Framework · MTCIT

The Executive Regulations of Oman's Personal Data Protection Law

Ministerial Decision 34/2024 turns the law into procedure. These are the provisions most organizations meet first, and the places where the regulations have not yet caught up with the 2026 amendment.

Last verified against official sources: 26 September 2026

The regulations at a glance

Instrument
Ministerial Decision 34/2024
In force
5 February 2024
Compliance period
Extended by Ministerial Decision 6/2025; ended 5 February 2026
Breach notice to the Ministry
Within 72 hours (Article 30 of the Executive Regulations)
Breach notice to data subjects
Within 72 hours where serious harm or high risk is likely (Article 32 of the Executive Regulations)
Rights requests
Free of charge; answer within 45 days (Article 16 of the Executive Regulations)
Sensitive data permits
Decision within 45 days of a complete application; no answer means rejection; appeal to the Minister within 60 days; valid up to 5 years

Breach notification

The controller must notify the Ministry's competent department within 72 hours of becoming aware of a breach that poses a risk to the rights of data subjects. Where the breach would result in serious harm or high risk to a data subject, the controller must also notify that person within 72 hours. Read the breach guide.

Requests from data subjects

Requests to exercise the rights in Article 11 of the law are free. The controller must answer within 45 days of receiving the request. The data subject may ask for processing to stop until the request is decided, and any refusal must give reasons within the same period (Articles 16 and 17 of the regulations).

Permits for sensitive data

The regulations set the procedure for the Ministry permit that Article 5 of the law requires for sensitive data. The Ministry decides within 45 days of receiving all the required data and documents, and no answer within that period means the application is rejected. The applicant may appeal to the Minister within 60 days. A permit is valid for up to 5 years. Read the permits guide.

The data protection officer

The controller must designate a personal data protection officer. Articles 34 to 36 of the regulations set the officer's qualifications and duties and require the controller to make the officer's contact details available.

Where the regulations lag the amended law

As of our last check on 26 September 2026, no amendment to Ministerial Decision 34/2024 had been published to match Royal Decree 68/2026. Two new provisions of the law refer to controls the regulation will set: the minister-specified cases in Article 5 bis(3) and human review of automated decisions in Article 14. Article 22 of the law now requires explicit consent for commercial marketing, but Article 22 of the regulations still says written consent. Complaint handling is not a gap: the regulations already set the period for deciding a complaint, and a complaint left undecided in that period counts as rejected (Article 43 of the regulations).

Until the regulations are updated, read them together with the amended law. Under the amending decree, anything contrary to the amendments is repealed, so a provision of the regulations built on the original wording of the law, such as the written marketing consent in Article 22 of the regulations, should not be relied on without advice.

How AccuSights helps

We turn the regulations into procedures your team can run: a breach runbook, a request log with the 45 days clock, permit applications and the officer's charter. We track the regulations and tell you when the Ministry updates them. See our services.

AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the Ministry of Transport, Communications and Information Technology, the Cyber Defence Centre, OCERT, the Central Bank of Oman or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. English quotations of Omani law are translations; the Arabic text published in the Official Gazette is binding.

Sources

  1. MTCIT, Executive Regulations of the Personal Data Protection Law (Ministerial Decision 34/2024) (opens in a new tab)
  2. MTCIT, Executive Regulations, official English text (Official Gazette 1531) (opens in a new tab)
  3. Dentons, Oman PDPL grace period extension (23 January 2025) (opens in a new tab)
  4. Royal Decree 68/2026 amending the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
  5. Baker McKenzie, Oman: strengthening its data protection regime (22 September 2026) (opens in a new tab)

Ten minutes to know exactly where you stand

Tell us what you do and what data you hold. We will show you what the amended Personal Data Protection Law asks of you, where the gaps usually are, and the shortest route to ready. No slides, no pitch.