Guide · Executive Regulations

Personal data breach notification in Oman: the 72-hour rule

Two clocks, both 72 hours long: one for the Ministry, one for the people affected. What triggers each, and a response process that fits.

Last verified against official sources: 26 September 2026

The rule at a glance

Who notifies
The controller
The Ministry
Within 72 hours of becoming aware, if the breach poses a risk to the rights of data subjects (Article 30 of the Executive Regulations)
The people affected
Within 72 hours of becoming aware, if the breach would result in serious harm or high risk to them (Article 32 of the Executive Regulations)
Ministry direction
The Ministry may also direct that data subjects be notified
Base duty
Article 19 of the law

Both clocks start at awareness

Each 72 hours runs from when you become aware of the breach, not from when your investigation ends. You will rarely have every fact in time. Decide early, notify on time, and update as you learn more.

The two tests differ. The Ministry must hear about any breach that poses a risk to data subjects' rights. Individuals must hear about it when the harm is serious or the risk is high. Record your reasoning for both decisions.

A response process that fits

  1. Record the moment of awareness. Log the date and time. Both clocks start there.
  2. Contain and preserve. Stop the exposure and keep the logs and evidence.
  3. Assemble the team. Your data protection officer, legal, IT and the business owner of the affected data.
  4. Apply both tests. Is there a risk to data subjects' rights? Is serious harm or high risk likely for individuals? Write down the reasoning.
  5. Notify the Ministry within 72 hours where the first test is met.
  6. Notify the people affected within 72 hours where the second test is met, in language they can act on.
  7. Close the loop. Record the incident, decisions and fixes, and feed the lessons back into your controls.

Rehearse it before you need it

Run a tabletop exercise at least once a year: a realistic scenario, the real team, and a clock. Most gaps show up in the first hour, when nobody is sure who decides.

How AccuSights helps

We write the runbook with you, name the owners, rehearse it, and map it to the incident rules of any other framework you follow, so one process serves them all. See our services.

AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the Ministry of Transport, Communications and Information Technology, the Cyber Defence Centre, OCERT, the Central Bank of Oman or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. English quotations of Omani law are translations; the Arabic text published in the Official Gazette is binding.

Sources

  1. MTCIT, Executive Regulations, official English text (Official Gazette 1531) (opens in a new tab)
  2. MTCIT, Executive Regulations of the Personal Data Protection Law (Ministerial Decision 34/2024) (opens in a new tab)
  3. Royal Decree 6/2022 issuing the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)

Ten minutes to know exactly where you stand

Tell us what you do and what data you hold. We will show you what the amended Personal Data Protection Law asks of you, where the gaps usually are, and the shortest route to ready. No slides, no pitch.