Law & Technology

Cybercrimes in Jordan: An Awareness Guide to the Legal Framework and Initial Steps

This article provides an educational overview of cybercrime regulation in Jordan, examples of conduct that may raise legal issues, and practical steps for preserving evidence and contacting the competent authorities without assuming an outcome. The legal characterization depends on the facts and law in force; consult a Jordanian lawyer before taking action.

Updated: 10 September 2026

Prepared and reviewed by: Ashraf Al-Khawaja

01

1. Legal framework: what is a cybercrime?

In Jordan, the principal statutory reference is Cybercrimes Law No. 17 of 2023, listed by the Legislation and Opinion Bureau. The official Arabic text and any later amendments should always be checked. This does not mean that every online dispute or post is automatically criminal; the legal characterization depends on the specific act, intent, method, harm, status of the affected person, and other applicable laws. In its awareness material, the Public Security Directorate describes cybercrime broadly as a criminal act or omission committed through a technological means or resulting directly or indirectly from information technology. A professional overview published by Dentons, read alongside the Jordan Open Source Association’s unofficial English translation for comparison only, identifies examples such as unauthorized access to a network, system, or account; impersonating a person or entity through an account or website; phishing for financial information; tampering with data or disrupting systems; and certain forms of unlawful online content or incitement. These are awareness examples, not an exhaustive list, and they do not by themselves establish that any particular incident is a crime.

02

2. Content and digital identity: why context matters

Posts, reposts, or account management may raise legal questions where they involve impersonation, misinformation, defamation, incitement, an invasion of another person’s privacy, or the use of personal data without a lawful basis. Dentons’ overview discusses provisions concerning the person who effectively manages a website or account and responsibility for unlawful content, as well as circumvention of an Internet Protocol address when it is connected to an intention to commit a crime or prevent its discovery. This should not be read to mean that every pseudonym or every use of a virtual private network is criminal by itself; intent, facts, and the law in force remain decisive. Human Rights Watch and Amnesty International have each criticized what they view as the breadth or vagueness of some provisions and the risks to expression and political criticism. Those are positions attributed to the two organizations, not a Jordanian judicial holding. As a practical precaution, verify the source and context before posting or reposting, avoid publishing personal data or private screenshots without a clear reason, and distinguish reporting a documented fact from making an accusation or unsupported conclusion that may create legal exposure.

03

3. Reporting and preserving digital evidence

The Public Security Directorate’s official Cybercrime Unit page identifies the unit as a technical investigative body and lists the Criminal Investigation Department location, the free number 196 with internal extensions, and ecrimes@psd.gov.jo for contact. Verify the official page before relying on contact details because they may change. The National Cybersecurity Centre states that complaints involving cyber extortion, electronic exploitation, or theft of personal or card information should be directed to the Public Security Directorate/Criminal Investigation Department, and that incidents involving children or women should be directed to the Family Protection and Juvenile Department. Keep messages, URLs, account names and identifiers, posting dates and times, transaction records or receipts, and relevant email information. Preserve original copies on the device where possible, without editing or deleting them. Do not alter screenshots or conversations, redistribute sensitive material merely to prove it, or negotiate or pay under extortion pressure before obtaining appropriate advice. The official Cybercrime Unit explains that logs and message traces can matter and that an Internet Protocol address at a specific time and date may be useful technical evidence, but connecting it to a named user requires information from the Internet service provider. A screenshot alone therefore does not necessarily establish the perpetrator’s identity or prove the entire case.

04

4. Prevention and practical limits

Useful first-line precautions include using strong, separate passwords, enabling multifactor authentication, installing applications from official stores, checking website addresses and the identity of anyone requesting financial information or verification codes, and limiting public information on accounts. Organizations may also benefit from defined access permissions and properly maintained system logs, subject to applicable law and internal policies. These are general safety measures, not a substitute for an incident-specific assessment or advice from the competent authority. This information cannot determine by itself whether someone bears criminal responsibility, whether evidence is sufficient, or which procedure is appropriate. Those questions depend on the complete facts, the source and integrity of the evidence, intent, jurisdiction, and the law in force at the relevant time. Consult a Jordanian lawyer before filing a complaint, publishing a response, handing over a device, or taking any other action; this article offers no definitive conclusion or guarantee of outcome.

Notice: this article is general educational information and does not constitute legal advice or a final assessment of any matter.

Sources and references

Verify the official text and latest amendments before relying on this material professionally.

Read also