Guide · Personal Data Protection Law
Explicit consent and data subject rights in Oman
Since 7 September 2026, the controller must prove explicit consent instead of written consent, and every consent request must carry set contents. There are exactly four ways to process without consent. Here is how to get consent right and how to answer the people who ask about their data.
Last verified against official sources: 26 September 2026
What a valid consent request contains
Under Article 10, as replaced, the request must be clear, explicit and understandable, and must include:
- the details of the controller and of the processor, if there is one;
- how to contact the personal data protection officer;
- the objectives and nature of the processing;
- any other information needed to meet the conditions of the law.
The controller must be able to prove the consent. Keep a record of what the person saw, when they agreed and how. Consent is also needed before you use data for a new purpose.
The four cases that need no consent
- A legal obligation imposed by a law, judgment, order or court decision.
- Data available to the public in a manner that does not contravene the law.
- A vital interest of the data subject, when they cannot be contacted.
- A contract with the data subject that includes evidence the processing complies with the law.
Everything else needs consent. Processing under these four cases is still inside the law, so every other duty applies to it.
Answering rights requests
Requests to exercise the rights in Article 11 are free. Under Article 16 of the Executive Regulations, you must answer within 45 days of receiving the request. The data subject may ask you to stop processing until you decide, and a refusal must give reasons within the same period.
- Log every request with the date it arrived.
- Verify the requester's identity in proportion to the request.
- Find the data across systems and processors.
- Answer, or refuse with reasons, within 45 days.
- Keep the record.
Automated decisions
Article 14, as replaced, requires controllers and processors that use automated processing to protect privacy and confidentiality and not to harm the data subject. The data subject may object to a decision that results from automated processing, and the controller or processor must bring in a human to review it, under controls the regulation will set.
In practice: list the decisions your systems make about people, explain them in your consent requests, and set up a route for objections with a named reviewer.
Marketing
Commercial advertising and marketing need the data subject's explicit consent before you send them, under Article 22. Keep consent for marketing separate from consent for the service.
How AccuSights helps
We review your consent requests and contracts against the new Article 10, set up the request log and the 45 days clock, and design the human review route for automated decisions. See our services.
AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the Ministry of Transport, Communications and Information Technology, the Cyber Defence Centre, OCERT, the Central Bank of Oman or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. English quotations of Omani law are translations; the Arabic text published in the Official Gazette is binding.
Sources
- Royal Decree 68/2026 amending the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
- Royal Decree 6/2022 issuing the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
- MTCIT, Executive Regulations, official English text (Official Gazette 1531) (opens in a new tab)
- Baker McKenzie, Oman: strengthening its data protection regime (22 September 2026) (opens in a new tab)