Reference

Who regulates what in Oman

Seven bodies shape cybersecurity and data protection in Oman. Knowing which one governs which question saves weeks.

The authorities

Ministry of Transport, Communications and Information Technology (MTCIT)

The regulator for the Personal Data Protection Law. Issues its controls and procedures, verifies compliance, receives complaints and breach notifications, grants permits for sensitive data, and approves external auditors.

Applies to: Every controller and processor of personal data of people in Oman, wherever the processing happens.

mtcit.gov.om (opens in a new tab)

Cyber Defence Centre

The national reference for protecting Oman's interests in cyberspace, established by Royal Decree 64/2020, and the place to report a cyber incident. The Personal Data Protection Law applies without prejudice to its competences.

Applies to: National cybersecurity and the reporting of cyber incidents. The data protection law applies without prejudice to its competences, and MTCIT's guidance says sensitive personal data needs the Centre's approval before it is transferred abroad.

cdc.gov.om/en (opens in a new tab)

National Centre for Information Safety (OCERT)

The National Centre for Information Safety, operating under the Ministry. Publishes security advisories and runs digital trust services and the national cybersecurity industry programme.

Applies to: Security advisories, digital trust services and the national cybersecurity industry programme.

www.cert.gov.om (opens in a new tab)

Central Bank of Oman (CBO)

Licenses and supervises banks, finance and leasing companies, money exchange companies and payment service providers, and sets their Cyber Security and Resilience Framework.

Applies to: Banks operating in Oman and their foreign branches, finance and leasing companies, money exchange companies and payment service providers licensed by the Central Bank of Oman.

cbo.gov.om (opens in a new tab)

Financial Services Authority (FSA)

Regulates the capital market and the insurance sector. It replaced the Capital Market Authority under Royal Decree 20/2024.

Applies to: Capital market firms and insurance companies.

fsa.gov.om (opens in a new tab)

Ministry of Health

Licenses and regulates healthcare providers and health services.

Applies to: Healthcare providers and health services.

www.moh.gov.om (opens in a new tab)

Telecommunications Regulatory Authority (TRA)

Regulates telecommunications operators and internet service providers.

Applies to: Telecommunications operators and service providers.

www.tra.gov.om (opens in a new tab)

Quick answers

Who do I report a personal data breach to?

The Ministry of Transport, Communications and Information Technology, within 72 hours, under Article 30 of the Executive Regulations. Read the breach guide.

Who issues permits for sensitive data?

The Ministry, under Article 5 of the law. Read the permits guide.

Where do I report a cyber incident?

To the Cyber Defence Centre. If the incident is also a personal data breach, the Ministry must be notified within 72 hours as well.

Does the CBO framework apply to my fintech?

It applies to banks, finance and leasing companies, money exchange companies and payment service providers licensed by the Central Bank of Oman. Applicants to the CBO FinTech sandbox are also pointed to it: the sandbox application form lists it under General Guidelines. Read about the framework.

Ten minutes to know exactly where you stand

Tell us what you do and what data you hold. We will show you what the amended Personal Data Protection Law asks of you, where the gaps usually are, and the shortest route to ready. No slides, no pitch.