Guide · Royal Decree 68/2026

What changed in Oman's data protection law on 7 September 2026

Royal Decree 68/2026 rewrote large parts of the Personal Data Protection Law. It took effect the day after publication, with no transition period. Here is every change and what it means for you.

Last verified against official sources: 26 September 2026

The amendment at a glance

Instrument
Royal Decree 68/2026, amending Royal Decree 6/2022
Issued
3 September 2026
Published
Official Gazette issue 1664, 6 September 2026
In force
7 September 2026
Transition period
None
Executive Regulations
Not yet amended to match, as of 26 September 2026
Every change, article by article
ArticleWhat changedWhat it means for you
Article 1, definitionsHealth data now includes data about the provision of health care that reveals health status. The controller is a legal person, and the old reference to determining the purpose and means of processing is removed. Automated processing is defined.More data counts as health data and may need a permit. Review what you hold about care and treatment.
Article 2, scopeThe law applies to processing of personal data of natural persons in Oman, inside or outside Oman.Foreign companies serving people in Oman are in scope with no local entity.
Article 3, exclusionsLegal obligation, vital interest, contract and public data are no longer outside the law. Personal or family processing is excluded only if the data is not published.Processing you once treated as out of scope now carries every duty in the law.
Article 5 bis, newExceptions to the permit rule for employee data within internal operations, security cameras required by competent entities, and cases the minister sets. Employee data may go to third parties only with the employee's written consent.Set clear internal-use rules for staff data and record the security basis for CCTV.
Article 7, the MinistryLicensing of service providers that evaluate compliance becomes approval of external auditors that evaluate compliance. Preparing guidance forms, preparing and publishing periodic reports on the Ministry's own activity, and keeping the register of controllers and processors are no longer listed among the Ministry's duties.If the Ministry requests an external audit, the auditor must be Ministry-approved.
Article 10, consentExplicit consent was already required in 2022. The controller must now prove explicit consent (previously written consent), and consent also covers a change of purpose. The request must include (a) the controller and any processor, (b) how to contact the data protection officer, (c) the objectives and nature of processing and (d) any other information needed to meet the conditions of the law.Rewrite every consent request and keep proof of each consent.
Article 10 bis, newFour cases without consent: legal obligation, public data, vital interest when the person cannot be contacted, and a contract that shows compliant processing.Add compliance evidence to contracts you rely on. There is no legitimate interests ground.
Article 14, automated processingControllers and processors using automated processing must protect privacy and avoid harm. Data subjects may object to automated decisions, which then need human review. The old prior written notice in Article 14 is removed; part of its content (the controller and processor, the officer's contact details and the purpose) now sits in the Article 10 consent request.Inventory automated and AI-assisted decisions and set up a human review route.
Article 15, erasureErase personal data as soon as the purpose ends, except for an existing dispute or a legal obligation. This replaces the old Article 15 duty to follow the controls and procedures the Ministry sets.Replace open-ended retention with purpose-based deletion.
Article 22, marketingCommercial marketing needs explicit consent, where the original text said written.Update marketing opt-in wording and records.
Articles 25 and 27, offencesBoth offence provisions are replaced. They now attach to the new Article 10 consent duty and to Articles 13 and 14, including automated processing.Treat consent records, processing controls and automated-decision safeguards as enforcement priorities.

What to update first

  1. Consent requests. Every form, app screen and contract that collects consent must now carry the Article 10 contents, and you must be able to prove each consent.
  2. Scope. If you process data of people in Oman from abroad, you are now in scope. Name a data protection officer and build the processes.
  3. Legal bases. Map each activity to consent or one of the four Article 10 bis cases. Where you rely on a contract, add the compliance evidence to it.
  4. Automated decisions. List every decision a system makes about people and set up a human review route for objections.
  5. Retention. Delete data when its purpose ends, and document the dispute or legal obligation wherever you keep it longer.
  6. Health data. Recheck whether care-related data you hold now counts as health data that needs a permit.

What did not change

The sensitive data permit in Article 5, the cross-border transfer rule in Article 23, the requirement for every controller to identify a data protection officer in Article 20, and the breach duty in Article 19 remain as they were. The 72 hours deadlines in the Executive Regulations still apply.

About the text. The English wording on this page follows a translation of the decree. The Arabic text in Official Gazette issue 1664 is binding. Before you rely on exact wording, check it against the Arabic.

How AccuSights helps

A focused review against the amended law: we test your consent requests, contracts, automated decisions and retention rules, and give you a ranked list of fixes. See our services.

AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the Ministry of Transport, Communications and Information Technology, the Cyber Defence Centre, OCERT, the Central Bank of Oman or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. English quotations of Omani law are translations; the Arabic text published in the Official Gazette is binding.

Sources

  1. Royal Decree 68/2026 amending the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
  2. MTCIT, Royal Decree 68/2026 listing (opens in a new tab)
  3. Baker McKenzie, Oman: strengthening its data protection regime (22 September 2026) (opens in a new tab)
  4. Royal Decree 6/2022 issuing the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
  5. MTCIT, Executive Regulations of the Personal Data Protection Law (Ministerial Decision 34/2024) (opens in a new tab)

Ten minutes to know exactly where you stand

Tell us what you do and what data you hold. We will show you what the amended Personal Data Protection Law asks of you, where the gaps usually are, and the shortest route to ready. No slides, no pitch.