Guide · Executive Regulations
Personal data breach notification in Oman: the 72-hour rule
Two clocks, both 72 hours long: one for the Ministry, one for the people affected. What triggers each, and a response process that fits.
Last verified against official sources: 26 September 2026
The rule at a glance
- Who notifies
- The controller
- The Ministry
- Within 72 hours of becoming aware, if the breach poses a risk to the rights of data subjects (Article 30 of the Executive Regulations)
- The people affected
- Within 72 hours of becoming aware, if the breach would result in serious harm or high risk to them (Article 32 of the Executive Regulations)
- Ministry direction
- The Ministry may also direct that data subjects be notified
- Base duty
- Article 19 of the law
Both clocks start at awareness
Each 72 hours runs from when you become aware of the breach, not from when your investigation ends. You will rarely have every fact in time. Decide early, notify on time, and update as you learn more.
The two tests differ. The Ministry must hear about any breach that poses a risk to data subjects' rights. Individuals must hear about it when the harm is serious or the risk is high. Record your reasoning for both decisions.
A response process that fits
- Record the moment of awareness. Log the date and time. Both clocks start there.
- Contain and preserve. Stop the exposure and keep the logs and evidence.
- Assemble the team. Your data protection officer, legal, IT and the business owner of the affected data.
- Apply both tests. Is there a risk to data subjects' rights? Is serious harm or high risk likely for individuals? Write down the reasoning.
- Notify the Ministry within 72 hours where the first test is met.
- Notify the people affected within 72 hours where the second test is met, in language they can act on.
- Close the loop. Record the incident, decisions and fixes, and feed the lessons back into your controls.
Rehearse it before you need it
Run a tabletop exercise at least once a year: a realistic scenario, the real team, and a clock. Most gaps show up in the first hour, when nobody is sure who decides.
How AccuSights helps
We write the runbook with you, name the owners, rehearse it, and map it to the incident rules of any other framework you follow, so one process serves them all. See our services.
AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the Ministry of Transport, Communications and Information Technology, the Cyber Defence Centre, OCERT, the Central Bank of Oman or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. English quotations of Omani law are translations; the Arabic text published in the Official Gazette is binding.
Sources
- MTCIT, Executive Regulations, official English text (Official Gazette 1531) (opens in a new tab)
- MTCIT, Executive Regulations of the Personal Data Protection Law (Ministerial Decision 34/2024) (opens in a new tab)
- Royal Decree 6/2022 issuing the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)