Reference
Which Omani rules apply to your sector
A starting map. The Personal Data Protection Law applies across every sector; sector authorities add their own requirements on top.
Sector by sector
Banks, insurers and financial institutions
CBO-licensed institutions carry the central bank's cyber requirements alongside the data protection law. The Financial Services Authority regulates the capital market and the insurance sector.
What applies
- The CBO Cyber Security and Resilience Framework, Circular BM 1194, for banks, finance and leasing companies, money exchange companies and payment service providers.
- The Financial Services Authority, which replaced the Capital Market Authority under Royal Decree 20/2024, for capital market firms and insurers.
- Insurers that process health data need an MTCIT permit under Article 5.
- The Personal Data Protection Law for customer and employee data, including explicit consent and the 72 hours breach rules.
- PCI DSS wherever cardholder data is stored, processed or transmitted.
Healthcare providers
The Ministry of Health licenses healthcare providers. For data protection, health data needs an MTCIT permit, and the 2026 amendment widened what counts as health data.
What applies
- A permit before processing health data, under Article 5. See the permits guide.
- The new definition covers data about the provision of health care that reveals health status.
- Breach notices within 72 hours, and a data protection officer for every controller.
Government entities
Units of the state's administrative apparatus and other public legal persons implementing the competences prescribed to them by law are excluded from the data protection law for that processing, but national cybersecurity expectations apply.
What applies
- Article 3 excludes processing by units of the state's administrative apparatus and other public legal persons implementing the competences prescribed to them by law.
- The Cyber Defence Centre, established by Royal Decree 64/2020, is the national reference for cybersecurity and the place to report a cyber incident.
- Affiliated companies and contractors should check whether their own processing falls outside that exclusion.
Telecommunications
Operators answer to the TRA for licensing and to the data protection law for subscriber data.
What applies
- TRA licensing and regulatory requirements for operators.
- The Personal Data Protection Law for subscriber data, including breach notices within 72 hours.
Technology, cloud and AI providers
Providers often act as processors for their clients and increasingly make automated decisions about people.
What applies
- Processor obligations under the Personal Data Protection Law when you handle client data.
- Article 14: privacy safeguards for automated processing and human review of automated decisions on objection.
- Transfers outside Oman only under the controls in the Executive Regulations, including the data subject's explicit consent under Article 37 of the regulations, and Cyber Defence Centre approval before sensitive personal data goes abroad.
Retail and e-commerce
The main obligations come from customer personal data, marketing and card payments.
What applies
- Explicit consent before commercial marketing, under Article 22.
- Consent requests that meet the new Article 10, and erasure when the purpose ends.
- PCI DSS for cardholder data.
Foreign companies serving people in Oman
Since 7 September 2026, the law reaches processing of personal data of people in Oman wherever it takes place.
What applies
- Article 2 brings you into scope even without an Omani entity.
- Transfers out of Oman need the data subject's explicit consent under Article 37 of the Executive Regulations, unless an international agreement obligation applies or the data is anonymised, and sensitive personal data needs Cyber Defence Centre approval first.
- Name a data protection officer, meet the consent rules and prepare for the 72 hours breach notices.
- Read what changed in 2026.
Last verified against official sources: 26 September 2026
Sources
- Royal Decree 6/2022 issuing the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
- Royal Decree 68/2026 amending the Personal Data Protection Law (English translation, decree.om) (opens in a new tab)
- MTCIT, Executive Regulations, official English text (Official Gazette 1531) (opens in a new tab)
- MTCIT, personal data protection (opens in a new tab)
- Central Bank of Oman, Cyber Security and Resilience Framework (CS&RF) (opens in a new tab)
- Royal Decree 20/2024 establishing the Financial Services Authority (English translation, decree.om) (opens in a new tab)
- Cyber Defence Centre (opens in a new tab)
- PCI Security Standards Council, PCI DSS (opens in a new tab)
Ten minutes to know exactly where you stand
Tell us what you do and what data you hold. We will show you what the amended Personal Data Protection Law asks of you, where the gaps usually are, and the shortest route to ready. No slides, no pitch.