Reference
Who regulates what in Oman
Seven bodies shape cybersecurity and data protection in Oman. Knowing which one governs which question saves weeks.
The authorities
Ministry of Transport, Communications and Information Technology (MTCIT)
The regulator for the Personal Data Protection Law. Issues its controls and procedures, verifies compliance, receives complaints and breach notifications, grants permits for sensitive data, and approves external auditors.
Applies to: Every controller and processor of personal data of people in Oman, wherever the processing happens.
Cyber Defence Centre
The national reference for protecting Oman's interests in cyberspace, established by Royal Decree 64/2020, and the place to report a cyber incident. The Personal Data Protection Law applies without prejudice to its competences.
Applies to: National cybersecurity and the reporting of cyber incidents. The data protection law applies without prejudice to its competences, and MTCIT's guidance says sensitive personal data needs the Centre's approval before it is transferred abroad.
National Centre for Information Safety (OCERT)
The National Centre for Information Safety, operating under the Ministry. Publishes security advisories and runs digital trust services and the national cybersecurity industry programme.
Applies to: Security advisories, digital trust services and the national cybersecurity industry programme.
Central Bank of Oman (CBO)
Licenses and supervises banks, finance and leasing companies, money exchange companies and payment service providers, and sets their Cyber Security and Resilience Framework.
Applies to: Banks operating in Oman and their foreign branches, finance and leasing companies, money exchange companies and payment service providers licensed by the Central Bank of Oman.
Financial Services Authority (FSA)
Regulates the capital market and the insurance sector. It replaced the Capital Market Authority under Royal Decree 20/2024.
Applies to: Capital market firms and insurance companies.
Ministry of Health
Licenses and regulates healthcare providers and health services.
Applies to: Healthcare providers and health services.
Telecommunications Regulatory Authority (TRA)
Regulates telecommunications operators and internet service providers.
Applies to: Telecommunications operators and service providers.
Quick answers
Who do I report a personal data breach to?
The Ministry of Transport, Communications and Information Technology, within 72 hours, under Article 30 of the Executive Regulations. Read the breach guide.
Who issues permits for sensitive data?
The Ministry, under Article 5 of the law. Read the permits guide.
Where do I report a cyber incident?
To the Cyber Defence Centre. If the incident is also a personal data breach, the Ministry must be notified within 72 hours as well.
Does the CBO framework apply to my fintech?
It applies to banks, finance and leasing companies, money exchange companies and payment service providers licensed by the Central Bank of Oman. Applicants to the CBO FinTech sandbox are also pointed to it: the sandbox application form lists it under General Guidelines. Read about the framework.
Last verified against official sources: 26 September 2026
Sources
- MTCIT, personal data protection (opens in a new tab)
- Cyber Defence Centre (opens in a new tab)
- Oman National CERT (opens in a new tab)
- Central Bank of Oman, Cyber Security and Resilience Framework (CS&RF) (opens in a new tab)
- Central Bank of Oman, FinTech Regulatory Sandbox application (opens in a new tab)
- Royal Decree 20/2024 establishing the Financial Services Authority (English translation, decree.om) (opens in a new tab)
Ten minutes to know exactly where you stand
Tell us what you do and what data you hold. We will show you what the amended Personal Data Protection Law asks of you, where the gaps usually are, and the shortest route to ready. No slides, no pitch.