Cybersecurity and data protection compliance in Oman

Oman's data protection law changed on 7 September 2026. Know exactly where you stand.

The Personal Data Protection Law is fully enforceable, and Royal Decree 68/2026 rewrote its consent rules, expressly extended it to processing outside Oman and added duties for automated decisions. AccuSights maps these requirements to one set of controls, collects the evidence once, and shows you the gaps before the Ministry or an auditor does.

Built from the official texts. Every page on this site names its source and the date we last checked it.

New: Royal Decree 68/2026 took effect on 7 September 2026, with no transition period. The controller must now prove explicit consent, where the previous text asked it to prove written consent, and every consent request must carry set contents. The law reaches processing of personal data of people in Oman wherever it happens, four situations that were previously outside the law are now covered by it but need no consent, and data subjects can object to automated decisions and ask for human review. Read the full change guide.

What the platform does

Three jobs, done continuously, so compliance becomes the by-product of running securely rather than a project you repeat every year.

Map

One control set, every requirement

Your controls are mapped once to the Personal Data Protection Law as amended, its Executive Regulations, sector rules such as those of the Central Bank of Oman, and international standards such as ISO/IEC 27001.

Evidence

Collected once, reused everywhere

Consent records, processing records, policies and configurations are gathered once and linked to every requirement they satisfy, so the same proof answers the Ministry and your auditor.

Visibility

A read-only compliance agent

The agent observes your cloud and infrastructure configuration and reports drift against your control set. It cannot change your systems. Every fix stays in your hands.

One control, several rulebooks

An illustration at requirement level. In an engagement we map your actual controls to the specific provisions that apply to you.

Your controlWhere it counts

A consent request that names the controller, the processor and the data protection officer

  • Personal Data Protection LawArticle 10, as replaced by Royal Decree 68/2026: explicit consent the controller can prove
  • EU GDPR, for clients in the EUArticle 7: the controller must be able to demonstrate consent

Personal data breaches reported in time

  • Executive RegulationsNotify the Ministry within 72 hours, under Article 30 of the Executive Regulations
  • Executive RegulationsNotify the people affected within 72 hours where serious harm or high risk is likely, under Article 32 of the Executive Regulations
  • EU GDPR, for clients in the EUArticle 33: notify the supervisory authority within 72 hours

Data deleted when its purpose ends

  • Personal Data Protection LawArticle 15, as replaced: erase immediately, with two exceptions
  • ISO/IEC 27001Annex A 8.10 Information deletion and 5.33 Protection of records
How one control maps across Omani and international requirements

Key dates

  1. The Personal Data Protection Law is issued by Royal Decree 6/2022.

  2. The Executive Regulations, issued by Ministerial Decision 34/2024, come into force, with a period to comply.

  3. The compliance period, extended by Ministerial Decision 6/2025, ends. The law is fully enforceable.

  4. Royal Decree 68/2026 amends the law, the day after publication in Official Gazette issue 1664. No transition period.

How we work with you

  1. Assess

    The Cybersecurity and Data Protection Assessment measures your controls against the law as amended, its Executive Regulations and your sector rules, and ranks the gaps by risk.

  2. Get ready

    We rewrite consent requests and contracts for the 2026 rules, set up the data protection officer role, prepare the evidence and close the gaps in the order that matters.

  3. Stay current

    The read-only compliance agent reports configuration drift, and we track the Executive Regulations as the Ministry updates them to match the amended law.

Why AccuSights

Founded in the United States by people who have done this work inside the institutions that spend the most on security.

More than two decades of assessments

Our founder has assessed banks, card networks, health insurers and technology companies on site, then presented the findings to their boards.

Clinical precision in healthcare

Our healthcare programs are led by a physician trained in medicine and surgery. Controls are designed with clinicians, not against them.

Sourced, dated and independent

Every rule on this site links to the official text and shows when we last verified it. We are not affiliated with any authority.

Common questions

Does Oman's PDPL apply to companies outside Oman?

Yes. Since 7 September 2026, Article 2, as replaced by Royal Decree 68/2026, expressly applies the law to the processing of personal data of natural persons in Oman, whether the processing happens inside or outside Oman. Read what changed.

Is consent still required?

Consent remains the default. Explicit consent was already required in 2022. What changed is that the controller must now prove explicit consent instead of written consent, consent also covers any change of purpose, and the request must carry set contents. Article 10 bis lists four situations where it is not needed: a legal obligation or court order, data available to the public, a vital interest when the person cannot be contacted, and a contract with the person that shows the processing complies with the law. Read the consent guide.

How fast must a personal data breach be reported?

The controller must notify the Ministry within 72 hours of becoming aware of a breach that poses a risk to the rights of the people concerned, under Article 30 of the Executive Regulations. Those people must be told within 72 hours where the breach would result in serious harm or high risk, under Article 32 of the Executive Regulations. Read the breach guide.

Do we need a data protection officer?

Yes. Article 20 of the law requires every controller to identify a personal data protection officer. There is no size threshold. The Executive Regulations set the officer's qualifications and duties.

Is AccuSights approved by the Ministry?

No. AccuSights is an independent firm and is not affiliated with, or endorsed by, any Omani authority. The Ministry decides whether you meet the law. We help you understand it, prepare, and stay ready.

Ten minutes to know exactly where you stand

Tell us what you do and what data you hold. We will show you what the amended Personal Data Protection Law asks of you, where the gaps usually are, and the shortest route to ready. No slides, no pitch.