Framework · MTCIT

Oman's Personal Data Protection Law, as amended

The law issued by Royal Decree 6/2022, read together with the changes made by Royal Decree 68/2026. What it requires, who it reaches, and where to begin.

Last verified against official sources: 26 September 2026

The law at a glance

Instrument
Royal Decree 6/2022, issued 9 February 2022
Amended by
Royal Decree 68/2026, in force 7 September 2026
Regulator
Ministry of Transport, Communications and Information Technology (MTCIT)
Detailed rules
Executive Regulations, Ministerial Decision 34/2024
Fully enforceable
Since 5 February 2026
Breach notice
72 hours, under the Executive Regulations
Official text
The Arabic text published in the Official Gazette is binding. English versions are translations.

Amended on 7 September 2026. This page reflects Royal Decree 68/2026. Pages elsewhere that describe written consent, a law whose reach outside Oman was not stated, or the original exclusions in Article 3 are out of date. See every change.

Who the law applies to

Article 2, as replaced, applies the law to the processing of personal data of natural persons in Oman, whether the processing is carried out inside or outside Oman. A company with no presence in Oman is in scope if it processes the personal data of people in Oman.

Article 3 lists what is excluded: protecting national security or the public interest, units of the state's administrative apparatus and other public legal persons implementing the competences prescribed to them by law, protecting the state's economic and financial interests, detecting or preventing a crime on a formal written request from investigating entities, purely personal or family processing unless the data is published, and certain research by authorised entities where no one can be identified in the published results.

The controller is now defined as the legal person that carries out the processing itself or entrusts it to a processor.

Personal data may be processed, or its purpose changed, only within a framework of transparency, honesty and respect for human dignity, and after the explicit consent of the data subject. The controller must be able to prove that consent. The consent request must be clear, explicit and understandable, and must state the controller and any processor, how to contact the data protection officer, and the objectives and nature of the processing.

Explicit consent was already required in the 2022 text. The amendment replaced the controller's duty to prove written consent with a duty to prove explicit consent, extended consent to any change of purpose, and set the contents of the request.

Article 10 bis allows processing without consent in four cases only:

  1. To implement a legal obligation imposed on the controller by a law, judgment, order or court decision.
  2. Where the data is available to the public in a manner that does not contravene the law.
  3. To protect a vital interest of the data subject when it is not possible to contact them.
  4. To perform a contract to which the data subject is a party, provided the contract includes evidence that the processing complies with the law.

There is no general legitimate interests ground. Marketing messages of a commercial nature need the data subject's explicit consent first, under Article 22.

Sensitive data needs a permit

Article 5 prohibits processing genetic data, biometric data, health data, racial origin, sex life, political or religious opinions, philosophical beliefs, criminal convictions or data relating to security measures, except with a permit from the Ministry. The amendment widened the definition of health data to include data about the provision of health care that reveals a person's health status.

New Article 5 bis creates exceptions for the data of people working for the controller, within its internal operations, for surveillance cameras required by the competent entities, and for other cases the minister specifies. Read the permits guide.

Rights of the data subject

Article 11 gives data subjects rights that include withdrawing consent, requesting correction or blocking, obtaining a copy of their data, having it transferred to another controller, requesting erasure, and being notified of a breach. Under Article 16 of the Executive Regulations, the controller must respond within 45 days of receiving a request.

Article 14, as replaced, adds a right to object to decisions that result from automated processing. The controller or processor must then bring in a human to review the decision.

What every controller must do

  • Put in place controls and procedures for processing, including risk assessment and technical and organizational measures (Article 13).
  • Erase personal data as soon as the purpose of processing ends, unless there is an existing dispute with the data subject or a legal obligation to keep it (Article 15).
  • Notify the Ministry and data subjects of breaches under the rules in the Executive Regulations (Article 19). Read the breach guide.
  • Identify a personal data protection officer. Every controller needs one (Article 20).
  • Obtain explicit consent before sending commercial marketing (Article 22).
  • Transfer personal data outside Oman only in line with the controls and procedures in the Executive Regulations, and never where the data was processed in violation of the law or the transfer would harm the data subject (Article 23). Article 37 of the Executive Regulations requires the data subject's explicit consent before a transfer, unless an obligation under an international agreement applies or the data is anonymised, and Articles 38 to 40 set an adequacy assessment the Ministry may ask to see. Article 23 applies without prejudice to the competences of the Cyber Defence Centre, and MTCIT's guidance says sensitive personal data needs the Centre's approval before it is transferred abroad.

The Ministry's role

Under Article 7, as replaced, the Ministry implements the law without prejudice to the competences of the Cyber Defence Centre. Its duties include issuing controls and procedures, verifying that controllers and processors comply, receiving and deciding complaints from data subjects, and approving the external auditors that evaluate compliance.

Where to start

  1. List your processing activities, including any that happen outside Oman for people in Oman.
  2. For each one, record whether it relies on consent or one of the four Article 10 bis cases.
  3. Rewrite consent requests to include every item the new Article 10 requires.
  4. Add compliance evidence to customer contracts you rely on for the contract exception.
  5. Check whether any processing involves sensitive data that needs a permit.
  6. Name your data protection officer and publish the contact details.
  7. Set retention rules so data is erased when its purpose ends.
  8. Rehearse the 72 hours breach process.

How AccuSights helps

We assess your processing against the law as amended, rewrite the consent and contract language, set up the officer role, and map the obligations to one control set shared with ISO/IEC 27001 and any sector rules you follow. See our services.

AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the Ministry of Transport, Communications and Information Technology, the Cyber Defence Centre, OCERT, the Central Bank of Oman or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. English quotations of Omani law are translations; the Arabic text published in the Official Gazette is binding.

Sources

  1. Royal Decree 6/2022 issuing the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
  2. Royal Decree 68/2026 amending the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
  3. MTCIT, Royal Decree 68/2026 listing (opens in a new tab)
  4. Baker McKenzie, Oman: strengthening its data protection regime (22 September 2026) (opens in a new tab)
  5. MTCIT, Executive Regulations, official English text (Official Gazette 1531) (opens in a new tab)
  6. MTCIT, personal data protection (opens in a new tab)
  7. Cyber Defence Centre (opens in a new tab)

Ten minutes to know exactly where you stand

Tell us what you do and what data you hold. We will show you what the amended Personal Data Protection Law asks of you, where the gaps usually are, and the shortest route to ready. No slides, no pitch.