Checklist · Personal Data Protection Law

Oman data protection readiness checklist

Twelve checks against the law as amended and its Executive Regulations. If you cannot answer yes to one, that is where to start.

Last verified against official sources: 26 September 2026

Twelve readiness checks
CheckWhat good looks likeBasis
ScopeYou know every activity that processes data of people in Oman, including processing done abroad.Article 2
Legal basisEach activity relies on explicit consent or one named Article 10 bis case.Articles 10 and 10 bis
Consent requestsEvery request names the controller and processor, the officer's contact route, and the objectives and nature of processing.Article 10
Proof of consentYou can show who consented, to what, when and how.Article 10
ContractsContracts you rely on for processing contain evidence that it complies with the law.Article 10 bis
Sensitive dataYou hold a Ministry permit, or a documented Article 5 bis basis, for every sensitive category you process.Articles 5 and 5 bis
OfficerA personal data protection officer is named and the contact details are available.Article 20
Rights requestsRequests are logged and answered within 45 days.Article 16 of the Executive Regulations
Automated decisionsEvery automated decision about people has a human review route for objections.Article 14
RetentionData is erased when its purpose ends, unless a dispute or legal obligation is documented.Article 15
Breach responseA rehearsed process meets both 72 hours deadlines.Article 30 of the Executive Regulations; Article 32 of the Executive Regulations
TransfersTransfers outside Oman follow the controls in the Executive Regulations: the data subject's explicit consent unless an international agreement obligation applies or the data is anonymised, an adequacy assessment ready if the Ministry asks for it, and Cyber Defence Centre approval before sensitive data goes abroad.Article 23; Articles 37 to 40 of the Executive Regulations

How AccuSights helps

The Cybersecurity and Data Protection Assessment runs these checks against evidence, not interviews alone, and ranks the gaps by risk. See our services.

AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the Ministry of Transport, Communications and Information Technology, the Cyber Defence Centre, OCERT, the Central Bank of Oman or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. English quotations of Omani law are translations; the Arabic text published in the Official Gazette is binding.

Sources

  1. Royal Decree 6/2022 issuing the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
  2. Royal Decree 68/2026 amending the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
  3. MTCIT, Executive Regulations, official English text (Official Gazette 1531) (opens in a new tab)
  4. MTCIT, personal data protection (opens in a new tab)

Ten minutes to know exactly where you stand

Tell us what you do and what data you hold. We will show you what the amended Personal Data Protection Law asks of you, where the gaps usually are, and the shortest route to ready. No slides, no pitch.