies and procedures governing processing operations, reviewing technical, security, and organizational measures, coordinating with competent authorities, managing risks associated with data processing, and responding to data breach incidents and mitigating their consequences.
Furthermore, the importance of appointing a Data Protection Officer becomes particularly evident in the context of cross-border transfers of personal data, as the transfer of data to another country or an international organization requires the existence of an adequate level of legal and practical protection for personal data. The European General Data Protection Regulation (GDPR) affirmed this principle through Article (45), which permits the transfer of personal data to a third country or an international organization where the European Commission has determined that such country or organization ensures an adequate level of protection. This assessment is based on several criteria, including the effectiveness of the legal framework for data protection, the existence of institutional safeguards, and oversight mechanisms that ensure respect for data subject rights and the enforcement of data protection rules.
From this perspective, a question arises regarding the extent to which sufficient institutional safeguards exist within the Jordanian legal system, particularly in light of the absence of an explicit provision requiring all governmental entities to appoint a Data Protection Officer. Can the data protection framework be considered complete in cases where personal data is exchanged with foreign entities or international organizations, while the governmental entity responsible for collecting and processing such data is not subject to a specialized internal oversight mechanism responsible for monitoring compliance with the provisions of the Personal Data Protection Law?
This question becomes increasingly significant in cases requiring cooperation or data exchange with foreign entities, such as embassies, international organizations, or public authorities in other countries. The confidence of such entities in sharing or exchanging data is closely linked to the availability of effective legal and institutional safeguards within the receiving Country. Although the appointment of a Data Protection Officer alone does not constitute a decisive criterion for assessing the adequacy of protection under Article (45) of the European General Data Protection Regulation, the absence of such officers within governmental entities may be regarded as an indicator of insufficient institutional safeguards necessary to ensure effective data governance. This, in turn, may affect the assessment of whether the required level of protection is fully established and may impact the country’s ability to build the necessary trust in cross-border data transfer operations.
Maysam Abu Hamdah
