Checklist · Personal Data Protection Law
Oman data protection readiness checklist
Twelve checks against the law as amended and its Executive Regulations. If you cannot answer yes to one, that is where to start.
Last verified against official sources: 26 September 2026
| Check | What good looks like | Basis |
|---|---|---|
| Scope | You know every activity that processes data of people in Oman, including processing done abroad. | Article 2 |
| Legal basis | Each activity relies on explicit consent or one named Article 10 bis case. | Articles 10 and 10 bis |
| Consent requests | Every request names the controller and processor, the officer's contact route, and the objectives and nature of processing. | Article 10 |
| Proof of consent | You can show who consented, to what, when and how. | Article 10 |
| Contracts | Contracts you rely on for processing contain evidence that it complies with the law. | Article 10 bis |
| Sensitive data | You hold a Ministry permit, or a documented Article 5 bis basis, for every sensitive category you process. | Articles 5 and 5 bis |
| Officer | A personal data protection officer is named and the contact details are available. | Article 20 |
| Rights requests | Requests are logged and answered within 45 days. | Article 16 of the Executive Regulations |
| Automated decisions | Every automated decision about people has a human review route for objections. | Article 14 |
| Retention | Data is erased when its purpose ends, unless a dispute or legal obligation is documented. | Article 15 |
| Breach response | A rehearsed process meets both 72 hours deadlines. | Article 30 of the Executive Regulations; Article 32 of the Executive Regulations |
| Transfers | Transfers outside Oman follow the controls in the Executive Regulations: the data subject's explicit consent unless an international agreement obligation applies or the data is anonymised, an adequacy assessment ready if the Ministry asks for it, and Cyber Defence Centre approval before sensitive data goes abroad. | Article 23; Articles 37 to 40 of the Executive Regulations |
How AccuSights helps
The Cybersecurity and Data Protection Assessment runs these checks against evidence, not interviews alone, and ranks the gaps by risk. See our services.
AccuSights is an independent cybersecurity and compliance firm. We are not affiliated with, endorsed by, or acting for the Ministry of Transport, Communications and Information Technology, the Cyber Defence Centre, OCERT, the Central Bank of Oman or any other authority. This site is general information, not legal advice. The regulator has the final say on what a rule requires and whether you meet it; we help you interpret, scope, close gaps and stay ready. English quotations of Omani law are translations; the Arabic text published in the Official Gazette is binding.
Sources
- Royal Decree 6/2022 issuing the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
- Royal Decree 68/2026 amending the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
- MTCIT, Executive Regulations, official English text (Official Gazette 1531) (opens in a new tab)
- MTCIT, personal data protection (opens in a new tab)