Guide · Royal Decree 68/2026
What changed in Oman's data protection law on 7 September 2026
Royal Decree 68/2026 rewrote large parts of the Personal Data Protection Law. It took effect the day after publication, with no transition period. Here is every change and what it means for you.
Last verified against official sources: 26 September 2026
The amendment at a glance
- Instrument
- Royal Decree 68/2026, amending Royal Decree 6/2022
- Issued
- 3 September 2026
- Published
- Official Gazette issue 1664, 6 September 2026
- In force
- 7 September 2026
- Transition period
- None
- Executive Regulations
- Not yet amended to match, as of 26 September 2026
| Article | What changed | What it means for you |
|---|---|---|
| Article 1, definitions | Health data now includes data about the provision of health care that reveals health status. The controller is a legal person, and the old reference to determining the purpose and means of processing is removed. Automated processing is defined. | More data counts as health data and may need a permit. Review what you hold about care and treatment. |
| Article 2, scope | The law applies to processing of personal data of natural persons in Oman, inside or outside Oman. | Foreign companies serving people in Oman are in scope with no local entity. |
| Article 3, exclusions | Legal obligation, vital interest, contract and public data are no longer outside the law. Personal or family processing is excluded only if the data is not published. | Processing you once treated as out of scope now carries every duty in the law. |
| Article 5 bis, new | Exceptions to the permit rule for employee data within internal operations, security cameras required by competent entities, and cases the minister sets. Employee data may go to third parties only with the employee's written consent. | Set clear internal-use rules for staff data and record the security basis for CCTV. |
| Article 7, the Ministry | Licensing of service providers that evaluate compliance becomes approval of external auditors that evaluate compliance. Preparing guidance forms, preparing and publishing periodic reports on the Ministry's own activity, and keeping the register of controllers and processors are no longer listed among the Ministry's duties. | If the Ministry requests an external audit, the auditor must be Ministry-approved. |
| Article 10, consent | Explicit consent was already required in 2022. The controller must now prove explicit consent (previously written consent), and consent also covers a change of purpose. The request must include (a) the controller and any processor, (b) how to contact the data protection officer, (c) the objectives and nature of processing and (d) any other information needed to meet the conditions of the law. | Rewrite every consent request and keep proof of each consent. |
| Article 10 bis, new | Four cases without consent: legal obligation, public data, vital interest when the person cannot be contacted, and a contract that shows compliant processing. | Add compliance evidence to contracts you rely on. There is no legitimate interests ground. |
| Article 14, automated processing | Controllers and processors using automated processing must protect privacy and avoid harm. Data subjects may object to automated decisions, which then need human review. The old prior written notice in Article 14 is removed; part of its content (the controller and processor, the officer's contact details and the purpose) now sits in the Article 10 consent request. | Inventory automated and AI-assisted decisions and set up a human review route. |
| Article 15, erasure | Erase personal data as soon as the purpose ends, except for an existing dispute or a legal obligation. This replaces the old Article 15 duty to follow the controls and procedures the Ministry sets. | Replace open-ended retention with purpose-based deletion. |
| Article 22, marketing | Commercial marketing needs explicit consent, where the original text said written. | Update marketing opt-in wording and records. |
| Articles 25 and 27, offences | Both offence provisions are replaced. They now attach to the new Article 10 consent duty and to Articles 13 and 14, including automated processing. | Treat consent records, processing controls and automated-decision safeguards as enforcement priorities. |
What to update first
- Consent requests. Every form, app screen and contract that collects consent must now carry the Article 10 contents, and you must be able to prove each consent.
- Scope. If you process data of people in Oman from abroad, you are now in scope. Name a data protection officer and build the processes.
- Legal bases. Map each activity to consent or one of the four Article 10 bis cases. Where you rely on a contract, add the compliance evidence to it.
- Automated decisions. List every decision a system makes about people and set up a human review route for objections.
- Retention. Delete data when its purpose ends, and document the dispute or legal obligation wherever you keep it longer.
- Health data. Recheck whether care-related data you hold now counts as health data that needs a permit.
What did not change
The sensitive data permit in Article 5, the cross-border transfer rule in Article 23, the requirement for every controller to identify a data protection officer in Article 20, and the breach duty in Article 19 remain as they were. The 72 hours deadlines in the Executive Regulations still apply.
About the text. The English wording on this page follows a translation of the decree. The Arabic text in Official Gazette issue 1664 is binding. Before you rely on exact wording, check it against the Arabic.
How AccuSights helps
A focused review against the amended law: we test your consent requests, contracts, automated decisions and retention rules, and give you a ranked list of fixes. See our services.
AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the Ministry of Transport, Communications and Information Technology, the Cyber Defence Centre, OCERT, the Central Bank of Oman or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. English quotations of Omani law are translations; the Arabic text published in the Official Gazette is binding.
Sources
- Royal Decree 68/2026 amending the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
- MTCIT, Royal Decree 68/2026 listing (opens in a new tab)
- Baker McKenzie, Oman: strengthening its data protection regime (22 September 2026) (opens in a new tab)
- Royal Decree 6/2022 issuing the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
- MTCIT, Executive Regulations of the Personal Data Protection Law (Ministerial Decision 34/2024) (opens in a new tab)